Skip to content
Pigeon
Menu
Product Technology Privacy Download
Privacy Terms

Legal

Privacy policy

Last updated 2 September 2026 Pigeon Messenger · Operator: Kastia · Contact: [email protected] Applies to iOS, iPadOS, Android, Windows, macOS, and this website.

This is the privacy policy for store listings (Apple App Store, Google Play, Microsoft Store) and for the in-app copy at Settings → Privacy policy. A copy is also served at api.kastia.net/privacy. Use of Pigeon is also governed by our Terms of use. This is not legal advice.

On this page
  1. Who we are
  2. What we never see
  3. Information we collect
  4. How we use it
  5. Who we share it with
  6. Permissions by platform
  7. Nearby (Bluetooth)
  8. On your device
  9. Purchases and Plus
  10. Retention
  11. Deleting your account
  12. Children
  13. Safety
  14. Your choices and rights
  15. Security
  16. Changes

Who we are

Pigeon is a messenger operated for closed beta by Kastia. Contact: [email protected]. This policy describes how the Pigeon apps, website (kastia.net), and related servers handle information.

What we never see

Private messages, group messages, channel posts, stickers, GIFs, and file attachments are end-to-end encrypted on your device before they leave it. The server stores opaque envelopes and encrypted media blobs. We cannot read that content. Push through Apple and Google still says only “New message”, because we cannot read chats. After your device decrypts a message, Settings → Privacy mode (off by default) may show a preview on the on-device banner; turn Privacy mode on to keep “New message” only. Encrypted backups are sealed with a passphrase that never leaves your device.

We do not sell personal information. We do not use your chats for advertising. We do not use advertising SDKs, analytics SDKs, or cross-app tracking. We do not collect precise location. We do not request an advertising identifier.

Information we collect

To run an account and deliver mail we store:

  • Username and display name
  • Optional profile photo, and group or channel name and picture
  • Email address and/or phone number used for one-time sign-in codes
  • If you use Google sign-in: the email and identifier in Google’s ID token (we do not receive your Google password)
  • If you use Sign in with Apple: the Apple user identifier and, if you share it, an email (including Hide My Email)
  • Device names, device tokens, push tokens, and public keys needed for encryption and delivery
  • Group and channel membership and roles
  • User ids of people you block, so we can stop delivering their cloud mail to you
  • Plan entitlements (Free or Plus) and, if you pay through a store, the store’s non-message receipt data needed to honor the purchase
  • Delivery metadata: that a device sent or received an envelope, which conversation it belongs to, approximate size, and time
  • Coarse activity status you choose (online, away, offline, do not disturb), visible to people you already chat with — not a last-seen clock

Display names, usernames, and profile or channel pictures are visible to people you chat with. They are not end-to-end encrypted.

This website may receive standard server logs (IP address, browser type, pages requested) to operate kastia.net and fight abuse. We do not use them to read your chats. We also count how often the website download button is clicked, stored as daily totals by platform (for example Windows) without an identifier for the visitor.

How we use it

We use this information to create and secure your account, deliver messages, apply plan limits, send sign-in codes, wake your device with a generic notification, fix bugs you report, and comply with law. We do not use message contents because we cannot read them.

If you are in the EEA, UK, or a similar jurisdiction, we process account and delivery data to perform the contract of providing Pigeon, and (where required) with your consent for optional permissions such as Bluetooth or notifications. You may withdraw OS permission in system settings.

Who we share it with

We do not sell your information. We share only what a processor needs to provide Pigeon, and we require those parties to protect it no less carefully than this policy. Message plaintext is not shared because we do not have it.

PartyWhyPlatforms
Apple App Store listing and review; Sign in with Apple; Apple Push Notification service (a generic wake-up, not message text); in-app purchase receipts when Plus is sold through Apple iPhone, iPad, Mac
Google Google sign-in (ID token); Firebase Cloud Messaging for Android notifications; Google Play distribution, Play Billing receipts, and Play integrity when the Android app is listed Android, and Google sign-in on other platforms when enabled
Microsoft Windows desktop app; Microsoft Store listing and billing if we distribute there; Windows notification delivery. Windows Hello stays on the device Windows
Email or SMS providers Deliver a one-time sign-in code to the address or number you gave us All
Object storage / hosting / CDN Store sealed media and backup blobs; serve the website and API. They see ciphertext and ordinary connection metadata, not message text All

Those companies have their own terms and privacy policies (including Apple’s, Google’s, and Microsoft’s) for the services they provide. Store payments are processed by the store, not by Kastia as a card processor.

Permissions by platform

Pigeon asks the operating system only for what a feature needs. You can refuse or later turn a permission off in iOS, Android, Windows, or macOS settings. Paid features (when Plus exists) are not conditioned on granting optional permissions.

