Privacy policy

Last updated 11 October 2026 · Terms of use

The short version

What this policy covers

Perch is open source: anyone can build it, change it and run their own server. The official services are a non-commercial project run by one person, Arif Çınar Tekin (“we”), as an individual. This policy covers only what he runs and publishes:

It does not cover Perch Servers or sync relays run by other people, or builds of Perch published by others. If you sign in to someone else's server, its operator is the data controller and their own policy applies. We have no access to those servers and can't see, change or delete anything on them. The apps show which server you're connected to, and that server's own policy when it has published one.

Questions, requests and complaints about our services: [email protected].

Using Perch without an account

The browser extension and the iPhone and Android apps work without any account. Your subscriptions, categories, read and starred articles, settings and notes are stored only on your device (in the browser's extension storage, or in the app's files on your phone, left out of cloud backups on Android). Nothing is sent to us.

To show you your feeds, your device itself connects to other sites:

Some things never leave the device at all: the app lock's PIN (kept in the iPhone's Keychain, Android's Keystore or the browser), the fingerprint or face that opens it (checked by the phone, never seen by Perch), the camera picture when you scan a chain's QR code (read on the phone and not kept), the app icon and background picture you choose, and the starter packs and Explore list, which ship inside the apps, so choosing one tells no server anything.

The extension asks for no site access when installed. It asks for one site at a time when you add a feed from it, or for all sites only if you turn on automatic feed discovery. It reads a page only when you open Perch on it, and only the feed links the page names.

The web reader (app.perch.ws)

The reader at app.perch.ws works like the extension: your subscriptions, reading and notes are stored in your browser, and a sync chain links it to your other devices. A web page isn't allowed to fetch other sites itself, so it asks our server to fetch feeds and article pages for it. These requests carry no account or cookie, and the server keeps no record of who asked. It keeps each fetched page for 10 minutes in a cache shared by everyone, so a popular feed is fetched once: the server can tell which feeds are popular, not who reads them. Images inside articles still load straight from the publisher.

Sync chains (sync.perch.ws)

A sync chain links your devices without an account. Everything is encrypted on your devices with a key derived from the chain code, which never leaves them. Even feed addresses and record names are hidden. Our relay stores:

We can see how many records a chain has, how big they are and when they change. We cannot see what they contain. Read state is forgotten after 60 days, deleted items after 90 days, and a chain no device has used for 180 days is deleted with everything in it. You can delete a chain at any time from Settings → Sync.

A Perch account on account.perch.ws

A Perch account is your name for sharing notes as public pages. It isn't needed to read, and it doesn't sync your library: your feeds, what you read and your notes stay on your devices (and in your sync chain, encrypted). The server keeps only this:

What Why
Username and display name To sign in, and to sign your shared notes (as @username).
A hash of your recovery code To let you set a new password if you forget yours. The code is made on your device and shown to you once; we keep only a hash of it.
A hash of a key derived from your password To check your password. Your password never leaves your device: the app derives a key from it (Argon2id) and the server stores only a hash of that key.
Signed-in devices: a name, when it signed in, when it was last seen So you can see and sign out your devices. The name is a generic label the app sends, such as “Perch on iPhone” or “Web · MacIntel”. Sessions expire after 180 days unused.
The notes you share To show them at their public address. Only the notes you choose to share, until you stop sharing or delete them.

Shared notes

Notes are private. When you share one, Perch publishes a copy at a random address (app.perch.ws/shared/…) that anyone with the link can read. The page shows your note, the article's title, link and source, your @username and the dates. It asks search engines not to index it, but anyone who has the link can copy it. Editing the note updates the page; deleting the note or choosing “Stop sharing” removes it.

Each shared page has a report form. A report stores the reason, what you write and, only if you give it, a way to reach you. We use reports only to review the page, and delete the contact address once the report is dealt with.

No email

account.perch.ws doesn't ask for an email address and never sends email. A forgotten password is replaced with your recovery code. We have no way to write to you, so there are no newsletters, announcements or reminders.

Instead of an email check or a CAPTCHA, signing up asks your device for a few seconds of computation (a “proof of work”). It sends nothing about you; it just makes creating accounts in bulk expensive.

Perch Servers run by other people can be set up to send email for sign-up and password reset. That's their choice and their responsibility.

