Privacy Policy
Last updated: June 28, 2026
Ping provides QR-based personal and organization chat. This policy maps the data Ping collects, why we use it, and the choices available to you.
Contact
Questions, privacy requests, and account deletion help can be sent to [email protected]. You can also review deletion options at /account/delete.
Data We Collect
Account and profile data
We collect account identifiers such as your email address, Firebase user id, username, display name, avatar, timezone, authentication provider details, Apple Hide My Email relay status, Apple relay linking consent records, login audit metadata, and preferences you save.
Chat and QR data
We store QR short codes, chat links, conversation ids, timestamps, sender roles, message metadata, read receipts, reactions, and conversation state. Personal encrypted chats store encrypted message payloads, public keys, device ids, and encrypted key envelopes so your own linked devices can decrypt messages. Organization chats may be available to authorized organization members for operations, support, analytics, moderation, and audit history.
Device, camera, and notification data
If you scan a QR code, your browser or device camera is used to read the code. Ping receives the QR link or short code you open, not a continuous camera feed. For mobile notifications, we store push tokens, platform, app id, device id, active chat presence, and last-seen times.
Billing, organization, and analytics data
For organization workspaces, we store organization names, slugs, memberships, roles, permissions, subscription tier, Stripe customer/subscription identifiers, QR labels, response settings, message analytics settings, and aggregated analytics where enabled. Payment card details are handled by Stripe and are not stored directly by Ping.
Support, security, and usage data
We may collect support messages, email delivery records, IP address, user agent, crash or error logs, cookie preferences, attribution parameters, and security event records needed to operate, debug, secure, and improve Ping.
How We Use Data
We use data to create and authenticate accounts, generate QR links, deliver chat messages, sync encrypted-device state, send push or email notifications, prevent abuse, enforce workspace permissions, process subscriptions, provide support, measure reliability, comply with law, and improve the product.
Sharing and Service Providers
We share data with service providers that help operate Ping, including authentication providers such as Firebase, Apple, and Google; hosting and infrastructure providers; push notification providers such as Apple Push Notification service, Firebase Cloud Messaging, and Expo; Stripe for billing; security and anti-abuse providers; analytics tools; and email delivery providers. Organization chat content and metadata may be visible to authorized members of the organization workspace that owns the conversation.
Apple Hide My Email
If you sign in with Apple using Hide My Email, Ping treats relay addresses from privaterelay.appleid.com and private.icloud.com as privacy-protected addresses. Normal personal Apple email addresses, including regular icloud.com addresses, are treated as ordinary email addresses unless Apple identifies them as private relay addresses. Ping does not merge accounts by private relay email alone. If you choose to link that account to Google or email sign-in, Ping asks for consent before associating the relay account with directly identifying login information.
Your Choices
You can update profile information in settings, manage linked login methods, turn mobile notifications on or off in your device settings, deny camera permission, and manage analytics cookies through the Privacy Choices control. Organization administrators can configure some organization analytics and messaging settings.
Account Deletion
You can request account deletion from Settings while signed in or by visiting /account/delete. Deletion removes your Ping user account and associated personal chat links, conversations, device records, push tokens, and memberships where deletion is allowed. If you are the only owner of an organization, you must transfer or delete that organization first. We may retain limited records where required for security, billing, tax, legal, dispute, or abuse-prevention purposes.
Retention
We keep account data while your account is active. Chat, organization, billing, security, and support records are retained as needed to provide the service, honor organization settings, protect users, resolve disputes, and meet legal obligations. Existing encrypted personal messages may remain unreadable to Ping even while stored.
Security
Ping uses technical and organizational safeguards such as authenticated API access, permission checks, encryption in transit, encrypted personal message payloads, and limited administrative access. No service can guarantee absolute security.
Children
Ping is not directed to children under 13. If you believe a child provided personal information to Ping, contact us at [email protected].
Changes
We may update this policy as Ping changes. The updated version will be posted here with a new effective date.
