Privacy Policy
Effective date: [DD MONTH YYYY] · Last updated: [DD MONTH YYYY]
Perdio ("Perdio", "we", "us") is operated by Benjamin Sasson, an individual trading as Perdio, of [SERVICE ADDRESS] — the Service is provided by an individual, and "we" and "us" refer to that person. This policy explains what personal data the Perdio mobile app (iOS and Android), the Perdio web dashboard and the Perdio API process, why, who we share it with, how long we keep it, and the rights you have.
Perdio is a business-expense tool: it captures receipts, extracts their details, matches them to card transactions, groups them into trips and exports finished expense reports. Almost everything in this policy follows from that single purpose.
- Controller: Benjamin Sasson, [SERVICE ADDRESS]
- Privacy contact: privacy@perdio.app
- Supervisory authority (EEA/UK): [LEAD SUPERVISORY AUTHORITY]
1. Summary
- We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
- No advertising SDKs, ad identifiers or third-party analytics or tracking are used in the app.
- We do not track you across other apps or websites.
- Your receipts, expenses, mailbox and card data are used only to provide the features you turn on.
- You can export everything we hold and permanently delete your account from inside the app, at Settings → Privacy & data.
- Everything is optional except your account: mailbox, calendar, card and accounting connections are off until you connect them, and can be disconnected at any time.
2. Data we process
2.1 Account and profile
- Email address and sign-in identity. Authentication is handled by Amazon Cognito; you may sign in with an email and password or, optionally, with Google.
- First, middle and last name; display name; for group owners, the organisation name.
- Role (individual, group manager, group member, trial), and settings such as home currency, expense categories and language.
- Your unique inbound email address (for example u-7h3k@in.perdio.app) and any per-trip addresses.
2.2 Expenses and receipts
- Receipt and invoice files you capture with the camera, pick from your photo library, upload, send to your Perdio inbound address, or that Perdio finds in a mailbox you connected — images and PDFs.
- The fields extracted from them: merchant, total, subtotal, tax, tip, discount, line items, currency, date, payment method, and any invoice link found in a source email.
- What you add or edit: category, notes, business or personal flag, reimbursement flag, service start and end dates, mileage distance, per-diem entries.
- Trips: name, description, dates, locations, currency, optional budget, status.
- Travel-policy settings, policy-violation flags, approval decisions and approval notes.
- Generated reports (PDF, CSV, XLSX) and the record of where they were exported.
2.3 Card and bank-transaction data (only if you connect a card)
If you use card matching, you link your financial institution through Plaid. You enter your institution credentials with Plaid, never with Perdio — we never see or store them. From Plaid we receive and store the institution name, the last four digits of the card (never a full card number), and transactions: merchant, amount, currency and date. We use this only to match transactions to receipts and to surface unmatched card spend. Plaid's handling of your data is governed by the Plaid End User Privacy Policy.
2.4 Mailbox data (only if you connect a mailbox)
If you connect Gmail or Microsoft Outlook, Perdio requests read-only access and reads only the folders or labels you select, within the date range and sender filters you set for a scan. It looks for receipts and invoices, extracts their details, and stores what it imports, together with a de-duplication key so the same email is never imported twice.
- We do not read mail outside the folders, labels and filters you choose.
- We do not use mailbox content for advertising, and we never sell it.
- You can disconnect at any time in Settings → Integrations, and revoke access directly in your Google or Microsoft account.
Google API Services Limited Use disclosure. Perdio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail and Google Calendar data solely to provide and improve the receipt-capture and trip-detection features you enabled; we do not transfer or use that data for advertising; we do not sell it; we do not allow humans to read it except with your explicit consent (for example when you ask support to investigate a specific import), where required for security or to comply with law, or on aggregated anonymised data used for internal operations; and we do not use Google user data to develop, improve or train generalised or non-personalised AI or machine-learning models.
2.5 Calendar data (only if you connect a calendar)
With read access to Google Calendar, Perdio proposes trips from events that look like travel (dates and locations). Event data is used only to suggest and populate trips.
2.6 Accounting systems (only if you connect one)
If you connect QuickBooks, SAP Concur or Expensify, Perdio pushes the expense reports you choose to export and stores the identifier the accounting system returns.
