Legal
Privacy Policy
How Ping handles information, written against what the app actually does.
Effective 30 August 2026 · Version 1.0
The short version
Ping has no accounts, so there is no profile of you anywhere. Everything you post is encrypted on your iPhone, for the specific friends you chose, before it leaves the device. We operate one relay server that passes those encrypted parcels along when a friend's phone is offline. It cannot read any of them, and we hold no key that would let it.
The app runs no analytics, no advertising, and no tracking of any kind. There is no third-party SDK in Ping that collects anything about you. We do not sell or share personal information, and there is no commercial arrangement under which we could. This website is the one exception — it uses Google Analytics to count visits, and section 8 says exactly what that does and does not see.
The rest of this page is the specific, complete version. The privacy page says the same thing in plainer language, and the technical page explains the mechanism.
1. Who we are
Ping is operated by Atypical Co. LLC ("we", "us"), the data controller for the limited information described here.
- Privacy and data rights
- privacy@pingworld.co
- Security reports
- security@pingworld.co
- Everything else
- hello@pingworld.co
- Registered address
- [REGISTERED ADDRESS — required before publication]
2. There is no account
Ping does not ask for an email address, a phone number, a password, a username, or a sign-in of any kind. We do not use Sign in with Apple, and we do not create a record for you on our systems when you install the app.
When you first open Ping, your iPhone generates your identity locally. Your owner identity key is created inside the Secure Enclave and cannot be extracted from the device by us, by you, or by anyone else. Your device also holds signing and key-agreement subkeys in the iOS Keychain. Your display name and profile picture are chosen by you, stored on your device, and shared only with friends you have added.
Because there is no account, there is nothing for us to look up, disclose, suspend, or hand over about you as a person. We cannot tell you who a given device belongs to, because we do not know.
3. What stays on your device
The following never leaves your iPhone in a form we or anyone else can read:
- Your photos, videos, live photos, voice notes, messages and posts, and everything your friends have shared with you.
- Your friends list. No copy is transmitted to us at any point.
- Your profile name and picture, other than as shared directly with your friends.
- The on-device search index and any text or image analysis, which is performed locally using Apple's on-device frameworks.
- Your read positions, conversation settings, and how far back you have chosen to keep things.
Ping stores this in an encrypted database in the app's private container, protected by iOS file protection. Media files are content-addressed and stored as encrypted blobs.
4. What our relay holds
Two phones are rarely awake at the same moment, so we operate a single relay server (we call it the box) that accepts encrypted parcels and hands them to the recipient device when it next connects.
What the relay stores, for each parcel:
- Ciphertext. The encrypted content itself. It is encrypted on the sending device, for the specific recipient devices chosen by the sender, using per-object keys. The relay holds no key that opens any of it, and we cannot create one.
- Wrapped access keys and publication attestations. Also opaque to us. A wrapped key can only be opened by the recipient device it was created for.
- A small routing header that must be readable for delivery to work at all: an object identifier, the sending device's public key, a timestamp, a reconciliation domain identifier, a size class, and a signature. This header contains no names, no message type, no recipient list, and no content.
The relay does not hold your friends list, your display name, your profile picture, or any record connecting a device to a person.
How long the relay keeps it
- Standard
- 29 days, after which parcels are deleted automatically. Any one namespace is capped at 256 MB.
- With Memory
- Three years for content you authored, as described in section 9.
- Large media
- Anything over 16 MB — including video — never touches the relay. It transfers directly between devices.
Our relay runs on a virtual server rented from DigitalOcean, LLC. DigitalOcean provides the machine and its storage; it has no access to keys and, like us, can only ever see ciphertext.
5. What we necessarily learn
Any system with a server has a shape. Here is ours, stated exactly:
- That a device connected to the relay, and roughly when.
- How much encrypted data moved, and in which direction.
- The IP address a device connected from, as an unavoidable property of network transport. We do not log IP addresses to durable storage for analytics, profiling, or any other secondary purpose.
- A device's public key, which is how the relay knows which parcels to hand over. It identifies a device, not a person, and we hold nothing that maps it to one.