If someone took our server

We try to keep as little as possible, so that a stolen disk or a leaked backup says little about you. Here is exactly what it would contain:

Deleted data is overwritten in the database rather than left on disk, and is gone from backups within 14 days. How to check which code our server runs is on the transparency page.

What we don't collect

The server's own output contains start-up messages and error messages; these don't include IP addresses or what you read.

Cookies and local storage

account.perch.ws sets one cookie when you sign in there: your session, HTTP-only and sent only to account.perch.ws. The reader at app.perch.ws sets none; it keeps your Perch account's sign-in in your browser's storage, like the extension. There are no other cookies, so there is no cookie banner. This site (perch.ws) sets no cookies; it remembers your language choice in your browser's local storage, which never leaves your device.

Who else is involved

Using our servers therefore means your data is transferred outside Türkiye and the EU. If you don't want that, use Perch without an account, or run your own server.

How long we keep things

Deleting your data

You can delete your Perch account yourself: on account.perch.ws, in the iPhone and Android apps (Settings → Perch account) or in the extension (Settings → Perch account). It deletes your account, its sessions and the notes you shared at once. Data on your devices stays there until you remove it or uninstall the app. You can export your subscriptions as OPML at any time.

Your rights

Under Türkiye's data protection law (KVKK, article 11) and, where it applies, the EU GDPR, you can ask what we hold about you, get a copy, have it corrected or deleted, and object to how it is used. Most of this you can do yourself in the app; for anything else write to [email protected]. We answer within 30 days. You can also complain to the Personal Data Protection Authority (KVKK) or your local data protection authority.

The legal basis for what we store is that it's needed to provide the service you asked for (KVKK art. 5(2)(c); GDPR art. 6(1)(b)), and, for abuse protection, our legitimate interest in keeping the service working.

Children

Perch accounts are for people 13 and older.

Changes

If we change what we collect, we'll update this page first and announce it here and in the apps — we have no email address to write to you. Every version of this page is in the project's history.

Gizlilik politikası

Son güncelleme 11 Ekim 2026 · Kullanım koşulları

Kısaca

Bu politika neyi kapsar

Perch açık kaynaklıdır: herkes onu derleyebilir, değiştirebilir ve kendi sunucusunu çalıştırabilir. Resmi hizmetler, tek bir kişinin, Arif Çınar Tekin'in (“biz”) bireysel olarak ve ticari amaç gütmeden işlettiği bir projedir. Bu politika yalnızca onun işlettiği ve yayınladıklarını kapsar:

Başkalarının işlettiği Perch sunucuları ya da senkron aktarıcıları ile başkalarının yayınladığı Perch sürümleri bu politikanın kapsamında değildir. Başkasının sunucusuna giriş yaparsan veri sorumlusu o sunucunun işletmecisidir ve onun politikası geçerlidir. Bu sunuculara erişimimiz yoktur; oradaki hiçbir şeyi göremez, değiştiremez ya da silemeyiz. Uygulamalar hangi sunucuya bağlı olduğunu ve o sunucu yayınlamışsa kendi politikasını gösterir.

Hizmetlerimizle ilgili soru, talep ve şikayetler için: [email protected].

Perch'ü hesapsız kullanmak

Tarayıcı eklentisi ile iPhone ve Android uygulamaları hesap olmadan çalışır. Abonelikler, kategoriler, okunan ve yıldızlanan makaleler, ayarlar ve notlar yalnızca cihazında saklanır (tarayıcının eklenti deposunda ya da telefonunda uygulamanın dosyalarında; Android'de bulut yedeğine dahil edilmez). Bize hiçbir şey gönderilmez.

Akışları gösterebilmek için cihazın başka sitelere doğrudan bağlanır:

Bazı şeyler cihazdan hiç çıkmaz: uygulama kilidinin PIN'i (iPhone'un Keychain'inde, Android'in Keystore'unda ya da tarayıcıda), kilidi açan parmak izi ya da yüz (telefon kontrol eder, Perch hiç görmez), bir zincirin QR kodunu okuturken kameranın görüntüsü (telefonda okunur, saklanmaz), seçtiğin uygulama ikonu ve arka plan resmi, ve uygulamaların içinde gelen başlangıç paketleri ile Keşfet listesi; birini seçmek hiçbir sunucuya bir şey söylemez.

