Last updated 20 August 2026 · TGF Digital Ltd, United Kingdom
This describes exactly what Peregrine collects, why, and who else sees it. It is written to be read rather than to be defensible, so where something is a genuine limitation it says so.
Peregrine is operated by TGF Digital Ltd, a company registered in England and Wales. Company number: registration in progress — this page is updated the day it is issued. Registered office: registration in progress — this page is updated the day it is issued. Not VAT registered, so no VAT is added to these prices. For anything on this page, including a request to see or delete your data, email tgf@xpose.online.
This distinction matters if you are an agency, because your client will ask about it.
| When | What | Why | Kept |
|---|---|---|---|
| You send an enquiry | Name, email, company, number of sites, the site you named, your message, your IP address, browser user agent and referring page | To reply, and to work out what to quote. IP and user agent are kept because the form is public and they are what let us recognise abuse. | Until you ask us to delete it |
| You measure a site | The address you typed, and the sizes of the images on it | To produce the report. The result is cached for 30 minutes so a shared link does not hammer the site being measured. | 30 minutes, then gone |
| You upload an image to the demo | The image itself | To optimise it and show you the result | Deleted before the response is written — it is never stored |
| You have an account | Name, email, a hashed password, session cookie, and the sites on your account | To let you sign in and see your own portfolio and nobody else’s | While the account exists |
| You subscribe | Stripe customer and subscription identifiers, plan, number of sites, amount | To know what you are paying for. Card numbers never reach our servers — they go directly to Stripe. | Six years, for UK accounting requirements |
| Your site serves images | Counts and byte sizes of converted files, per day | To show usage in the console and to bill correctly | While the site is on the service |
These are the only third parties involved, and each one only receives what it needs. This table is the live sub-processor list: we give account holders 30 days’ notice by email before adding to it, so it is the page to check rather than a document to request.
| Who | What they get | Where |
|---|---|---|
| Bunny.net | The image files we deliver on your behalf, and standard CDN request logs | EU (storage in Germany or the UK, delivered worldwide) |
| Stripe | Your payment details, name and billing address, directly — not via us | EU / US |
| Mailgun | The contents of enquiry notifications sent to us | EU |
| Google reCAPTCHA Enterprise | Signals from the forms on this site, to tell a person from a bot | EU / US |
| Netcup | Hosting for our servers | Germany |
Under UK GDPR you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Email tgf@xpose.online and we will do it within 30 days — usually the same week, because there is not very much of it. If you are unhappy with how we have handled that, you can complain to the Information Commissioner’s Office.
Passwords are stored hashed, never in plain text. API keys are stored as hashes too, so a database dump does not hand anyone working keys for the sites we deliver. Credentials for third parties live in root-owned files on the servers, not in the applications that face the web — the console cannot reach the CDN account key even if it were compromised. Everything is served over HTTPS.
If this changes materially we will email account holders rather than quietly updating the date at the top.
This notice describes our actual practice accurately, but it has not been reviewed by a solicitor. If you need a warranty to that effect before signing something, say so and we will get it reviewed.