Privacy Policy
Last updated: 14 May 2026
App: Pidge ("we", "us").
Contact: sendapidge@proton.me
This policy describes how Pidge collects, uses, and shares information when you use our mobile application, website, and related services. By using Pidge, you agree to this policy.
1. What we collect
Account, authentication & profile
- Sign-in: Email address. You may use password sign-in or email magic links (OTP). Authentication is provided by Supabase Auth; passwords are stored using their standard security practices (not as plaintext on our servers).
- Registration: During signup we collect your username (unique identifier), date of birth (to verify you meet our minimum age requirement of 18), and the timestamp of your acceptance of these Terms and our Privacy Policy.
- Profile: Display name (nickname), optional phone number (for matching and friend features), avatar choice (preset avatar identifier), and your product analytics preference (whether usage analytics is on or off).
- Session: Auth tokens are stored on your device (e.g. secure storage / browser storage) so you stay signed in.
Social graph & groups
- Friends: Friend requests and friendships (including status), and related timestamps.
- Groups: Friend group names, membership, icons, and settings you configure (e.g. who can invite or create events).
Invites, hangouts & chat
- Plans & invites: Invite type (e.g. standard plans and "birdcall" beacons), titles/descriptions, times, location text, optional coordinates (latitude/longitude) and place labels, share links/codes, expiry, host notes, and cancellation notes where applicable.
- Recipients & RSVP: Who is invited, RSVP status, and—for guests without an account—guest name and/or email you or they provide so we can track the invite and send transactional messages.
- Hangout chat: Messages you send in temporary hangout chat, including content, sender, and timestamps.
- Group chat: Messages you send in Coop (friend group) chats, including content, sender, and timestamps.
Saved places
- Labels and locations you save (name text and optional coordinates) for quick reuse when creating plans.
Location & maps (when you use those features)
- Device location: If you allow it, we may read approximate or precise coordinates to center the map, suggest places, or fill in an address (using the platform location APIs on iOS/Android, or the browser geolocation API on web).
- Place search: When you search for a venue or address, your search text (and sometimes location bias) is sent to Google services (Maps / Places), where permitted by your platform and API configuration.
- Reverse geocoding: Converting coordinates to a human-readable address may use Apple/Google services through Expo on native apps, and on web may use OpenStreetMap Nominatim (or similar).
Calendar (optional)
- If you add a hangout to your calendar, the app may request permission to create a calendar event on your device. We use this to write the event you asked for; we do not read or upload your full calendar contents to our servers.
Device contacts (optional)
- If you use the feature to find friends from your contacts, we request access to phone numbers in your address book. With your permission, we read those numbers on your device, normalize them, and send them to our servers only to check whether those numbers belong to existing Pidge users. We do not use your contacts for advertising, and we do not sell contact data.
Push notifications
- Push tokens and related data needed for delivery (via Expo and platform push services such as Apple / Google) so we can notify you about invites, updates, and similar events.
Product analytics (opt-in)
- If you turn Usage analytics on in Account settings, we use PostHog (EU-hosted) to understand how the app is used. That may include:
- Screen / route views (screen names and route parameters),
- Custom product events (e.g. hangout created, RSVP, friend actions, errors summarized as categories),
- Touch autocapture (interactions with UI elements),
- App lifecycle events,
- Identification of your analytics profile with your user id and, where applicable, email and signup timing, and
- Feature flags and related telemetry.
- If you leave analytics off or opt out, we do not send this usage data.
Crash & error reporting
- We may use Sentry for crash and error reporting. That can include error details, stack traces, device type, OS, app version, and related diagnostic data. This is separate from the in-app Usage analytics toggle.
Website & infrastructure
- When you load our website, join flows, or APIs, hosting providers (e.g. Vercel) may process standard server logs such as IP address, user agent, and timestamps.
Email delivery
- Account emails (magic links, password reset, etc.) are sent through Supabase Auth's email flow.