Eklenti kurulurken hiçbir siteye erişim istemez. Ondan bir akış eklediğinde yalnızca o site için izin ister; tüm siteler için izni yalnızca otomatik akış bulmayı açarsan ister. Bir sayfayı yalnızca Perch'ü o sayfada açtığında okur, o da sayfanın belirttiği akış bağlantılarıyla sınırlıdır.

Web okuyucu (app.perch.ws)

app.perch.ws'teki okuyucu eklenti gibi çalışır: aboneliklerin, okudukların ve notların tarayıcında saklanır; bir senkron zinciri onu diğer cihazlarına bağlar. Bir web sayfasının başka siteleri kendisi çekmesine izin verilmediği için, akışları ve makale sayfalarını sunucumuzdan ister. Bu istekler hiçbir hesap ya da çerez taşımaz ve sunucu kimin istediğini kaydetmez. Çekilen her sayfayı herkesin ortak kullandığı bir önbellekte 10 dakika tutar; böylece popüler bir akış bir kez çekilir. Sunucu hangi akışların popüler olduğunu bilir, kimin okuduğunu bilmez. Makalelerdeki resimler yine doğrudan yayıncıdan yüklenir.

Senkron zincirleri (sync.perch.ws)

Senkron zinciri, cihazlarını hesap olmadan birbirine bağlar. Her şey, zincir kodundan türetilen ve cihazlarından hiç çıkmayan bir anahtarla cihazlarında şifrelenir. Akış adresleri ve kayıt adları bile gizlidir. Aktarıcımız şunları saklar:

Bir zincirde kaç kayıt olduğunu, ne kadar büyük olduklarını ve ne zaman değiştiklerini görebiliriz; içlerinde ne olduğunu göremeyiz. Okundu bilgisi 60 gün, silinen öğeler 90 gün sonra unutulur. 180 gün boyunca hiçbir cihazın kullanmadığı zincir, içindekilerle birlikte silinir. Bir zinciri istediğin an Ayarlar → Senkron'dan silebilirsin.

account.perch.ws'te bir Perch hesabı

Perch hesabı, notları herkese açık sayfa olarak paylaştığın adındır. Okumak için gerekmez ve kitaplığını senkronlamaz: akışların, ne okuduğun ve notların cihazlarında (ve şifreli olarak senkron zincirinde) kalır. Sunucu yalnızca şunları tutar:

Ne Neden
Kullanıcı adı ve görünen ad Giriş için ve paylaştığın notlarda imza olarak (@kullanıcıadı).
Kurtarma kodunun özeti Şifreni unutursan yenisini belirleyebilmen için. Kod cihazında üretilir ve sana bir kez gösterilir; biz yalnızca özetini saklarız.
Şifrenden türetilen anahtarın özeti Şifreni doğrulamak için. Şifren cihazından çıkmaz: uygulama ondan bir anahtar türetir (Argon2id), sunucu yalnızca o anahtarın özetini saklar.
Giriş yapılmış cihazlar: bir ad, giriş zamanı, son görülme zamanı Cihazlarını görebilmen ve oturumlarını kapatabilmen için. Ad, uygulamanın gönderdiği genel bir etikettir; örneğin “Perch on iPhone” ya da “Web · MacIntel”. Kullanılmayan oturumlar 180 gün sonra sona erer.
Paylaştığın notlar Herkese açık adreslerinde gösterebilmek için. Yalnızca paylaşmayı seçtiğin notlar, paylaşmayı durdurana ya da silene kadar.

Paylaşılan notlar

Notlar gizlidir. Birini paylaştığında Perch, bağlantıya sahip herkesin okuyabileceği rastgele bir adreste (app.perch.ws/shared/…) bir kopyasını yayınlar. Sayfada notun, makalenin başlığı, bağlantısı ve kaynağı, @kullanıcıadın ve tarihler görünür. Sayfa arama motorlarından dizine eklenmemesini ister, ama bağlantıya sahip olan herkes içeriği kopyalayabilir. Notu düzenlersen sayfa güncellenir; notu silersen ya da “Paylaşmayı durdur”u seçersen sayfa kaldırılır.

Her paylaşılan sayfada bir şikayet formu vardır. Şikayet; nedeni, yazdıklarını ve yalnızca verirsen sana ulaşma yolunu saklar. Şikayetleri yalnızca ilgili sayfayı incelemek için kullanırız; iletişim adresini şikayet sonuçlandığında sileriz.