2.7 Subscriptions and purchases
Subscriptions are purchased through the Apple App Store or Google Play and mediated by RevenueCat. Perdio never receives your payment-card details. We store the entitlement record: tier, product identifier, store subscription identifier, status, seat count, renewal date, auto-renew flag and whether the purchase was made in the store's production or sandbox environment. RevenueCat also processes a store-provided app or device identifier to attribute purchases to your account.
2.8 Groups and sharing
- If you accept an invitation to a group, the manager who invited you can see the trips, expenses, receipts and policy violations in your account, and can approve or reject expenses. The invitation screen tells you this before you accept, and you can leave the group.
- If you share your trips with a viewer, that person can see — and, at the permission level you grant, export or update — your trips and expenses. You control and can revoke this at any time.
- Group and share invitations store the invited person's email address and the invitation status.
2.9 Operational data
- Audit log: account-lifecycle events (registration, tier changes, invitations sent and accepted, member transfers, subscription and seat changes, complimentary grants) with timestamps and the acting or affected account.
- Server logs and infrastructure telemetry: IP address, timestamps, request paths, user agent and error diagnostics, used for security, abuse prevention, debugging and availability.
2.10 Device permissions
| Permission | Why | Optional? |
|---|---|---|
| Camera | Photograph a receipt | Yes — use the gallery, email or manual entry instead |
| Photo library | Pick an existing receipt image | Yes |
| Files and documents | Attach a PDF invoice | Yes |
Perdio does not request device location, contacts, health data, microphone recording or advertising identifiers.
2.11 What we do not collect
Precise or coarse location; contacts; biometrics; health or fitness data; advertising identifiers; browsing history outside Perdio; racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic, biometric, health or sexual-orientation data. Please do not put special-category data into expense notes.
3. Why we process it (lawful bases)
| Purpose | Data | Lawful basis |
|---|---|---|
| Create and run your account; capture, extraction, matching, trips, reports, export | 2.1, 2.2 | Performance of a contract (Art. 6(1)(b)) |
| Mailbox scanning, calendar trip detection, card linking, accounting export | 2.3–2.6 | Consent (Art. 6(1)(a)), withdrawable by disconnecting |
| Billing, entitlement and seat enforcement | 2.7 | Contract; legal obligation for tax records |
| Group management, policy enforcement, approvals | 2.8 | Contract |
| Security, fraud prevention, reliability, debugging | 2.9 | Legitimate interests (Art. 6(1)(f)) |
| Service emails (verification, invitations, important changes) | 2.1 | Contract |
| Legal requests and defending claims | as required | Legal obligation / legitimate interests |
We do not use your data for automated decision-making producing legal effects. Policy-violation flags are configured by your group's manager, are always visible to you, and a human — the manager — makes every approval decision.
4. Automated processing and AI
To read a receipt, Perdio uses Amazon Textract (AWS) for optical character recognition, and Anthropic Claude (Anthropic PBC) to extract structured fields from a receipt image or PDF when OCR alone is insufficient, to suggest a category, and to decide whether an email in a scanned folder is a receipt or invoice.
The content of a receipt file, or of an email in a folder you asked Perdio to scan, may therefore be sent to these providers solely to produce the result you asked for. Anthropic processes it as our service provider under its commercial terms and does not use it to train its models. We do not use your data to train our own models, and we do not use it to develop or improve any generalised AI or machine-learning model.
Accuracy. OCR and AI output can be wrong or incomplete, and some receipts may not be recognised or imported at all. Every suggestion is editable, and you are responsible for reviewing each expense and report before submitting, exporting or relying on it — see section 11 of the Terms & Conditions.
5. Who we share data with
We do not sell personal data and we do not disclose it for advertising. We share it only with:
Sub-processors, under data-processing agreements:
| Recipient | Role | Data |
|---|---|---|
| Amazon Web Services (region eu-west-1) | Hosting, database, storage, authentication, inbound email, OCR | All service data |
| Anthropic PBC | AI receipt extraction, categorisation, email classification | Receipt files, scanned email content |
| Plaid Inc. | Card linking and transaction sync | The account data you authorise |
| RevenueCat, Inc. | Subscription entitlement management | Purchase identifiers, app or device identifier |
| Apple Inc. / Google LLC | Processing your subscription purchase | Purchase and billing data |
| exchangerate.host | Currency conversion rates | Currency pairs only — no personal data |
| Amazon SES | Service and invitation emails | Email address, message content |
Services you connect, at your instruction: Google (Gmail, Calendar), Microsoft (Outlook), Intuit QuickBooks, SAP Concur, Expensify. Data you send to them is then governed by their own policies.
