Skip to content

Privacy policy

On this page 12 sections

Last updated: October 2, 2026

Who we are

Perception is operated by aimley OÜ, a private limited company registered in Estonia (registry code 14585949) with its registered address at Tornimäe tn 5, 10145 Tallinn, Estonia. In this policy, "Perception", "we" and "us" mean aimley OÜ.

This policy covers perception.to, app.perception.to, the Perception MCP connector and the Perception REST API. It explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and what you can ask us to do with it.

aimley OÜ is the controller of the personal information described here. If your company has signed a data processing agreement with us, that agreement governs the data we process on your company's behalf.

Information we collect

Information you give us

  • Your name, email address and profile photo when you create an account, including what Google shares with us if you sign in with Google
  • Your company name, your role (in-house, agency or freelance) and the companies, people and topics you choose to track
  • What you create in the product, such as questions you ask the AI analyst, saved prompts, spaces, reports, research notes and API key labels
  • Email addresses of teammates you invite to your plan
  • Billing details. Stripe collects and stores your card details. We keep your Stripe customer ID, plan, billing email and payment status.
  • Messages you send us by email, through the in-app feedback form or through the chat widget on perception.to
  • Your email address if you subscribe to our newsletter

Information we collect automatically

  • Device and browser type, operating system, IP address and the approximate location it implies
  • A device ID we derive from your browser, language, screen and timezone settings when you sign in to app.perception.to, used to keep track of your active sessions
  • Pages you visit, features you use and time spent, measured with Google Analytics
  • Referral sources and campaign parameters
  • MCP and API usage: which tool or endpoint you called, when, response size, latency and the credits it used
  • Error logs from our own servers

Cookies and similar technologies

perception.to and app.perception.to use Google Analytics 4 to measure traffic and feature use. perception.to loads it through Google Tag Manager. The Intercom chat widget on perception.to sets its own cookies so a conversation carries across pages. Firebase Authentication uses your browser's storage to keep you signed in to app.perception.to. You can block or delete cookies in your browser settings.

How we use your information

  • To run your account and deliver the product, including briefings, alerts, dashboards, and MCP and API responses.
  • To answer the questions you ask our AI features. This sends your question to one of the AI providers listed below.
  • To bill you and manage your subscription.
  • To send service emails, such as password reset links, billing notices, briefings and trial reminders.
  • To send our newsletter and product updates if you opted in. Each one has an unsubscribe link.
  • To enforce rate limits and usage allowances, and to stop abuse such as repeated free-trial signups.
  • To fix bugs and decide what to build next, using usage and error data.
  • To meet our legal, tax and accounting obligations.

We rely on our contract with you to run your account, deliver the product and bill you. We rely on our legitimate interests for security, abuse prevention, product analytics and service emails. We rely on your consent for the newsletter. We rely on legal obligation for tax and accounting records.

Who we share it with

We never sell your personal data. We share it with the service providers below, and each one receives only what it needs to do its job for us.

  • Google (Google Cloud, Firebase and the Gemini API): hosting, databases, sign-in and AI processing
  • Cloudflare: website hosting, DNS, network security and our API gateway
  • Stripe: payments and invoices
  • Brevo: account emails and the newsletter
  • OpenAI, Anthropic, Perplexity and DeepSeek: AI models that process the questions you ask our AI features and the records we retrieve to answer them
  • Intercom: the chat widget on perception.to
  • EmailJS: delivers messages from the in-app feedback form
  • Google Analytics: website and app analytics
  • Telegram: internal alerts to our team. A new signup or subscription alert includes your name, email, company and plan.

We also share personal information in these cases:

  • Legal compliance: when the law, a court order or the protection of our legal rights and safety requires it
  • Business transfers: as part of a merger, acquisition or asset sale, with advance notice to you
  • Your consent: with your explicit permission, for purposes this policy does not cover

Data security

Here is how we protect your information today:

  • All traffic to our sites, app and API uses HTTPS. Google Cloud and Cloudflare encrypt stored data by default.
  • Firebase Authentication handles passwords. We never see or store them.
  • Database security rules limit your account data and content to you and your team, deny anything they do not explicitly allow, and block browser access to API key records.
  • Admin tools and admin data require an admin account, checked on our servers.
  • Our core infrastructure providers, Google Cloud, Cloudflare and Stripe, hold SOC 2 and ISO 27001 certifications for their own services.

No method of transmitting or storing data over the internet is fully secure. If a breach affects your personal information, we will tell you and the relevant authority as the law requires.

Your privacy rights

Depending on where you live, you may have the following rights over your personal information:

  • Access: ask for a copy of the personal data we hold about you
  • Rectification: ask us to correct inaccurate or incomplete data
  • Erasure: ask us to delete your personal data, subject to legal retention requirements
  • Portability: ask for your data in a machine-readable format
  • Restriction: ask us to limit how we process your data
  • Objection: object to processing based on our legitimate interests
  • Withdraw consent: withdraw consent you gave us at any time

To exercise these rights, contact us using the details below. We will respond within 30 days. You can also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or the data protection authority where you live.

API and MCP connector access

Perception runs a remote MCP (Model Context Protocol) server and a REST API that let AI assistants and other applications query our narrative intelligence data. When you connect through either one:

  • Authentication: The MCP connector signs you in with OAuth 2.1 and PKCE. For API keys, we store a SHA-256 hash of each key and check every request against it. For personal keys you create in account settings, we also keep an encrypted copy so you can view the key again there. Only our backend holds the secret that decrypts it, and our database rules block browser access to key records.
  • Data accessed: Most tools read from Perception's record of public sources, including media coverage, podcasts, company disclosures, regulatory filings, earnings calls and public conversations. Some tools also return market or chain data from third-party providers. One tool writes data: perception_save_research stores research notes for your account or team, and perception_recall_research reads them back. Only the account or team that saved a note can recall it, and notes delete automatically after 90 days.
  • Usage logging: We log each tool call and API request with the tool or endpoint name, time, latency, response size, credits used, your key prefix and your account ID. We use these logs for billing, rate limits and reliability. Our request logs redact search terms, entity names and any context you pass to a tool.
  • Rate limits: API access is limited to 60 requests per minute, with a daily cap on full-text article retrievals.
  • Third-party platforms: When you use the Perception connector through an AI platform such as Claude or ChatGPT, that platform's privacy policy governs how it handles your queries and our responses.

Data retention

We keep personal information for as long as we need it to provide our services and for the purposes in this policy. To close your account, email us at the address below. When you close your account, we delete or anonymize your personal data within 90 days, except where the law requires us to keep it. We keep invoices and payment records for seven years, as Estonian accounting law requires. MCP research notes delete automatically after 90 days.

International data transfers

We are based in Estonia. Our main servers and databases run on Google Cloud in the United States, and several of our providers process data in the United States and other countries. For transfers out of the European Economic Area, we rely on the Standard Contractual Clauses or EU-US Data Privacy Framework certification in our providers' data processing terms. DeepSeek processes data in China, which has no EU adequacy decision.

Updates to this policy

We may update this Privacy Policy to reflect changes in our practices or applicable laws. We will notify you of material changes by email or a prominent notice on our platform at least 30 days before they take effect.

Contact us

If you have questions, concerns or requests about this Privacy Policy or our data practices, contact us: