Privacy policy
The short version. Perfica is local-first. Your projects, boards, chats and API keys stay on your computer. What the agents send to AI models goes straight from your computer to the providers you pick, not through us. We receive personal data only if you create an account, buy Perfica Cloud, send us a bug report or write to us. We do not sell personal data, and neither the app nor this website has advertising or tracking.
1. Who is responsible
Uezar Labs, which operates Perfica, is the controller (responsable) of the personal data described here, under Chile’s Ley 19.628 as amended by Ley 21.719 and, where they apply, the EU and UK General Data Protection Regulation (GDPR). Contact: privacy@perfica.dev.
2. What stays on your computer
These are kept on your computer and are never sent to us:
- your projects and their files;
- your boards (loopspaces), the Manager’s chats, run logs and reports;
- your API keys, stored encrypted on the device;
- your settings;
- voice dictation: the speech model runs on your computer, and your audio is not sent anywhere.
You control this data. You can delete it by deleting the files, or by uninstalling the app and removing its data folder.
3. What leaves your computer, and where it goes
To the AI model providers you choose
Prompts, and the files, command output and images the agents read, are sent from your computer to the model providers you pick (for example OpenAI, Anthropic, Google, OpenRouter or NVIDIA), with your own API key. Local model servers such as Ollama or LM Studio keep them on your machine. We do not receive or see this data. Each provider handles it under its own terms and privacy policy.
Web search and web pages
When an agent searches the web, the query goes to the search service in use: Brave or Tavily if you added a key for one; otherwise the search engine bundled with the app (SearXNG), which sends the query from your computer to public search engines, and if that fails, to public developer sites (npm, GitHub, Stack Overflow, MDN, Wikipedia). Pages the agents open are fetched directly from your computer.
Updates and downloads
The app contacts other services to work, and each of them receives your IP address and ordinary technical request data, as any web request does:
- GitHub, to check for and download updates, and to download the list of model prices;
- Hugging Face and jsDelivr, to download the speech model when you turn on dictation;
- Google’s storage, to download the browser the agents use to look at web pages;
- Docker Hub, if you use the Docker sandbox;
- OpenRouter and, with your key, Google, to list the models available.
We receive nothing from these requests.
Bug reports
Only when you choose to send one. A report is filed through your own GitHub account as a public issue on our GitHub repository. It contains what you write and attach, plus the app version and your operating system. Anyone can read it, so do not include personal data you do not want published.
Where the app sends a bug report to our own server instead, it shows you exactly what will be sent, with keys, file paths and project content removed, and sends nothing until you confirm.
Usage statistics, only if you turn them on
Where the app offers usage statistics, they are off until you turn them on, and you can turn them off at any time. When on, the app sends events about how it is used (for example which first-run steps were completed) to PostHog, which processes them for us. They never include your project content, file paths, prompts, model output or keys, and they are not linked to your name or account.
4. What we process, why, and on what legal basis
| Data | Why | Legal basis |
|---|---|---|
| Account, if you create one: email, name, password (stored only as a hash), and the devices you sign in on (a device’s public key, label and when it was last seen) | To run your account, sign you in and keep it secure | Contract |
| Cloud sync: the boards you sync (loops, bubble settings and prompts, task cards) | To keep your boards the same across devices | Contract |
| Key vault: API keys you upload, encrypted with AES-256-GCM, and a masked hint to tell them apart | To store your keys and hand them only to your signed-in devices | Contract |
| Purchases: your email, country, what you bought, subscription status and transaction references, received from Paddle | To give you Cloud, handle refunds, and keep accounting and tax records | Contract; legal obligation |
| Bug reports you send | To find and fix problems | Consent (you choose to send one); legitimate interest in fixing the software |
| Usage statistics, only if you turn them on | To learn where people get stuck and improve the app | Consent, which you can withdraw at any time |
| Messages you send us, and requests about your data | To answer you and handle your request | Legitimate interest; legal obligation for data requests |
| Website: technical data such as your IP address, handled by our hosting provider | To deliver and protect perfica.dev | Legitimate interest |
Payments. Paddle, our merchant of record, collects your payment and billing details and is responsible for them under its own privacy policy. We never receive your full card details.
This website is a static site hosted on Cloudflare Pages. It uses no analytics and no tracking cookies. It stores your light or dark theme choice in your own browser, and nothing else.
We do not make decisions about you based only on automated processing.
5. Who we share it with
We share personal data only with the service providers that help us run Perfica, and only what each needs:
- the hosting provider that runs our account and sync server;
- Paddle, for purchases (as an independent controller);
- Cloudflare, which hosts this website;
- GitHub, for bug reports and releases;
- PostHog, only if you turn on usage statistics;
- our email provider, for messages you send us.
We also disclose data when the law requires it. We do not sell personal data or share it for advertising.
6. International transfers
Some of these providers process data outside Chile and outside your country, including in the United States. When personal data is transferred, we rely on the safeguards the law requires, such as standard contractual clauses or an adequacy decision, or the transfer is necessary to provide the service you asked for.
7. How long we keep it
- Account, sync and vault data: while your account exists. When you delete your account (you can do it in the app), it is deleted from our systems, and from backups as they are replaced.
- Purchase records: as long as tax and accounting law requires.
- Messages and data requests: as long as needed to handle them and any follow-up.
- Bug reports on GitHub: until the issue is deleted. Ask us and we will delete one.
- Usage statistics: no longer than needed to understand how the app is used, and deleted when you ask.
8. Your rights
You have the right to:
- access the personal data we hold about you;
- rectify it if it is wrong or incomplete;
- delete it (supresión);
- object to its processing (oposición);
- portability: receive it in a structured, commonly used format, or have it sent to someone else;
- restrict or block its processing while a request is resolved;
- withdraw consent at any time, where we rely on it, without affecting what was done before.
To exercise any of them, write to privacy@perfica.dev. It is free. We may ask you to confirm your identity, and we answer within 30 days; if a request is complex, we may extend that once, as the law allows, and tell you why. Much of your account data can also be seen and deleted in the app itself.
If you are not satisfied with our answer, you can complain to Chile’s Agencia de Protección de Datos Personales or, in the EU or UK, to your local data protection authority.
9. Security
API keys are stored encrypted, on your device and in the vault. Passwords are stored only as hashes. Devices sign in with their own keys, and connections to our servers are encrypted. No system is perfectly secure. If a breach affects your personal data, we will tell you and the authorities as the law requires.
10. Children
Perfica is not meant for anyone under 16, and we do not knowingly collect personal data from children.
11. Changes to this policy
We will publish any new version on this page with a new version number and effective date. When this policy or the terms change, the app asks you to accept the new version before agents work on your computer again.
12. Language
This policy is published in English and Spanish. If the two versions differ, the English version controls.
13. Contact
Uezar Labs. Privacy and data requests: privacy@perfica.dev. Everything else: support@perfica.dev.