Privacy Policy

Last updated: August 31, 2026

1. Overview

perfbit (“we”, “our”, or “us”) provides performance monitoring for React Native applications. This policy explains what data we collect, why we collect it, and how we use it when you use our service at perfbit.app or our SDK.

The data controller for your account information is perfbit, a sole proprietorship based in Bengaluru, India. Full legal details of the operator are available on request at privacy@perfbit.app. For the performance telemetry your app sends us, you are the controller and we act as your processor - the terms of that arrangement are set out in our Data Processing Agreement.

2. Data we collect

Account information

When you sign in with GitHub, we receive your GitHub username, public profile name, and email address. We use this only to identify your account and communicate with you.

Performance telemetry (SDK data)

Our SDK collects performance measurements from your app and sends them to our servers. This includes:

  • App cold start duration, and warm start duration when the app returns to the foreground from the background
  • Screen load times per screen name
  • Slow and frozen frame rates
  • Network request timing and status codes. We record only the origin and path of each request - query strings and fragments are stripped in the SDK before anything is sent, and we never receive request bodies, response payloads, or headers
  • Crash counts, and the error message and stack trace of each crash
  • The app version you pass to the SDK, and the platform the app is running on (iOS or Android). We do not collect the OS version or the device model
  • An anonymous session ID (generated randomly, not linked to any end user)

The SDK does not ask for or read contacts, location, photos, advertising identifiers, or any user-generated content, and it never assigns a persistent identifier to an individual end user.

One honest caveat about crash data: a stack trace is produced by your application, not by us, so it can incidentally contain whatever your code had in scope when it failed - including values that identify a person. We do not use crash data to identify anyone, and our SDK redacts common patterns such as email addresses and tokens before sending. You remain in control of what your own code puts into an error, and the SDK lets you disable crash capture entirely.

Usage data

We collect standard web server logs (IP address, browser type, pages visited) to operate and secure the dashboard. We do not run third-party product analytics or advertising trackers on this site, and the only cookies we set are the ones required to keep you signed in - which is why you are not asked to accept a cookie banner. If we add analytics later, we will list the provider below and update this policy first.

3. How we use your data

  • Populate your performance dashboard with build-over-build metrics
  • Send you account-related email when it matters - trial expiry, billing receipts, security and service notices. These are transactional; we do not send marketing email
  • Detect abuse or unauthorized SDK usage
  • Improve the product based on aggregate usage patterns

We do not sell your data to third parties. We do not use your data to train AI or machine-learning models.

4. Third-party services

We share data with these sub-processors to operate the service:

Supabase

Authentication, database hosting, and storage of all performance telemetry

DodoPayments

Payment processing, invoicing, and tax handling as Merchant of Record

Vercel

Application hosting and content delivery, including server logs

Resend

Delivery of transactional email - trial reminders, receipts, and service notices

The current list, including what each provider handles and where it operates, is maintained on our sub-processors page. We give at least 30 days' notice before adding or replacing any of them.

5. Where your data is stored

Your account information and all performance telemetry are stored in the United States, in our Supabase project in the US East, N. Virginia (us-east-1) region. Our sub-processors are also US-based, except DodoPayments which additionally operates in Singapore.

If you are in the European Economic Area, the United Kingdom, or Switzerland, this means your data is transferred outside your region. We rely on the European Commission's Standard Contractual Clauses, incorporated into our Data Processing Agreement, as the legal basis for that transfer, together with the encryption and access controls described in section 8.

6. Data retention

Performance event data is retained for 90 days on the Indie plan and 180 days on the Studio plan. When your account is deleted or your subscription expires and is not renewed, your event data is deleted within 30 days. Account information (email, billing history) is retained for up to 7 years as required for tax compliance.

7. Your rights

Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, export it in a portable format, or object to how we use it. We apply these rights to everyone, not only to people in regions that require it.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising - as those terms are defined under the California Consumer Privacy Act. We have never done so. There is therefore nothing to opt out of, and we will not discriminate against you for exercising any privacy right.

You do not need to ask us for most of these. Your dashboard settings have a one-click export of everything we hold about you, and a delete option that cancels any subscription and permanently removes your workspace, apps, and all collected performance data.

For anything else, or if you would rather we handled it, email us at privacy@perfbit.app. We will respond within 30 days.

8. Security

All data is encrypted in transit (TLS 1.2+) and at rest. Access to your data is enforced in the database itself through row-level security, so one customer's queries cannot reach another customer's data even if application code has a bug. Access to production systems is limited to the people who operate the service.

About your ingestion API key. This key is embedded in your published mobile app, which means anyone who downloads that app can extract it. It is an identifier, not a password - the same model used by tools like Sentry and PostHog - so we deliberately keep it retrievable in your dashboard rather than pretending it is a secret. What protects you is that the key only ever writes performance events for a single app, never reads your data, is rate limited, and can be rotated from your settings at any time if you need to cut off a published build.

No system is perfectly secure. If a breach affects your personal data we will tell you without undue delay, and within 72 hours notify the relevant supervisory authority where we are required to.

9. Children

perfbit is a developer tool intended for adults. We do not knowingly collect data from anyone under 13. If you believe a minor has created an account, contact us and we will delete it promptly.

10. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and notify you by email at least 14 days before the change takes effect.

11. Contact

Questions about this policy? privacy@perfbit.app