Privacy Policy
Last updated: August 25, 2026
1. Introduction
This Privacy Policy explains how Mindzone Technologies LLC ("Mindzone," "we," "us," or "our"), a company registered and operating in the United Arab Emirates, collects, uses, discloses, and protects your personal information when you use the PingRoom and PingRoom Agents mobile applications (each an "App" and together the "Apps"), our website at pingroom.io (the "Website"), and any related services (collectively, the "Service").
PingRoom is the rooms, pings, and push-notification App: it lets users create rooms, invite members, and send instant pings to them. PingRoom Agents is a separate managed-agent App that uses the same PingRoom account. The Apps are offered through the platforms and release channels we make available; availability may vary by App and platform. By accessing or using our Service, you acknowledge that you have read and understood the practices described in this Privacy Policy.
This Privacy Policy is issued in compliance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") and its implementing regulations, as well as other applicable data protection laws and regulations.
2. Information We Collect
The information we collect depends on how you use the Apps. We collect data needed to provide, secure, and improve the Service.
2.1 Account Information
The Apps use one unified PingRoom account system. Your account, profile, plan, and entitlements may therefore be recognized across both Apps. Depending on the App and feature, the Service supports the following account types:
- Guest Accounts: When you use PingRoom without registering, we may create a guest account with a system-generated identifier. No name or email address is required for guest access.
- Verified Accounts: If you choose to upgrade your account, we collect your email address for authentication purposes. Verification is performed via a one-time password (OTP) sent to your email, or by signing in with Apple, Google, or Telegram, in which case we receive your basic profile identifiers (such as your provider account identifier, name, and email, where the provider makes them available). PingRoom accounts have no password of their own; we never see or store one.
On iOS, PingRoom Agents can optionally detect a valid PingRoom session through an Apple Keychain access group shared by the two Apps. PingRoom Agents reads this shared item only to validate the session and offer the matching account. It does not write to or delete the shared item. Only after you choose to continue does PingRoom Agents save an App-private copy of that session in secure storage. Signing out of PingRoom Agents clears its private copy but does not sign you out of PingRoom.
2.2 Profile & Contact Card Data
In PingRoom, if you create a personal room or a contact card, we store the links and details you choose to share, which may include a phone number or social handles you add yourself, solely to display them to the people you share them with. You decide what goes on your card, and you can edit or remove it at any time. Your personal room may have a public handle (for example, pingroom.io/@you) that you choose; sharing it is entirely your decision.
2.3 Device & App Information
Each App creates a random, App-scoped, opaque installation identifier and sends it with requests to our Service. We use it as an anti-abuse and fraud signal, including to prevent repeated use of one-time gifts, referrals, or promotions. It is independent of your account and is not cleared merely because you sign out or change accounts. It is not derived from Android ID or another persistent platform identifier and is not an advertising identifier. On Android, uninstalling the App removes the local identifier; a later installation creates a new one. On iOS, a random identifier stored in Keychain may survive reinstall where Apple permits.
PingRoom also collects the following information to deliver push notifications. PingRoom Agents does not provide push notifications and does not collect a push token for that purpose:
- PingRoom Device Push Token: A unique token issued by Apple Push Notification service (APNs) for iOS devices or Firebase Cloud Messaging (FCM) for Android devices. This token is required to deliver push notifications to your specific device.
- Platform Type: Whether your device runs iOS or Android, used to operate the Apps and, in PingRoom, route notifications through the correct channel.
- App Version: The version and identity of the App installed on your device, used for compatibility, security, and required-update checks.
2.4 Room & Notification Data
When you use PingRoom, we store data related to your rooms and notifications:
- Room Membership: Records of which rooms you have created or joined, your role within each room, and the room's configuration (name, icon, color, quick-action buttons).
- Notification Content: The title and body of notifications you send or receive, including metadata such as timestamps, the sender, the trigger source (manual, webhook, location trigger, or time trigger), and delivery status.
- Attachments: Images, supported documents, and archives you upload to a notification, together with file metadata needed to store and deliver them. Unattached uploads are removed after 24 hours; attached files otherwise follow the related notification’s lifecycle.
- Location Pings: When you choose to attach a place to a Ping, we store the precise latitude and longitude and any optional place label or address as part of that notification. A Location Ping is deliberate Content that remains in notification history and follows the same retention lifecycle; it is different from the on-device geofence processing described in Section 2.8.
- Webhook Configurations: If you set up webhook integrations for a room, we store the webhook endpoint codes, secrets, and associated configuration.
- Time Trigger Settings: If you configure scheduled notifications, we store the schedule parameters (frequency, time, days) and the notification content to be sent.
2.5 Agent Data
The Service supports two agent types. A Managed Agent is configured in PingRoom Agents and executed by our Managed Agent runtime. A Connected Agent is an externally hosted agent or application that you authorize to use supported Service interfaces on your behalf.
