← Back to Pertly

Privacy Policy

Last updated: 2026-10-08

The short version

Pertly recommends things to do near you. To do that we need a small amount of personal data — your account, your location, and what you've told us about your preferences. We don't sell it. We don't share it with advertisers. Some features send the minimum information needed to approved AI or search providers. Ask Pertly can use your conversation and selected personalisation context when you keep personalisation switched on; public-web research uses a separate non-personal search query. You control saved assistant memories explicitly. You can request account deletion at any time from settings. There is a 14-day grace period before irreversible deletion so you can cancel if it was a mistake.

Who we are

Pertly is operated by PERTLY LTD, a company registered in England and Wales under company number 17388422. Its registered office is 167-169 Great Portland Street, 5th Floor, London, W1W 5PF. PERTLY LTD is the data controller responsible for the personal data described in this policy.

What we collect

  • Account: email address and (optional) display name. If you sign in with Google, we may also receive your Google account name and profile photo from Supabase Auth.
  • Location: the postcode or English city you set, plus GPS coordinates when you grant the browser permission. Settings shows which source currently controls discovery. Used only to show nearby results and route plans.
  • Preferences: the activity types, travel radius, going-out times, and mood you set in onboarding or later in settings.
  • Cultural preferences:the cultural backgrounds you'd like to see represented in your recommendations (e.g. South Asian, Southern European). This is optional— you can skip it during onboarding or clear it in settings. We use it only to weight which venues we surface to you; we don't share it with the AI providers used by normal discovery. If you keep Ask Pertly personalisation switched on, a relevant preference may be included in the protected context sent to its approved AI provider so it can tailor an answer or comparison.
  • Activity: impressions of cards we show you, taps on detail pages, items you save, search queries, and the Surprise Me plans you generate. Used to improve the recommendations you see and (where you opt in) to mark plans as completed.
  • Acquisition and app usage: a random identifier stored by your browser, session identifiers, a broad referral source (such as Google, Threads, or direct), and whether a signed-in user reached a useful app action or returned on another day. Pertly stores a one-way hash of the browser identifier, not the original value, and does not store a full referring URL for this reporting.
  • Ask Pertly: the messages you send, task history, generated drafts and revisions, research receipts, and any memories you explicitly confirm. Personalisation can be switched off per task, and a proposed memory is not saved until you confirm it.
  • Group plans: saved items you turn into a group plan, invite links, guest names, and guest votes. Public group plan links can be opened by anyone who has the link.
  • Billing and referrals: your Plus access state, referral code/status, Stripe customer ID, subscription/pass status, immediate-access consent version and timestamp, purchase confirmation status, and webhook records needed to prevent duplicate billing updates. Stripe handles payment card details; Pertly does not store full card numbers.
  • Feedback: bug reports, app feedback, and visit ratings you choose to send.
  • Technical and security data: IP address, browser and device information, request logs, crash details, performance traces, and limited interaction data captured when an error occurs. We use this to keep Pertly secure and diagnose faults. Error replays may record the steps around a crash, with sensitive fields masked.

How and why we use your data

  • To provide the service you request, including your account, nearby discovery, plans, saved items, group plans, Ask Pertly, and paid access. We rely on our contract with you.
  • To personalise and improve Pertly, including ranking recommendations, remembering your choices, measuring feature usefulness, and improving coverage. We rely on our legitimate interests in operating and improving the service.
  • To protect Pertly and its users, including preventing abuse, enforcing limits, investigating faults, and securing accounts. We rely on our legitimate interests and, where applicable, legal obligations.
  • To administer payments and records. We rely on our contract with you and legal obligations relating to tax, accounting, fraud prevention, and disputes.

GPS access is controlled by your browser or device. You can deny or withdraw that permission and use a postcode or city instead. Cultural preferences are optional content interests; we do not use them to infer your ethnicity, nationality, or identity.

