Privacy Policy
Last updated: August 25, 2026
1. Overview
This Privacy Policy explains how Persim (“we,” “us,” or “our”) collects, uses, and shares information when you use the Persim service (the “Service”). It applies to the Service only, and not to any third-party site or product we link to.
2. Information we collect
Account information. When you register, we collect your email address and authentication credentials, along with any display name or profile details you choose to provide. Authentication is handled by Supabase on our behalf.
Organization information. We record which organizations you belong to and your role within each, in order to determine what you are permitted to access.
Content you submit. We store the prompts, prompt versions, contexts, test cases, and test runs you create, together with the conversations you conduct through the Service. Conversations include message text and, where you use voice features, audio transcripts.
Usage data. We record operational metadata such as model token counts, request timestamps, and feature usage, which we use for quota enforcement, billing preparation, and diagnostics.
Technical data. Our infrastructure providers log standard technical information such as IP address, browser type, and request paths as part of delivering and securing the Service.
3. How we use information
- To provide, maintain, and operate the Service.
- To authenticate you and enforce access controls between organizations.
- To generate model responses in reply to your prompts and conversations.
- To monitor usage, prevent abuse, and investigate security incidents.
- To diagnose defects and improve reliability and performance.
- To communicate with you about the Service, including beta and support messages.
4. Third parties who process your data
We rely on a small number of subprocessors to operate the Service. They receive only the data necessary to perform their function:
- OpenAI — receives the prompt and conversation content you submit, in order to generate text and Realtime voice responses. Content is transmitted to OpenAI each time you run a prompt or conduct a conversation.
- Supabase — provides authentication and the PostgreSQL database in which your account, organization, prompt, and conversation records are stored.
- Vercel — hosts and serves the application, and processes standard request logs (including IP address and user agent) as part of delivering and securing it.
- Google Analytics — where enabled, receives aggregate usage and traffic measurements. See “Cookies and analytics” below for what is and is not sent.
We do not sell your personal information, and we do not share it with third parties for their own advertising purposes.
5. Cookies and analytics
Essential cookies. We use cookies that are strictly necessary to operate the Service, principally to keep you signed in and to maintain your session. These cannot be disabled without breaking authentication.
Analytics. We may use Google Analytics to understand how the Service is used in aggregate — which pages are visited, how often, and from what general region. Where analytics is enabled, it is configured so that no personal information is sent to Google: we do not transmit your email address, account identifier, organization name, or any prompt or conversation content. Google Analytics sets its own cookies and receives a truncated IP address for approximate geographic reporting.
We never send the content of your prompts, conversations, or transcripts to any analytics provider.
[Reviewer note: analytics is not yet enabled in the application. Before turning Google Analytics on, confirm that IP anonymization is active, that no user or organization identifier is passed as a custom dimension, and that a consent mechanism is in place if the Service is offered to visitors in the EEA or UK.]
6. Model training
We do not use your content to train our own models. Content transmitted to OpenAI is subject to OpenAI’s API data usage policies. You should review those policies directly and confirm that the applicable configuration matches your expectations before submitting sensitive material.
7. Data sharing within organizations
The Service is designed for team use. Content you mark as shared, and content you create within an organization, may be visible to other members of that organization according to their role. Administrators may have access to content and usage data associated with their organization. Do not submit material to an organization workspace that you do not intend other members of that organization to see.
8. Data retention
We retain your account and content for as long as your account is active. Deleted records may be retained in a soft-deleted state and in routine backups for a limited period before being purged. When you close your account, we delete or anonymize your personal information within a commercially reasonable period, except where retention is required by law.
9. Security
We use technical and organizational measures to protect your information, including encryption in transit, authenticated access to all data endpoints, and access controls that scope every database query to the requesting user and organization. No system is perfectly secure, and we cannot guarantee absolute security. The Service is in beta and has not undergone independent security certification.
10. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal information we hold about you, and to object to or restrict certain processing. You may exercise these rights by contacting us at contact@persim.app. We will respond within the period required by applicable law.
If you are located in the European Economic Area or the United Kingdom, additional rights may apply under the GDPR, including the right to lodge a complaint with your supervisory authority. [If you intend to serve EEA/UK users, this section requires expansion: identify a lawful basis for each processing purpose, describe international transfer safeguards, and name an EU/UK representative if required.]
11. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date above and, where appropriate, notify you through the Service.
13. Contact
Questions about this Privacy Policy may be sent to contact@persim.app.