Privacy Policy

Last updated: 1 September 2026

This Privacy Policy explains how Perch (“Perch”, “we”, “us”, “our”) collects, uses, and protects your data when you visit our website, create an account, connect your marketing platforms, and use the Perch reporting app.

Perch is a product operated by Thriving Colibri Ltd. The app is hosted at perch.thrivingcolibri.ai and our marketing site at perch.marketing. We process personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.


1. Who we are

For the purposes of data protection law, the data controller for your Perch account and our website is:

Thriving Colibri Ltd
68 Filton Road, Bristol, BS7 0PB, United Kingdom
Company registration number: 16548767

Email: hello@thrivingcolibri.ai

Note that for the marketing data inside accounts you connect (see section 2), you are usually the controller and we act as your processor. Section 8 covers that in full.


2. The data we collect

We only collect what we need to run the service. Depending on how you use Perch, that includes:

Information you give us directly

  • Waitlist details: if you ask to be told when Perch opens, we collect your email address, the date you joined, and which page you signed up from. We use it to confirm you are on the list and to email you when the beta opens, and for nothing else. You can leave the list at any time by replying to any email we send you.
  • Account details: your name, email address, and password. Sign-in is handled by our authentication provider (Supabase), which stores your password in a hashed form. We never see or store your password in plain text. You can also sign in with Google, in which case we receive your name and email from Google.
  • Team and invitation details: if you invite colleagues to your workspace, we process the email addresses you invite so we can send the invitation and add them to your team.
  • Billing details: if you subscribe to a paid plan, payment is handled by Stripe. We receive your plan, billing status, and the limited details Stripe shares with us (such as the last four digits of your card and your billing country). We do not store full card numbers.
  • Report content you create: the dashboards, manual metrics, notes, annotations, budgets, per-client context (a goal, an overall target cost per lead or return on ad spend, and free-text notes that inform your read), and branding you add to your reports.
  • Enquiries and feedback: anything you send us when you contact us or submit feedback through the app.

Marketing platform data you connect

The core of Perch is bringing your marketing data into one clear report. When you connect a platform, you authorise us (through our connection provider, Composio) to access that account’s reporting data so we can build your report. This currently covers:

  • Google Ads, Google Analytics 4, Google Search Console, Google Business Profile, and Meta (Facebook and Instagram) Ads.

For Google Business Profile we read your listing’s local visibility — views on Search and Maps, calls, direction requests, website clicks, messages, and the search terms that surfaced your listing — on a read-only basis. Perch never edits, publishes, or changes a listing.

We request this data on a read-only basis for reporting. Perch does not create, edit, pause, or delete campaigns, audiences, or any settings in your connected accounts. For Google Ads, Google Analytics, and Search Console, the authorisation tokens that keep these connections live are held securely by Composio rather than in our own database. For Meta, the authorisation token is stored securely in our own database, accessible only to the Perch service and never exposed to your browser. You can disconnect any platform and delete its data at any time — see Deleting your data.

Google user data and Limited Use

Perch’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: we use the Google Ads, Google Analytics, Search Console, and Google Business Profile data you connect only to build and show your reports to you. We do not use it to serve advertising, we do not sell it, and we do not transfer it to anyone except as needed to provide Perch to you.

Connecting Perch to your AI tools

You can connect your Perch reports to an AI assistant such as Claude, so you can ask it for breakdowns of your data and have it arrange your reports. You start this either by pasting a connection token we generate for you, or by approving a one-click connection (an OAuth authorisation) on a consent screen. There you choose the scope: your whole account (the AI tool can read and arrange reports for every client in your account) or a single client (the connection is locked to that one client, useful if you hand it to that client’s own team). Either way a connection only ever reaches clients in your own account, it is read-only toward your ad platforms, and it never lets the AI tool change your accounts.

For each connection we store only what is needed to run it: a hashed connection token (never the token itself) and, for a one-click connection, the registration details of the AI app (such as its name and return address) and a short-lived, single-use authorisation code. You can see and revoke any connection at any time on the Connect to Claude page. When your report figures are read this way they are returned to the AI tool you connected, which handles them under its own terms.

Information we collect automatically

  • Usage and device data on our marketing site: where you allow analytics and advertising cookies, we collect information such as your IP address, browser, device, pages visited, referring source, and how you interact with the site. See our Cookie Policy for the full detail.
  • Essential app data: inside the app we use a small number of strictly necessary cookies and similar technologies to keep you signed in and to keep the service secure.

We do not intentionally collect special category data (such as health, ethnicity, or religious belief). Please don’t put sensitive information into free-text fields such as notes.


3. How we use your data and our lawful bases

Under UK GDPR we must have a lawful basis for processing your data. Here is what we do and why:

What we doWhyLawful basis
Email you about the waitlistTo confirm you are on the list and tell you when the beta opensConsent
Create and run your account and workspaceTo provide the service you signed up forPerformance of a contract
Fetch and display data from the platforms you connectTo build the reports you asked forPerformance of a contract (and as your processor for client data)
Generate the optional AI summary of a reportTo provide the read feature when you request itPerformance of a contract
Take payment and manage your subscriptionTo run paid plans and billingPerformance of a contract / legal obligation
Send team invitations and service emailsTo run your team and keep you informed about the serviceLegitimate interests / performance of a contract
Respond to enquiries and feedbackTo support you and improve PerchLegitimate interests
Measure and improve our marketing site with analyticsTo understand what is workingConsent (via the cookie banner)
Run and measure advertising (Google Ads, Meta)To show relevant ads and measure their performanceConsent (via the cookie banner)
Keep records, prevent abuse, and meet legal dutiesTo run the business responsibly and comply with the lawLegitimate interests / legal obligation

Where we rely on legitimate interests, we have weighed our interest in running and improving Perch against your rights, and we only proceed where your rights don’t override that interest.