Where the data comes from

Most personal data comes directly from you or from how you use Pertly. We also receive account details from Google when you choose Google sign-in, payment and subscription status from Stripe, and technical diagnostics from our hosting and monitoring providers. Venue, event, weather, map, and routing information comes from the public and commercial sources listed below.

What we don't do

  • We don't sell your data.
  • We don't share it with advertisers or data brokers.
  • We don't track you across other sites or apps.
  • We don't knowingly collect data from children under 13. We ask whether you're 18 or over so we can hide age-restricted recommendations where needed.

AI processing

Some of Pertly's most editorial features are powered by third-party AI models. When AI is involved, here's exactly what we share:

  • Surprise Me itineraries are normally curated by DSeek (formerly DeepSeek), an AI provider based in China, with Groq as a fallback if DeepSeek is unavailable. We send only the current outing choices needed to assemble the plan, such as your selected mood, broad city or area, time, weather, companion mode, requested activity types, and public candidate venue details. We do not send your name, email, account ID, payment details, precise GPS coordinates, free-text requests, profile cultural preferences, saved places, booking clicks, feedback, or other activity history.
  • Editorial subtitles on feed cards and Surprise Me stops are generated by Groq, a US-based AI provider. We send the venue name, category, and your active mood.
  • Venue classification (tagging venues with moods, cultures, and indoor/outdoor flags) also runs on Groq, but this happens at our data-ingestion stage before any user interaction — no personal data is involved.
  • Ask Pertly conversations may be processed by Google Cloud Vertex AI or Groqwhen model assistance is enabled. We send the current task messages and only the preference, Saved, adventure, feedback, location, or memory context needed for the request. We do not send your email address, account ID, passwords, payment details, or private tokens as account metadata. Personal information you include in a message may be processed as part of that conversation. Vertex requests use an EU endpoint. Google does not use this data to train its models without our permission; we do not grant that permission. Under standard abuse monitoring, Google may retain flagged prompts for up to 90 days and authorised personnel may review them. We do not claim zero retention for Vertex. Groq's Zero Data Retention control is enabled for Pertly inference calls; provider usage metadata does not contain prompts or responses.
  • Ask Pertly public-web research uses Brave Search API only when current public information is needed. Pertly converts the request into a short, non-personal research objective before searching. Raw conversation text, account details, personal constraints, and model instructions are not sent to Brave. Brave may retain the search query for up to 90 days in the United States for billing, troubleshooting, and legal obligations. Pertly does not store Brave snippets or result text; it fetches selected publisher pages directly and stores a bounded source receipt.

AI-generated copy may occasionally contain errors or characterisations that don't perfectly match a venue. Treat it as editorial recommendation, not verified fact.

Personalisation and automated processing

Pertly uses automated ranking and AI to predict which activities may suit you and to generate recommendations and plans. This is a form of profiling, but Pertly does not use it to make decisions that have legal or similarly significant effects on you. You can change your preferences, turn off Ask Pertly personalisation for a task, remove assistant memories, or ignore any recommendation.

International data transfers

Because we use third-party services in the US and China (see above), some data crosses international borders. Where personal data is involved we rely on appropriate safeguards under UK GDPR, including applicable standard contractual clauses and the UK Addendum. We minimise each request and exclude direct account identifiers. Brave's standard Search API query logs are kept in the US and are not covered by the same processor terms; we therefore send only the non-personal projected research objective described above.

Third parties we use

Beyond the AI providers named above:

Where Pertly runs

  • Supabase — authentication and database (data stored on EU servers).
  • Google OAuth — optional Google sign-in, handled through Supabase Auth.
  • Vercel — frontend hosting.
  • Railway — backend hosting.
  • Sentry — error monitoring and performance diagnostics. We use it to understand crashes and production issues, not for advertising.
  • Google Cloud Vertex AI— AI processing for Ask Pertly using an EU endpoint, subject to Google's Cloud Data Processing Addendum and standard abuse-monitoring retention described above.
  • Groq — approved AI processing for Ask Pertly and selected editorial features, with Zero Data Retention enabled for inference inputs and outputs.
  • Brave Search API — non-personal public-web research objectives for Ask Pertly. Brave may keep standard search-query logs for up to 90 days in the United States.