- Apple push tokens, described in section 6.
We minimise this and we do not pretend it is zero. We do not build profiles from it, and it is not combined with anything else, because there is nothing else.
Diagnostic logs. The app and the relay write operational logs. They are engineered never to contain message content, user text, full keys, or full identifiers — identifier prefixes only. No crash reporter or logging service that uploads content is present in Ping.
6. Notifications
When something arrives for a phone that is not connected, the relay asks Apple's Push Notification service to wake it. The push payload is empty — it carries a single content-available flag and nothing else, always. It contains no sender, no message, no preview, and no count.
Your phone wakes, fetches the encrypted parcel, decrypts it locally, and composes the notification you see on your own device. Every word on your lock screen was written by your iPhone from content only it could read.
What this costs, plainly: Apple learns that a particular device token was woken, and how often. Apple does not learn who woke it, what it was about, which conversation it belonged to, or how large it was. Push tokens are held by the relay solely to deliver these wakes, and are deleted when a device stops using Ping.
7. The one outside service
The app makes exactly one outbound request to a service that is not ours: the GIF picker in chat, which searches GIPHY's catalogue. (The website is separate — see section 8.)
- It is available in chat only. There is no GIF picker anywhere in the feed.
- When you search, your search text and your IP address reach GIPHY. That is the entire disclosure, and it happens only while you are actively typing in the picker.
- The GIF you choose is downloaded by your phone, encrypted, and delivered as bytes — never as a link. Your friend's device never contacts GIPHY, and GIPHY never learns that anyone received anything.
- Nothing is remembered. No search history, no recents, no favourites, no cookies, no disk cache.
- There is no GIPHY SDK in Ping. The request is a plain HTTPS call, and GIPHY receives no identifier from us.
GIPHY's own privacy practices govern what it does with a search query and an IP address. If you never open the GIF picker, Ping never contacts them.
8. This website
pingworld.co is separate from the app, and it is the one place we measure anything. This site uses Google Analytics to count visits and see which pages people read. That is a deliberate exception to everything above, and we would rather write it down here than let you find it in a network inspector.
What it means in practice:
- Google receives the pages you view on this site, and coarse details such as device type, browser, and approximate region. Your IP address is used in transit to derive that region; Google Analytics 4 does not log or store it.
- It learns nothing about the app. Ping itself contains no analytics, no identifier is shared between the app and this site, and nothing measured here can be connected to a device, a post, a friend, or a person.
- Advertising signals are denied permanently, for every visitor, everywhere — ad storage, ad user data and ad personalisation are all switched off. We do not advertise, we do not build audiences, and we do not use this data for marketing.
- In the EEA, the UK and Switzerland, analytics storage is denied by default, so no analytics cookie is set. Measurement there is cookieless unless and until you consent.
- Legal basis: consent where consent is required, and our legitimate interest in knowing whether this site works elsewhere.
Any content blocker will stop it, and the site works identically without it. Google's own opt-out is available at tools.google.com/dlpage/gaoptout.
Google acts as our processor for this, under its Google Analytics data processing terms.
9. Permissions, and what each one is for
iOS asks before granting any of these, and Ping works without every one of them. None of this data is transmitted to us in readable form.
- Camera and microphone
- Capturing photos and videos in the app. Nothing is recorded unless you press the shutter.
- Photo library
- Choosing existing pictures to post. Ping supports limited-library access, and only reads what you select.
- Location
- Attaching where you were to a post, when you choose to. Coordinates are never transmitted. A place or a workout route is rendered into a picture on your device, and only that picture is shared. No recipient, relay, or future reader receives a coordinate.
- Health
- Attaching a workout you choose to share. Ping reads only the workout you attach. Health data is never used for advertising or marketing, is never sold, and is never shared with any third party.
- Journaling suggestions
- Offering things you might want to post about. Suggestions are produced by iOS on your device.
- Local network
- Connecting directly to a friend's phone on the same network, which avoids the relay entirely.
- Notifications
- Waking the app so posts and messages arrive, as described in section 6.
Ping does not use the App Tracking Transparency framework, because Ping does not track you across apps or websites and has nothing to ask permission for.
