Security and data
How Perch handles your files and your data, what stays on your device, what is processed in the cloud, and the providers involved.
Perch is built for work where confidentiality matters. This page explains exactly how your files are accessed, what stays on your machine, what is processed off it, and who processes it. We would rather tell you precisely how it works than ask you to take it on faith.
How Perch accesses your files
On the desktop, Perch operates under a permission mode that you control:
- Default. Perch works only inside folders you explicitly approve.
- Auto Review. Common working folders (Desktop, Documents, Downloads, Projects) are available; anything else asks first.
- Take the Wheel. Any folder in your home directory is available, within the limits below.
You choose the level of autonomy, and you can change it at any time. Perch does not roam your disk on its own.
Protected by default
Sensitive paths are always off limits
A built-in blocklist prevents Perch from reading credentials and system locations in every mode, including Take the Wheel. This covers items such as SSH and cloud keys, environment and credential files, key and certificate files, and protected system directories. The block applies before any permission mode is evaluated, so autonomy never overrides it.
Actions that require confirmation
The highest-risk actions are never taken automatically. Force pushes and bulk deletions always prompt for your confirmation, in every mode short of Take the Wheel, so an automated step cannot quietly do something irreversible on your behalf. In Auto Review, the other consequential actions are checked by a separate reviewer before they run, rather than always interrupting you; see permission modes for how that reviewer decides and when it still stops to ask you.
Analysis runs in a sealed sandbox
When Perch runs analysis code to verify numbers or process data, that code executes in a sandbox with network access and package installation disabled, isolated from the rest of your machine. The analysis is shown in the transcript, so you can see what was run, not only what was concluded.
What is processed off your device
Perch is local-first for access and control, but it is not air gapped, and we will not imply otherwise. To produce an answer, the material needed for that turn, including relevant document content, is sent to our inference providers for processing. If you index a folder, those files are split into passages and stored in your workspace so retrieval can work. Your memory and conversation history are stored in your workspace as well. All of this is scoped to your account and workspace.
Data boundaries by plan
Pro and Enterprise stay outside the data program
Activity generated while Pro or Enterprise is active is excluded from AI training and dataset licensing, including activity under complimentary Pro access. Bring-your-own-key and self-hosted usage is excluded on every plan. Perch does not sell or license User Content or customer-identifiable activity from these categories, or use it to train models or improve products for other customers.
These commitments apply across the service:
- Request content is sent to an inference provider only to produce the requested output. Perch does not permit its inference providers to train on that request content or share it with underlying model vendors.
- Data is encrypted in transit and at rest through Perch's infrastructure providers.
- Account and workspace access is scoped by authentication and membership controls.
- You can request deletion of account and workspace data, subject to lawful retention requirements and the limits for data that is no longer reasonably linkable, described below.
The Starter Data Program
The free Starter plan includes a data program that helps support Perch-funded hosted usage. It is enabled by default after a versioned notice is shown and can be turned off at any time in Settings → Privacy.
The program applies only to eligible activity generated while an account or workspace is on Starter, Perch is funding the hosted model request, and the program is enabled. It does not apply to Pro, Enterprise, active or complimentary Pro access, bring-your-own-key usage, or self-hosted usage. Eligibility is based on the plan and inference source in effect when the interaction is generated; changing plans later does not reclassify earlier activity.
The program applies prospectively to eligible interactions generated on or after September 13, 2026, after the notice has been presented and the applicable acknowledgement recorded. Existing Starter users participate prospectively only after acknowledgement. Historical activity is not included without separate explicit authorization.
Starter datasets are not raw user traces
Perch may turn eligible Starter activity into Derived Training Data through filtering, redaction, abstraction, transformation, annotation, generalization, aggregation, suppression, and quality review. This can preserve the structure that is useful for improving agents, including transformed or deidentified task descriptions, model inputs and outputs, tool selections, tool arguments and results, failures and retries, workflow steps, evaluation results, and approval, rejection, or correction signals.
Perch may use or commercially license Derived Training Data for AI training, fine-tuning, evaluation, benchmarking, testing, and development, including by third parties. It is not a copy of a user's raw trace.
The program excludes:
- raw prompts, chats, model outputs, tool arguments, and tool results;
- files, documents, workspace materials, and confidential source material;
- email content and browser page content, even when a structural tool-action pattern is retained;
- names, account and profile details, personal information, and payment information;
- credentials, passwords, authentication tokens, API keys, and other secrets; and
- any record that remains reasonably linkable to a person, account, workspace, customer, organization, or confidential source.
Before data leaves Perch, controls are designed to remove direct and indirect identifiers, detect sensitive content and secrets, abstract source-specific details, suppress rare identifying events, deduplicate repeated material, and reject records that cannot be safely transformed. Recipients are contractually barred from reidentification, reconstruction of User Content, combining data to identify a source, contacting affected people or organizations, and targeted advertising.
Turning the program off stops future eligible collection and use and, where feasible, removes eligible records that are still raw and have not been exported or incorporated into Derived Training Data. Once data is no longer reasonably linkable to its source, Perch may no longer be able to associate it with an account or remove it from a delivered dataset or trained model. Operational processing needed to provide, secure, support, debug, meter, and enforce Perch continues.
See the Starter plan guide and Privacy Policy for the complete scope.
Subprocessors
Perch relies on the following providers to operate the service:
- Amazon Web Services (Amazon Bedrock). Model inference.
- Weights and Biases (W&B Inference). Model inference.
- Fireworks. Model inference.
- Supabase. Authentication, your workspace index, memory, and conversation storage.
We keep this list current. If you need our data processing terms for a security review, contact us.