Pero is a voice-first task manager: you say what is on your mind, Pero turns it into tasks and notes and assembles a plan for your day. This policy explains what data the Pero app and its backend collect, why, who processes it, and how you can delete it.
This policy applies to the Pero mobile application, the website at peroday.app and the backend service behind them (together, the "Service").
When you hold the capture button or ask Pero a question by voice, the audio is sent to our backend for transcription. The audio is processed in memory and is not stored. Only the transcript is kept, as part of your content.
The Service is operated by Oleh Chausov, an individual developer residing in Kharkiv, Ukraine (the data controller). Contact: support@pero.day.
sendDefaultPii = false) and your content is not attached.Pero does not collect your location, contacts, photos or camera images, does not read other apps on your device, and does not use advertising identifiers. The iOS App Tracking Transparency prompt is shown on first launch to satisfy platform rules; your answer does not change what Pero collects, because Pero does not track you across other companies' apps or websites.
| Purpose | Data | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Run the Service: store and sync your content, build your daily plan | Content, identifiers, preferences | Performance of a contract |
| Turn speech into text and triage it (Section 4) | Voice, transcripts, content | Performance of a contract; explicit consent for any special-category data your content may reveal (Article 9(2)(a)) |
| Sign-in and account recovery | Sign-in details, identifiers | Performance of a contract |
| Subscriptions and quotas | Subscription status, counters | Performance of a contract |
| Reminders | Push token, reminder settings, time zone | Performance of a contract (you turn reminders on) |
| Product analytics | Usage events | Legitimate interest in understanding and improving the product |
| Crash reporting, security, rate limiting | Error reports, IP, counters | Legitimate interest in keeping the Service working and safe |
| Answering support requests | Your message and email | Legitimate interest / contract |
| Legal obligations | As required | Legal obligation |
We do not sell your personal data and we do not use it for advertising.
AI is the core of Pero, not an add-on. The following happens on our backend:
Text you type into the capture field is treated exactly like a transcript and goes through triage. Text you type while editing an existing task or note is stored and indexed, but is not sent to a language model on its own; it becomes part of the context the model sees when you later capture something, ask a question or when the weekly review is generated.
When AI processing starts. The backend refuses AI requests until your account has an AI-processing timestamp. That timestamp is set when you pass the microphone step of onboarding, whether or not you grant microphone access. By continuing past that step you agree to the processing described here. There is currently no in-app switch to turn AI processing off while keeping your account. To stop it, delete your account (Section 8) or write to support@pero.day.
No training. We use every AI provider under its business or API terms, under which your content is not used to train the provider's models. We do not train models on your content either. Your name, email and sign-in identifiers are never sent to AI providers; only your content and a random request ID are.
Mistakes. Models make mistakes. Pero marks guesses in the interface and lets you correct them, but you remain responsible for checking what ends up in your plan. AI output does not produce legal or similarly significant effects on you in the sense of GDPR Article 22.
| Processor | What they do for Pero | Data they see | Location | Privacy page |
|---|---|---|---|---|
| Cloudflare, Inc. | Hosting of the backend, database (D1), object storage for backups (R2), key-value cache, queues, AI Gateway, Workers AI (speech to text, embeddings) | All backend data; audio in transit; transcripts and content for AI | Global edge network, primarily US/EU | cloudflare.com/privacypolicy |
| Google LLC (Gemini API) | Language model for triage, planning, questions, weekly review | Transcripts, typed captures, task and note text | US | ai.google.dev/gemini-api/terms |
| Google LLC (Firebase) | Anonymous, Apple and Google sign-in (Firebase Authentication); push delivery (Cloud Messaging) | Identifiers, email/name if shared, push token, notification text | US | firebase.google.com/support/privacy |
| Apple Inc. | Sign in with Apple; App Store payments and subscriptions | Apple user identifier; payment data stays with Apple | US | apple.com/legal/privacy |
| RevenueCat, Inc. | Subscription management and receipt validation | App user ID, purchase and subscription history | US | revenuecat.com/privacy |
| PostHog, Inc. | Product analytics | Usage events, user ID, subscription status, time zone, device and app version | US | posthog.com/privacy |
| Functional Software, Inc. (Sentry) | Crash and error monitoring | Stack traces, device and app version, user ID | US | sentry.io/privacy |
| Backblaze, Inc. | Cold storage of encrypted weekly database backups | Encrypted backup archives only | US | backblaze.com/company/privacy |
The full, versioned list of subprocessors is maintained separately: see Subprocessors.
We may also disclose data when the law requires it, to enforce our Terms, or to protect the rights and safety of users. If Pero is ever sold or merged, your data may move to the new operator under this policy.
We are based in Ukraine; our processors are mostly in the United States and run on global networks. Where data leaves the EEA, the UK or Switzerland we rely on the processors' Standard Contractual Clauses and, for US providers certified under the EU-US Data Privacy Framework, on that framework. Ask support@pero.day if you want details of a specific safeguard.
No system is perfectly secure. If we learn of a breach affecting your data we will notify you as the law requires.
| Data | Kept for |
|---|---|
| Your content, account and preferences | While your account exists |
| Voice audio | Not stored; discarded after transcription |
| Anonymous (guest) accounts | Deleted after 30 days without activity, unless the account holds a subscription |
| A guest account after you sign in and it is merged | The old guest record is kept 90 days, then deleted |
| Usage events (PostHog) | Until you delete your account, then removed within 30 days |
| Error reports (Sentry) | 90 days |
| Rate-limit counters | Reset daily |
| Retry cache (idempotency keys and cached responses) | Up to 48 hours |
| Server request logs | Short-lived operational logs on Cloudflare |
| Database backups | Daily copies 30 days, weekly 12 weeks, monthly 12 months on Cloudflare R2; weekly archives about 12 months in Backblaze cold storage |
| Deletion audit record | 400 days; contains only a hash of your user ID and timestamps |
Deleting your account. In the app open Settings, then Account, then Delete account. Before the final step you can download a JSON copy of your profile. When you confirm:
Deleting the app from your device does not delete your account. Deleting your account does not cancel an App Store subscription; cancel it in your Apple account settings.
Depending on where you live, you can ask us to:
Write to support@pero.day. We answer within 30 days and may ask you to confirm that you control the account. We will not treat you differently for exercising a right.
California residents: we do not sell or share personal information for cross-context advertising, and we use the content you capture only to provide the Service.
You can use Pero without signing in. Your data is then tied only to a random identifier stored on your device. If you delete the app or lose the device, we cannot recover that account. When you later sign in with Apple or Google, the guest data is moved into the signed-in account. Guest accounts that stay inactive for 30 days are deleted automatically unless they hold a subscription.
Pero is not directed at children under 13, and we do not knowingly collect data from them. Where local law sets a higher age for consent (up to 16 in parts of the EEA), that age applies. If you believe a child has an account, write to support@pero.day and we will delete it.
We will update the effective date at the top when this policy changes and record the change in our changelog. For material changes we will also tell you inside the app. Using Pero after a change takes effect means you accept the updated policy.
Oleh Chausov, Kharkiv, Ukraine. Email: support@pero.day.