[go: up one dir, main page]

Perfectly Imperfect, Inc.

Privacy Policy

Last updated: August 31, 2026

1. Who we are and what this covers

This policy explains how Perfectly Imperfect, Inc. ("Perfectly Imperfect", "PI", "we"), located at 191 President St., #2, Brooklyn, New York 11231, collects, uses, and shares information when you use PI.FYI, perfectlyimperfect.fyi, our newsletters, and our mobile apps (the "Services"). We are the data controller for this processing.

It doesn't cover third-party sites and services that PI links to. Recommendations are full of links, and once you leave, the destination's own policies apply.

2. What we collect

Things you give us:

  • Account basics: email address, username, name, date of birth (to verify you're 18+), and a password (stored hashed, never in plain text). Optionally a phone number, which we verify by text message.
  • Profile details you choose to add: photo, bio, links and social handles, location (like your city), interests, values, relationship status, preferred streaming service, and theme choices.
  • Content: recommendations, posts, comments, lists, newsletter posts, direct messages, and images you upload, including screenshots you submit to turn into recommendations.
  • Contacts, if you use "invite friends": with your permission, we upload the contacts you share (names, email addresses, phone numbers, and contact photos) to help you find and invite people. This includes information about people who aren't on PI; we use it only for matching and invitations you send, we don't sell it, and anyone can ask us to remove their contact information (Section 11).
  • Imports you connect: for example your Goodreads books, Google saved places, or a subscriber list you bring from another newsletter platform. When you connect an account (like Google), we store the access credentials needed to run the import you asked for.
  • Messages to us: support requests and feedback.

Things we collect automatically:

  • Activity: what you post, view, like, bookmark, follow, search for, and click; events you RSVP to and games you play; which feed items we showed you and which ones you actually saw (including roughly how long); which affiliate product links you follow; and which profiles you view (see Section 5; profile owners may be able to see this).
  • Device and technical data: IP address, browser and OS, app version, timezone, screen size, push-notification token, and cookies (see our Cookie Policy). For fraud and bot protection we also use device-fingerprinting and CAPTCHA signals.
  • Email engagement: whether emails we send are delivered, opened (where detectable), and which links get clicked, along with the IP address, device type, and approximate location of those events.
  • Location: the location you put on your profile (which we geocode with Google's services), and, only if you grant the permission, your device's location to auto-fill your city. We don't track your movements.
  • How you found us: if you arrive from an ad or a link, we capture referral and ad-click identifiers (from platforms like Meta, TikTok, Google, or Reddit) so we can tell which of our ads and campaigns work.

Things we get from others: basic details from sign-in providers you choose (like Google: name, email, profile photo), and subscription status from payment providers (Stripe, Apple, Google, RevenueCat), and purchase, return, and commission reports from affiliate networks and participating merchants after an affiliate link is followed. One more that deserves plain words: if you subscribe to a PI newsletter by email without creating an account, or a newsletter author imports a subscriber list that includes your address, we create a minimal record (your email and the newsletter it belongs to) so we can deliver it and honor unsubscribes. We don't email you anything else, and you can claim that record as an account or ask us to delete it at any time.

3. How we use it

  • Running PI: accounts, profiles, feeds, search, scenes, messages, notifications, and newsletters.
  • Personalization: building a taste profile from your posts and activity so your feeds, search results, and matches reflect what you're into, using automated systems (Section 4).
  • Email and newsletters: sending what you subscribed to, and measuring opens and clicks so we (and newsletter authors) know what's working.
  • Safety and integrity: moderation (automated and human), spam and bot detection, security, and enforcing our Terms of Use.
  • Analytics and product improvement: understanding how PI is used so we can make it better.
  • Measuring our advertising: knowing whether the ads we run for PI actually bring people here (Section 6).
  • Affiliate links: choosing monetized product links, attributing purchases and returns, calculating commissions, and detecting reporting problems. PI may associate a click or transaction with your account internally when you are signed in.
  • Aggregated research and insights: Section 7.
  • Legal compliance: meeting our obligations and defending our rights.

Where GDPR applies, our legal bases are: performing our contract with you (running the Services), our legitimate interests (personalization, safety, analytics, promoting PI), your consent where we ask for it (like marketing emails, contacts access, or device location), and legal obligations.

