LEGAL

Privacy
Policy.

What information Perpetuity collects, how it is used, and the choices you have over your data.

LAST UPDATED: 24 JULY 2026GDPR-ALIGNED

Perpetuity ("we," "us," or "our") operates the Perpetuity intelligence platform accessible at perpetuity.works and its subdomains. This Privacy Policy explains what information we collect, how we use it, and the choices you have over your data. If you have questions, contact us at hello@perpetuity.works.

1

Google API Services — Limited Use

Perpetuity's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

2

Information We Collect

Account information

When you sign in with Google, we receive your name, email address, and profile photo from your Google account. This is used to create and identify your Perpetuity account.

Google Workspace data

To operate your intelligence workspace, Perpetuity requests access to the following three Google API scopes. We request only what is required for each specific feature.

ScopeWhat we accessWhy we need it
gmail.readonlyEmail metadata: sender, recipient, subject, date, and labels. We do not read message bodies or attachments.To identify correspondence that may require your attention — active leads, unanswered enquiries, tender notifications — and surface them in your workspace
gmail.sendThe ability to send an email on your behalfTo dispatch outreach drafts and replies that you have explicitly reviewed and approved within the platform. Sending is never autonomous or in bulk — every message requires your individual per-message approval.
calendar.readonlyCalendar event metadata: title, time, attendees, and locationTo surface upcoming meetings, prepare briefings for scheduled calls, and align intelligence delivery to your schedule

Scopes we do not request: Perpetuity does not request access to Google Drive, Google Contacts, Google Sheets, or any other Google service beyond the three listed above.

Data stored from Gmail

From the Gmail readonly scope we store the following per email:

  • Headers: sender name and address, recipient address, subject line, date, Gmail label IDs
  • Snippet: a short body preview of up to approximately 250 characters supplied by the Gmail API — this is derived from message body content, not pure metadata
  • AI-generated classification stored persistently: action type, priority, sentiment, suggested action, reply tone, and a 2–3 sentence synthesis summarising what the email requires — generated from the snippet and subject, then written back to our database

We do not store full message bodies, attachment content, or attachment filenames. Gmail messages are ingested within a rolling 90-day window.

Data stored from Calendar

From the Calendar readonly scope we store the following per event:

  • Event fields: title, description (the full text of the event description field, which may contain agenda items or meeting notes), start time, end time, location, video meeting link, and status
  • Attendees: each attendee's email address, display name, and RSVP status
  • AI-generated classification stored persistently: event type, priority, whether preparation is needed, and preparation notes — generated from title and description

Calendar events are synced within a window of 30 days in the past and 30 days ahead, with a maximum of 250 events per sync.

Usage and log data

We collect standard server logs including your IP address, browser type, pages visited, and timestamps. This is used for security, debugging, and service improvement.

3

How We Use Your Information

Perpetuity is a personal productivity tool. All data is used solely to operate your own workspace — no data from one user's account is used to benefit any other user or any party other than you.

Specifically, we use your data to:

  • Identify emails that may need a reply and surface them as action items
  • Generate summaries and daily briefings for your review
  • Prepare draft replies and outreach that you review and approve before any message is sent
  • Surface upcoming calendar commitments and prepare relevant briefings
  • Send notifications about your workspace via email or Telegram where you have enabled these
  • Respond to your support requests
  • Detect and prevent fraud, abuse, or security incidents

We do not sell your personal data or your Google Workspace data to any third party. We do not use your data for advertising. We do not share your data with data brokers or ad networks.

We do not use your Google Workspace data — including Gmail or Calendar content — to train, fine-tune, or improve any generalised AI model, including large language models. All AI processing of your workspace data is performed solely to generate outputs for your own account. Anthropic's API terms explicitly prohibit use of API inputs and outputs to train their models.

4

Data Storage and Security

Your data is stored in our database infrastructure hosted by Supabase. Supabase provides encryption at rest at the infrastructure level (AES-256 storage encryption) and all data in transit uses TLS. Access to your workspace data is enforced by row-level security policies — no other user can read your data.

OAuth credentials (access tokens and refresh tokens) are stored in your account record in the database and are protected by the same row-level access controls. They are not additionally encrypted at the application layer beyond what the database infrastructure provides.

We take reasonable technical and organisational precautions to protect your data against unauthorised access, loss, or destruction. No system is perfectly secure; if you suspect unauthorised access to your account, contact us immediately at hello@perpetuity.works.

5

Data Retention and Deletion

We retain your account data for as long as your account is active.

You may disconnect your Google integration at any time from the Connections page in your dashboard. Disconnecting an integration permanently deletes your stored OAuth tokens from our database and revokes our access to your Google account. We will not make further requests to Google APIs on your behalf after disconnection.

Disconnecting does not automatically delete historical email metadata or calendar data already ingested. To request full deletion of all data associated with your account, email hello@perpetuity.works from the address linked to your account. We will confirm and complete deletion within 30 days.

There is no automatic retention window or scheduled deletion for ingested data; data is retained until you request deletion as described above.

6

Third-Party Services

Perpetuity integrates with the following third-party services to operate the platform. We share with each only the minimum data necessary to provide the corresponding feature.

  • Google LLC — identity sign-in and Workspace API access, governed by Google's Privacy Policy and the Google API Services User Data Policy
  • Supabase — authentication infrastructure and database hosting (your data at rest)
  • Anthropic — AI language model processing (claude-sonnet-4-6, claude-haiku-4-5) used to generate intelligence outputs from your data; Anthropic does not use API inputs/outputs to train models
  • Railway — backend application hosting (infrastructure layer)
  • Vercel — frontend application hosting (infrastructure layer)
  • Resend — transactional email delivery for workspace notifications
  • Telegram — optional notification and assistant channel, enabled only if you connect it; no Google Workspace data is sent to Telegram

Your Google Workspace data is not sold, transferred to data brokers or advertisers, or shared with any party not listed above.

7

Your Rights

Depending on your jurisdiction, you may have rights including:

  • The right to access the personal data we hold about you
  • The right to correct inaccurate data
  • The right to request deletion of your data
  • The right to restrict or object to processing
  • The right to data portability

To exercise any of these rights, contact hello@perpetuity.works.

8

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by updating the "Last Updated" date at the top of this page and, where appropriate, by emailing registered users. Your continued use of the platform after a policy update constitutes acceptance of the revised terms.

9

Contact

For privacy-related enquiries or requests:
hello@perpetuity.works

Perpetuity · perpetuity.works