E-posta yok

account.perch.ws e-posta adresi istemez ve hiç e-posta göndermez. Unutulan bir şifre, kurtarma kodunla yenilenir. Sana yazmamızın hiçbir yolu olmadığı için bülten, duyuru ya da hatırlatma da yoktur.

Kayıt sırasında e-posta doğrulaması ya da CAPTCHA yerine cihazın birkaç saniyelik bir hesap yapar (“işlem kanıtı”). Bu senin hakkında hiçbir şey göndermez; yalnızca toplu hesap açmayı pahalı hale getirir.

Başkalarının işlettiği Perch sunucuları, kayıt ve şifre sıfırlama için e-posta gönderecek şekilde ayarlanabilir. Bu onların tercihi ve sorumluluğudur.

Sunucumuz ele geçirilirse

Çalınan bir disk ya da sızan bir yedek senin hakkında olabildiğince az şey söylesin diye mümkün olduğunca az veri tutuyoruz. İçinde tam olarak şunlar bulunur:

Silinen veriler diskte bırakılmaz, veritabanında üzerine yazılır; 14 gün içinde yedeklerden de silinir. Sunucumuzun hangi kodu çalıştırdığını nasıl kontrol edeceğin şeffaflık sayfasında.

Neleri toplamıyoruz

Sunucunun kendi çıktısında açılış mesajları ve hata mesajları bulunur. Bunlarda IP adresi ya da ne okuduğun yer almaz.

Çerezler ve yerel depolama

account.perch.ws, orada giriş yaptığında tek bir çerez kullanır: oturum çerezi. Bu çerez yalnızca HTTP üzerinden okunabilir ve yalnızca account.perch.ws'e gönderilir. app.perch.ws'teki okuyucu hiç çerez kullanmaz; Perch hesabının oturumunu eklenti gibi tarayıcının deposunda tutar. Başka çerez olmadığı için çerez bildirimi de yoktur. Bu site (perch.ws) çerez kullanmaz; dil tercihini tarayıcının yerel deposunda hatırlar, bu bilgi cihazından çıkmaz.

Başka kimler işin içinde

Dolayısıyla sunucularımızı kullanmak, verinin Türkiye ve AB dışına aktarılması anlamına gelir. Bunu istemiyorsan Perch'ü hesapsız kullanabilir ya da kendi sunucunu çalıştırabilirsin.

Ne kadar süre saklıyoruz

Verini silmek

Perch hesabını kendin silebilirsin: account.perch.ws'te, iPhone ve Android uygulamalarında (Ayarlar → Perch hesabı) ya da eklentide (Ayarlar → Perch hesabı). Bu işlem hesabını, oturumlarını ve paylaştığın notları tek seferde siler. Cihazlarındaki veriler, sen kaldırana ya da uygulamayı silene kadar orada kalır. Aboneliklerini istediğin zaman OPML olarak dışa aktarabilirsin.

Hakların

6698 sayılı Kişisel Verilerin Korunması Kanunu'nun 11. maddesi ve uygulandığı durumlarda AB Genel Veri Koruma Tüzüğü (GDPR) kapsamında hakkında hangi verileri tuttuğumuzu sorabilir, bir kopyasını alabilir, düzeltilmesini ya da silinmesini isteyebilir ve işlenmesine itiraz edebilirsin. Bunların çoğunu uygulamada kendin yapabilirsin; geri kalanı için [email protected] adresine yaz. 30 gün içinde yanıt veririz. Kişisel Verileri Koruma Kurumu'na ya da bulunduğun yerdeki veri koruma otoritesine de şikayette bulunabilirsin.

Sakladığımız verilerin hukuki dayanağı, istediğin hizmeti sunmak için gerekli olmalarıdır (KVKK m. 5/2-c; GDPR m. 6/1-b). Kötüye kullanıma karşı alınan önlemlerin dayanağı ise hizmeti çalışır tutmaktaki meşru menfaatimizdir.

Çocuklar

Perch hesapları 13 yaş ve üzeri içindir.

Değişiklikler

Topladığımız veriler değişirse önce bu sayfayı güncelleriz ve bunu burada ve uygulamalarda duyururuz; sana yazabileceğimiz bir e-posta adresi yok. Bu sayfanın her sürümü projenin geçmişinde durur. Bu metnin Türkçe ve İngilizce sürümleri arasında fark olursa Türkçe sürüm esas alınır.