Your inbox, your contacts and your deals are the most sensitive data your business owns. Perpetuity was built from day one so that data stays yours: encrypted, isolated, hosted in the European Union and never used to train AI. This page explains exactly how we protect it.
LAST UPDATED: 29 SEPTEMBER 2026
Every connection between your browser, our application and our servers is encrypted with TLS 1.3, the current industry standard. Everything we store is encrypted at rest with AES-256. The keys that let Perpetuity read your Google Workspace (OAuth tokens) are stored encrypted, used only on our servers, and never sent to a browser or exposed in any response.
Perpetuity's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
We connect to Gmail, Calendar, Drive and Contacts for one reason: to run your intelligence workspace. That comes with firm rules:
Perpetuity runs on providers that meet the security standards of the world's largest software companies:
Database and authentication. AWS Frankfurt (eu-central-1). This is where your workspace data lives.
API servers. AWS Amsterdam (europe-west4).
Web application. Global edge network.
Your account data and workspace content are stored in the EU. Individual requests may pass through Vercel's global edge network on their way to our EU servers.
You sign in with Google OAuth 2.0, managed through Supabase Auth. We never see or store your Google password.
Row-level security policies scope every record in our database to your account. Another account cannot query your data, by design, at the database level.
Access and refresh tokens are encrypted, used server-side only, and never returned to the browser.
From your Perpetuity dashboard under Connections, click Disconnect next to Google Workspace. Or remove Perpetuity from your Google Account permissions page. Access is revoked immediately, your stored tokens are deleted, and we make no further requests to Google on your behalf.
Email hello@perpetuity.works from the address linked to your account to request full deletion of your account and all associated data. We confirm receipt and complete deletion within 30 days.
If you believe you have found a vulnerability, or suspect unauthorised access to your account, contact us immediately at hello@perpetuity.works. Every report is taken seriously and answered promptly. We do not run a formal bug bounty programme yet, and we are grateful for responsible disclosure.