The site is still being built — nothing on it is final yet.Write to hi@perly.io to hear things first, or wait for the announcement.

← Back to perly.io
Perly

Privacy Policy

Last updated: September 2026

The short version. Perly keeps your account, the records you create, and the few things you switch on — alerts, plans, watched addresses, notifications. Everything it keeps is listed below, grouped by what it is for. No wallet connections, no seed phrases, no exchange API keys, no access to your funds. Nothing is sold, shared with advertisers, or used to train anything.

What Perly keeps.

  • Your account — your email address; your password as a hash nobody can reverse (there is none if you sign in with Google or X); for Google or X sign-in, the name, email and picture that provider shares; a display name; when you joined; and where you first arrived from — the site, chart and language — and when.
  • Signing in — the sessions you are signed in with, and the IP address and browser each was opened from, kept by the sign-in service to protect the account.
  • Your ledger — portfolios (name, description, target), transactions (coin, side, quantity, price, fee, time, exchange, tags, notes, and the fingerprints that spot a duplicate import), and the goals you set on them.
  • What you switch on — price alerts and planned orders; DCA plans with your time zone and reminder text; market alerts; watched wallet addresses with their labels and the balances read for them; a log of the reports you generate (period, method and format — never amounts); the push address your browser gives for notifications; and a connected Telegram chat (its id, username and first name).
  • Invitations and membership — your invite code, who invited you and whom you invited, codes you redeem, club membership (seat, cohort, amount paid, dates), and, if you join the Shoal, your alias and the weekly figures it ranks.
  • Your vault — if you create one: your encryption key as wrapped by each way you open it (passphrase, recovery code, passkey), with that opener's label and when it was last used. Never the key itself.

Who else handles it. Perly runs on a few providers that process data on its behalf and for no one else: Supabase (the database and sign-in, in the EU), Vercel (hosting) and Resend (sign-in emails). Google or X take part only if you sign in with them, Telegram only if you connect a chat, and your browser's push service only if you turn notifications on. The addresses you watch are looked up in public blockchain explorers from our servers, not from your browser.

Who can read it. Your rows are protected by PostgreSQL row-level security, enabled and forced on every user-owned table. A query made from any other account returns nothing — not an error, nothing. Data is encrypted in transit and at rest, and your password is stored only as a hash, so nobody at Perly can read it or sign in as you.

What we can never reach. Perly holds no wallet connection, no seed phrase, no private keys and no exchange API keys — there is nowhere in the system for them to live. Your funds are outside our reach by construction: we could not move, freeze, or spend them if we wanted to, and we cannot trade on your behalf.

Access is locked down. Nobody outside Perly is given your records — not partners, not advertisers, not analytics vendors; the providers above process them only to run the service. Inside Perly, access is restricted to what keeping the service running strictly requires, such as restoring a backup or fixing a fault you have reported. It is not routine and your ledger is not browsed.

Encrypted portfolios. Your portfolios can be encrypted in your own browser, all of them at once, with a key only you hold. An encrypted portfolio's amounts, prices, fees, totals, notes, tags, description and target reach our servers only as ciphertext we cannot open. What stays readable is what lists and sorting need: the portfolio's name, each entry's coin and time, and fingerprints that spot a duplicate import. Alerts, plans and watched addresses you set on it are stored in the clear, because the server has to read them to act on them.

What we do not do. We do not sell your data, share it with advertisers, or use it to train anything. The marketing site sets no cookies unless you allow it: page-view analytics loads only after you choose Allow in the cookie notice, and declining leaves the site cookie-free. The app's sign-in pages ask the same question before they count a visit. Inside the app nothing is counted, and the only cookies are the ones that keep you signed in and remember your language, your display settings and where you first arrived from.

Deletion. Deleting a transaction, a portfolio or your whole account — Settings → Delete account — removes the data permanently. There is no soft-delete archive of your ledger. Messages already delivered to a Telegram chat stay in that chat.

Your responsibility. The figures Perly shows are computed from what you typed in. Keep your password to yourself, and treat the output as your own records — we cannot verify your entries against any exchange, and we are not liable for decisions taken on them. See the Terms.

Questions or requests: hi@perly.io

← Back to perly.io

© 2026 Perly. All rights reserved.