Privacy policy
Updated 7 October 2026
What stays on your device
Your wallet, logs, name, settings, and service end date stay on this device under perkwatch-state-v1. The Hub filter and the last tab you used are kept separately under perkwatch-ui-v1, also on this device. Before a snapshot import or a household join, a backup copy is saved on this device too.
We can’t see what you track.
Purchases
Purchases are handled by Apple. PerkWatch never receives your card number, billing address, or Apple Account details. The app asks the App Store whether Watch is active and saves the answer on this device.
Household sync
Household sync is optional, off by default, and end-to-end encrypted. The creating phone makes a random 256-bit key that stays in each phone’s iOS Keychain and reaches the partner only inside the invite link, after the #. Your wallet, logs, and goals are encrypted with AES-256-GCM before they leave the phone, so neither we nor Cloudflare can read them.
The pairing service (a Cloudflare Worker) stores only that encrypted copy plus minimal metadata: random member ids, a hashed sign-in secret for each phone, timestamps, whether the household creator has Watch (with a renewal date), short-lived invite codes, and push tokens if you allow notifications. Push banners never say which card or how much. Leaving removes your phone; the last phone to leave deletes the household.
While an invite is waiting, the creator’s phone keeps it (link and key) in the Keychain so it can show it again, and deletes it when the partner joins, when it expires, or on New invite. Each phone’s last-sync time is stored inside the encrypted copy, so the service can’t read it.
Households from 0.085 and 0.086 used a reversible encoding, not encryption. 0.087 reads that copy once to keep anything new, erases it from the service, and re-pairs with encryption.
Demo mode
Demo mode (perkwatch://demo) shows a sample wallet kept in memory only. It never replaces your data, never syncs, and schedules no reminders.
Snapshot files
A snapshot file isn’t encrypted and goes only where you send it. Anyone with the file can read it.
Feedback & suggestions
Feedback & suggestions in the app sends what you type (name, email, message, and an optional screenshot), plus a short tag (who you are, your branch and status, the cards you marked as owned, and the build), through Web3Forms.
This website
The contact form on the support page sends what you type (your name if you give one, email, topic, and message) through Web3Forms to our inbox. We don’t sell it.
This site has no ads, analytics, or trackers. It is hosted on Cloudflare, which handles the requests your browser makes to load it.
Children
PerkWatch is not directed at children under 13.
In short
No accounts. No ads. No sale of data. No Plaid.
Contact
Questions about privacy? Use the contact form on the support page and choose the topic Privacy, or use Feedback & suggestions in the app.