Privacy policy

Pigeon Messenger · Operator: Kastia · Contact: [email protected]
Last updated 25 August 2026 · Applies to iOS, iPadOS, Android, Windows, macOS, and this website.

This is the privacy policy for store listings (Apple App Store, Google Play, Microsoft Store) and for the in-app copy at Settings → Privacy policy. A copy is also served at api.kastia.net/privacy. Use of Pigeon is also governed by our Terms of use. This is not legal advice.

Who we are

Pigeon is a messenger operated for closed beta by Kastia. Contact: [email protected]. This policy describes how the Pigeon apps, website (kastia.net), and related servers handle information.

What we never see

Private messages, group messages, channel posts, stickers, GIFs, and file attachments are end-to-end encrypted on your device before they leave it. The server stores opaque envelopes and encrypted media blobs. We cannot read that content. Push notifications say only “New message” — never the text. Encrypted backups are sealed with a passphrase that never leaves your device.

We do not sell personal information. We do not use your chats for advertising. We do not use advertising SDKs, analytics SDKs, or cross-app tracking. We do not collect precise location. We do not request an advertising identifier.

Information we collect

To run an account and deliver mail we store:

Display names, usernames, and profile or channel pictures are visible to people you chat with. They are not end-to-end encrypted.

This website may receive standard server logs (IP address, browser type, pages requested) to operate kastia.net and fight abuse. We do not use them to read your chats.

How we use it

We use this information to create and secure your account, deliver messages, apply plan limits, send sign-in codes, wake your device with a generic notification, fix bugs you report, and comply with law. We do not use message contents because we cannot read them.

If you are in the EEA, UK, or a similar jurisdiction, we process account and delivery data to perform the contract of providing Pigeon, and (where required) with your consent for optional permissions such as Bluetooth or notifications. You may withdraw OS permission in system settings.

Who we share it with

We do not sell your information. We share only what a processor needs to provide Pigeon, and we require those parties to protect it no less carefully than this policy. Message plaintext is not shared because we do not have it.

PartyWhyPlatforms
Apple App Store listing and review; Sign in with Apple; Apple Push Notification service (a generic wake-up, not message text); in-app purchase receipts when Plus is sold through Apple iPhone, iPad, Mac
Google Google sign-in (ID token); Firebase Cloud Messaging for Android notifications; Google Play distribution, Play Billing receipts, and Play integrity when the Android app is listed Android, and Google sign-in on other platforms when enabled
Microsoft Windows desktop app; Microsoft Store listing and billing if we distribute there; Windows notification delivery. Windows Hello stays on the device Windows
Email or SMS providers Deliver a one-time sign-in code to the address or number you gave us All
Object storage / hosting / CDN Store sealed media and backup blobs; serve the website and API. They see ciphertext and ordinary connection metadata, not message text All

Those companies have their own terms and privacy policies (including Apple’s, Google’s, and Microsoft’s) for the services they provide. Store payments are processed by the store, not by Kastia as a card processor.

Permissions by platform

Pigeon asks the operating system only for what a feature needs. You can refuse or later turn a permission off in iOS, Android, Windows, or macOS settings. Paid features (when Plus exists) are not conditioned on granting optional permissions.

We do not need precise GPS. Nearby uses Bluetooth proximity, not a map of your city.

Nearby (Bluetooth)

When you turn Nearby on, your device advertises a short identity beacon over Bluetooth so other Pigeon users can find you. People (and radios) nearby can observe that traffic, including proximity and timing. Message bodies on Nearby are still end-to-end encrypted. Relays forward opaque bytes only. Turn Nearby off and the advertising stops.

On your device

Decrypted messages, keys, and contacts you save (@usernames, nicknames, and notes) live in app storage on the device. Contacts are not a server address book. Encrypted backups may include your contact list, sealed with the same passphrase. Uninstalling the app deletes the local copy. Use a device passcode and the optional in-app lock.

Purchases and Plus

Private messaging is free. An optional Plus plan, when offered, is extra capacity (space, limits, devices) — not weaker privacy and not a way for us to read chats. If you buy Plus, Apple, Google, or Microsoft (depending on where you paid) processes the payment. We receive enough to unlock the entitlement, not your full card number. Store refund and cancellation rules are those of Apple, Google Play, or Microsoft.

Retention

Cloud envelopes are kept according to your plan, then deleted. OTP codes are short-lived. You can remove a device, sign out, or leave a group or channel. We keep the minimum needed to operate sign-in and delivery, and any record we are legally required to keep (for example a store purchase receipt).

Deleting your account

You can delete your Pigeon account and the personal data we are not legally required to keep.

Deletion removes the account record, profile, membership, devices, and sealed envelopes we store for you. Message plaintext is not on our servers to delete. Other people may still have copies of messages you sent, on their devices. We may retain purchase records the stores or tax law require. Uninstalling the app without deleting the account does not delete the server account.

This section is the public “privacy choices” page for App Store Connect, Google Play Data safety, and Microsoft Store.

Children

Pigeon is not directed at children under 13, and we do not knowingly collect their information. You must be at least 13 (or the higher age required in your country) to use Pigeon. If you believe a child has an account, email [email protected] and we will delete it.

Safety

You can report an account from a profile or a group member in the app. A report emails [email protected] with the username, user id, conversation id, and the reason you typed — never message plaintext, decrypted payloads, or attachments. We cannot read end-to-end encrypted chats, so we cannot moderate private message content. Block is local to this device and is not synced to our servers.

Your choices and rights

We do not sell or share personal information for cross-context advertising (California CPRA and similar laws). You may request access to the account data we hold, or deletion, by emailing [email protected]. We will not discriminate against you for exercising those rights.

Security

We encrypt private traffic on the device before it is sent. Transport uses HTTPS. We do not keep message keys on the server. No system is perfect: an unlocked or malware-infected device can still show what you could see. More detail: Technology.

Changes

We will update this policy when the product changes. The date at the top will change. The in-app copy ships with your build. Continued use after an update means the new policy applies to that use. Material changes will be noted in the app or on this page.

Questions: [email protected] · Terms of use