10. Memory
Memory is an optional paid feature. With it, the relay keeps the parcels you authored for three years instead of 29 days, so a new iPhone can pull your own history back.
- It changes how long we hold ciphertext, not what we can read. It remains encrypted, and we still hold no key.
- It covers content you authored. It does not archive other people's content.
- The key that opens a restore is stored in your iCloud Keychain, which is end-to-end encrypted by Apple. Apple cannot read it, and neither can we. There is no recovery phrase to write down.
- Cancelling ends the extended retention. Your parcels then age out on the standard 29-day schedule.
Purchases are processed by Apple through the App Store. We never see your payment method, card details, or billing address. We receive only a subscription status for the device.
11. Deleting things
On your device. Deleting a message, a post, or a whole conversation removes it from your iPhone. You can also set a conversation to keep things for a limited time. This applies to your device — your friends keep their own copies, and Ping says so in the interface rather than implying otherwise.
Everywhere. Content you authored can be retracted. A retraction is signed by you, travels to every device that received the content, and removes it there.
On the relay. Parcels age out automatically. Deleting the app and its data ends your use of Ping entirely; anything still held for you expires on the schedule in section 4. To have content removed from the relay sooner, write to privacy@pingworld.co.
Because there is no account, there is no "delete my account" to perform — there was never a record to delete.
12. Children
Ping is not directed to children. You must be at least [MINIMUM AGE — confirm 13 or 16] years old to use it. We do not knowingly collect information from children below that age, and because there is no account system we have no age or identity information about anyone. If you believe a child is using Ping in a way that concerns you, write to privacy@pingworld.co.
13. Your rights
If you are in the UK, EU, or EEA, the UK GDPR and GDPR give you rights over personal data. The honest position is that Ping holds almost nothing that qualifies, and holds nothing that identifies you as a person.
Legal bases
- Contract. Operating the relay so your posts reach your friends, and providing Memory if you buy it.
- Legitimate interests. Keeping the service running securely, preventing abuse, and acting on reports of objectionable content.
- Consent. Every device permission in section 8, which you grant through iOS and can withdraw at any time in Settings.
Exercising them
Write to privacy@pingworld.co. You have the right to access, correct, erase, restrict, port, and object. Two practical limits, stated rather than buried:
- We cannot produce the content of your posts or messages in response to any request, including your own, because we cannot decrypt it. Your own copy is on your iPhone.
- We cannot verify that a device belongs to you, because we hold no identity information. A request that requires us to link a device to a person is one we cannot fulfil.
You may complain to your local supervisory authority — in the UK, the Information Commissioner's Office; in the EU, the authority for your country.
California
We do not sell or share personal information as those terms are defined by the CCPA and CPRA, and we have never done so. We do not use personal information for cross-context behavioural advertising. Ping serves no advertising of any kind.
International transfers
Our relay is hosted in [RELAY REGION — confirm before publication]. Ciphertext held there is unreadable to any party in any jurisdiction, including us, which is the practical protection that matters most. Where personal data is transferred internationally, we rely on appropriate safeguards including Standard Contractual Clauses with our infrastructure provider.
14. Security
Content is encrypted with per-object, per-recipient keys before it leaves your device. Identity keys are Ed25519 and X25519; your owner key is a P-256 key held in the Secure Enclave. Content is sealed with ChaChaPoly and addressed by SHA-256. Connections to the relay are authenticated with a certificate your device pins exactly, and every session requires a signed challenge before anything moves.
No system is perfect, and one property is worth stating: to receive posts while your phone is locked, Ping's database uses iOS protection that permits access after the device's first unlock. This is the same setting every messaging app that delivers notifications must use. Transport encryption and per-object keys are unaffected.
If you find a flaw, we want to hear about it first: security@pingworld.co.
15. Changes
If we change this policy, we will post the new version here with a new effective date. If a change materially reduces the protections described here, we will say so in the app before it takes effect. We will not make a change that gives us the ability to read your content, because that would require rebuilding the product around a different premise, and we would tell you that plainly rather than amend a policy page.
Questions: privacy@pingworld.co.
