Last updated August 5, 2026
When you sign in with GitHub OAuth, we receive your name, email address, and avatar URL. We also store the organizations, packages, and package archives you create or publish, and basic metadata about bearer tokens (name, last-used date — never the raw token value).
Your GitHub profile is used to authenticate you and identify you within your org. We don't run ads, don't use ad-tracking, and don't sell your personal data to anyone.
Account and package metadata live in PostgreSQL (hosted on Supabase). Package archives are stored on Backblaze B2. The application itself runs on Fly.io. Org invites are currently shared as a direct link; we plan to send them by email via Resend once that's built. All are commercial infrastructure providers bound by their own data-processing terms.
Perchly sets one strictly-necessary session cookie to keep you signed in. We don't use analytics or ad-tracking cookies.
You can ask us to access, export, or delete the personal data we hold about you at any time — email the support address below and we'll handle it manually. If you delete your GitHub-linked account's data, any orgs where you're the sole owner will need a new owner assigned first.
If this policy changes in a way that affects how we handle your data, we'll update the date above and, for material changes, email affected users directly.
Questions or complaints about how we handle your data go to support@perchly.dev — we'll respond as soon as we can.