PerlTurner Pension SolutionsBack to Perl →

Documents

Terms of ServiceAgreementPrivacy PolicyYour dataAcceptable Use PolicyHow you may use itData and AI Usage DisclosureWhat powers it

Your data

Privacy Policy

Last updated August 16, 2026

1. Who we are and what this covers

Retirement Plan Specialists, Inc., a Florida corporation doing business as Turner Pension Solutions ("TPS," "we," "us"), operates Perl, a web-based research and prospecting service for retirement-plan professionals at app.tps5500.com.

This Policy explains what personal information we collect from and about the people who use Perl, how we use and share it, how long we keep it, and the choices you have. It also explains, in Section 4, an important distinction: the retirement-plan filing data inside Perl is public government record, and we are not its source.

This Policy does not apply to TPS's separate third-party administration business.


2. The short version

  • We collect the business-contact information you give us to request and hold an account, plus a limited record of how you use the Service.
  • We do not store the text of your conversations with Perl.
  • We do not sell your personal information, and we do not use it for targeted advertising.
  • Our AI provider is contractually prohibited from training its models on your content.
  • Public Form 5500 filing data is in the Service because it is public record. If you believe a filing about you or your company is wrong, the correction has to happen at the filing, not in our copy — see Section 4.
  • You can ask us to access, correct, or delete your account information at any time (Section 9).

3. Information we collect about you

3.1 Information you give us

Access-request and registration information. When you request access, we collect your first and last name, business email address, firm or company name, and — where the form asks — your telephone number, professional role or position, business street address, city, state, ZIP code, and any message you write to us. We also record our own internal review status, review date, reviewer, and review notes.

Account profile. Once provisioned, we hold the same identity and contact fields on your user profile, along with your account status, your plan tier, and your billing status.

Support and other correspondence. Emails and messages you send us, and our replies.

Payment information. Payments are processed by Stripe, Inc., which collects your payment-card or bank information directly. We do not receive or store your full payment-card number. We receive and store only a billing status, plan tier, and transaction records.

3.2 Information generated by your use of the Service

Authentication records. Because sign-in uses a single-use link emailed to you, we store authentication records including your email address, sign-in tokens and their expiry, and active session records.

Saved work. Searches you save and prospect lists you save (including the snapshot of plan records in the list), each associated with your email address.

Generated reports. When you have Perl build a plan report or dossier, we store the full text of that report along with your email address as the person it was generated for. These report records are kept as a permanent, insert-only record and are not deleted when you delete your account — see Section 9.4, which explains this and how to ask us about it.

Usage record. A running count of the messages you have sent, the date and time you were last active, and operational logs of each request. Those logs record metrics about a request — which model handled it, how many processing steps it took, token counts, and our cost — rather than the content of it. They do, however, record which plans you researched and which filing documents you downloaded, associated with your email address. We use this for troubleshooting, cost management, and abuse detection.

Profile signals — please read this one. Perl maintains a profile of what you research and how you write, so that she can be more useful and can match your register. It works like this: on approximately every tenth message you send (counted over the life of your account), the text of that single message, truncated to about 1,200 characters, is sent to a separate, smaller AI model. That model returns up to four short topic tags describing what you were researching — for example "401k prospecting" or "schedule h" — and a short note about your communication style, for example whether you write formally or casually and at what technical depth.

We store those tags and that note. We do not store the message itself. The tags accumulate into a running tally over time, so a long-standing account may hold a substantial list of the subjects it has researched. The style note is replaced each time and may be up to a few hundred words. We instruct the model not to include personal data or the raw text of your message in what it returns, and we have no reason to believe it does, but we do not independently filter its output before storing it.

Accounts used for sales demonstrations are excluded from this process entirely, and from the usage counters.

Assistant personalization settings. We store, per account, a relationship label, a preferred form of address, and personalization notes used to shape Perl's tone.

Who at TPS can see this. Our administrators can view, for each account, the profile and contact information, message count, last-active time, the most frequent inferred topic tags, and the stored style note. This access is limited to authorized TPS personnel and is used for support, account management, and improving the Service.

