Privacy Policy for Appigeon

Version 13, 15 September 2026

This policy describes how we process your data when you use Appigeon, the slow messaging app with virtual pigeons. The service is evolving: it may change, and so may this policy. In that case we will ask you to accept the new version.

1. Data controller

Luca Trinchero. Contact: info@appigeon.com

2. Data we collect

Data you provide at sign-up:

Data you can add using the app:

Your phone's address book (only if you grant permission):

If you allow access to your contacts, the app computes a code with a one-way function for each phone number and each email address in your address book, on your phone, and sends only those codes to our server. Numbers and addresses never leave your phone in the clear, and your contacts' names never reach us: they stay on the device. On our servers each code is transformed a second time with a secret key that never leaves our systems: it is this second step that makes the codes impossible to trace back to the numbers, because the code computed by the phone, taken on its own, could still be compared against a list of already known numbers.

It serves two purposes: showing you which people in your address book are already on Appigeon, and notifying the people who have you in their address book when you sign up (just as we notify you when someone you have in your address book signs up). The notice is sent once per number.

You can revoke the contacts permission at any time from your phone settings: from then on the app stops reading the address book. If you do not want your number used to notify people who have you in their address book, you can ask the contact in section 1, even if you are not one of our users.

Data generated using the app:

If you report another user or a letter:

If you report a problem or ask for support:

Waiting list data (only if sign-ups are capped and you end up in the queue):

We open sign-ups in batches, so as not to exceed what the service can handle. If the places for the month are gone when you try to sign up, we put you on the waiting list. At that moment you are not a user yet: you have no profile, no loft, no pigeons. All we keep about you is this:

Your position in the queue is not visible to other users. Waiting list email addresses belong, by definition, to people who are not users of the service yet: they end up in no contact list, receive no other communications, are not used for advertising and are not passed on to anyone. They serve only the three emails described in section 3.

Subscription data (only if you take out a paid plan):

Usage data (ONLY if you consent):

Technical data:

To confirm your loft is really where you live (anti-abuse), when setting or changing it we may ask once for your device location: we use it to check the loft is nearby and we do not store it. Denying it does not block use of the app.

3. What we use data for

We do not sell your data. We do not use your data for advertising. We do not profile. We do not track whether you open the emails we send you.

4. What other users see

To let you recognise people you know (friends, people you exchange pigeons with or write to), other users you interact with may be shown:

Loft location: three precision levels, chosen by you. Other users never see your written address: on the map they see your loft as a point, whose precision depends on your relationship with the person looking.

How the approximate area works: the shown point falls at a random spot inside the circle of the chosen radius, not at its centre, and stays stable over time (it does not change every time the map opens). Both precisions ("Favorites" and "Everyone") can be adjusted at any time in the app, under Profile, Privacy and security section, Loft location. We remind you with a notice when you add your first contact. In case of a technical error the system still shows the approximate area, never the exact spot.

If you remove a contact (or remove their star), from new flights onwards that person only sees the precision of their new level: someone who is no longer your contact goes back to seeing only the approximate area. Flights and caravans already sent may however keep the location already shared at send time (the data has already been transmitted).

Legal basis: sharing identifying data and the approximate location between users is necessary for the social function of the service, that is recognising the people you interact with and letting pigeons travel between lofts (performance of the contract, art. 6.1.b GDPR). Your exact location is shared only by your explicit choice: when you star a contact (if you kept the "Exact" level for favorites) or when you set the "Exact" level for a group yourself. For people who are not your contacts, only the approximate area ever remains.

This data is visible only inside the app to other users of the service, is not public on the web and is not indexed by search engines.

Messages are protected by end-to-end encryption: only sender and recipient can read the content. Loft coordinates are metadata needed to compute and draw the route and follow the privacy rules described above.

5. Where data is and who processes it for us

Data is hosted on Google Firebase (Google Ireland Ltd.), with the database in the europe-west8 (Milan, Italy) region. Google acts as a data processor under its cloud service terms. For city search and for the loft address we use Google Places and Google Geocoding: when you type in the city field we send Google the text you write and an approximate position to rank the results; when you choose or move the loft point on the map we send Google the coordinates of that point to show you the matching address. Requests are sent from your device, so Google also receives its IP address. We do not send Google your name or your account.

If you consent to the optional usage statistics, the pseudonymised usage events are processed through Google Firebase Analytics (Google Ireland Ltd.), which acts as a data processor. Without your consent these events are not collected.

Crash and error reports are processed through Firebase Crashlytics (Google Ireland Ltd.), which acts as a data processor under its own terms for cloud services. Unlike the usage statistics, this collection does not depend on your consent: it is what keeps the service standing.

Sending emails

The emails the service sends (login verification, security notices about your account and, if you left an address, the waiting list messages) are delivered through Resend, which acts as a data processor and receives only the recipient address and the text of the message. We do not transmit the content of your letters, which is end-to-end encrypted and never travels by email.