4. Cookies, analytics, and advertising

On our marketing site we use cookies and similar technologies for essential function, analytics, and advertising. The analytics and advertising tags, including Google Analytics 4, Google Ads (conversion and remarketing tags), and the Meta (Facebook) Pixel, are non-essential and load only after you give consent through our cookie banner.

We use Google Consent Mode v2, so until you consent these tags are set to a denied state and don’t store or share identifying cookies. You can accept, reject, or change your choices at any time. Every cookie and tag we use is listed in our Cookie Policy.

The Perch app itself (behind sign-in) does not run advertising tags. It uses only the strictly necessary cookies needed to sign you in and keep the service secure.


5. The AI summary feature

Perch can generate a written summary (a “read”) of a report. When you request one, the relevant report figures are sent to our AI provider, Anthropic (the Claude API), to produce the summary, which is then shown back to you.

Anthropic processes this data only to return the result and, under its API terms, does not use it to train its models. The summary is generated automatically and is for general guidance only. There is no solely automated decision that produces a legal or similarly significant effect on you. Always check the figures and use your own judgement before acting on a summary.


6. Who we share your data with

We don’t sell your personal data. We share it only with trusted service providers (“processors”) who help us run Perch, and only as far as needed. These currently include:

  • Vercel: hosts and serves the app and website.
  • Supabase: provides authentication and securely stores your account, workspace, and report data.
  • Composio: manages the secure connections to your marketing platforms and the authorisation tokens behind them.
  • Stripe: processes subscription payments.
  • Resend: sends service and team-invitation emails.
  • Anthropic: generates the optional AI summary (see section 5).
  • Google: Google sign-in; the Google Ads, Google Analytics, Search Console, and Business Profile APIs for the accounts you connect; and Google Analytics and Google Ads on our marketing site where you have consented.
  • Meta Platforms: the Meta Ads API for the accounts you connect, and the Meta (Facebook) Pixel on our marketing site where you have consented.

Each processor handles your data under a contract that requires them to keep it secure and use it only on our instructions. We may also disclose data where we are legally required to (for example, to comply with a court order), or to protect our rights, property, or safety.


7. International transfers

Some of our providers (such as Vercel, Supabase, Stripe, Composio, Resend, Anthropic, Google, and Meta) may process data on servers outside the UK, including in the United States. Where data leaves the UK, we rely on appropriate safeguards recognised under UK data protection law, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the UK extension to the EU-US Data Privacy Framework, so your data stays protected to UK standards.


8. Your clients’ data and your responsibilities

Perch is built for marketers and agencies. If you connect accounts that contain the personal data of your own clients or customers (for example, a client’s ad or analytics account), then for that data you are the controller and Perch acts as your processor. We process it only to provide the reporting service to you, on your instructions.

You are responsible for:

  • having the right and a lawful basis to connect those accounts and bring their data into Perch;
  • making sure your own privacy notices cover the use of a reporting tool like Perch;
  • only inviting people who are entitled to see that data into your workspace.

If you need a data processing agreement for this arrangement, email hello@thrivingcolibri.ai.


9. How long we keep your data

We keep personal data only as long as we need it:

  • Waitlist email: kept until the beta opens and we have invited you, or until you ask us to remove you, whichever comes first.
  • Account and report data: kept while your account is active. If you delete your account or ask us to, we delete or anonymise it within a reasonable period.
  • Connected platform data: fetched to build your reports and cached only as long as needed to run the service. Disconnecting a platform stops further access; see Deleting your data.
  • Billing records: kept for as long as the law requires (for example, for tax and accounting).
  • Enquiries and feedback: kept while we are in contact and for a reasonable period afterwards.

10. Your rights

Under UK GDPR you have the right to:

  • Be informed about how we use your data (this policy).
  • Access the personal data we hold about you.
  • Rectification of inaccurate data.
  • Erasure of your data (the “right to be forgotten”).
  • Restrict processing in certain circumstances.
  • Data portability, to receive your data in a portable format.
  • Object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent at any time where we rely on consent (this won’t affect processing already carried out).

To exercise any of these, email hello@thrivingcolibri.ai. We will respond within one month. There is no charge unless a request is clearly unfounded or excessive.


11. How to complain

If you are unhappy with how we have handled your data, please contact us first so we can put it right. You also have the right to complain to the UK’s data protection regulator:

Information Commissioner’s Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113


12. Security

We take reasonable technical and organisational measures to protect your data against loss, misuse, and unauthorised access, including encrypted connections, hosted infrastructure with access controls, and keeping platform authorisation tokens either with our connection provider or in a part of our database that only the Perch service can read. No method of transmission over the internet is completely secure, but we work to protect your information and keep our practices under review.


13. Children

Perch is aimed at businesses and is not directed at children under 16. We don’t knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.


14. Changes to this policy

We may update this policy from time to time. When we do, we will change the “Last updated” date at the top, and we will make significant changes clear. Please check back occasionally.


15. Contact us

Thriving Colibri Ltd
68 Filton Road, Bristol, BS7 0PB, United Kingdom
Email: hello@thrivingcolibri.ai