4. Personalization and automated systems

PI learns what you're into so your feeds, search results, and matches feel like yours. Here's how that works:

  • Your taste profile. We turn your posts and activity into internal signals that power recommendations, search, discovery, and taste matching. These signals exist to serve you content; they aren't shared with other users or partners.
  • Automated features. Some features use automated systems to do their job, like turning a screenshot you submit into a recommendation, answering a search question, or flagging content for moderation review. Where specialized service providers help us run these features, they process content only on our instructions and are contractually barred from using it for their own purposes.
  • Protecting your content. We block bulk scraping and automated harvesting of PI. What you post here is for the community, not for bots.

5. What other people can see

  • Public content is public. Your profile, recommendations, lists, and comments are visible to anyone (including off-PI, via search engines and link previews), unless you use a privacy setting that limits them.
  • Profile views can be visible. When you view someone's profile while logged in, we record it, and PI features may show that person that you viewed their profile. Browse logged out if you don't want that.
  • Taste features. Things like taste-match scores are shown to the people you match with.
  • Games and leaderboards. Public leaderboards show your username and stats from playing and posting.
  • Location scenes. If you add a location to your profile, we may add you to public community spaces for your city or neighborhood. You can leave any scene, and you can hide your location on your profile in settings.
  • Newsletter authors see their subscribers. If you subscribe to a member's newsletter, that member can see that you're subscribed, whether their emails to you are opened and clicked, and, where the feature is enabled, your email address. Our Terms require authors to use subscriber data only for their newsletter and never to sell it, but once an author exports their list, they're independently responsible for it (like on any newsletter platform).
  • Messages. DMs are visible to the people in the conversation, and to our moderation systems and team when messages are reported or flagged for safety.

6. Who we share data with

Service providers that process data on our behalf, under contracts limiting them to that purpose:

What forProviders
Hosting, storage & deliveryRender, Cloudflare (CDN, storage, bot protection), Google Cloud
Email & SMSResend, Mailgun, Twilio
Analytics, monitoring & feature flagsMixpanel, PostHog, Sentry, LaunchDarkly, Better Stack
Search & content processingSpecialized processing and search providers, limited by contract to acting on our instructions
PaymentsStripe, Apple, Google, RevenueCat (we never store full card numbers)
Push notificationsExpo, Google Firebase
Location & mapsGoogle Maps / Places
Misc featuresKlipy & Giphy (GIF search), Shopify (merch rewards)

Advertising platforms. To measure and improve the ads we run for PI, we send conversion events (like "signed up") to Meta with hashed identifiers (email, phone, and name, all hashed before sending) plus technical data like IP address, and we use TikTok and Reddit measurement pixels on our website. Some privacy laws call this "sharing" or "targeted advertising," and you have the right to opt out: email [email protected] with "opt out of ad sharing" and we'll exclude your data going forward. We don't show third-party targeted ads inside PI, and we don't give advertisers your personal information. Sponsored placements in PI are clearly labeled and their sponsors get aggregate performance stats only.

Affiliate networks and merchants. Some product links are affiliate links. When you follow one, Affiliate.com, Awin, and participating merchants receive the destination and an opaque click reference so they can route the visit and report purchases, returns, and commissions. The reference does not contain your PI user ID, email address, or PI's anonymous browser identifier. PI may connect the resulting report to your account internally when you were signed in, but we do not send that identity to the affiliate provider.

Newsletter authors you subscribe to, as described in Section 5.

Other users: whatever you make visible to them (Section 5).

Legal reasons: when required by law, legal process, or to protect the rights and safety of our users, the public, or PI.

Corporate transactions: if PI is involved in a merger, acquisition, financing, or asset sale, data may be transferred as part of it; this policy would continue to apply until changed with notice.

What we don't do: we do not sell your personal information. Not your email, not your messages, not your profile. Not to data brokers, not to anyone.

7. Partnerships and research

What this community collectively knows about taste is valuable, and part of how we keep PI running is putting it to work through partnerships: things like trend and audience research for brands, studios, labels, and researchers. Here is what that means for your data, plainly:

  • Partners only ever see aggregate, anonymized trends built from public activity. Think "what this community is listening to," never "what you personally did." Nothing a partner receives identifies you, and we maintain this data so it can't reasonably be linked back to you.
  • Your name, email, and contact information are never part of it. Neither are private posts, private accounts' content, or direct messages.
  • We commit publicly to not re-identifying this data, and we contractually require everyone who receives it to honor the same commitment.
  • If we materially change how these programs work, we'll update this policy and tell you before the change takes effect.

8. Cookies

Our Cookie Policy lists the cookies and similar technologies we use (ours and third parties') and how to control them.

