Legal
Privacy policy
What personal data this service handles, why it is allowed to, how long it stays, and what you can make us do about it.
In effect from 30 August 2026 · Perdurance
This policy is written under Regulation (EU) 2016/679 (the GDPR) and Spanish Organic Law 3/2018 (LOPDGDD). Perdurance is established in Spain, so those rules apply to it directly rather than by extension.
Two roles, and the difference matters
Perdurance handles personal data in two distinct capacities, and your rights differ depending on which one is in play.
As a controller, for the data that exists because you have an account with us: your email address, your credentials, your billing records, our server logs. We decide why and how that data is handled, and this policy is the notice for it.
As a processor, for everything you send through the service: the request bodies you submit, the responses that come back, every stored chunk, and the provider credentials you configure. We do not decide what is in that content or why it is sent. You do. We hold it, execute against it, and give it back to you. If that content contains personal data, you are its controller and we act only on your instructions. The data processing agreement is the contract for that, and it — not this policy — governs it.
If you are an individual whose personal data reached us because a Perdurance customer put it in a prompt, we are not your controller and cannot lawfully act on your request directly. Write to the customer whose service you were using. If you reach hello@perdurance.dev instead, we will pass the request on where we can identify who it belongs to.
Who the controller is
- Operator
- José Cabrero-Holgueras
- Trading as
- Perdurance
- Established in
- Madrid, Spain
- Contact
- hello@perdurance.dev
No data protection officer is appointed. Article 37 GDPR requires one only where the core activity involves large-scale systematic monitoring or large-scale processing of special-category data, and neither describes this service. Data protection enquiries are answered at hello@perdurance.dev.
What we hold as controller
| Category | What it is | Legal basis | How long |
|---|---|---|---|
| Account | Your email address, a hash of your password, the name of your organisation and its workspaces, and the role you hold in each. Where you sign in through Google or GitHub there is no password, and we store instead the identifier the sign-in provider knows you by. | Performance of a contract — art. 6(1)(b) | While the account exists, then deleted. |
| Sign-up attempts | For each attempt to create an organisation, whether or not it succeeded: a one-way keyed hash of the network address it came from, the email domain, and the address itself reduced to the inbox it reaches — never the address as it was typed. | Legitimate interests — art. 6(1)(f): keeping sign-up open to the public without letting a script take it over. | As long as the rate limit counts it, then swept. Twenty-four hours by default. |
| Address confirmation | When a deployment asks you to confirm your address, a prefix and a one-way hash of the link we sent. The link itself is never written down, which is why a lost one is replaced rather than looked up. | Performance of a contract — art. 6(1)(b) | Until the link expires, then swept. Twenty-four hours. |
| Credentials | Sessions and API keys, each stored as a public prefix and a one-way hash. The secret half is never written down. | Performance of a contract — art. 6(1)(b) | A session lasts 24 hours. An API key lasts until you end it. |
| Operational logs | IP address, timestamp, request identifier and outcome for calls made to the service. | Legitimate interests — art. 6(1)(f): keeping the service up, and detecting abuse of it. | Rolling, and no longer than 90 days. |
| Billing records | What you were charged and for what. Your card is never seen by us — see Payments below. | Legal obligation — art. 6(1)(c): Spanish accounting and tax law. | As long as Spanish accounting and tax law requires. |
| Correspondence | What you write to us, and what we write back. | Legitimate interests — art. 6(1)(f): answering you. | While it is useful to the matter, then deleted. |
Providing this data is not optional in the sense that there is no account without it. There is no other consequence of declining: we ask for nothing we do not need to run the service, and there is no field on any form whose only purpose is marketing.
What we do not do
- We do not train anything on your content. No prompt, response or stored chunk is used to train, fine-tune or evaluate a model, ours or anyone else’s. The software has no such capability.
- We do not sell or rent personal data, and we do not share it for anyone’s advertising.
- We do not track you across the web. There is no analytics package, no advertising pixel and no third-party script on this site. The cookie policy sets out the whole of what is stored on your device.
