Privacy Policy
Last updated: July 10, 2026
The short version: we store what's needed to deliver your notifications and sync your history — nothing more. Everything is encrypted in transit. We don't read your messages, we don't train models on them, and we don't sell data. You can delete your account and all of its data whenever you want.
1. What we collect
- Account. You sign in with your Apple account; we receive an identifier and, optionally, your name and email — which may be Apple's private relay address if you chose to hide yours. When you sign in with email, we store your email address.
- Channels and messages. Your channels and the notifications that flow through them — titles, bodies, replies, attachments, and their delivery state — so your history syncs across your devices.
- Device tokens. The push tokens Apple assigns your devices, so we can deliver notifications through Apple's push service.
- Billing state. Purchases run through Apple. We receive transaction identifiers and your subscription state — never your card details.
2. Sealed channels
For channels where the content itself is a secret, you can turn on a sealed channel — optional end-to-end encryption, per channel. On sealed channels, titles, bodies, replies, tap-to-copy values, links, filenames, and the bytes of photos and files are encrypted on your device, and our servers store only ciphertext for those fields. The keys stay on your devices and agents. Live Activity status and delivery metadata are not sealed — the public manifest lists exactly what is.
3. Group channels
Group channels are shared spaces: encrypted in transit, not end-to-end. Members of a group channel see its messages — that's the point of a group.
4. How we use your data
To run Pidge: deliver notifications, route replies back to your agents, sync history, prevent abuse, and provide support. That's it. No ads. No selling data. No training AI models on your content.
5. Error monitoring and analytics
We use error monitoring (Sentry) to catch crashes and bugs; reports are scrubbed of notification content, tokens, and keys before they leave our systems. This website may use privacy-respecting, cookieless analytics; the app itself carries no analytics or tracking SDKs.
6. Where your data lives
Pidge is hosted in the United States. We rely on a small set of subprocessors to run the service: Railway (hosting), Apple (push delivery and payments), and Sentry (error monitoring).
7. Retention and deletion
You're in control: delete a notification, a channel, or your entire account directly in the app. Deleting your account removes your data from our systems.
8. Children
Pidge is not directed at children under 13, and we don't knowingly collect their data.
9. Your rights
You can access and delete your data in the app. For anything else — a copy of your data, a question, a complaint — write to support@pidge.sh and a human will answer.
10. Changes to this policy
If we change this policy in a way that matters, we'll post the new version here and update the date above.