Who is responsible
pergrn is operated by Troels Hedegaard. For privacy, account, or data requests, email trolz@hey.com.
pergrn is available worldwide. Privacy rights can differ by location; mandatory rights that apply where you live are not limited by this policy.
Data pergrn handles
- Account data: your email address, Supabase user ID, authentication records, and essential session cookies.
- Project data: project names, descriptions, statuses, technology labels, links, environment notes, integration identifiers, ordering, notes, and checklist state.
- Collaboration data: invitee emails, membership and invite timestamps, and live presence data such as email, user ID, and online time within a shared project.
- Uploads: project logos and banners. These are stored in publicly readable buckets and should not contain confidential or sensitive information.
- Reading and research data: saved article details, research names, brain dumps, generated findings, links, and status.
- Feedback: your account email and user ID, category, message, current app path, and submission time.
- Optional integration data: Vercel or Expo access tokens, team/project identifiers, and deployment/build metadata when you choose to connect those services.
- Technical data: standard request and hosting logs, error diagnostics, browser-held preferences, and offline project copies described below.
Why the data is used
- Authenticate you and maintain your session.
- Store, sync, display, and share the projects you choose.
- Provide realtime and offline-first notes and links.
- Run optional integrations and AI research that you start.
- Respond to feedback, support, privacy, and security requests.
- Operate, secure, debug, and improve the service.
- Meet legal obligations where they apply.
Depending on the context, processing is necessary to provide the service you request, based on legitimate interests in running and protecting pergrn, directed by your optional feature choices, or required by law.
AI research
AI research is optional and runs only when you start it. The research name and brain dump are sent through Vercel AI Gateway to Anthropic for agentic web research. The original input and gathered context are then sent through the gateway to OpenAI for structured findings.
Search queries are derived from your input, and relevant public-web results become part of the research context. Do not submit passwords, access tokens, confidential client information, special-category personal data, or other information you would not want processed by those providers.
Service providers and data sharing
pergrn uses service providers to operate the product. Current recipients include Supabase for authentication, database, storage, and realtime features; Vercel for hosting and AI Gateway; Resend and configured SMTP for authentication email; Anthropic and OpenAI for user-started research; and Vercel or Expo APIs when you connect those integrations.
Project collaborators receive access to the project you share, including its metadata, notes, links, member emails, and live presence. Public logo and banner URLs can be accessed by anyone who has the URL.
Personal data is not sold, and the current application contains no advertising pixels or marketing analytics integration. Providers may process technical data under their own terms and retention practices.
Cookies and browser storage
Essential Supabase cookies maintain authentication. pergrn also stores your theme under theme and project-card choice under pergrn:project-card-view in localStorage.
Notes and links are read from and written to the server directly; pergrn does not keep an offline copy of project content in your browser. Versions before September 2026 stored one in IndexedDB for offline editing, and a copy left behind by such a version remains until browser site data is cleared.
Retention and deletion
Account and product content are generally retained while the account or content remains in use. Current controls let you delete projects, reading-list entries, research items, collaborators, and optional Vercel/Expo connections.
There is not yet a self-service account-deletion or full export flow. Email trolz@hey.com to request access, correction, export, restriction, objection, feedback removal, or full account deletion.
Clearing a project image from the form does not necessarily remove the underlying public storage object immediately. Browser IndexedDB, operational logs, backups, and provider records can also remain for a limited period or require separate handling. Contact the address above if a public upload or other residual copy needs removal.
International processing
Providers and users may be located outside Denmark or the European Economic Area. Data can therefore be processed in other countries. Applicable transfer safeguards and mandatory local protections apply where required; provider-specific processing is also governed by the provider's terms.
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to complain to a data-protection authority. Contact trolz@hey.com to exercise a right. Identity may need to be verified before a request is completed.
Children
pergrn is not directed to children who cannot legally agree to these terms or provide their own data under applicable law. If you believe a child has provided personal data improperly, contact the address above.
Changes and questions
This policy may change as the product, providers, or legal obligations change. Material updates will be reflected by a new last-updated date and, where appropriate, an in-product notice. Questions can be sent to trolz@hey.com.