Legal
Privacy Policy
What Perch collects, at a glance
The short version, for the apps: your Mac does the diagnosis and keeps the results to itself. Pair an iPhone and it reads a copy across your own network. Neither app runs any analytics or crash reporting. This website is different from both apps: it keeps a waitlist and counts anonymous visits.
| Data | Where it goes |
|---|---|
| Scan results & device list | Your Mac only |
| Wi-Fi measurements | Your Mac only |
| Diagnosis history | Your device only |
| Pairing key & certificate | Your Mac's Keychain |
| App analytics | None collected |
| Crash reports | None collected |
| Waitlist name & email | Google Sheets |
| Website page views | Vercel Web Analytics, anonymous |
About this policy
This policy explains how Rahul Kumar Gupta, trading as SRS Tech ("we", "our", "us"), of Bengaluru, Karnataka, India, handles data for Perch. Perch is two apps that share one core: Perch for Mac and Perch for iPhone. Where the two differ, this policy names which app it means.
Both apps are in build. Neither has been released, and this policy describes what each one does today so it stays accurate the day either app ships.
Your network data stays on your network
Your network data stays on your network. Scan results, device addresses, network names, IP addresses and hostnames go into a database file on your own Mac.
There is no server, no cloud, and nothing about your network travels past your own local network.
What your paired iPhone reads, and what it does not
Pair an iPhone with your Mac and it can read some of what the Mac holds. For each device it lists: hardware address, IPv4 address, hostname and vendor name. It also reads the Mac's latest verdict and its watch samples, which carry signal, negotiated rate, channel, band and gateway latency.
Network names and BSSIDs never cross to the phone. They stay on the Mac.
That connection runs over your own network, pinned with TLS to the one certificate you approved by comparing six digits shown on both screens. A Mac with no pairing on its books, and no pairing window open, opens no port for a phone to reach.
What the iPhone cannot see
Some of this sits outside Perch's reach, in your favour. iOS gives a normal App Store app no signal strength, no neighbouring networks, no channel and no band. iOS enforces that limit, and Perch has no way around it.
iOS also returns a fixed, spoofed hardware address to every third-party app. The iPhone app can never read the real hardware addresses of other devices on your network, or name their makers. Reading your network's name or an access point's identifier needs an entitlement Perch does not request.
Permissions, and what each buys
Four prompts altogether: three on the Mac, one on the phone. Each one arrives next to what it buys, and none of them lands during onboarding.
- Location Services, on the Mac. Names the networks around you, decides the country code that governs which channels Perch can recommend, and unlocks a beacon detail some access points broadcast. The scan works without it: refuse it and Perch still counts your neighbours, grades the contention and gives you the verdict, but refusing costs more than named neighbours; it also costs the country code that decides which channels Perch can legally recommend, and the beacon detail.
- Local Network, on the Mac. Asked before Perch looks for devices on your network.
- Notifications, on the Mac. Asked when you switch alerts on, and again when you open the pairing window. Never at launch.
- Local Network, on the iPhone. Asked ahead of the phone's first measurement: Perch tells you the ask is coming and why beforehand, explains it in five languages, and reports a refusal as a refusal rather than as a broken router.
Every destination Perch contacts
Perch reaches a small, fixed set of addresses, and every one is disclosed in the app before it dials out:
- Your router.
- The DNS server your Mac is already configured to use.
- Cloudflare's
1.1.1.1, and Quad9's9.9.9.9when the first goes quiet. - One reserved address, used only to detect a local interceptor.
- Cloudflare's
speed.cloudflare.com, for the opt-in bufferbloat check. That download stops at 100 MB and spends around 25 MB on a typical home connection.
Those servers see your IP address, the same as any website you open. Perch sends none of your data to any of them.
Analytics and crash reporting: none
No analytics SDK is integrated into either app. Nothing about your use of Perch is collected. There is no account, and there is no opt-out, because there is nothing to opt out of.
Perch's privacy manifest, filed with Apple for every release, is the verifiable form of that claim. Its first three declarations, quoted as the app's own words to Apple: no tracking, no tracking domains, no collected data types.
The manifest also lists two Apple APIs Perch calls, with a reason for each: one saves your bufferbloat opt-in where no other app can read it, and one reads how long your iPhone has been running so Perch can time a measurement. The boot time itself stays on your phone; the only thing Perch takes from it is how long something took.
If Perch ever adopts consented product-usage analytics, it will carry no network identifier, and this policy will be updated before it ships.
Pairing and the local channel
The first time you open pairing, the Mac app generates a P-256 private key and a self-signed certificate, both held in your Mac's login Keychain. Pairing an iPhone means comparing a six-digit number derived from that certificate on both screens and confirming they match. The phone then pins the certificate's digest as its whole trust decision for that Mac.
Reinstalling the Mac app changes the certificate. The phone refuses the old digest and asks you to pair again, because accepting a changed certificate silently would be indistinguishable from an attack.
Each pairing is its own token: individually visible and individually revocable from your list of paired devices. Tokens expire at 90 days and renew on their own as that date approaches.
Purchases, once they exist
Nothing in Perch is purchasable today. When it is, Apple's StoreKit will hand the app a signed transaction, and the app checks that transaction on your own device. There is no licence server and no receipt server; verification happens on your device.
The website and the waitlist
This site works differently from the two apps described above. Join the waitlist and your name and email go, through Google Apps Script, into a private Google Sheet. Cloudflare Turnstile and a hidden field guard the form against automated submissions. You will receive two emails: a confirmation right away, and then one message telling you Perch is ready to install.
The website also counts anonymous page views through Vercel Web Analytics. It sets no cookies and does not identify visitors.
Retention and deletion
The Mac keeps its data in one file, named and set apart on purpose so you can find it and delete it yourself. Deleting it clears your scan history, your device list and your watch history in one step.
The iPhone writes its own copy of that file inside its app sandbox. Delete the app and iOS removes it with everything else in that sandbox.
A waitlist entry lives in our Google Sheet until we remove it. Email support@srstech.in to ask.
Children's privacy
Perch is built for adults managing a home network and is not directed at children under 13. We do not knowingly collect personal information from anyone that age. If you believe a child has given us personal information, contact us and we'll delete it.
Your rights
Depending on where you live, you may have the right to access, correct or delete personal data we hold about you, or to withdraw consent at any time.
Because your network and diagnostic data stays on your own device, there is usually nothing on our side to access or delete beyond a waitlist entry. Email support@srstech.in and we'll handle it directly.
Changes to this policy
We may update this policy as the apps near release. Each update changes the "last updated" date at the top of this page. Continuing to use Perch after an update means you accept the revised policy.
Contact
Questions about this policy or your data:
Rahul Kumar Gupta, trading as SRS Tech
Bengaluru, Karnataka, India
support@srstech.in
srstech.in