SECURITY

Your data is yours.
Always.

Your inbox, your contacts and your deals are the most sensitive data your business owns. Perpetuity was built from day one so that data stays yours: encrypted, isolated, hosted in the European Union and never used to train AI. This page explains exactly how we protect it.

TLS 1.3AES-256EU DATA · FRANKFURTNEVER TRAINS AI

LAST UPDATED: 29 SEPTEMBER 2026

✓

Our commitments to you

commitments.sh
$ perpetuity --commitments
✓Your data is never sold. Not to advertisers, not to data brokers, not to anyone.
✓Your data never trains AI. Your email, calendar, documents and contacts are never used to train or improve any AI model, ours or anyone else's.
✓Your account is sealed. Every account is isolated at the database level. No other customer can ever see your data.
✓Everything is encrypted. In transit with TLS 1.3, at rest with AES-256.
✓Your data stays in Europe. Your workspace data is stored in Frankfurt, under EU jurisdiction and GDPR.
✓Nothing goes out without you. Perpetuity drafts. You approve. No email is ever sent on your behalf without your explicit sign-off.
✓You can leave at any time. Disconnect in one click, and request full deletion whenever you want.
1

Encryption, end to end

Every connection between your browser, our application and our servers is encrypted with TLS 1.3, the current industry standard. Everything we store is encrypted at rest with AES-256. The keys that let Perpetuity read your Google Workspace (OAuth tokens) are stored encrypted, used only on our servers, and never sent to a browser or exposed in any response.

2

Google Workspace data

Perpetuity's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

We connect to Gmail, Calendar, Drive and Contacts for one reason: to run your intelligence workspace. That comes with firm rules:

  • Read-only by default. The only write permission we request is for Gmail, so we can send replies you have explicitly approved. Nothing else.
  • No selling, no advertising. Your workspace data is never sold and never used for advertising of any kind.
  • No model training. Your data is never used to train, fine-tune or improve any general AI model, including large language models. Every AI output generated from your data exists only inside your own account.
  • No one reads your email. Perpetuity staff do not access your workspace data, except where strictly required for a security investigation or by law.
  • Minimum access. We request only the permissions each feature needs. The full list is in our Privacy Policy.
3

Enterprise-grade infrastructure in the EU

Perpetuity runs on providers that meet the security standards of the world's largest software companies:

FRANKFURTSOC 2 TYPE II
Supabase

Database and authentication. AWS Frankfurt (eu-central-1). This is where your workspace data lives.

AMSTERDAM
Railway

API servers. AWS Amsterdam (europe-west4).

EDGESOC 2 TYPE II
Vercel

Web application. Global edge network.

Your account data and workspace content are stored in the EU. Individual requests may pass through Vercel's global edge network on their way to our EU servers.

4

Access you control

No passwords to steal

You sign in with Google OAuth 2.0, managed through Supabase Auth. We never see or store your Google password.

Isolation by design

Row-level security policies scope every record in our database to your account. Another account cannot query your data, by design, at the database level.

Tokens stay on the server

Access and refresh tokens are encrypted, used server-side only, and never returned to the browser.

5

Leave whenever you want

Disconnect in one click

From your Perpetuity dashboard under Connections, click Disconnect next to Google Workspace. Or remove Perpetuity from your Google Account permissions page. Access is revoked immediately, your stored tokens are deleted, and we make no further requests to Google on your behalf.

Delete everything

Email hello@perpetuity.works from the address linked to your account to request full deletion of your account and all associated data. We confirm receipt and complete deletion within 30 days.

6

Report a security issue

If you believe you have found a vulnerability, or suspect unauthorised access to your account, contact us immediately at hello@perpetuity.works. Every report is taken seriously and answered promptly. We do not run a formal bug bounty programme yet, and we are grateful for responsible disclosure.