Privacy
Last updated 26 August 2026
PINGO forwards a copy of an email into a phone notification, without asking for a signup, a password, or an account. This page describes what data that requires, in plain terms, matched to what the running service actually does.
The short version
- No account, no email address, no password, ever — there is nothing to sign up for.
- The content of your email is never written to our database. Not temporarily, not encrypted, not ever.
- No analytics, no tracking cookies, no third-party trackers of any kind run on this site.
- Payment details are never seen or stored by us — Stripe handles and holds those directly.
What we store, and why
Creating an address needs nowhere near the amount of data a normal account would. What's kept:
- The address itself — a random id (e.g. kx7m2pqr), not linked to your name or email.
- Your device's push subscription — the endpoint and keys your browser or phone issues when you turn on notifications, plus an optional label you give that device.
- Anything you type in yourself — an optional address label, the login page(s) of your real inbox (so a tap can open the right one), and any keyword mute rules you set up.
- A timestamp per email that arrives — used only to enforce the monthly notification limit and show your own activity chart. No sender, subject, or content is attached to it.
- One IP address and coarse location (country/city), captured only at the moment an address is created — derived from our host's edge network, not looked up against a third-party service — used solely to prevent one person stacking unlimited free addresses.
- If you connect Telegram: your Telegram chat id and the display name/username Telegram gives us, so messages can be delivered to the right chat.
- If you pay: a Stripe checkout session id, so your address can be marked unlimited. Card details are handled and stored by Stripe alone; we never receive them.
- If you use the contact form: whatever you type into it, plus IP/location for the same abuse-prevention reason as above.
- If you redeem an AppSumo code: the redemption/license code needed to verify it.
How your email is actually handled
This is the part most privacy policies gloss over, so it's worth being exact:
- The forwarded copy lands on a mail-receiving worker that reads it in memory only.
- The sender and subject line are used to build your notification, then discarded. They are never written to our database.
- One narrow exception: if an email is the very first one an address receives, or is addressed directly to the address itself, and it contains what looks like a “confirm your forwarding” link, that link is saved just long enough to show a confirm button in the app — and cleared once you tap it. This exists purely so a one-time provider confirmation step (Gmail, Hostinger, etc.) doesn't get permanently stuck.
- Optional full-content relay: if you explicitly turn this on for a specific address, the complete email — including attachments — is relayed live to your own connected Telegram chat. It passes through our server only for the duration of that single request and is never written to our database, on or off.
- Every other email is sender-and-subject only, used to build a notification, then gone.
Who else touches this data
| Service | What it sees |
|---|---|
| Cloudflare | The raw forwarded email, in memory, to extract sender/subject/link |
| Neon (Postgres) | The structured data listed above |
| Netlify | Hosts the application and its API |
| Stripe | Payment processing and card details |
| Google / Apple / Mozilla push services | Relay the encrypted push notification to your device; the payload is encrypted so these services cannot read its content |
| Telegram | If you opt in: delivers the notification, and optionally the full email, to your own chat |
| AppSumo | If purchased there: verifies your redemption code |
How long we keep it
Data tied to an address exists for as long as that address does. Deleting an address from within the app permanently and immediately removes it and everything linked to it — devices, activity history, Telegram connection. Removing a single device only removes that device's subscription; the address and its other devices are unaffected.
Your control over it
Because there's no account or identity behind an address, there's no separate identity check for data requests either: whoever holds the address (in the app, or as the address string itself) can view its activity, export it, or permanently delete it, instantly, from Settings. If you'd rather we do it on your behalf, email on@pingo.email.
International transfers
Our hosting, database, and edge infrastructure (Netlify, Neon, Cloudflare) operate globally, so data may be processed in countries other than your own as a normal consequence of how those services route traffic.
Changes
If this policy changes, the update will be posted here with a new effective date.
Contact
Questions about this policy or your data: on@pingo.email.