Pero privacy

Privacy

Effective date: September 2, 2026

Pero is a voice-first task manager: you say what is on your mind, Pero turns it into tasks and notes and assembles a plan for your day. This policy explains what data the Pero app and its backend collect, why, who processes it, and how you can delete it.

This policy applies to the Pero mobile application, the website at peroday.app and the backend service behind them (together, the "Service").

Your voice — not stored

When you hold the capture button or ask Pero a question by voice, the audio is sent to our backend for transcription. The audio is processed in memory and is not stored. Only the transcript is kept, as part of your content.

1. Who we are

The Service is operated by Oleh Chausov, an individual developer residing in Kharkiv, Ukraine (the data controller). Contact: support@pero.day.

2. Data we collect

2.1. Data you provide

Your content. Tasks (title, note, estimate, priority, deadline, status, completion time), notes, goals on three horizons, projects, quick wins and your daily 1-3-5 plans. This includes everything you say into the microphone once it has been turned into text.
Voice recordings. When you hold the capture button or ask Pero a question by voice, the audio is sent to our backend for transcription. The audio is processed in memory and is not stored. Only the transcript is kept, as part of your content.
Sign-in details. If you sign in with Apple or Google, we receive the identifier the provider assigns to you and, if you share it, your email address and name. Pero does not use passwords.
Preferences. Your time zone, reminder on/off and reminder time, the language used for speech recognition, and the date you passed the microphone step of onboarding (this is when AI processing is enabled, see Section 4).
Support requests. Anything you send to support@pero.day.

2.2. Data collected automatically

Account identifiers. On first launch the app creates an anonymous account (Firebase Anonymous Authentication) with a random user ID. Signing in later links that ID to your Apple or Google identity.
Usage events. The app and the backend send product analytics events to PostHog: for example that a capture was made, a task was closed, a screen was opened, a subscription changed, or an account deletion step was reached. Events carry your user ID, subscription status, guest/registered status, time zone, app version, OS version, device model and manufacturer, device language, screen size and network type. They do not carry your content, email or name.
Crash and error reports. If the app or backend hits an error, Sentry receives the stack trace, app version, OS version, device model and your user ID. Personal details are switched off (sendDefaultPii = false) and your content is not attached.
Push notification token. If you enable reminders, a Firebase Cloud Messaging token for your device is stored on your account.
IP address and request IDs. Our backend on Cloudflare sees your IP address on every request and uses it for rate limiting and abuse prevention. It is not written to your account record. Every request also carries a random request ID that appears in server logs.
Rate-limit and idempotency counters. Per-user daily request counters and 24-hour idempotency keys, used to enforce fair-use quotas and to make retried requests safe.
On-device cache. The app keeps a local copy of your content and settings on your device so that you can read and edit tasks offline.

2.3. Data we receive from third parties

Subscription status. The App Store and RevenueCat tell us whether you hold an active Pro subscription and when it expires. We never see your payment card details.
Sign-in identity. Apple or Google confirm your identity and hand us the identifier and optional email described in Section 2.1.

2.4. Data we do not collect

Pero does not collect your location, contacts, photos or camera images, does not read other apps on your device, and does not use advertising identifiers. The iOS App Tracking Transparency prompt is shown on first launch to satisfy platform rules; your answer does not change what Pero collects, because Pero does not track you across other companies' apps or websites.

3. Why we use it and on what legal basis

PurposeDataLegal basis (GDPR / UK GDPR)
Run the Service: store and sync your content, build your daily planContent, identifiers, preferencesPerformance of a contract
Turn speech into text and triage it (Section 4)Voice, transcripts, contentPerformance of a contract; explicit consent for any special-category data your content may reveal (Article 9(2)(a))
Sign-in and account recoverySign-in details, identifiersPerformance of a contract
Subscriptions and quotasSubscription status, countersPerformance of a contract
RemindersPush token, reminder settings, time zonePerformance of a contract (you turn reminders on)
Product analyticsUsage eventsLegitimate interest in understanding and improving the product
Crash reporting, security, rate limitingError reports, IP, countersLegitimate interest in keeping the Service working and safe
Answering support requestsYour message and emailLegitimate interest / contract
Legal obligationsAs requiredLegal obligation

We do not sell your personal data and we do not use it for advertising.