If you use PingRoom Agents, we store the agent definitions and content you submit, including names, purposes, instructions, permissions, model settings, builder requests and conversation history, test tasks, trigger settings, run inputs and outputs, status, errors, token usage, and event history. The builder may use your description together with a limited list of Rooms you can access, including their names and internal identifiers, to propose an agent definition. We also store model-connection details such as the connection name, model identifier, supported API host, and any credential you provide. Provider credentials are encrypted at rest, decrypted only on our server to verify or use that connection, and are not returned to PingRoom Agents after saving.
A Managed Agent may run manually or wake from a schedule, a signed webhook, or activity in a watched Room. A run may send the agent definition, task or trigger input, relevant Room or account context, prior run messages, and request metadata to a Model Provider. The model may request supported tools that read or change PingRoom resources. Tool names, arguments, results, model responses, usage, and run events are returned through and recorded by our runtime so the run can continue and you can review or troubleshoot it.
Some tools run within the permissions and limits you configured; actions designated as sensitive pause and create a pending approval for an authorized person. We store the proposed action, encrypted arguments, approval or rejection, reviewer, timestamps, and expiry state. Approval controls reduce risk but do not make model output or automated actions error-free. You can pause an agent, disable a trigger, reject a pending action, or cancel a supported run.
Managed Agents can use either PingRoom AI, for which Mindzone selects and operates the connection to a third-party Model Provider, or a provider connection you add with your own credential. Before PingRoom AI first sends your data to a third-party AI provider, the applicable App identifies the provider and the categories of data involved and asks for your permission. That permission covers later runs and configured background triggers until you withdraw it or disable the feature. Section 6.4 explains the different responsibilities for PingRoom AI and your own provider connections.
To recover an interrupted creation or test-run flow, PingRoom Agents may also save pending draft or task state locally. This may include the job description, proposed or edited definition, instructions, test task, connection identifier, idempotency key, trigger draft, and progress state. On mobile, these sensitive recovery records use operating-system secure storage; in a web build they use local browser storage.
For Connected Agents, we store registration, operator, activation, and optional public-listing details; authorized scopes and access credentials; and associated approvals, questions, handoffs, and event or usage records needed to administer, secure, and revoke access.
2.6 Subscription and Purchase Data
If you purchase a paid feature through an App, we receive subscription and entitlement status, product identifiers, and purchase, renewal, cancellation, or refund events from Apple, Google, or RevenueCat. For web subscriptions processed by Stripe, we provide your name, email address, and PingRoom user ID to Stripe and receive customer and subscription identifiers, subscription and payment status, and billing events. Apple, Google, and Stripe process your payment details; Mindzone does not receive or store your full payment-card number.
2.7 Usage Data
We collect account-linked usage data to understand feature use, diagnose failures, secure the Service, and improve the Apps. Analytics events may be associated with your PingRoom user ID and may include whether you use a guest or verified account and your subscription plan. This data may include:
- Features, screens, and actions accessed and frequency of use
- Screen views and the product actions you choose to take
- Device platform, App identity, and App version
- PingRoom notification delivery success and failure rates
- Request and security metadata, which may include IP address, timestamp, route, response status, device or browser information, and authentication, rate-limit, fraud, or abuse events
- Bounded diagnostic events, such as an error type and the allowlisted App surface where it occurred; optional analytics do not include raw error messages, stack traces, or raw URLs
We analyze this data at the account level and in aggregate. If you enable optional App analytics, PostHog processes those events on our behalf. Google Analytics for Firebase is deactivated at the native configuration level in the current Apps and does not collect App analytics, even after an affirmative analytics choice. We filter product-event fields to exclude notification bodies, precise Location Pings, location-trigger coordinates, managed-agent instructions, tasks or outputs, invite or activation codes, provider credentials, and raw error messages. PostHog receives the IP address used for the connection, but we disable its IP-based geolocation feature. We do not send PostHog your precise GPS position or saved location-trigger coordinates. You can change the analytics setting in the applicable App; disabling it stops future optional events and clears the local optional-analytics identity and pending queues, but cannot retract events already processed.
2.8 Location Data (PingRoom Only)
PingRoom has two distinct, optional location features: Location Pings you choose to share and device-side location triggers.
Location Pings: When you tap the location attachment control, the App asks the operating system for your location. A place is shared only after you choose it and send the Ping. We store its precise coordinates and any label or address with the notification and disclose it to the Room recipients and other destinations enabled for that Room, such as connected agents, managed-agent tools, channel mirrors, or outgoing webhooks. Opening, previewing, geocoding, navigating to, or sharing the place may also send the coordinates and ordinary device or network information to the map, geocoding, navigation, or sharing provider you choose, under that provider's terms.