People you choose: the manager of a group you join, and any viewer you share your trips with.
Others: professional advisers, and authorities or counterparties where required by law, to enforce our Terms, or to protect rights and safety. In a merger, acquisition or asset sale, data may transfer to the successor, which remains bound by this policy or gives you notice of a change.
A current sub-processor list is maintained at [https://perdio.app/legal/subprocessors].
6. International transfers
Perdio is hosted in the European Union — AWS eu-west-1, Ireland — so your account, expenses and receipt files stay in the EU. Some sub-processors are in the United States. Where we transfer personal data out of the EEA, the UK or Switzerland we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) or another valid mechanism, together with encryption in transit and at rest. Request a copy of the safeguards at privacy@perdio.app.
7. Retention
| Data | Retention |
|---|---|
| Account, trips, expenses, receipt files | While your account exists; deleting an item removes it immediately |
| Generated report files | 90 days, then purged automatically (reports can be regenerated) |
| Import de-duplication markers | 365 days; they hold only an internal source key |
| OAuth tokens for connected services | Until you disconnect the service or delete your account |
| Audit log | 24 months |
| Server and security logs | 90 days |
| Billing and tax records | As required by law (typically 7 years), independent of account deletion |
When you delete your account we permanently erase your database records, your receipt and report files in object storage, and your sign-in identity. Deletion is irreversible. Records we must keep by law and anonymised aggregates are retained as above; backups roll off within 30 days.
8. Your rights
Wherever you are, you can do the following yourself at Settings → Privacy & data:
- Access and portability — download everything Perdio holds about you as a JSON file. OAuth tokens and invitation tokens are excluded for security; they are credentials, not your data.
- Erasure — permanently delete your account and all associated data.
- Rectification — edit your profile, expenses, trips and settings at any time.
- Withdraw consent — disconnect any mailbox, calendar, card or accounting integration.
In the EEA, the UK and Switzerland you also have the right to restrict or object to processing, and to complain to your supervisory authority ([LEAD SUPERVISORY AUTHORITY]).
California residents have the rights to know, delete, correct and to opt out of sale or sharing under the CCPA/CPRA. We do not sell or share personal information, and we do not process sensitive personal information to infer characteristics. We will not discriminate against you for exercising a right, and you may use an authorised agent. Residents of other US states with comprehensive privacy laws have equivalent rights; we conduct no targeted advertising or profiling with legal effects, so there is no opt-out to make.
To exercise a right you cannot complete in the app, email privacy@perdio.app, or use [https://perdio.app/legal/delete-account] to request deletion. We respond within 30 days (extendable where the law allows), and may need to verify your identity against the account email.
9. Security
- TLS in transit; encryption at rest for the database and for receipt and report storage.
- Receipt and report files live in private object storage, reachable only through short-lived presigned URLs.
- OAuth access and refresh tokens are encrypted at rest with managed keys.
- Every record is scoped to its owning account and checked on every API request; group and share access is checked against the permission you granted.
- Production access is restricted to authorised personnel on a least-privilege basis.
No guarantee. No system, and no transmission over the internet, can be made perfectly secure. We apply the measures above but we cannot and do not guarantee that your data will never be lost, altered or accessed without authorisation, or that the Service is free of vulnerabilities. You are responsible for keeping your credentials and inbound address secure, for the sharing settings you choose, and for keeping your own independent copies of records you need to retain — Perdio is not a backup or archival service. To the maximum extent permitted by applicable law we are not liable for loss or damage resulting from a security incident, unauthorised access, or loss, deletion or corruption of data; sections 12 and 13 of the Terms & Conditions apply to this policy as well, except where mandatory data-protection or consumer law provides otherwise.
If a breach affects your personal data we will notify you and the relevant regulators as required by law.
10. Children
Perdio is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact privacy@perdio.app and we will delete it.
11. App stores
The Apple App Store and Google Play process your download and purchase independently of us, under their own privacy policies. We receive aggregated, non-identifying store metrics and the subscription status described in section 2.7.
12. Changes
We update this page when our processing changes, and update the "Last updated" date. For material changes we notify you in the app or by email before they take effect, and where the law requires it we ask for your consent again.
13. Contact
Benjamin Sasson, [SERVICE ADDRESS] Privacy: privacy@perdio.app · Support: [support@perdio.app]