Voice dictation — a third party is involved. The chat interface includes an optional microphone button. If you use it, your browser sends the audio from your microphone to its own vendor's cloud speech-recognition service — Google for Chrome, Microsoft for Edge — which returns a text transcript that becomes your message. This happens in your browser, between you and your browser's vendor, before it reaches us. We do not receive or store the audio, and we receive only the resulting text as if you had typed it. That processing is governed by your browser vendor's privacy policy, not ours. If you would rather no third party process your voice, type instead of dictating.

Technical and security information. Our network provider and our hosting platform automatically process information including your IP address, browser user-agent, request timestamps, and pages requested, for delivery, performance, abuse prevention, and security. Our access-request form additionally processes your IP address to rate-limit submissions, and uses a bot-detection service that receives similar technical signals.

A note about our own email. When you submit an access request, the contents of that request are also emailed to us so that we see it promptly. That means a copy of what you submitted exists in our business mailbox independently of our database, and is retained under our ordinary business email retention rather than the database schedule in Section 7.

3.3 What we do not collect

We do not knowingly collect, and ask you not to submit, Social Security numbers, financial-account numbers, health information, government-identification numbers, participant-level retirement-plan data, or information about anyone under 18. The Service is not designed for and must not be used for these.

3.4 We do not keep a transcript of your conversations

The questions you ask Perl and the answers she gives are not written to a conversation or transcript table in our database. They are transmitted to our AI provider for processing (Section 6) and are held in your browser for the duration of your session; when that session ends they are gone.

Two honest qualifications, so this statement is not read for more than it says:

  1. Reports are an exception. If you ask Perl to build a plan report or dossier, that output is saved — see "Generated reports" in Section 3.2. It is a document you asked for, not a transcript, but it is assistant-written text we keep and associate with you.
  2. We keep facts derived from your conversations. The usage record and profile signals in Section 3.2 are generated from what you ask. We do not keep the questions; we do keep counts, topic tags, the plans you researched, and a note on your writing style.

4. Public Form 5500 filing data — an important distinction

The retirement-plan information in Perl comes from Form 5500 and Form 5500-SF annual reports, their schedules, and their attachments, filed by plan sponsors and administrators with the U.S. Department of Labor and published by the Department as public records, along with related public datasets. We also retrieve individual filing documents from Department of Labor systems.

Those public filings contain some information about individuals — for example the names of plan sponsors' and administrators' signing officials, business addresses, and the names of service providers and their compensation. That information is in the Service because the U.S. government publishes it as public record. We are not its source, we did not collect it from the individuals concerned, and we cannot change what a filing says.

If you believe a filing about you or your organization is inaccurate: the correction must be made at the source, by the plan's filer, through an amended filing with the Department of Labor. We refresh our copy from the Department's published data on a recurring basis, so a corrected or amended filing will appear in the Service after the Department publishes it. If you believe our copy misstates what a filing actually says, write to us at perl@wehelppeopleretire.com and we will investigate.

Public filing data is also, by its nature, historical. Filings describe a plan year that has already closed, and are published on a delay. See the Data and AI Usage Disclosure for detail.


5. How we use information

We use the information described in Section 3 to:

PurposeExamples
Provide the Serviceauthenticate you, run your searches, generate reports and exports, save your work
Manage accessreview access requests, provision and suspend accounts, enforce seat limits
Personalizeshape Perl's tone and topical focus using the profile signals in Section 3.2
Bill and collectprocess subscriptions, apply referral credits, send invoices and receipts
Support yourespond to your questions and troubleshoot
Secure and improvedetect abuse and fraud, enforce rate limits, monitor performance and cost, fix defects, and develop features using aggregated or de-identified usage information
Communicatesend service, security, billing, and account notices, and — with your consent or as otherwise permitted — occasional product news you can unsubscribe from
Complymeet legal, tax, accounting, and recordkeeping obligations, and respond to lawful requests

We do not use your information to make decisions about you that produce legal or similarly significant effects without human involvement, and we do not engage in profiling for that purpose. The profile signals in Section 3.2 affect only how Perl writes to you and what she anticipates you are interested in.


6. How we share information

We do not sell personal information. We do not share it for cross-context behavioral advertising. We disclose it only as follows.

6.1 Service providers. We use the following providers to operate the Service. Each processes information only as needed to provide its service to us, under contract.

