Skip to content
◒Percipio
ProductHow it worksDevelopersPricingCompare
Sign inGet API access

Legal

Privacy Policy

This policy explains what Percipio processes, why we process it, and the choices available to developers and end users.

Effective July 3, 2026
On this page
Scope and rolesInformation we processHow we use informationCustomer DataService providersRetentionDeletion and exportInternational transfersYour rightsSecurityCookiesChildrenChanges and contact
Questions?privacy@percipio.tech

1. Scope and roles

This Privacy Policy applies to the Percipio website, developer platform, APIs, and related support services (the “Services”).

Percipio acts as a controllerwhen it determines how developer account, website, security, and business-contact information is used. When a customer sends conversations or end-user information through the API, Percipio generally acts as that customer's processor or service provider. The customer determines why the end-user information is processed and is responsible for providing notices, obtaining any required consent, and responding to end-user requests.

If you use an application powered by Percipio, contact that application's provider first. We assist customers with verified end-user privacy requests.

2. Information we process

Developer and organization information

  • Name of your organization and your work email address.
  • Password hashes, email-verification status, sessions, and API-key metadata.
  • Support messages and other information you choose to send us.

Service and device information

  • Request ID, route, method, response status, latency, timestamp, and API-key prefix.
  • Standard network and device data made available by browsers, hosting providers, and security systems, such as IP address and user agent.

Customer Data

  • End-user identifiers chosen by the customer.
  • Conversation messages submitted through the API.
  • Derived structured user state, including goals, projects, preferences, relationships, interests, expertise, memories, confidence values, events, and context snapshots.

3. How we use information

We process information to:

  • Provide, secure, maintain, and troubleshoot the Services.
  • Authenticate developers and manage organizations and API keys.
  • Transform submitted conversations into structured state and prompt-ready context.
  • Prevent abuse, investigate incidents, and enforce our Terms.
  • Communicate about accounts, security, support, and material service changes.
  • Comply with law and protect the rights and safety of Percipio and others.

Where applicable, our legal bases include performing a contract, pursuing legitimate interests in operating and securing the Services, complying with legal obligations, and consent where required.

4. How we handle Customer Data

We process Customer Data only to provide and secure the Services, follow documented customer instructions, comply with law, and prevent abuse. Customers retain their rights in Customer Data. Percipio does not sell Customer Data, share it for cross-context behavioural advertising, or use it to train generalized AI models.

The extraction system is designed to rely on user-authored evidence, track uncertainty, and exclude protected or highly sensitive traits from structured state. These controls reduce risk but do not replace a customer's obligation to collect appropriate data and use it lawfully.

A Data Processing Addendum or written order form may supplement this Policy. If it conflicts with this Policy for Customer Data, the signed agreement controls.

Customers can use Percipio's API to export or delete an end user's data. Export returns the user shell, unpurged messages, current structured state, immutable versions, events, and context snapshots. Deletion removes the end user and cascades conversations, messages, state, versions, events, and snapshots.

5. Service providers and disclosures

We disclose information only when needed to operate the Services, follow customer instructions, complete a corporate transaction, protect rights and safety, or comply with law. Key service providers currently include:

ProviderPurpose
RenderApplication hosting, networking, and managed PostgreSQL infrastructure.
OpenAIStructured extraction of evidence-backed candidate state changes.
ResendAccount verification and password-recovery email delivery.

Providers may process information only for the services they provide to us, subject to their contractual and legal obligations.

6. Retention

Our default production retention periods are:

  • Raw conversation messages and extraction payloads: 90 days.
  • API request metadata: 30 days.
  • Privacy audit metadata: retained to evidence export and deletion requests without retaining conversation content or derived user state.
  • Structured state, versions, events, and context snapshots: retained while needed to provide the Services or until deletion is requested or required.
  • Account and security records: retained while the account is active and afterward where reasonably necessary for security, dispute resolution, or legal compliance.

Backups and logs may persist for a limited period before being overwritten. We may retain information longer when required by law, subject to a valid legal hold, or needed to establish or defend legal claims.

7. Deletion and export APIs

Percipio provides customer-accessible endpoints for privacy operations: GET /v1/users/{external_user_id}/export and DELETE /v1/users/{external_user_id}. These endpoints are organization-scoped and require a valid server-side API key.

Export and deletion requests create metadata-only audit records containing the organization, request ID, external user ID, action, and timestamp. The audit record does not include conversations, state documents, event payloads, or context snapshots.

End users should usually make requests through the customer application they use. We help customers fulfill verified requests when they route those requests to us.

8. International transfers

Percipio and its providers may process information in Canada, the United States, and other countries where they operate. Those countries may have different privacy laws. Where required, we use contractual and organizational safeguards for international transfers.

9. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information; object to or restrict certain processing; withdraw consent; or complain to a privacy regulator.

Developers can request assistance at privacy@percipio.tech. End users should usually contact the customer application that collected their information. We may need to verify identity and authority before completing a request, and legal exceptions may apply.

We do not discriminate against anyone for exercising a privacy right. We do not sell personal information or share it for targeted advertising, so no sale or sharing opt-out is required for those practices.

10. Security

We use technical and organizational measures intended to protect information, including tenant-scoped access, hashed credentials and tokens, secure session cookies, CSRF protection, content-minimized request logs, and retention controls. No system can guarantee absolute security. See our Security page or report a concern to security@percipio.tech.

11. Cookies

The developer platform uses strictly necessary cookies to maintain authenticated sessions and protect state-changing requests. Percipio does not currently use third-party advertising cookies or cross-site behavioural tracking.

12. Children

Developer accounts are not directed to children, and we do not knowingly create accounts for anyone under 18. Customers whose applications serve children are responsible for obtaining required parental consent and complying with child-privacy laws before sending information to Percipio.

13. Changes and contact

We may update this Policy as the Services and legal requirements change. We will update the effective date and provide additional notice when a change materially affects how we process information.

Privacy questions and requests can be sent to privacy@percipio.tech.

◒PercipioThe Human Understanding API.
DocumentationPrivacySecurityTerms