We collect only the minimum data required to deliver the service:
Account Information: Your email address and username.
Profile: Your display name and, if you set one, a profile photo.
Date of Birth: Used solely to verify you meet the minimum age
requirement. We do not use it for any other purpose.
Messages & Media: The content you send — text, photos,
videos and voice messages — is stored so it can be delivered and shown in your
conversations.
Device Token: A push-notification identifier, used only to deliver
notifications to your device (and your Apple Watch, if paired).
Diagnostics: If a crash occurs, anonymous crash information may be
collected to help us fix it. It is not used to identify or track you.
Phone Number (optional): If you sign up or sign in with your phone, or
add it to your profile, we store it so friends who already have your number can find
you. A one-time code is sent by SMS to verify it.
Sign in with Apple: If you use it, we receive the name and email (or
Apple's private relay email) that Apple shares with us.
Contact Discovery (optional): If you turn it on, phone numbers and emails
from your address book are hashed on your device and only the hashes are sent to match
people already on PIING.
Location (optional): Only while Friends Map sharing is on, your latest
location is stored and shown to the friends you choose. Each update expires after 4
hours.
Calls: Call history (who called whom, when, voice or video, and whether
it was answered). Call audio and video are not recorded.
Security Logs: Your IP address and device type, used for sign-in
sessions, rate limiting and preventing abuse.
Problem Reports: When you send a report from the app's Help form, we
receive your description, the screen you were on, recent screens, device and app version,
network type and any screenshot you attach. Reports are sorted by a person and, only if you
have allowed AI services in Settings → AI, also by AI services run by other companies;
emails and phone numbers are removed before a report is sent to them.
2. How Your Data Is Protected
In transit: All communication with our servers is encrypted using
standard transport security (HTTPS/TLS).
Passwords: Stored only as a strong one-way hash (PBKDF2). We never
store your password in a readable form.
End-to-end encryption: one-to-one text messages in the PIING app are
end-to-end encrypted when both people use a current version of the app, so we can't read
them. Photos, videos, voice messages, group chats, Stories and the web chat are protected in
transit only.
3. AI Features
PIING's smart replies, voice-message transcripts, summaries and translation can use AI. Where they
run decides who sees your data, so here is exactly what happens.
On your phone first (Apple): On iPhones that support Apple Intelligence
(iOS 26 or later), PIING uses Apple's on-device model for smart replies and summaries, Apple's
speech recognition — set to on-device only — for voice-message transcripts, and
Apple's language detection. These run entirely on your phone. Nothing is sent to us, to Apple or
to anyone else, and they also work in end-to-end encrypted chats.
AI services run by other companies — only if you allow it: If your phone
can't do something on-device, PIING can send it to AI services run by other companies. Before
anything is ever sent, the app asks for your permission and shows which companies would receive
it. If you say no, nothing is sent and PIING uses simple suggestions made on your phone. You can
change your mind at any time in Settings → AI.
What is sent, and only when you use the feature:
Smart replies: the last few messages of the chat you are replying in.
Voice-message transcripts: the audio of that voice message, when you tap Transcribe.
Summaries and translation: the text you ask PIING to summarise or translate.
Auto Chat (only if you turn it on): the incoming message and a few of your recent messages, so a reply can be written.
Problem reports: the description you write, with emails and phone numbers removed.
We do not attach your name, account ID or phone number to these requests (anything written
inside the text itself is part of the text).
Who may receive it: the AI services PIING has an account with. The full list of
companies that may be used is: Groq, Google (Gemini), OpenRouter, Cerebras, SambaNova, Mistral AI,
DeepSeek, Together AI, Fireworks AI, Hugging Face, Cloudflare (Workers AI), NVIDIA, Ollama, GitHub
(Microsoft) Models, OVHcloud, Scaleway, Cohere, Z.ai, Alibaba Cloud (Qwen), SiliconFlow,
ModelScope, OpenCode and Routeway. The permission prompt in the app names the ones in use at that
moment. These companies process the request to answer it and may keep it under their own terms;
PIING does not use any of them to train models on your messages.
Never sent to an AI service: end-to-end encrypted messages (they stay on your
phone and are only ever handled by Apple's on-device features), and messages other people report to
us — reported messages are reviewed by a person, not by an AI service.
4. Service Providers
We use other companies only to run the service. They process data on our behalf, only for that
purpose, and none of them may use it for their own advertising:
Hosting and database: our servers and database are hosted with cloud providers (Fly.io for the servers).
Media storage and call relay: photos, videos and voice messages are stored on Cloudflare, and Cloudflare relays call connections when two phones can't reach each other directly. One-to-one calls are encrypted between the two phones (DTLS-SRTP), so Cloudflare can't decrypt them.
App updates: Expo checks for and delivers app updates in PIING versions before 4.0.5.
Group calls: group voice and video calls (up to 16 people) go through Cloudflare's media servers so everyone can hear and see each other. They are encrypted in transit but are not end-to-end encrypted, and PIING does not record them.
Live broadcasts: if you go live or watch a live, the video and sound go through Cloudflare Stream so they can reach viewers. Live video is not end-to-end encrypted and PIING does not record it. Live comments are stored by PIING so the host can moderate them, and reports go to PIING's moderators.
Notifications: Apple's push notification service, and Expo's push service, deliver notifications. Notifications for end-to-end encrypted messages never contain the message.
Crash reports: if the app crashes, anonymous crash details (device model, app version and what went wrong, never your messages) may be sent to our crash-reporting provider, Sentry, so we can fix it.
Sign-in codes and emails: SMS and email delivery providers send one-time codes and password-reset emails.
AI services: only if you allow them — see section 3.
5. What We Do Not Do
No ad trackers or ads: We do not track you across other apps or sites, and we show no ads.
No selling your data: We never sell or rent your personal data.
No raw address-book upload: Contact discovery is opt-in and uses on-device hashes — we do not upload your raw address book.
No background location tracking: Location is only used if you turn on Friends Map sharing; it is off by default.
No behavioral profiling: We do not build advertising profiles.
6. Data Deletion
You can delete your account at any time from within the app
(Settings → Delete Account). Your account is scheduled for deletion
and permanently removed after 30 days; signing back in within that window cancels the
deletion. Once permanent, your account information, messages and tokens are removed from
our servers.