ProviderWhat it does for usWhat it processes
Render Services, Inc.application hosting and managed PostgreSQL databaseall stored account, profile, and saved-work data; server logs
Cloudflare, Inc.DNS, TLS, network security and filtering, bot detection on our registration form, and object storage for filing documentsIP address, request metadata, technical signals; stored filing documents
Anthropic PBthe AI models that generate Perl's answers, read filing documents, and derive the profile signals in Section 3.2the content of your requests and the filing data retrieved to answer them; separately, the single-message excerpt described in Section 3.2
Resend — Plus Five Five, Inc.sending transactional email, including sign-in links, access-request notifications, and account noticesyour email address and message content
U.S. Department of Labor (EBSA)source of Form 5500 filing documents, which we retrieve on requestthe identity of the filings requested. We retrieve using a single TPS account, so the Department does not learn which of our users asked. When you download a filing document, your browser fetches it from Department systems at that moment
Your browser vendor (Google for Chrome, Microsoft for Edge) — only if you use voice dictationconverting your speech to textthe audio from your microphone, sent by your browser directly to the vendor. See Section 3.2. We do not receive the audio. This is governed by your browser vendor's privacy policy
Stripe, Inc.subscription billing and payment processingyour billing contact and payment information, which it collects directly

We may add or change providers. We will keep this table current and will update the Last Updated date when we do.

6.2 Our AI provider does not train on your content. Our agreement with our AI provider prohibits it from training its models on content submitted through its API. As of the date of this Policy, its commercial terms state: "Anthropic may not train models on Customer Content from Services." That provider retains submitted content for a limited period for abuse detection and legal compliance under its own policies.

6.3 Within TPS. Our own personnel and contractors may access information as needed to run the Service and support you, subject to confidentiality obligations. If you participate in the Referral Credit Program, information about a referral you make will be used by TPS's third-party administration business to evaluate and service that referral.

6.4 Legal and safety. We may disclose information where we reasonably believe it is required by law, subpoena, or other lawful process, or is necessary to enforce our terms, protect our or others' rights, safety, or property, or investigate suspected fraud or abuse. Where lawfully permitted, we will make reasonable efforts to notify you first.

6.5 Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy or a successor policy with comparable commitments. We will notify you of a material change in the controller of your information.


7. How long we keep information

CategoryRetention
Access requests never acted onwe purge these periodically, generally after 180 days
Access requests we approved or declinedretained indefinitely as a record of the access decision
Copies of access requests in our business emailunder our ordinary business email retention
Account profile, personalization, and saved workfor the life of your account, then 90 days after termination, then deleted — see Terms of Service §13.5
Generated reports and dossiersretained indefinitely, including after account deletion — see Section 9.4
Authentication sessions and sign-in tokenssign-in tokens expire about 15 minutes after issuance and sessions after about 7 days; expired records are removed when the account is deleted
Usage counters and profile signalsfor the life of your account; deleted with the account
Operational and security logs7 days
Billing and tax recordsas required by law, generally seven years
Public Form 5500 filing dataretained as a historical research archive; this is public record and is not deleted on request — see Section 4

We may retain information longer where necessary to comply with law, resolve a dispute, or enforce our agreements.


8. Security

We protect information with measures including: transport encryption (TLS) for all traffic; a managed database with encryption at rest, provider-managed patching, and automated backups; a network layer with filtering and bot detection in front of the application; a read-only database role, read-only transactions, and a query guard, so that the queries the assistant writes against the Form 5500 data cannot modify it; separate least-privilege credentials, each confined to its own area, for the small number of operations that do write; parameterized statements for all writes, so that no assistant-written query is ever executed as a write; secrets held in the hosting platform's encrypted store rather than in code; and access limited to personnel who need it.

No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any required regulator as and when the law requires.


9. Your choices and rights

9.1 Rights we offer everyone. Regardless of where you live, and regardless of whether a particular privacy law applies to us, you may ask us to:

  • Confirm and access — tell you whether we hold personal information about you, and give you a copy in a portable format;
  • Correct — fix inaccurate information in your account;
  • Delete — delete your account and the personal information associated with it;
  • Export — provide a one-time export of your saved work;
  • Opt out of marketing — stop sending you non-essential email (you cannot opt out of service, security, and billing notices while you have an account); and
  • See and withdraw personalization — ask us what topic tags and style note we hold about you, and ask us to turn the personalization off. There is currently no self-service control for this in the Service; it is done by request to us, and we will honor it. 9.2 How to exercise them. Email perl@wehelppeopleretire.com from the address on your account, or write to the postal address in Section 13. We will respond within 45 days and may extend once by another 45 days with notice. We may need to verify your identity, which we will normally do by confirming control of the account email address. There is no charge unless a request is excessive or repetitive.

