Privacy policy
This is the privacy policy for store listings (Apple App Store, Google Play, Microsoft Store) and for the in-app copy at Settings → Privacy policy. A copy is also served at api.kastia.net/privacy. Use of Pigeon is also governed by our Terms of use. This is not legal advice.
Who we are
Pigeon is a messenger operated for closed beta by Kastia. Contact: [email protected]. This policy describes how the Pigeon apps, website (kastia.net), and related servers handle information.
What we never see
Private messages, group messages, channel posts, stickers, GIFs, and file attachments are end-to-end encrypted on your device before they leave it. The server stores opaque envelopes and encrypted media blobs. We cannot read that content. Push notifications say only “New message” — never the text. Encrypted backups are sealed with a passphrase that never leaves your device.
We do not sell personal information. We do not use your chats for advertising. We do not use advertising SDKs, analytics SDKs, or cross-app tracking. We do not collect precise location. We do not request an advertising identifier.
Information we collect
To run an account and deliver mail we store:
- Username and display name
- Optional profile photo, and group or channel name and picture
- Email address and/or phone number used for one-time sign-in codes
- If you use Google sign-in: the email and identifier in Google’s ID token (we do not receive your Google password)
- If you use Sign in with Apple: the Apple user identifier and, if you share it, an email (including Hide My Email)
- Device names, device tokens, push tokens, and public keys needed for encryption and delivery
- Group and channel membership and roles
- Plan entitlements (Free or Plus) and, if you pay through a store, the store’s non-message receipt data needed to honor the purchase
- Delivery metadata: that a device sent or received an envelope, which conversation it belongs to, approximate size, and time
Display names, usernames, and profile or channel pictures are visible to people you chat with. They are not end-to-end encrypted.
This website may receive standard server logs (IP address, browser type, pages requested) to operate kastia.net and fight abuse. We do not use them to read your chats.
How we use it
We use this information to create and secure your account, deliver messages, apply plan limits, send sign-in codes, wake your device with a generic notification, fix bugs you report, and comply with law. We do not use message contents because we cannot read them.
If you are in the EEA, UK, or a similar jurisdiction, we process account and delivery data to perform the contract of providing Pigeon, and (where required) with your consent for optional permissions such as Bluetooth or notifications. You may withdraw OS permission in system settings.
Who we share it with
We do not sell your information. We share only what a processor needs to provide Pigeon, and we require those parties to protect it no less carefully than this policy. Message plaintext is not shared because we do not have it.
| Party | Why | Platforms |
|---|---|---|
| Apple | App Store listing and review; Sign in with Apple; Apple Push Notification service (a generic wake-up, not message text); in-app purchase receipts when Plus is sold through Apple | iPhone, iPad, Mac |
| Google sign-in (ID token); Firebase Cloud Messaging for Android notifications; Google Play distribution, Play Billing receipts, and Play integrity when the Android app is listed | Android, and Google sign-in on other platforms when enabled | |
| Microsoft | Windows desktop app; Microsoft Store listing and billing if we distribute there; Windows notification delivery. Windows Hello stays on the device | Windows |
| Email or SMS providers | Deliver a one-time sign-in code to the address or number you gave us | All |
| Object storage / hosting / CDN | Store sealed media and backup blobs; serve the website and API. They see ciphertext and ordinary connection metadata, not message text | All |
Those companies have their own terms and privacy policies (including Apple’s, Google’s, and Microsoft’s) for the services they provide. Store payments are processed by the store, not by Kastia as a card processor.
Permissions by platform
Pigeon asks the operating system only for what a feature needs. You can refuse or later turn a permission off in iOS, Android, Windows, or macOS settings. Paid features (when Plus exists) are not conditioned on granting optional permissions.
- Notifications — to show “New message.” Optional.
- Bluetooth — only if you turn Nearby on. Optional.
- Camera, photos, or files — only if you set a profile picture or attach a file. Optional. Files are encrypted on the device before upload.
- Face ID, Touch ID, fingerprint, or Windows Hello — optional in-app lock. Biometrics never leave the device.
- Network — to talk to Pigeon’s servers over HTTPS.
We do not need precise GPS. Nearby uses Bluetooth proximity, not a map of your city.
Nearby (Bluetooth)
When you turn Nearby on, your device advertises a short identity beacon over Bluetooth so other Pigeon users can find you. People (and radios) nearby can observe that traffic, including proximity and timing. Message bodies on Nearby are still end-to-end encrypted. Relays forward opaque bytes only. Turn Nearby off and the advertising stops.
On your device
Decrypted messages, keys, and contacts you save (@usernames, nicknames, and notes) live in app storage on the device. Contacts are not a server address book. Encrypted backups may include your contact list, sealed with the same passphrase. Uninstalling the app deletes the local copy. Use a device passcode and the optional in-app lock.
Purchases and Plus
Private messaging is free. An optional Plus plan, when offered, is extra capacity (space, limits, devices) — not weaker privacy and not a way for us to read chats. If you buy Plus, Apple, Google, or Microsoft (depending on where you paid) processes the payment. We receive enough to unlock the entitlement, not your full card number. Store refund and cancellation rules are those of Apple, Google Play, or Microsoft.
Retention
Cloud envelopes are kept according to your plan, then deleted. OTP codes are short-lived. You can remove a device, sign out, or leave a group or channel. We keep the minimum needed to operate sign-in and delivery, and any record we are legally required to keep (for example a store purchase receipt).
Deleting your account
You can delete your Pigeon account and the personal data we are not legally required to keep.
- In the app (iPhone, Android, Windows, Mac): Settings → Delete account. Type your username to confirm. We remove the account immediately in normal cases.
- If you cannot open the app: email [email protected] from the email on the account. Tell us the username. We complete deletion within 30 days and email you when it is done.
Deletion removes the account record, profile, membership, devices, and sealed envelopes we store for you. Message plaintext is not on our servers to delete. Other people may still have copies of messages you sent, on their devices. We may retain purchase records the stores or tax law require. Uninstalling the app without deleting the account does not delete the server account.
This section is the public “privacy choices” page for App Store Connect, Google Play Data safety, and Microsoft Store.
Children
Pigeon is not directed at children under 13, and we do not knowingly collect their information. You must be at least 13 (or the higher age required in your country) to use Pigeon. If you believe a child has an account, email [email protected] and we will delete it.
Safety
You can report an account from a profile or a group member in the app. A report emails [email protected] with the username, user id, conversation id, and the reason you typed — never message plaintext, decrypted payloads, or attachments. We cannot read end-to-end encrypted chats, so we cannot moderate private message content. Block is local to this device and is not synced to our servers.
Your choices and rights
- Edit display name and profile photo in Settings
- Manage contacts, nicknames, and notes on the device
- Revoke other devices
- Turn Nearby off; turn notification, Bluetooth, or photo permission off in the OS
- Export or restore an encrypted backup (the passphrase stays on the device)
- Sign out, leave a group or channel, or delete your account
We do not sell or share personal information for cross-context advertising (California CPRA and similar laws). You may request access to the account data we hold, or deletion, by emailing [email protected]. We will not discriminate against you for exercising those rights.
Security
We encrypt private traffic on the device before it is sent. Transport uses HTTPS. We do not keep message keys on the server. No system is perfect: an unlocked or malware-infected device can still show what you could see. More detail: Technology.
Changes
We will update this policy when the product changes. The date at the top will change. The in-app copy ships with your build. Continued use after an update means the new policy applies to that use. Material changes will be noted in the app or on this page.
Questions: [email protected] · Terms of use