Perk legal
Privacy Policy
Effective: September 6, 2026 · Last updated: September 6, 2026
This Policy explains what Perk collects, why, who receives it, how long it is kept, and the choices and GDPR rights available to you. Perk does not sell personal data or use private messages or AI prompts for third-party advertising.
1. Controller and scope
The controller is 1st-flame UG (haftungsbeschränkt), Schnellerstraße 60, 12439 Berlin, Germany. This Policy applies to Perk's websites, apps and connected services. Contact [email protected] for privacy requests. We have not appointed a data protection officer unless a current in-product notice says otherwise.
2. Data we collect
Account and identity data: name, username, email, phone number, date of birth or age confirmation, language, authentication provider identifiers and account status. Profile and social data: biography, interests, photos, connections, follows, blocks, visibility settings, posts, reactions, comments and reports.
Content and communications: prompts, AI conversations, messages, shared files, images, audio, video, call signalling and content you create with document, presentation, tutor, calendar, browser, drive and job tools. Voice features may stream audio for transcription or response generation. Raw audio is retained only where the feature clearly says so or you choose to save it.
Technical and activity data: IP address, timestamps, device and browser information, app version, locale, cookie and session identifiers, security events, feature interactions, approximate network-derived location and diagnostics. Precise location, camera, microphone, contacts or notifications are accessed only after device permission or an action that clearly requires them.
Transaction and partner data: purchase or reservation amount, currency, status, credits, redemptions, partner venue and limited billing identifiers. Payment card or wallet credentials are normally collected by the payment provider, not Perk.
Data from others: sign-in providers, app stores, payment providers, users who interact with or report you, partner venues, linked services and public web sources you ask a browser or AI feature to retrieve.
3. Purposes and legal bases
Contract: create and secure your account; provide social, messaging, calling, AI, storage, productivity, reservations, credits and purchases; synchronise settings; and provide support. Steps requested before a contract also rely on this basis.
Legitimate interests: prevent fraud and abuse; keep the Service safe; diagnose reliability; understand aggregate feature performance; moderate content; protect legal claims; and improve Perk where those interests are not overridden by your rights. You may object to this processing.
Consent: optional precise location, microphone, camera, contacts, notifications, non-essential cookies, marketing, and special-category data where consent is the appropriate basis. You may withdraw consent prospectively at any time.
Legal obligation and public interest: tax and accounting records, valid government requests, consumer obligations, sanctions, safety and illegal-content duties. Vital interests may apply in a genuine emergency.
4. AI processing
When you use an AI feature, Perk processes your prompt, selected files and the context needed to answer. Inputs may be sent to contracted AI, speech, image or document providers acting for Perk or, where clearly identified, to a third-party service you choose.
Do not include unnecessary sensitive data or another person's confidential information. Perk may run automated safety classifiers and abuse detection, but does not make solely automated decisions producing legal or similarly significant effects about you unless separately explained with safeguards. Human reviewers may inspect limited content when needed for support, safety, abuse investigation or quality evaluation under access controls.
We do not permit service providers to use Perk customer content for their independent advertising. Whether content may be used to improve Perk models or features will be controlled by a specific notice or setting where required; this Policy does not treat service use as blanket consent.
5. Visibility and sharing with other users
Profile fields and social content are shared according to the audience you choose and product defaults shown to you. Public content can be indexed or copied. Messages are shared with recipients; reports may include the reported content and nearby context. Blocking, deletion and audience changes limit future access but cannot remove copies another person already made.
6. Service providers and other recipients
We disclose only what is needed to providers supporting cloud hosting and storage, content delivery, authentication (including Apple, Google and Firebase), AI and speech processing, security, email and notifications, customer support, maps and location, communications, analytics that we actually enable, app stores, payments and partner redemptions.
We may disclose data to professional advisers, auditors, insurers, competent authorities, or a buyer in a merger or asset transaction subject to appropriate confidentiality and notice. We may share aggregated or de-identified information that does not reasonably identify you. We do not sell or rent personal data.
7. International transfers
Providers may process data outside the EEA, including in the United States. We use an adequacy decision where available, including the EU–US Data Privacy Framework for certified recipients, or European Commission Standard Contractual Clauses plus supplementary measures as appropriate. Contact us for information about applicable safeguards.
8. Retention
Account and profile data are generally kept while your account is active. Content is kept until you delete it or the account, subject to product-specific controls. Operational logs are ordinarily retained for up to 12 months; security and fraud records may be kept up to 24 months; cookie consent records for up to 12 months; and transaction, tax and accounting records for the statutory period, commonly 6 to 10 years in Germany.
Deleted data may remain in encrypted backups for up to 90 days before rotation. We may retain a limited record longer to comply with law, resolve disputes, enforce rights, protect safety or honour a block list. Exact periods can differ when a feature gives a more specific notice.
9. Security
We use access controls, encryption in transit, secure cookies, logging, backups and organisational measures appropriate to risk. No service is perfectly secure. Protect your credentials and report suspected compromise. End-to-end encryption applies only where a conversation is explicitly labelled as such.
10. Your choices and rights
Depending on law, you may access, correct, delete or port your data; restrict or object to processing; withdraw consent; and complain to a supervisory authority. You can also manage profile visibility, audiences, permissions, blocks, notifications and some AI history in the product.
Send requests to [email protected]. We may verify identity and may retain information where an exemption applies. You may complain to the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit) or your local EEA authority.
11. Children
Perk is for users aged 16 and over. We do not knowingly collect data from children under 16. If you believe someone under 16 uses Perk, contact us so we can investigate and take appropriate action.
12. Cookies and device storage
The website uses strictly necessary session, security, locale and consent storage. Optional third-party or analytics technologies must not load until the required choice is made. Details, names, purposes and durations are in the Cookie Policy.
13. Changes and contact
We will post updates with a new effective date and provide additional notice for material changes. Privacy questions and rights requests: [email protected]. Postal address: 1st-flame UG (haftungsbeschränkt), Schnellerstraße 60, 12439 Berlin, Germany.