LAST UPDATED: 16 JUNE 2026
We take the security of your data seriously. This page describes the practices we follow to protect your information and how you can manage your data and access. For security-related questions, contact us at gyurovik@gmail.com.
All data transferred between your browser and Perpetuity's servers is encrypted using TLS 1.3. This applies to the web application, API calls, and any webhook communications.
Data stored in our database infrastructure is encrypted at rest using AES-256, provided by Supabase. OAuth tokens and other credentials are stored in encrypted form and are never exposed to other users or returned to the browser.
Perpetuity's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
We access your Google Workspace data (Gmail, Calendar, Drive, Contacts) to operate your intelligence workspace. Our commitments regarding this data:
Perpetuity is built on the following infrastructure providers, each operating under their own security and compliance programmes:
Your account data and workspace content are stored in Supabase's EU region where applicable. We do not control the precise geographic routing of individual API requests through Railway and Vercel's edge infrastructure.
Perpetuity uses Google OAuth 2.0 for authentication, managed through Supabase Auth. We do not store passwords. Your credentials are handled entirely by Google and Supabase — we never see your Google account password.
All data in the database is scoped to your account using row-level security policies. Your workspace data is not accessible to other users or accounts.
OAuth access and refresh tokens are stored encrypted in the database. They are used server-side to access your Google Workspace data and are never exposed in the browser or returned in API responses.
You can revoke Perpetuity's access to your Google account at any time from two places:
Disconnecting revokes our access immediately. We delete the stored tokens and will not make further requests to Google APIs on your behalf.
To request full deletion of your Perpetuity account and all associated data, email gyurovik@gmail.com from the address linked to your account. We will confirm receipt and complete deletion within 30 days.
If you believe you have discovered a security vulnerability or suspect unauthorised access to your account, please contact us immediately:
We take all reports seriously and will respond promptly. We do not have a formal bug bounty programme at this time, but we are grateful for responsible disclosure.
Perpetuity · perpetuity.works