← Perkfolio

Privacy Policy

Last updated August 23, 2026

Overview

Perkfolio is an independent, personal project that helps you track recurring credit card statement credits and expiring offers across your card wallet. It is not affiliated with, endorsed by, or sponsored by any credit card issuer, Plaid Inc., Google, or Slack Technologies, LLC. This policy explains what information Perkfolio collects, how it's used, and the choices you have.

Information We Collect

  • Account information — your email address, and, if you sign in with Google, your name and profile photo, handled by our authentication provider (Supabase Auth).
  • Card and benefit data you enter — the cards you add, benefits you track, redemption history, notes, and ROI inputs.
  • Bank connection data (optional) — if you connect an account via Plaid, we receive account and institution metadata and transaction data, used only to suggest possible redemptions for you to confirm.
  • Google Tasks access (optional)— if you connect Google Tasks, we use it solely to create and check off reminder tasks in a dedicated "Perkfolio" task list.
  • Gmail access (optional)— if you connect Gmail, we read it only to find loyalty-program redemption confirmations, and store only the subject, sender, and Gmail's own snippet of a matching message — never the full body — for you to confirm or dismiss.
  • Notification settings — an optional Slack webhook URL you provide, used only to deliver your digest to your own Slack workspace, and — if you turn on push notifications in the iOS app — the device token Apple issues for that phone, used only to deliver your digest to it.
  • Usage and analytics data — pages visited, approximate location, device and browser type, collected via Google Analytics using cookies, in aggregate form.

How We Use Information

We use this information to operate the app: showing your dashboard, tracking expiration windows, matching bank transactions to benefits, sending Slack digests and Google Tasks reminders you've opted into, and improving the product based on aggregate usage patterns. We do not sell your information, and we do not use your financial or benefit data for advertising.

How We Store and Protect Information

Data is stored in a Postgres database (via Supabase) protected by row-level security, so each account can only read its own data. Plaid access tokens and Google refresh tokens are never stored in plain form — they're encrypted via Supabase Vault and can only be decrypted by server-side functions, never by the application directly or by other users. Database backups are encrypted and retained on a rolling basis.

Third-Party Services

Perkfolio relies on the following third parties, each of which processes data under its own privacy policy:

  • Supabase — database, authentication, and encrypted secret storage.
  • Vercel — application hosting and scheduled jobs.
  • Plaid — optional bank account linking and transaction retrieval.
  • Google — optional sign-in, optional Google Tasks integration, and optional read-only Gmail access for redemption detection.
  • Slack — optional digest delivery to a webhook you provide.
  • Resend — optional digest delivery by email.
  • Apple Push Notification service — delivery of push notifications to the iOS app, if you turn them on.
  • Google Analytics — aggregate product usage analytics.

Data Sharing

We don't sell or rent your data. Information is only visible to you. We may disclose information if required by law.

Your Choices

  • Disconnect Plaid or Google at any time from Settings — this deletes the stored token immediately and revokes access.
  • Export your data as a CSV from the app at any time.
  • Delete your account and everything in it — cards, credits, redemptions, and any connected tokens — from Settings → Danger zone → Delete account. It takes effect immediately and can't be undone. If you'd rather we do it for you, email sanchitcop19@gmail.com.

Data Retention

We keep your data for as long as your account is active. Deleting your account from Settings removes it — including any connected bank or Google tokens — immediately; if you ask us to delete it by email instead, we do so within a reasonable time. Encrypted backups age out on their own rolling schedule.

Children's Privacy

Perkfolio is not directed at, and should not be used by, anyone under 16.

Changes to This Policy

We may update this policy as the app evolves. Material changes will be reflected by updating the "Last updated" date above.

Contact

Questions about this policy? Email sanchitcop19@gmail.com.