This page explains what information PerkMind collects, how it's used, who it's shared with, and the choices you have.
Entity: Merchins LLC, a Missouri limited liability company, d/b/a PerkMind ("PerkMind," "we," "us")
Effective date: September 21, 2026
Contact: support@perkmind.app | Privacy/security requests: security@perkmind.app
PerkMind is a product of Merchins LLC, a Missouri limited liability company ("Merchins," "PerkMind," "we," "us"). This policy applies to the PerkMind iPhone and iPad app (including its Apple Watch companion and Share extension) and to this website, perkmind.app. It describes what PerkMind does today. Where something is planned but not built, we say so. For how we protect your data in plain language, see the Security and Privacy pages.
You sign in using Sign in with Apple. Apple gives us an identity token, and depending on what you choose to share, your name and an email address (which may be Apple's private relay address). Our backend verifies the token through Supabase Auth and creates a PerkMind account with a display name and user ID. Session tokens are stored in your device's Keychain, refreshed automatically, and required for every protected request. You can add multi-factor authentication (MFA) with an authenticator app; once you enroll, protected bank and account requests require it. Before you sign in, you must accept our Terms and acknowledge this Privacy Policy, and we record the version you accepted and when.
The cards you add: nickname, issuer, product, network, and reward metadata (reward rates and categories), plus optional details you choose to enter — the last four digits, cardholder name, expiration month and year, and signup-offer terms (bonus amount, required spend, and dates). These are stored on your device in the Keychain. We never ask for, transmit, or store a full card number, CVV, PIN, or signature. If you scan a card, the camera image is read on your device (Apple's Vision framework), the full number is used only in memory, and only the display-safe fields you confirm are saved.
If you connect an account, Plaid Link opens so you can sign in to your bank with Plaid — PerkMind never sees your bank credentials. Plaid gives our backend a token; we exchange it and store the resulting access token encrypted with AES-256-GCM, along with a sync cursor and basic institution details, in a database protected by per-user row-level security. Accounts and transactions are fetched when you sync, passed to your device, and cached there in the Keychain. We do not intentionally store your transactions on our servers.
PerkMind is sold as an auto-renewing subscription through the App Store. Apple handles payment; we do not receive your payment card. We may store signed App Store transaction data and subscription dates to confirm your access.
Location and notification processing is optional. If you turn on location recommendations, nearby-business detection and Best Card Entry Alerts, your device uses Apple's Core Location and MapKit to work out the business you are near, and the alert is a local notification generated on your device. We do not intentionally retain a history of your precise location, and location is not sent to our backend. You can switch these off at any time in Settings.
When you use the Share extension, PerkMind receives only the single page link you choose to send. It does not monitor your browsing.
If you use the contact form or email us, we receive your name, email address and message. The form's submissions are stored in Amazon Web Services and emailed to our support team. This website loads fonts from Google Fonts, which means your browser contacts Google when a page loads.
We do not sell your personal information, and we do not use your financial data for advertising or share it with data brokers.
Our providers run their own platform logs, which we do not control. We may also disclose information if required by law or to protect the rights, property, or safety of Merchins, our users, or others.
What we keep, and for how long:
Automated account deletion. You can delete your account inside the app. We first remove every linked bank connection with Plaid, then delete your PerkMind account and its associated records from our backend, and the app clears your session, wallet, notifications, and cached data from your device. You can also email security@perkmind.app if you need help. Deleting your account does not cancel your App Store subscription — manage that in your Apple ID subscription settings.
Deleting the app alone may not remove your data. iOS can keep Keychain items after an app is uninstalled. To make sure your wallet and session are removed, delete your account (or remove your cards and sign out) in the app before you delete the app.
Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act or the EU/UK GDPR, including the rights to access, correct, delete, or restrict processing of your data and to complain to a supervisory authority. We honor applicable requests as the law requires. PerkMind is currently offered in the United States.
Data is encrypted in transit with TLS, sensitive server-side tokens are encrypted at rest, and your wallet and session are kept in the iOS Keychain. No method is perfectly secure. To report a vulnerability, write to security@perkmind.app. More detail is on the Security page.
PerkMind is not directed to children under 13, and our Terms of Service require users to be at least 18. We do not knowingly collect personal information from children.
If we make a material change, we will update the effective date above and, where appropriate, tell you in the app. Please review this page from time to time.
Merchins LLC, doing business as PerkMind. Questions about this policy or your data: support@perkmind.app. Security or privacy requests: security@perkmind.app.