- We do not make automated decisions producing legal or similarly significant effects about you, and we do not profile you.
Payments
Sales are made through Polar as merchant of record. That means Polar — not Perdurance — is the seller on your invoice, collects the payment, and remits the tax. Your card details are given to Polar and are never transmitted to, or held by, us. Polar handles that data as a controller in its own right, under its own privacy notice at https://polar.sh. What reaches us is the fact of a payment and what it was for.
Who else sees it
Personal data is disclosed to the people below and to nobody else, except where a Spanish court or a competent authority compels disclosure by law.
| Recipient | What for | Where |
|---|---|---|
| Polar | Sale, payment and invoicing, as merchant of record | See the provider’s own privacy notice |
| Clerk | Sign-in for the hosted service: the email address and the identity of the Google or GitHub account it was used with | See the provider’s own privacy notice |
| Resend | Sending the message that confirms an address at sign-up, and nothing else; it carries the address and a one-time link | See the provider’s own privacy notice |
| Cloudflare | The challenge on the sign-up form, which tells a person from a script; it receives the network address the form was submitted from | See the provider’s own privacy notice |
Model providers are a deliberate exception. When the service calls an upstream provider, it does so with your credential under your contract with that provider. That makes the provider your processor, not ours, and puts the terms on which it handles your content between you and it.
Leaving the EEA
Personal data is held in the European Economic Area. Where a recipient named above operates outside it, the transfer is made under an adequacy decision where one covers the destination, and otherwise under the European Commission’s standard contractual clauses together with an assessment of whether local law lets those clauses do their job. You can ask us for the detail of any specific transfer.
Security
Concretely, and not as a claim about outcomes:
- Passwords are hashed with Argon2id and never stored in a recoverable form.
- API keys and session keys are stored as a public prefix and a keyed BLAKE3 hash. The secret half exists only in the reply that issued it — we cannot show you a key again, because we do not have it.
- Provider credentials are encrypted at rest, and one component holds the only path back to plaintext.
- Traffic is carried over TLS.
- Tenancies are isolated from one another, and access within a tenancy is decided per workspace by role.
- Sessions expire 24 hours after they are opened, and using one does not extend it.
No transmission over the internet and no store on a disk is perfectly secure, and this section is a description of what is done rather than a warranty that it will always suffice.
If something goes wrong
A personal data breach affecting data we control is notified to the Spanish Agencia Española de Protección de Datos within 72 hours of us becoming aware of it, unless it is unlikely to result in a risk to anyone, and to affected people without undue delay where the risk to them is high. Where the breach affects data we process on a customer’s behalf, we notify that customer without undue delay and they make the regulatory notification, as the data processing agreement sets out.
Your rights
Over data we hold as controller, you may ask us to:
- Give you a copy of it, and tell you what we do with it (art. 15).
- Correct it where it is wrong or incomplete (art. 16).
- Erase it (art. 17). Closing your account does this, save for records we are obliged to keep.
- Restrict what we do with it while a dispute about it is resolved (art. 18).
- Hand it over in a machine-readable form, to you or to someone you name (art. 20).
- Stop, where we rely on legitimate interests (art. 21).
Write to hello@perdurance.dev. We answer within one month, and say so if a request is complex enough to need the two further months article 12 allows. Exercising a right costs nothing and we will not treat you differently for it. We may ask you to confirm you are who you say you are, and we will ask for no more than is needed to establish it.
If we get it wrong, complain. The supervisory authority for Spain is the Agencia Española de Protección de Datos, at www.aepd.es. You may also complain to the authority where you live or work. You are not obliged to raise it with us first, though we would rather you did.
Children
The service is sold to businesses and to people acting professionally, and is not directed at children. Accounts are not knowingly opened for anyone under 18. If you believe a child has an account here, write to hello@perdurance.dev and it will be closed and its data deleted.
Changes
This policy changes when the service does. The date at the top is the date the current wording took effect. Where a change materially affects how personal data is handled, account holders are told by email before it takes effect rather than after.
Questions about this document go to hello@perdurance.dev.

