Privacy Policy
Effective: September 2, 2026
This policy explains what PINGD (“PINGD,” “we,” “us”), operated by the PINGD developer, collects, why, how long we keep it, who processes it on our behalf, and the choices and rights you have. PINGDis a group-planning app: you create a crew, ask “who's in?”, and people answer in or out. We designed it to need as little personal data as possible — there is no email, phone number, password, social login, advertising identifier, or third-party ad tracking — but the list below is the complete and accurate account of what we do handle.
1. Information we collect
Information you provide. The display name you type (you choose it; we don't verify it); the crew names, questions, and optional plan location/address you create; your answers (in / out) and optional ride preference (driving / getting a ride) and weekly availability you set; saved question templates; and the content of any abuse report you submit.
Contacts (optional).If you choose “choose from contacts” when inviting your crew, the app reads your device address book to show you a picker and hands the numbers you select to Apple's own Messages composer. Your contacts are never uploaded to our servers, never sent to us or any third party, and never stored anywhere off your device — nothing leaves your phone except the invite text you choose to send. You can decline this permission and copy/paste the invite link instead.
Device & security data. To keep the service trustworthy without accounts, each install gets a random device identifier, and on iOS we use Apple's App Attest to confirm requests come from a genuine, unmodified copy of the app. We store the attestation key reference, a per-device session token (only a one-way hash of it — never the token itself), your iOS version, the app version, and a last-seen timestamp.
Notifications.If you enable notifications, we store the push token(s) for your device (including Live Activity / lock-screen tokens) so your crew's pings can reach you.
Purchases. If you buy PINGD Premium, the purchase is processed by Apple. We and our subscription provider (RevenueCat) receive your subscription status, product identifier, an opaque app-user identifier, and transaction/event identifiers needed to grant and verify entitlements. We never receive your full payment-card details — Apple handles payment.
Usage data.We record that certain things happened in the app — a plan was created, answered in or out, or closed; a crew was made or joined; an invite was sent; a subscription started or ended — together with the time, a coarse measure of how quickly a plan was answered, and general figures such as crew size. Each record is attached to a one-way coded reference derived from your device identifier, not to your name, and we do not store the wording of your questions, your plan locations, your contacts, or any message content in these records. This is app-usage information only: we do not track you across other companies' apps or websites.
Technical & operational data. Like any internet service, our infrastructure processes your IP address transiently to deliver requests and to enforce abuse/rate limits, and generates short-lived operational logs. We don't use this to build advertising or cross-app tracking profiles.
2. How we use it
To run the app: to show your name beside your answer, deliver the pings your crew creates, count who's in, apply your ride/ availability, unlock and verify Premium, prevent abuse and fraud, keep the service secure, respond to support, and meet legal obligations. We do not sell your personal data, and we do not use it for third-party advertising.
Understanding and improving PINGD. We also keep a limited record of how the app is used — that a plan was created, that it was answered in or out, roughly how quickly, how large a crew is, and whether a subscription started or ended. These records are stored against a one-way coded reference, never your name, and they never contain the wording of a question, a plan's location, or any message content. We use them to see what is working, fix what isn't, and produce overall statistics about the service. If you are in the EU/EEA or UK, we rely on our legitimate interest in understanding and improving the service; you can object at any time (see section 6).
3. What your group chat sees
PINGDis social by design. Other members of a crew you join can see your display name, your in/out answers, your ride preference, and your weekly availability for that crew. Don't put anything in your name, questions, or plan location that you wouldn't want your crew to see. Lock-screen and notification cards may display the question and who's in; we never put a plan's street address in a push payload.
4. Service providers
We use a small set of vetted processors that handle data on our behalf under their own security and privacy commitments, only to provide the service:
- Apple — App Store, in-app purchases, push delivery (APNs), and App Attest.
- RevenueCat — subscription / entitlement management.
- Vercel — application hosting.
- Neon — database hosting.
- Upstash — rate-limiting / abuse protection.