Where venue and event data comes from

  • Google Places — venue photos, opening hours, ratings, and journey place search. Venue enrichment runs server-side without personal user data. When you explicitly search for a journey start, finish, or trip base, we send the place words you typed and a coarse location bias so Google can return useful nearby matches.
  • Ticketmaster, council RSS feeds, Data Thistle— event listings. Server-side only; we don't share your data with them.
  • Mapillary, Wikipedia, Wikidata — venue imagery. Server-side fetched.

Where your location helps the feed

  • Postcodes.io — postcode validation. We send only the postcode you typed.
  • OpenWeatherMap — weather context and a broad fallback for journey place search. We send only your approximate location or the place words you typed.
  • OpenRouteService— walking times for Surprise Me itineraries. We send the coordinates of the stops we're routing between.

Payments

  • Stripe — checkout, subscriptions, 7-day passes, receipts, payment recovery, and the customer billing portal.

Cookies and local storage

Pertly uses cookies and your browser's local storage to keep you signed in, remember your preferences (mood, last-seen tooltips, dismissed prompts), hold PWA install prompt state, and cache app data and static assets for speed and offline support. We also store random first-party visitor and session identifiers so we can understand whether people discover Pertly, sign up, find something useful, and return. These identifiers are not advertising cookies and are not used to track you across other sites. Sentry may use similar technology for error diagnostics, including a limited sample of sessions in which an error occurs. We don't use third-party advertising pixels or cross-site advertising cookies.

Data retention

  • Account data is kept while your account is active. On deletion (see Your rights) it is removed or anonymised after the 14-day grace period expires, except for records we must retain for legal, tax, fraud-prevention, or dispute purposes.
  • Activity data is kept according to its purpose: card impressions for up to 90 days and activity logs such as taps and searches for up to 180 days. Aggregated or anonymised statistics may be kept longer.
  • Acquisition sessions are kept for up to 180 days. Aggregated statistics that no longer identify a browser or account may be kept longer.
  • Surprise Me itinerariesyou don't save expire or are cleaned up automatically. Saved plans stay until you remove them.
  • Ask Pertly tasks, messages, drafts, and source receipts expire after 30 days unless you delete the task sooner. An accepted itinerary is kept separately as one of your plans. Confirmed memories remain until you delete them in settings or delete your account.
  • Group plan invite links and votes are kept long enough for the plan to run and for abuse/debugging protection, then archived or cleaned up.
  • Logs (server errors, request traces) are kept for up to 30 days for debugging and security.
  • Billing records are kept for as long as needed to administer your purchase and meet accounting, tax, fraud, and legal obligations.

Security

We use access controls, encryption in transit, restricted production credentials, monitoring, and data-minimisation controls designed to protect personal data. No online service can guarantee absolute security, so please use a strong password and contact us promptly if you believe your account has been compromised.

Your rights

Depending on the circumstances, UK data-protection law gives you rights to be informed, access your data, correct inaccurate data, ask us to erase it, restrict its use, receive portable data, and object to processing based on legitimate interests. Where we rely on consent, you can withdraw it at any time. These rights can have legal exceptions. Email us to exercise one; we may need to verify your identity and will normally respond within one month.

You can change many details and request account deletion from settings. Account deletion has a 14-day grace period during which you can cancel from the in-app banner or settings. After that, deletion is irreversible, subject to the limited records we must retain by law. You can also complain to the UK Information Commissioner's Office at ico.org.uk. We would appreciate the chance to address your concern first.

Changes to this policy

We may update this policy as Pertly, its providers, or the law changes. We will update the date above and give an in-app notice before a material change takes effect where appropriate.

Contact

Questions? Email hello@pertly.app. You can also write to PERTLY LTD at its registered office: 167-169 Great Portland Street, 5th Floor, London, W1W 5PF.