The site is still being built — nothing on it is final yet.Write to hi@perly.io to hear things first, or wait for the announcement.
Last updated: September 2026
The short version. Perly keeps your account, the records you create, and the few things you switch on — alerts, plans, watched addresses, notifications. Everything it keeps is listed below, grouped by what it is for. No wallet connections, no seed phrases, no exchange API keys, no access to your funds. Nothing is sold, shared with advertisers, or used to train anything.
What Perly keeps.
Who else handles it. Perly runs on a few providers that process data on its behalf and for no one else: Supabase (the database and sign-in, in the EU), Vercel (hosting) and Resend (sign-in emails). Google or X take part only if you sign in with them, Telegram only if you connect a chat, and your browser's push service only if you turn notifications on. The addresses you watch are looked up in public blockchain explorers from our servers, not from your browser.
Who can read it. Your rows are protected by PostgreSQL row-level security, enabled and forced on every user-owned table. A query made from any other account returns nothing — not an error, nothing. Data is encrypted in transit and at rest, and your password is stored only as a hash, so nobody at Perly can read it or sign in as you.
What we can never reach. Perly holds no wallet connection, no seed phrase, no private keys and no exchange API keys — there is nowhere in the system for them to live. Your funds are outside our reach by construction: we could not move, freeze, or spend them if we wanted to, and we cannot trade on your behalf.
Access is locked down. Nobody outside Perly is given your records — not partners, not advertisers, not analytics vendors; the providers above process them only to run the service. Inside Perly, access is restricted to what keeping the service running strictly requires, such as restoring a backup or fixing a fault you have reported. It is not routine and your ledger is not browsed.
Encrypted portfolios. Your portfolios can be encrypted in your own browser, all of them at once, with a key only you hold. An encrypted portfolio's amounts, prices, fees, totals, notes, tags, description and target reach our servers only as ciphertext we cannot open. What stays readable is what lists and sorting need: the portfolio's name, each entry's coin and time, and fingerprints that spot a duplicate import. Alerts, plans and watched addresses you set on it are stored in the clear, because the server has to read them to act on them.
What we do not do. We do not sell your data, share it with advertisers, or use it to train anything. The marketing site sets no cookies unless you allow it: page-view analytics loads only after you choose Allow in the cookie notice, and declining leaves the site cookie-free. The app's sign-in pages ask the same question before they count a visit. Inside the app nothing is counted, and the only cookies are the ones that keep you signed in and remember your language, your display settings and where you first arrived from.
Deletion. Deleting a transaction, a portfolio or your whole account — Settings → Delete account — removes the data permanently. There is no soft-delete archive of your ledger. Messages already delivered to a Telegram chat stay in that chat.
Your responsibility. The figures Perly shows are computed from what you typed in. Keep your password to yourself, and treat the output as your own records — we cannot verify your entries against any exchange, and we are not liable for decisions taken on them. See the Terms.
Questions or requests: hi@perly.io
© 2026 Perly. All rights reserved.