  • Notifications — to show “New message.” Optional.
  • Bluetooth — only if you turn Nearby on. Optional.
  • Camera, photos, or files — only if you set a profile picture or attach a file. Optional. Files are encrypted on the device before upload.
  • Face ID, Touch ID, fingerprint, or Windows Hello — optional in-app lock. Biometrics never leave the device.
  • Network — to talk to Pigeon’s servers over HTTPS.

We do not need precise GPS. Nearby uses Bluetooth proximity, not a map of your city.

Nearby (Bluetooth)

When you turn Nearby on, your device advertises a short identity beacon over Bluetooth so other Pigeon users can find you. People (and radios) nearby can observe that traffic, including proximity and timing. Message bodies on Nearby are still end-to-end encrypted. Relays forward opaque bytes only. Turn Nearby off and the advertising stops.

On your device

Decrypted messages, keys, and contacts you save (@usernames, nicknames, notes, phone numbers, emails, and addresses) live in app storage on the device. Contacts are not a server address book. Encrypted backups may include your contact list, sealed with the same passphrase. Uninstalling the app deletes the local copy. Use a device passcode and the optional in-app lock.

Purchases and Plus

Private messaging is free. An optional Plus plan ($3.99/mo or $29.99/yr when billing launches), when offered, is extra capacity: larger uploads, more devices, bigger groups, unlimited channels, longer retention, and priority support. Encryption and disappearing messages are never a paywall — they are included on Free. Plus is not weaker privacy and not a way for us to read chats. If you buy Plus, Apple, Google, or Microsoft (depending on where you paid) processes the payment. We receive enough to unlock the entitlement, not your full card number. Store refund and cancellation rules are those of Apple, Google Play, or Microsoft.

Retention

Cloud envelopes are kept according to your plan, then deleted. OTP codes are short-lived. You can remove a device, sign out, or leave a group or channel. We keep the minimum needed to operate sign-in and delivery, and any record we are legally required to keep (for example a store purchase receipt).

Deleting your account

You can delete your Pigeon account and the personal data we are not legally required to keep.

  • In the app (iPhone, Android, Windows, Mac): Settings → Delete account. Type your username to confirm. We remove the account immediately in normal cases.
  • If you cannot open the app: email [email protected] from the email on the account. Tell us the username. We complete deletion within 30 days and email you when it is done.

Deletion removes the account record, profile, membership, devices, and sealed envelopes we store for you. Message plaintext is not on our servers to delete. Other people may still have copies of messages you sent, on their devices. We may retain purchase records the stores or tax law require. Uninstalling the app without deleting the account does not delete the server account.

This section is the public “privacy choices” page for App Store Connect, Google Play Data safety, and Microsoft Store.

Children

Pigeon is not directed at children under 13, and we do not knowingly collect their information. You must be at least 13 (or the higher age required in your country) to use Pigeon. If you believe a child has an account, email [email protected] and we will delete it.

Safety

You can report an account from a profile or a group member in the app. A report emails [email protected] with the username, user id, conversation id, and the reason you typed — never message plaintext, decrypted payloads, or attachments. We cannot read end-to-end encrypted chats, so we cannot moderate private message content. Block is an account setting: we store the user ids you blocked so we can refuse new direct messages and skip live delivery of their cloud mail to you. Manage the list in Settings → Blocked users. It is not a server-wide ban of that person for everyone else.

Your choices and rights

  • Block or unblock people in Settings → Blocked users
  • Edit display name and profile photo in Settings → Account
  • Manage contacts, nicknames, notes, and contact details on the device
  • Revoke other devices
  • Turn Nearby off; turn notification, Bluetooth, or photo permission off in the OS
  • Export or restore an encrypted backup (the passphrase stays on the device)
  • Create a recovery code in Settings (we store a hash only; the code never leaves your device after you save it)
  • Sign out, leave a group or channel, or delete your account

We do not sell or share personal information for cross-context advertising (California CPRA and similar laws). You may request access to the account data we hold, or deletion, by emailing [email protected]. We will not discriminate against you for exercising those rights.

Security

We encrypt private traffic on the device before it is sent. Transport uses HTTPS. We do not keep message keys on the server. No system is perfect: an unlocked or malware-infected device can still show what you could see. More detail: Technology.

Changes

We will update this policy when the product changes. The date at the top will change. The in-app copy ships with your build. Continued use after an update means the new policy applies to that use. Material changes will be noted in the app or on this page.

Questions: [email protected] · Terms of use

Pigeon

Private messaging from Kastia.

[email protected]

Product

  • Download
  • Technology
  • Nearby
  • Windows download

Company

  • About
  • Investments
  • Careers
  • Contact

Legal

  • Privacy
  • Terms
  • Delete account

© 2026 Kastia · Pigeon Messenger