A Ping Can Carry The File
Private Attachments are in development for custom Pings and Questions, with previews for images, PDFs, Markdown, HTML, and text.

Attachments are now in source and local testing.
A custom Ping or Question can carry the file that gives the signal context: a report, screenshot, handoff note, PDF, or small image. Members see the event first and open the file when they need more detail.
This is a development update, not a release announcement. Attachments have not shipped publicly. Rollout and physical-device checks remain before we turn them on.
The File Stays With The Ping
PingRoom is not becoming a file library.
Each attachment belongs to one custom Ping or Question and appears beside its message. The file and the reason for sending it stay together.
A link points somewhere else and may change later. An attachment is the file itself, delivered privately with the signal that explains why someone should open it.
Attach From The Same Composer
Attach sits beside Add Link and Ask Question in the custom-Ping composer. Choose files from the system picker, review the selection, remove anything you do not need, and send once every upload is ready. The web composer also accepts files dropped from the desktop.
One Ping or Question can carry up to four files, each up to 5 MiB. Supported formats:
- PDF, Markdown, HTML, and plain-text documents
- JPG, JPEG, and PNG images
- ZIP archives
Unlisted formats are rejected, and every upload is checked against its extension: a ZIP must be a real archive, and a document or image must not have one hidden inside it. The narrow format list keeps preview behavior and privacy rules explicit.
Uploading Attachments will require Pro. Recipients who can see the Ping can open its files without Pro.
Open It Without Losing The Moment
A Ping with files shows a separate Attachments action and count. Open it to see the file list, then choose the one you need. Images render in place, PDFs support native viewing and zoom, Markdown and text stay scrollable, and HTML opens in a restricted viewer with scripts and external navigation disabled. A ZIP shows what is inside it — every entry with its name and size — without downloading or unpacking the archive, because that listing was recorded when the file was uploaded. Extracting is still your device's job, through Share.
Previews open in PingRoom's existing sheet instead of a separate file browser.
Private By Architecture
The push notification never carries file bytes, filenames, download URLs, or credentials. It carries only the number of attachments, so PingRoom can show the action immediately. The app then requests the file through an authenticated endpoint when a member chooses to open it.
Files live in private storage, not a public uploads folder. PingRoom checks the room, audience, and event visibility again on every read. Knowing an attachment ID is not enough to open it, and an upload that is never attached to a Ping expires after 24 hours.
These controls restrict access. They do not make every document harmless.
Agents Can Carry The Result Too
Connected agents use the same model: upload the file under the human account they are connected to, then attach its private ID to a Ping or Question. The CLI adds a repeatable --attach option, and the SDK exposes the same upload-and-send flow.
An agent can send a nightly report, generated image, or handoff note instead of dropping a public link into the room. MCP remains ID-only, so file bytes do not enter a base64 tool call.
Before We Turn It On
The backend, mobile composer, file viewers, agent API, SDK, and CLI paths are built. The remaining work is rollout: verify private storage and edge limits, ship fresh native builds, and test every viewer on physical iOS and Android devices.
After those checks, a Ping will carry the signal and the file needed to act on it.
Make a room. Tap once. Everyone knows.
PingRoom
The Ping that cuts through.