4. AI processing

AI is the core of Pero, not an add-on. The following happens on our backend:

Speech to text. Audio from the capture button and from voice questions is transcribed by a Whisper model running on Cloudflare Workers AI.
Triage and planning. Transcripts, text you type into the capture field, and the task titles and notes already on your account, are sent to a large language model to decide whether an utterance is a task, a note or a quick win, to fill in properties such as deadline or project, to answer questions you ask by voice, to assemble the daily 1-3-5 plan and to write a short weekly review. All of this runs on Google Gemini models, reached through Cloudflare AI Gateway. The backend can be switched to other model providers; if we do that, we will update this policy and the subprocessor list first.
Search index. Task titles and notes are converted into embeddings by a model on Cloudflare Workers AI so that voice questions can find relevant items.

Text you type into the capture field is treated exactly like a transcript and goes through triage. Text you type while editing an existing task or note is stored and indexed, but is not sent to a language model on its own; it becomes part of the context the model sees when you later capture something, ask a question or when the weekly review is generated.

When AI processing starts. The backend refuses AI requests until your account has an AI-processing timestamp. That timestamp is set when you pass the microphone step of onboarding, whether or not you grant microphone access. By continuing past that step you agree to the processing described here. There is currently no in-app switch to turn AI processing off while keeping your account. To stop it, delete your account (Section 8) or write to support@pero.day.

No training. We use every AI provider under its business or API terms, under which your content is not used to train the provider's models. We do not train models on your content either. Your name, email and sign-in identifiers are never sent to AI providers; only your content and a random request ID are.

Mistakes. Models make mistakes. Pero marks guesses in the interface and lets you correct them, but you remain responsible for checking what ends up in your plan. AI output does not produce legal or similarly significant effects on you in the sense of GDPR Article 22.

5. Who processes your data

ProcessorWhat they do for PeroData they seeLocationPrivacy page
Cloudflare, Inc.Hosting of the backend, database (D1), object storage for backups (R2), key-value cache, queues, AI Gateway, Workers AI (speech to text, embeddings)All backend data; audio in transit; transcripts and content for AIGlobal edge network, primarily US/EUcloudflare.com/privacypolicy
Google LLC (Gemini API)Language model for triage, planning, questions, weekly reviewTranscripts, typed captures, task and note textUSai.google.dev/gemini-api/terms
Google LLC (Firebase)Anonymous, Apple and Google sign-in (Firebase Authentication); push delivery (Cloud Messaging)Identifiers, email/name if shared, push token, notification textUSfirebase.google.com/support/privacy
Apple Inc.Sign in with Apple; App Store payments and subscriptionsApple user identifier; payment data stays with AppleUSapple.com/legal/privacy
RevenueCat, Inc.Subscription management and receipt validationApp user ID, purchase and subscription historyUSrevenuecat.com/privacy
PostHog, Inc.Product analyticsUsage events, user ID, subscription status, time zone, device and app versionUSposthog.com/privacy
Functional Software, Inc. (Sentry)Crash and error monitoringStack traces, device and app version, user IDUSsentry.io/privacy
Backblaze, Inc.Cold storage of encrypted weekly database backupsEncrypted backup archives onlyUSbackblaze.com/company/privacy

The full, versioned list of subprocessors is maintained separately: see Subprocessors.

We may also disclose data when the law requires it, to enforce our Terms, or to protect the rights and safety of users. If Pero is ever sold or merged, your data may move to the new operator under this policy.

6. International transfers

We are based in Ukraine; our processors are mostly in the United States and run on global networks. Where data leaves the EEA, the UK or Switzerland we rely on the processors' Standard Contractual Clauses and, for US providers certified under the EU-US Data Privacy Framework, on that framework. Ask support@pero.day if you want details of a specific safeguard.