Maps

The app's maps are drawn with image tiles that your phone downloads directly from MapTiler (api.maptiler.com). MapTiler therefore receives the device's IP address and the coordinates of the requested tiles, that is the area of the map you are looking at: if you are looking at your loft, or setting it on the map, the tiles requested at that moment cover the area it is in. We do not send it your account, your name, your messages, or the loft coordinates as a datum of their own. Tiles already downloaded stay in the phone's memory, so the same areas are not requested a second time.

The map provider can be replaced without an app update: if it changes, we state it here.

Purchases and subscriptions

Purchases happen in the stores: Apple's App Store and Google Play. They collect the payment and process your payment details as independent controllers, under their own policies, and that is where you manage renewal or cancellation of the subscription. The store notifies our servers automatically of the events concerning your subscription: activation, renewal, cancellation, expiry, refund. We need them to keep the plan on your account up to date even when the app is closed. These notifications contain the technical subscription data (transaction identifier, product purchased, dates and type of event), never your payment details.

The safety copy of your letters

Your letters open with a secret that lives on your phone, and if the phone is lost that secret goes with it. This is why we keep a sealed safety copy of it on our servers, and we make it ourselves: it leaves your phone the first time you open the app with your letters, without asking you anything. There are two seals. The first opens with your recovery code, 26 characters that your phone generates and keeps for itself, and that we ask you to also save among your passwords: it never reaches us. The second opens only inside our systems, in a digital vault hosted by Google Cloud in the European Union. Both are needed, so neither we nor whoever keeps your passwords can open the copy alone. We give it back to you, still sealed, only when you sign back into your account and verify at that moment the phone number or the email address linked to it; if you have recently changed one of them, we wait up to seven days. The legal basis is the performance of the contract (art. 6.1.b GDPR): the copy is what keeps your letters when you change phone, and it is part of the service. You can give it up at any time by turning off "Recovery if you change phone" in Settings, Security, Loft safety: when you turn it off we delete the whole copy straight away, keep no earlier versions and do not make it again until you turn the switch back on; we delete it in any case together with your account. If you lose your phone and have neither that code nor the 12 recovery words, those letters become unrecoverable, for us too.

6. How long we keep it

- Unsubscribing from the emails does not remove you from the queue, and does not delete the address earlier: we stop writing to you and keep the address, together with the fact that you unsubscribed, until the same 12-month term. This is what stops us writing to you again by mistake. If you want the address gone straight away, you can ask the contact in section 1 (see also section 7)

- If you get in and complete sign-up, the entry stops being a waiting list and becomes part of your account history: from then on it follows the account rules, that is it stays as long as the account exists and is deleted with it

- We do not write to bring you back after deletion, because after deletion we have nothing left to write to

- Technical purchase index: the transaction identifier assigned by the store, its link to the account that took out the subscription, and the archive of receipts already used. They serve to stop the same receipt counting for more than one account and to correctly attribute the renewals and refunds the store reports to us even after the account is closed. They contain no payment details (legal basis: legitimate interest in fraud prevention; limit to the right to erasure allowed by art. 17(3) GDPR)

- Letters already delivered: the letters you had sent and that were delivered remain with their recipient, like a paper letter received. They remain encrypted, only the recipient can read them, and they no longer bear your name: "Deleted user" is shown as the sender (legal basis: the recipient's legitimate interest in keeping their own correspondence)

- Problem reports and support requests: the technical description of a defect you reported stays, because it concerns the app and not you. What identifies you does not stay: after the account is deleted we remove from those reports the reference to your account and the screenshots you had attached, within thirty days of the deletion. Of support requests only this remains: that a request arrived, when, and that it was handled. They contain nothing else (legal basis: legitimate interest in fixing product defects, and the need to demonstrate that data subject requests were acted upon, art. 5(2) GDPR)

7. Your rights (GDPR)

You have the right of access, rectification, erasure, restriction, portability and objection. You can exercise them by writing to info@appigeon.com. You also have the right to lodge a complaint with the Italian Data Protection Authority.

The right to erasure has one limit only, described in section 6: after the account is closed, the traces described in section 6 remain (art. 17(3) GDPR).

If you are on the waiting list you have the same rights, even though you are not a user yet, and two options that should not be confused:

Changing your number and email is available directly in the app (Settings → Contacts). Consent to usage statistics can be withdrawn at any time from Settings. The address book permission is revoked from your phone settings.

8. Minimum age

The service is reserved for people aged at least 14.

9. Changes to this policy

Each new version will be presented to you in the app and must be accepted to keep using the service. Previous versions and the date of your acceptance remain recorded.


This text is identical, in the same version, to the one shown and accepted inside the app (privacy-v13.en.md).

Home   Versione italiana   Terms