9.3 Appeals. If we decline a request, we will tell you why. You may appeal by replying to our decision or writing to perl@wehelppeopleretire.com within 30 days. We will respond to an appeal within 45 days. If we deny the appeal, we will tell you how to contact your state attorney general or other applicable authority.

9.4 What we will and will not delete.

Deleting your account removes: your profile and contact information, your personalization settings and the style note Perl held about you, your usage counters and topic tags, your saved searches, your saved prospect lists, your access-request record, and your sign-in sessions and tokens.

It does not remove:

a. Generated reports and dossiers. These are held in a permanent, insert-only record that also contains your email address. As the Service is currently built, we cannot delete them, including at your request. b. Records we must keep for legal, tax, accounting, security, or dispute-resolution purposes. c. Files you previously exported and downloaded — those are yours to keep. d. Copies of correspondence in our business email. e. Public Form 5500 filing data, which is public record and is not personal information we collected from you — see Section 4. f. Operational and security logs, until they age out on their normal schedule.

If you want a report deleted and we are not yet able to do it, tell us at perl@wehelppeopleretire.com and we will tell you honestly where that stands rather than let the request sit.

9.5 No sale, no targeted advertising, no significant automated decisions. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use it for profiling in furtherance of decisions producing legal or similarly significant effects. There is therefore nothing to opt out of in those categories.

9.6 No discrimination. We will not deny you service, charge you a different price, or provide a different quality of service because you exercised a privacy right.


10. Children

The Service is for business use by adults. We do not direct it to anyone under 18 and do not knowingly collect personal information from anyone under 18. If we learn we have, we will delete it. Contact perl@wehelppeopleretire.com.


11. Location of processing

We operate in the United States, and information is stored and processed in the United States by us and by the providers in Section 6.1. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws differ from those where you live.


12. Changes to this Policy

We may update this Policy. If we make a material change, we will notify you by email to your registered address or by a conspicuous notice in the Service before it takes effect, and we will update the Last Updated date. We encourage you to review it periodically.


13. Contact us

Privacy questions, requests, and appeals: Email: perl@wehelppeopleretire.com Mail: Retirement Plan Specialists, Inc., d/b/a Turner Pension Solutions, 1517 W Broadway St., Oviedo, Florida 32765 Telephone: 407-365-3490


Cookie and Tracking Notice

Effective date: August 16, 2026

What we use

Perl uses a small number of technologies that store or read information on your device. As of the date of this Notice, all of them are strictly necessary to deliver the Service you have asked for.

WhatPurposeTypeRoughly how long
Session cookiekeeps you signed in after you use your sign-in linkstrictly necessary, first-partyuntil you sign out or the session expires
Sign-in / CSRF and callback cookiescomplete the email sign-in flow and protect against cross-site request forgerystrictly necessary, first-partyshort-lived, minutes to the sign-in session
Bot-detection token on the registration formtells us a human, not a script, submitted an access requeststrictly necessary, third-party (Cloudflare Turnstile)short-lived, per submission
Network security and performance cookiesrouting, filtering, and abuse prevention at our network layerstrictly necessary, third-party Cloudflare)per provider, typically up to 30 days
Local browser storageholds your in-progress conversation and interface preferences in your own browserstrictly necessary, first-partyuntil you clear it or close the session

What we do not use

We do not use advertising cookies, cross-site tracking, advertising pixels, social-media trackers, or session-recording tools. We do not sell information collected by these technologies and we do not use them to build advertising profiles.

Your choices

Because all current technologies are strictly necessary, we do not present a cookie consent banner. You can block or delete cookies in your browser settings, but the Service will not be able to keep you signed in if you block ours. Most browsers also offer a "Do Not Track" or Global Privacy Control signal; we do not currently respond to Do Not Track, and because we do not sell data or serve targeted advertising, there is nothing for a Global Privacy Control signal to opt out of.

Questions

perl@wehelppeopleretire.com