- Transactional emails about hangouts and invites may be sent through Resend, which processes recipient addresses and message content needed to deliver mail.
We do not sell your personal information.
2. How we use data
- To provide core features: friends, invites, groups, chat, maps/places, notifications, and account management.
- To operate optional product analytics when you opt in.
- To diagnose issues and improve stability via crash reporting.
- To maintain security and fix bugs.
- To comply with law when required.
3. Where data is processed
We use Supabase (database, authentication, and realtime). Data is processed in the EU.
We use Expo for push notifications and related services.
PostHog (product analytics, when you opt in) is EU-hosted.
Sentry may receive crash and error data when enabled.
If you use maps or place search, Google may process queries and location-related data per Google's policies.
On web, OpenStreetMap Nominatim may process coordinates for reverse geocoding.
Resend processes data needed to send transactional email.
Vercel may process HTTP logs when you use our web properties.
4. Retention
- Hangout chat messages are automatically deleted 10 days after the associated invitation expires or is cancelled.
- Group (Coop) chat messages are persistent and retained while the group exists or until you delete your account.
- Invitations are marked as expired when their expiry time passes (checked every 15 minutes).
- Account and profile data are kept until you delete your account.
- Invite history is retained while your account is active so you can view past hangouts.
- Analytics and crash data are retained according to PostHog / Sentry settings (typically 90 days for event data).
5. Your rights (GDPR)
Under the General Data Protection Regulation (GDPR) and Norwegian data protection law, you have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure (Right to be forgotten): Request deletion of your personal data. You can do this directly via Account → Delete my account.
- Restriction: Request that we limit processing of your data in certain circumstances.
- Data portability: Request your data in a structured, machine-readable format.
- Object: Object to processing based on legitimate interests.
- Withdraw consent: Where processing is based on consent (e.g. analytics, location), you may withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at sendapidge@proton.me. We will respond within 30 days.
Supervisory authority: You have the right to lodge a complaint with Datatilsynet (the Norwegian Data Protection Authority) if you believe your data protection rights have been violated.
6. Your choices
- Access & update: Edit profile and settings in the app.
- Product analytics: Use Account → Privacy & analytics → Usage analytics to opt in or out.
- Delete your account: Use Account → Delete my account in the app. This removes your account and associated data from our active systems within 30 days.
- Notifications: Disable push notifications in system settings or in-app.
- Permissions: Location, contacts, calendar, and notifications can be limited or revoked in system settings; some features may not work without them.
7. Legal basis for processing
| Purpose |
Legal basis (GDPR Art. 6) |
| Account creation & service delivery | Performance of contract |
| Push notifications about your invitations | Performance of contract |
| Product analytics (PostHog) | Consent (opt-in) |
| Location access for maps | Consent (device permission) |
| Contact matching for friend discovery | Consent (device permission) |
| Crash/error reporting (Sentry) | Legitimate interest (service stability) |
| Security & fraud prevention | Legitimate interest |
8. Age requirement
Pidge requires users to be at least 18 years old. We collect date of birth during registration to verify eligibility. We do not knowingly collect personal data from anyone under 18. If we become aware that a user is under 18, we will promptly delete their account and associated data.
9. International data transfers
Your data is primarily processed within the EU/EEA:
- Supabase: EU-hosted database and authentication.
- PostHog: EU-hosted analytics (when you opt in).
- Expo push notifications: May involve transfers to the US (Apple/Google push infrastructure). These transfers are covered by Standard Contractual Clauses or adequacy decisions where applicable.
- Google Maps: Data may be processed in Google's global infrastructure per Google's policies.
10. Changes
We may update this policy. We will post the new version and update the "Last updated" date. For material changes, we will notify you via the app or email. Continued use after the notice period means you accept the updated policy.
11. Contact
Questions about this privacy policy or your data:
Email: sendapidge@proton.me
Supervisory authority: Datatilsynet, Postboks 458 Sentrum, 0105 Oslo, Norway.