Back to Perco

Privacy Policy

How Perco collects, uses and protects your personal data, and the rights you have over it.

Effective date: 20 July 2026 · Last updated: 26 July 2026

These documents are published in English, and the English version is the governing text.

1. Who we are

Perco ("we", "us") is a coffee brewing log operated by LightRoast Studio, a sole trader (eenmanszaak) registered with the Dutch Chamber of Commerce (KvK) under number 98824546, at Blauwe Loper 60, 5612 TA Eindhoven, Netherlands. We are the controller of your personal data.

For any privacy question, or to exercise your rights, contact us at privacy@perco.app.

If you are in the EU/EEA, you also have the right to lodge a complaint with your local supervisory authority. Ours is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

2. What data we collect

  • Account: your email address and password (passwords are stored only as a salted hash by our authentication provider — we never see them). If you sign in with Google, we receive your basic Google profile (name, email address and profile picture) from Google instead of a password.
  • Profile: display name, avatar, bio, location text and website, if you choose to add them.
  • Your coffee data: brews, beans, equipment, recipes, cafés you save, and café visits (including notes, ratings and any photos you upload).
  • Social data: who you follow, followers, comments, likes and notifications.
  • Privacy settings: your visibility and feed preferences.
  • Payment status: if you buy Premium, we store your entitlement (that you have access and until when). Card and billing details are handled by our payment provider, Paddle — they never reach our servers.
  • Technical and security data: to run and protect the service we process limited technical data, including your IP address, request metadata, device/browser information, and rate-limit counters. Where you consent, we also process product-analytics and session-diagnostic data (see our Cookie Policy).

We do not collect special categories of data (such as health, political or biometric data), and we ask you not to put such data into free-text fields like brew notes.

3. How we use your data and our legal bases

  • To provide Perco — create your account, store your brews, show your feed and enable the social features according to your visibility settings. Legal basis: performance of our contract with you.
  • To keep Perco secure and working — rate limiting, abuse prevention, and essential error and crash monitoring so we can find and fix problems. This may involve limited technical data, including your IP address and account ID, attached to error reports. Legal basis: our legitimate interest in a safe, reliable service; you can object (see section 8).
  • To process Premium purchases. Legal basis: performance of our contract with you.
  • To send you service messages (password resets, security notices, important changes to the service or these terms). Legal basis: contract / legitimate interest.
  • To send you optional product updates about Perco, if you have asked to receive them (for example, as a beta user). Legal basis: your consent, which you can withdraw at any time.
  • For optional product analytics and session diagnostics — to understand what to improve. These do not run until you opt in. Legal basis: your consent, which you can give or withdraw at any time.

We do not make automated decisions that produce legal or similarly significant effects about you, and we do not carry out that kind of profiling.

4. Your social and public content

Perco is a social app, so some of what you create is meant to be seen by others. You control this through your visibility settings. Content you set to be visible to your followers or to the public can be seen by those users, and public content may be accessible to people who are not logged in and could be indexed by search engines. Please treat anything you make public accordingly. You can change a piece of content's visibility, or delete it, at any time.

5. Sharing and subprocessors

We do not sell your personal data, and we do not share it for cross-context behavioural advertising.

We rely on a small set of service providers ("subprocessors") that process data on our behalf, under contract — for hosting, database and authentication, email, error monitoring and payments. See the full list, with each provider's role, location and safeguards, on our Subprocessors page (/subprocessors).

If you sign in with Google, Google processes your sign-in as an independent identity provider under its own privacy policy.

We may disclose data where required by law, or where reasonably necessary to protect our rights or the safety of our users. If we are ever legally compelled to disclose your data, we will tell you unless we are legally prohibited from doing so.

6. International transfers

Your data is stored within the EU where possible — our database, authentication and file storage are hosted in Frankfurt, Germany. Some subprocessors are based outside the EEA (for example in the United States); where that is the case we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. The specific locations and safeguards for each provider are on the Subprocessors page.

7. How long we keep your data

  • Account and content: for as long as your account exists.
  • On account deletion: we permanently and irreversibly erase your personal data — your account, brews, notes, photos and comments — from our live systems. Beans you added to the shared catalogue remain available to other users but are anonymised, so they are no longer linked to you.
  • Server request logs: short-lived hosting logs, retained for about 24 hours.
  • Error and diagnostic data: technical error reports are retained for up to 30 days, then deleted.
  • Payment records: we keep the minimum entitlement and transaction records required by accounting and tax law for as long as the law requires.

8. Your rights

Depending on where you live, you have some or all of these rights: access, rectification, erasure, portability, restriction, objection, and the right to withdraw consent.

You can exercise the two most common rights yourself, right now, from your Profile: export a copy of your data, and permanently delete your account. For anything else — including objecting to processing we carry out under legitimate interest — email privacy@perco.app and we will respond within the timeframes the law requires (generally within one month under the GDPR). Exercising your rights is free, and we will not treat you differently for doing so.

9. EEA & UK

If you are in the EEA or the UK, the GDPR / UK GDPR applies to our processing. You have the rights listed above and the right to complain to your supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens).

10. California (CCPA/CPRA)

If you are a California resident: we do not sell or share your personal information as those terms are defined under the CCPA/CPRA. You have the right to know what we collect (see section 2), to request deletion, to correct inaccurate information, and not to be discriminated against for exercising these rights.

To exercise them, use the export and delete tools in your Profile or email privacy@perco.app.

11. Children

Perco is not intended for children. You must be at least 16 years old to create an account. If we learn that we have collected personal data from someone under 16, we will delete it.

12. Security

We protect your data with encryption in transit, row-level access controls so users can only reach their own data, hashed passwords, and least-privilege access to our systems. No service can promise perfect security, but we take measures appropriate to the data we hold. If a personal-data breach occurs that is likely to affect your rights, we will notify you and the relevant supervisory authority as the law requires.

13. Changes to this policy

We may update this policy as Perco evolves. When we make material changes we will update the effective date and, where appropriate, notify you by email. The "Last updated" date at the top always reflects the current version.

Contact

Questions about this document or your data? Email us at privacy@perco.app.