Legal
Privacy Policy
Last updated: 26 September 2026
Effective date: 26 September 2026
1. Who we are
Perfingo Pte. Ltd. (UEN 202232781W), a company incorporated in Singapore ("Perfingo", "we", "us"), operates the Perfingo personal financial planning application, available on the web and, where released, as an app for iOS, iPadOS and Android (the "App").
This policy explains what personal data and financial information the App collects, why, who we share it with, and what choices you have. It is written to satisfy Singapore's Personal Data Protection Act 2012 ("PDPA").
Data Protection Officer:Darren Lee, [email protected]
2. What we collect
2.1 Account information
When you create an account we collect your email address and password (the password is stored only in hashed form, by Supabase Auth), and generate an internal account identifier.
2.2 Financial plan and household data
To provide the planning and tracking features, you enter (or import) financial information directly into the App, including:
- Plan inputs: income, expenses, CPF details, housing, insurance, liabilities, goals, assumptions, family and dependant information, protection needs, current assets, emergency fund and financial-freedom targets, and general household information.
- Tracked actuals: bank and brokerage accounts you add manually, transactions, account balances, investment holdings, and portfolio observations.
- Imported bank and brokerage statements: if you use statement import, the file you upload is sent to our statement-extraction service, which reads the transactions and balances out of it with the help of an AI model (see §4). The transactions and balances are saved to your plan. The uploaded file itself is not kept once extraction finishes.
This is financial data about you (and, where you share a household, your partner). We treat it as sensitive. It is never used for advertising and it is never sold.
2.3 Household sharing: who inside Perfingo can see your data
- Couples: a partner you invite into your household can see and, depending on the access you grant, edit the shared plan and tracked actuals.
- Advisors: if you work with a financial advisor through Perfingo, you can grant that advisor's account view-only, plan-editing, or full access (including your tracked accounts). You control this and can change or remove it at any time.
Data shared this way is visible only to the household members and advisor you have granted access to. It is not shared with any other Perfingo user.
2.4 AI reports and chat
The App can write periodic reports on your plan and answer questions about it in a chat. To do this, the relevant figures from your plan and tracked actuals (for example balances, spending by category, goal progress) and any question you type are sent to a third-party AI model provider (see §4). The reports and chat history are saved to your account so you can read them again.
2.5 Bug reports you send us
If you use the App's "Report a problem" feature, whether you open it yourself or the App prompts you after something goes wrong, we collect:
- The description you type.
- A screenshot of your screen, if you choose to include one (on by default; you can preview it and turn it off before sending). A screenshot may show financial figures and anything else that was on screen.
- Your app version and device or browser details, the screen you were on, and a short trail of your recent actions (for example that a save failed), never the amounts or account content behind those actions.
- Technical error details when the report follows an error: a coarse error category and, where available, a stack trace.
- Your PostHog session identifier (see §3), so the report can be matched to a replay of that session.
- Your account identifier if you are signed in. Your email address is included only if you tick "okay to email me about this".
- For reports sent while signed out, a hashed form of your network address, kept only to cap how many reports one address can send in an hour.
Reports are stored in our database, emailed to our team, and may be filed as a private issue in our engineering team's GitHub repository, visible only to the Perfingo team. We use them only to diagnose and fix problems with the App.
3. Usage analytics
We collect information about how you use the App, which may include session recordings by our third-party analytics provider, to fix problems and improve it. This includes the screens you visit, the actions you take, and automatic error and crash reports. Our analytics provider is PostHog, which processes this data in the United States (see §8).
4. Who we share your data with
We use the following service providers to operate the App. Each receives only the data it needs for its function, under contractual terms that require it to protect the data and not use it for its own purposes.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, sign-in, and file storage | Your account details and all the plan, tracking, report and bug-report data described in §2 |
| Stripe | Payments for subscriptions bought on the web | Payment details and billing contact information. We never see or store your full card number |
| RevenueCat, with the Apple App Store and Google Play | Subscriptions bought in a mobile app, and keeping your subscription status in sync | Purchase and subscription-status information. Apple or Google, not Perfingo, process the payment itself |
| PostHog | Usage analytics, session recordings, and error reports | See §3 |
| Railway | Hosting for our backend services (plan calculation, market data, statement extraction, AI reports and chat) | Your data while those services work on it, for example your plan inputs when a projection is calculated |
| Cloudflare | Hosting and network delivery for the web App and this website | Your network address and the requests your browser makes |
| Resend and Brevo | Sending email: sign-in, password reset, account and service notices, bug-report alerts | Your email address and the content of the email |
| GitHub (private repository) | May hold a copy of a bug report as a private engineering issue (§2.5) | The content of the bug report |
| AI model providers | Reading transactions out of statements you import (§2.2), and writing AI reports and chat answers (§2.4) | The statement file you upload, or the plan figures and question needed for the report or answer, for as long as it takes to produce the result |
We choose AI model providers for quality and cost and may change them from time to time. We use them through their paid business APIs, and only choose providers whose terms do not allow them to train their models on the data we send. You can ask us at any time which providers we currently use.
We do not sell your personal data, and we do not share it with data brokers or advertisers.
5. Why we process your data
We process your data with your consent, given when you create an account, and to the extent the PDPA allows without consent, for:
- providing the planning, tracking, AI and household-sharing features you sign up for;
- processing subscription payments and managing your access to paid features;
- operating, securing and improving the App, including diagnosing bugs and crashes (§3);
- communicating with you about your account, billing, the service and support requests;
- complying with our legal obligations.
6. Your rights
Under the PDPA, you can:
- ask for access to the personal data we hold about you;
- ask us to correct data that is wrong;
- withdraw consent to our collection, use or disclosure of your data. We will tell you what withdrawing means first; for example, we cannot provide the App without your plan data;
- delete your account yourself at any time, in the App at Profile → Delete Account (see §7 for what happens next).
To do any of this, email our Data Protection Officer at [email protected]. We will reply within 30 days.
7. How long we keep your data
- While your account is open, we keep your plan, tracking, report and chat data so the App stays useful to you.
- When you delete your account, your sign-in is removed and your data is taken out of use immediately, then permanently erased within 30 days. If you share a household with a partner who keeps their account, the shared household stays with them.
- Payment records (what was charged, when, and for which subscription) are kept for 5 years, as Singapore law requires for business records, with your personal details removed from them when your account is erased.
- Bug reports are deleted within 12 months of being sent.
- Analytics data (§3): session recordings are kept for up to 90 days, and usage and error data for up to 7 years.
8. Where your data is stored and transferred
Your account, plan, tracking, report and bug-report data is stored with Supabase in its Singapore region.
Some of our providers process data outside Singapore: PostHog in the United States, and our AI model providers, email providers, Stripe and GitHub in countries that include the United States and China. When we transfer your data outside Singapore, we make sure the recipient is bound, by contract or by law, to protect it to a standard comparable to the PDPA, as the PDPA's Transfer Limitation Obligation requires.
9. Children
The App is not directed at children and is not intended for anyone under 18.
10. Changes to this policy
We may update this policy from time to time. If a change materially affects how we handle your data, we will tell you by email and in the App at least 30 days before it takes effect. For smaller changes, we update the "Last updated" date above.
11. Contact us
Perfingo Pte. Ltd., UEN 202232781W
60 Paya Lebar Road, #07-54, Paya Lebar Square, Singapore 409051
Data Protection Officer: Darren Lee, [email protected]
See also our Terms of Service and PDPA Collection Notice.