9. How long we keep things

  • Your account and content: for as long as your account exists.
  • Behavioral logs: feed-serving and impression logs are pruned on short rolling windows; email open records are deleted after 90 days (click, bounce, and complaint records are kept longer because deliverability depends on them).
  • Affiliate measurement: affiliate click records are deleted after 400 days. Transaction and commission records may be retained for up to seven years for accounting, tax, fraud prevention, and dispute purposes.
  • Marketing data: kept no longer than three years after your last interaction with us, or until you unsubscribe or object.
  • Legal and safety records: kept as long as required for compliance, disputes, and abuse prevention.

10. Deleting your account: exactly what happens

Delete your account in Settings → Delete Account (or email [email protected]). Deletion is permanent. Here's the honest breakdown:

  • Immediately, your account is deactivated and your email and username are detached from your profile. A background process then permanently deletes your profile, posts, messages, follows, and related records from our production systems.
  • What remains: a minimal record that the account existed (the email address, username, and account ID) so we can prevent ban evasion and meet legal obligations; log entries that age out on the schedules in Section 9; copies in encrypted backups until those rotate out; and emails or newsletters already delivered to other people's inboxes, which can't be recalled.
  • Content you shared into other surfaces, like a recommendation featured in an already-sent newsletter, stays in those sent copies, though it's removed from PI itself.
  • We process deletion requests within 30 days, as the law requires.

11. Your rights and controls

Controls in the product: email preferences (including per-newsletter unsubscribes and a member-newsletters master switch), push-notification settings, privacy settings (including hiding your location), blocking and muting, and account deletion. Every email we send has an unsubscribe link.

Rights you can exercise by contacting us: access a copy of your data, correct it, delete it, restrict or object to processing, withdraw consent, and data portability. Email [email protected]. We may need to verify your identity first. If you're in the EU/UK, you can also lodge a complaint with your data-protection authority.

Not on PI but in someone's contacts? If a PI user shared your contact information through "invite friends," email us and we'll remove it.

A note on browser signals: we don't currently respond to Do Not Track or Global Privacy Control browser signals; use the controls above, or email us, instead.

California residents: you have the rights to know, delete, correct, and opt out of "sale" or "sharing" of personal information, and not to be discriminated against for exercising them. In the last 12 months we collected the categories described in Section 2: identifiers (name, email, username, IP), internet activity, approximate geolocation, audio/visual content you post, your messages, commercial information (subscriptions), and inferences (taste profiles). We do not sell personal information. We "share" limited data for ad measurement as described in Section 6. To opt out, email [email protected] with "opt out of ad sharing." We don't use sensitive personal information beyond providing the Services. Authorized agents may submit requests on your behalf with proof of authorization.

12. Security

We use administrative, technical, and physical safeguards appropriate to the data we handle: encrypted connections, hashed passwords, access controls, and monitoring. No system is perfectly secure, so we can't guarantee absolute security; if we learn of a breach affecting your data, we'll notify you as the law requires. Found a vulnerability? Email [email protected].

13. International transfers

We're based in the United States and process data there (and wherever our service providers operate). If you use PI from elsewhere, your data is transferred to the US. Where EU, UK, or Swiss law applies, we rely on appropriate safeguards for those transfers, including the European Commission's Standard Contractual Clauses.

14. Minors

PI is for adults: you must be 18 or older, and we verify age at signup. We don't knowingly collect data from anyone under 18; if you believe we have, email [email protected] and we'll delete it promptly.

15. Child safety standards

PI.FYI strictly prohibits all forms of child sexual abuse and exploitation (CSAE), including grooming, solicitation, endangerment, and any content sexualizing minors. Uploading or sharing child sexual abuse material (CSAM) results in immediate account removal and reporting to law enforcement and appropriate authorities.

PI.FYI maintains in-app reporting for harmful content and behavior, including suspected CSAE; reports are reviewed promptly by our Trust & Safety team. If CSAM is detected or reported, we immediately remove it, preserve data as required for investigation, and report it to the appropriate authorities and hotlines as required by law. We comply with applicable child protection, online safety, and mandatory reporting laws in the jurisdictions where we operate.

For urgent child-safety concerns, contact our designated child-safety point of contact: [email protected].

16. Changes to this policy

When we change this policy, we'll update the date at the top; for material changes we'll notify you on the platform or by email before they take effect. We keep prior versions available on request.

17. Contact us

Privacy questions, requests, or complaints: [email protected], or by mail at Perfectly Imperfect, Inc., 191 President St., #2, Brooklyn, New York 11231.