- Expo — push delivery and app updates.
We do not sell or rent personal data, and we do not share it for third-party advertising. We may disclose information if required by law or to protect the rights, safety, and security of our users or the service.
Change of ownership. If PINGDis ever involved in a merger, acquisition, investment, reorganization, bankruptcy, or a sale of all or part of its assets, the information described in this policy may be reviewed under confidentiality as part of that process and transferred to the party that takes over the service. Any such successor receives the information subject to this policy, and it must continue to honor this policy until you are given notice of a different one. If a successor later wants to handle your information in a materially different way, you will be notified and given the chance to delete your account first. A transfer of this kind is not a “sale” of personal information as that term is defined under California law.
5. Retention
- Closed questions and their answers are automatically purged about 35 days after they close.
- Invite links are removed within ~7 days after they expire, are revoked, or are used up.
- Abuse reports are kept for up to 90 days for moderation.
- The usage records described in section 1 are kept for up to 24 months, then deleted.
- Overall statistics are kept indefinitely. We keep aggregated figures — daily totals, averages, and counts such as “plans created this week” or “share of plans answered within an hour.” These are group totals only. They contain no identifier of any kind, we suppress any figure small enough to single a person out, and they cannot be traced back to you or turned back into personal information. Because they are not personal information, they are unaffected by the deletion of your account.
- Your membership, profile, device, and notification data are kept while your account is active and removed when you delete your account or leave a crew (see below).
- Limited purchase records may be retained by us, Apple, and RevenueCat as required for tax, accounting, fraud-prevention, and legal obligations even after deletion. These contain only opaque identifiers, not your app activity.
6. Deletion & your choices
Delete your account. In the app, open the You screen and tap delete my account. This permanently removes your memberships across every crew on the device, your answers, your profile (ride / availability / templates), your device identity and session, your App Attest key reference, your push tokens, your usage records, and your Premium link on that device. Content others rely on that isn't personal to you — for example a plan you created that the rest of the crew answered — remains in the crew. The overall statistics described in section 5 are not personal information and are not affected. Reinstalling starts you completely fresh; a deleted account is never silently restored.
Leave a single group chat. Leaving one crew removes your membership, answers, and push subscriptions for that crew only.
Notifications. You can turn notifications off at any time in iOS Settings.
Usage records. You can ask us to stop keeping the usage records described in section 1, and to delete the ones already held for you, by emailing pingd.support@gmail.com. You do not need to give a reason, and the app keeps working normally either way.
Our commitment on aggregated data. We maintain the overall statistics in section 5 in a form that cannot be used to identify you. We do not attempt to re-identify them or to link them back to any person or device, we keep technical measures in place to prevent that, and we require anyone we ever share or transfer them to — including a successor under section 4 — to be bound by the same commitment.
Your rights.Depending on where you live (for example the EU/EEA/UK under GDPR, or California under the CCPA/CPRA), you may have the right to access, correct, delete, or port your data, to object to or restrict certain processing, and to not be discriminated against for exercising these rights. The in-app deletion above satisfies the core access/erasure right; for anything else, contact us and we will respond within the time the law requires. We do not “sell” or “share” personal information as those terms are defined under California law.
7. Security
Data is encrypted in transit (TLS). Session tokens are stored only as one-way hashes on our servers and in the device Keychain on your phone; App Attest binds requests to a genuine app install. No system is perfectly secure, but we work to protect your information and limit what we collect in the first place.
8. Children
PINGD is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
9. International users
We operate PINGD from, and process data in, the United States. If you use the app from outside the U.S., you understand your information is processed in the U.S. and other countries where our providers operate.
10. Changes
We may update this policy as the app evolves. We'll change the effective date above and, for material changes, provide reasonable notice. Continuing to use PINGD after an update means you accept the revised policy.
11. Contact
Questions or requests: pingd.support@gmail.com. See also our Terms of Use.
Last updated: September 2, 2026.