7. Security

— Your content is encrypted at rest with AES-256-GCM using a per-user key, which is itself wrapped by a server key. This covers task titles and notes, note bodies, transcripts, goal, project and quick-win titles, daily plan lines, weekly reviews, inbox questions and pending edits. Account metadata (email, preferences, push token) is stored without field-level encryption.
— One exception: to make a retried request safe, the backend caches the response to each write request, including the transcript and the parsed task titles, in plain text for up to 48 hours. This cache is keyed by a random request ID and expires on its own.
— All traffic between the app and the backend uses TLS.
— Backups are encrypted as whole archives.
— Access to production systems is limited to the operator.

No system is perfectly secure. If we learn of a breach affecting your data we will notify you as the law requires.

8. Retention and deletion

DataKept for
Your content, account and preferencesWhile your account exists
Voice audioNot stored; discarded after transcription
Anonymous (guest) accountsDeleted after 30 days without activity, unless the account holds a subscription
A guest account after you sign in and it is mergedThe old guest record is kept 90 days, then deleted
Usage events (PostHog)Until you delete your account, then removed within 30 days
Error reports (Sentry)90 days
Rate-limit countersReset daily
Retry cache (idempotency keys and cached responses)Up to 48 hours
Server request logsShort-lived operational logs on Cloudflare
Database backupsDaily copies 30 days, weekly 12 weeks, monthly 12 months on Cloudflare R2; weekly archives about 12 months in Backblaze cold storage
Deletion audit record400 days; contains only a hash of your user ID and timestamps

Deleting your account. In the app open Settings, then Account, then Delete account. Before the final step you can download a JSON copy of your profile. When you confirm:

  1. Your user record, encryption keys, content and counters are deleted from the primary database immediately. Entries in the retry cache expire within 48 hours; a few bookkeeping rows that hold only IDs, or titles encrypted with a key that no longer exists, are swept by scheduled jobs.
  2. If you signed in with Apple, your Apple sign-in token is revoked.
  3. Your RevenueCat customer record, PostHog person and events, and search index vectors are removed by background jobs, normally within minutes and always within 30 days.
  4. Copies of your data inside encrypted backups age out on the schedule above, at most about 12 months. We do not restore deleted accounts from backups except to recover from a system failure.

Deleting the app from your device does not delete your account. Deleting your account does not cancel an App Store subscription; cancel it in your Apple account settings.

9. Your rights

Depending on where you live, you can ask us to:

— access the personal data we hold about you;
— correct it;
— delete it (also available in-app, Section 8);
— restrict or object to processing based on legitimate interest, including analytics;
— receive a copy of your data in a machine-readable form (the in-app export covers your profile; write to us for a full export of your content);
— withdraw consent to AI processing (Section 4);
— complain to your data protection authority.

Write to support@pero.day. We answer within 30 days and may ask you to confirm that you control the account. We will not treat you differently for exercising a right.

California residents: we do not sell or share personal information for cross-context advertising, and we use the content you capture only to provide the Service.

10. Guest accounts

You can use Pero without signing in. Your data is then tied only to a random identifier stored on your device. If you delete the app or lose the device, we cannot recover that account. When you later sign in with Apple or Google, the guest data is moved into the signed-in account. Guest accounts that stay inactive for 30 days are deleted automatically unless they hold a subscription.

11. Children

Pero is not directed at children under 13, and we do not knowingly collect data from them. Where local law sets a higher age for consent (up to 16 in parts of the EEA), that age applies. If you believe a child has an account, write to support@pero.day and we will delete it.

12. Changes

We will update the effective date at the top when this policy changes and record the change in our changelog. For material changes we will also tell you inside the app. Using Pero after a change takes effect means you accept the updated policy.

13. Contact

Oleh Chausov, Kharkiv, Ukraine. Email: support@pero.day.

Version 2026-09-02.