Privacy Policy
What Perpendis actually stores.
1. Who is responsible
vbounds is the controller for account data and what you enter into the console. Where you process your own customers' personal data with Perpendis, you are the controller and we are the processor; a data-processing addendum is available from platform@vbounds.com.
2. What we store
| Account | Email address, display name if you give one, and the Firebase Authentication record. Passwords are never visible to us. |
| Workspace | Name, owner, and the list of member user ids. |
| AI systems | Name, base model, use case description, deployment tier, target standard, and the endpoint URL if you supply one. |
| Assessment runs | Scenario, timestamps, the domain result map, the engine result and its signed receipt, and any error message. |
| Evidence packs | A snapshot of the run above, the gap list, and the tokens of links issued from it. |
| Share links | The token, the relying party's name, the expiry, the revocation state, and a read-only copy of the pack. |
| Uploads | Documents you upload (policies, DPAs, incident logs); 20 MB per file; pdf, txt, md, json, png and docx only. |
| Saved array comparisons | Only if you press save on /diff: the name you type, a generated title, and the result numbers — element count, how many elements differ, the index and ulp distance of the first and worst difference, and the dtype. Never the arrays themselves. They are compared in your browser and are not uploaded, saved or not. |
| Daily save counter | One number per account per day, recording how many comparisons you saved, so the published daily limit can be enforced on our side rather than on trust. It holds a count and a date, nothing about the comparison. |
| Enquiries you submit | If you send the enquiry form on /request, we store what you enter — your email address, any name, company or project you give, the option you choose, your message, and the time it was sent — as one record in Cloud Firestore, and email a copy to ourselves so a person can reply. The form is write-only: a submission cannot be read, listed or changed from any browser, only by us. You can still just email us instead — the mailto links open a message in your own client and store nothing here. |
3. What we never store
- Model weights. The engine runs in your browser; tensors are not uploaded.
- API keys, tokens or passwords for your systems. No field for them; the console rejects an endpoint URL carrying a credential in its userinfo or query string.
- Prompts and completions from your production traffic.
- Advertising or cross-site tracking data. No advertising or session-replay scripts, and no advertising or cross-site tracking cookies. We use one privacy-protective analytics tool — Google Analytics 4, in a cookieless configuration that stores nothing on your device and uses no advertising identifiers (see section 4) — so there is still no cookie banner and nothing to consent to for storage on your device.
4. Cookies, local storage and analytics
Firebase Authentication keeps your session in local storage (IndexedDB) so you stay signed in. One key,
perpendis:theme, holds light or dark mode. We set no cookies of our own, and
none of this is read by anyone but this site.
Analytics. We use Google Analytics 4 (provided by Google Ireland Limited) to measure aggregate site traffic — pages viewed, approximate (city- or country-level) location, referrer, and device or browser type — so we can see what is used and improve it. We run it in a privacy-protective, cookieless configuration: it sets no cookies and stores nothing on your device, it uses no advertising identifiers (Google Signals and ad personalisation are switched off), and it does not store your IP address, which is used only in transit to derive coarse location and then discarded. This gives us counts and trends, never a profile of you. Our lawful basis is our legitimate interest in understanding aggregate usage; because nothing is stored on your device, there is no cookie banner. Data may be processed by Google in the United States under the EU–US Data Privacy Framework and the Standard Contractual Clauses. You can opt out at any time with the Google Analytics Opt-out Browser Add-on; and because analytics runs cookielessly and with advertising features disabled for every visitor by default, there is nothing to sell or share — the outcome a Global Privacy Control signal is designed to secure.
5. Who can read your data
- Members of your workspace, enforced by server-side rules; only the owner can change the membership list.
- Anyone holding a live share link you issued: the pack snapshot, the system description, the relying party's name, and the issue and expiry dates — not your other systems, runs, packs or uploads. Put nothing in a system description you would not show a relying party.
- vbounds staff, only where necessary to operate or support the service.
6. Processors and where data lives
Google is our infrastructure and analytics provider. Google Firebase (Hosting, Authentication, Cloud Firestore, Cloud Storage and Cloud Functions) is our infrastructure processor: it holds your account, console and enquiry-form data in Google Cloud regions and processes it solely on our instructions. Google Analytics 4 is our analytics processor: it receives only the cookieless, aggregate traffic pings described in section 4. When you submit the enquiry form, a Cloud Function sends a copy to our own mailbox through Resend (our email-delivery provider) so a person can reply; if instead you use the “email us” links, that message reaches the same mailbox through Namecheap (our domain's email-forwarding provider). Both carry that one message in transit, and no CRM, marketing platform or other vendor is in the path. Unlike Firebase, Google may also use analytics data for its own purposes, as set out in its privacy policy. Transfers outside the UK/EEA rely on the EU–US Data Privacy Framework and the Standard Contractual Clauses in Google's terms. Our DPA names Google (Firebase and Analytics), Resend (email delivery) and Namecheap (email forwarding) as our sub-processors; we give 30 days' notice before adding another.
7. How long we keep it
- Account and workspace data: while the account is open.
- Runs, packs and share documents: until you delete the system they belong to — that removes its runs, packs and share links.
- Saved array comparisons: until you delete them — the delete on /diff is a real delete, not a hidden flag.
- Daily save counters: one small record per day you saved something, kept while the account is open and removed with it.
- Consultation emails: deleted within 24 months of the last contact, or sooner if you ask — reply to the thread or email platform@vbounds.com.
- Form submissions stored in Firestore: kept while we act on the enquiry and deleted within 24 months of our last exchange with you, or sooner if you ask.
- After you ask us to close an account: deleted within 30 days.
8. Your rights
In the UK and the EEA you have the right to access, correct, delete, restrict, object to and port your personal data, and to complain to a supervisory authority (the ICO in the UK). Email platform@vbounds.com; we respond within 30 days. We do not make automated decisions with legal effects about individuals.
9. Security
Authorization is enforced by Firestore and Cloud Storage rules on the server, not in the browser, and every rule is tested. See the security page, including how to report a vulnerability.
10. Breach notification
If personal data you entrusted to us is exposed, we tell affected account holders and, where required, the relevant supervisory authority within 72 hours of becoming aware, with what we know at the time rather than waiting for a complete picture.
11. Children
Perpendis is a business tool, not directed at anyone under 18.
12. Changes
We post the updated date above and email account holders about any change that materially affects them.