Location triggers: These send a saved notification when your device enters or exits a boundary. Your device monitors the boundary locally using the operating system's native geofencing capability. For this feature:
- When you create a location trigger, PingRoom stores the name, center coordinates, radius, transition type, and associated room so the trigger can sync across sessions and be edited or deleted by you.
- Your device's operating system (iOS or Android) monitors the boundary locally and determines when you enter or exit it. PingRoom does not receive a continuous location feed.
- When a geofence event is triggered, your device sends a trigger signal to our server. That signal contains only the trigger identifier, not your current GPS position or travel path. Because the server already stores the saved center, radius, and transition type, the event tells us that the device entered or exited that saved area.
- PingRoom does not receive or store your ongoing position, GPS position when the trigger fires, or an automatically recorded travel path.
You can revoke location permission in system settings, delete saved triggers, or stop attaching places. Revoking permission stops new device access but does not delete a Location Ping or geofence configuration already stored; delete the related Content or configuration separately where the App provides that control.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Deliver PingRoom Push Notifications: In PingRoom only, use your device token to route notifications from room members, webhooks, location triggers, and time triggers to your device via APNs or FCM.
- Authenticate Your Account: Verify your identity through email OTP or a selected sign-in provider, manage App-specific sessions, and optionally offer the read-only iOS session handoff described in Section 2.1.
- Maintain and Operate the Service: Manage rooms, memberships, quick actions, webhooks, location shares, location triggers, time triggers, managed agents, model connections, schedules, signed hooks, watched-Room triggers, tool calls, approval requests, agent runs, and notification delivery records.
- Prevent Abuse and Fraud: Use the opaque device identifier and related account activity to enforce one-time offers, detect misuse, protect users, and secure the Service.
- Manage Purchases and Entitlements: Process subscription status, restore purchases, provide billing support, and unlock paid features across your unified account.
- Configure and Maintain the Apps: Provide your app with the correct service endpoints, check for required updates, and communicate maintenance status on launch.
- Improve the Service: Where optional analytics is enabled, analyze usage patterns, notification delivery performance, and error reports to fix bugs, improve reliability, and develop features.
- Communicate with You: Send you service-related communications, such as OTP codes, account updates, or important changes to this Privacy Policy (we do not send marketing emails).
- Comply with Legal Obligations: Process data as required to meet our obligations under UAE law and applicable regulations.
4. Push Notifications (PingRoom Only)
Push notifications are a core PingRoom function. PingRoom delivers them as follows:
- When you install PingRoom and grant notification permissions, your device's operating system generates a unique push token (an APNs token on iOS or an FCM token on Android).
- We register this token with our notification delivery service via a request authenticated using your account's JWT token. The token is stored in our device_tokens database along with your platform type and app version.
- When a notification is sent to a room you belong to, our backend enqueues a delivery job. Our dedicated notification service then delivers the notification directly to Apple (APNs) or Google (FCM), which in turn delivers it to your device.
- Our infrastructure sends each push directly to the applicable official platform service, APNs or FCM. We do not use an additional push-notification aggregator or intermediary.
- If your device token becomes invalid (for example, after uninstalling the app), Apple or Google will report the token as invalid, and our system will automatically remove it from our database.
You can disable push notifications at any time through your device's system settings. Disabling notifications will prevent delivery but will not affect your room memberships or other app functionality.
5. Legal Basis for Processing
Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), we process your personal data on the following legal bases:
- Consent: Where you have given clear consent for us to process your personal data for a specific purpose, such as granting push notification permissions in PingRoom, allowing optional App analytics, granting location permission, attaching a precise place, or allowing PingRoom AI to share the disclosed data with the named third-party Model Provider. You may withdraw consent at any time, although that does not undo prior processing.
- Contract Performance: Processing that is necessary to fulfill our contractual obligations to you, including delivering notifications, maintaining your rooms and managed agents, running the manual or triggered agent tasks you configure, carrying out permitted tool requests and approvals, and providing the core Service as described in our Terms of Service.
- Legitimate Interests: Processing that is necessary for our legitimate interests, provided those interests are not overridden by your rights. This includes maintaining the security and integrity of our Service, preventing fraud, analyzing aggregated usage data to improve the Service, and ensuring the technical reliability of notification delivery.
- Legal Obligation: Processing that is required to comply with UAE laws, regulations, or lawful requests from government authorities.
6. Data Sharing & Third Parties
We do not sell, rent, or trade your personal information to third parties. We share data only in the following limited circumstances:
6.1 People and Destinations You Choose
We share Content as needed to provide the audience and destinations you select. Room information, notifications, attachments, member profiles, contact shares, and precise places attached to Location Pings may be visible to the applicable Room members. Content you place in a public Room, public contact card, or public agent listing may be visible to anyone with access to that page or link. A Connected Agent or Managed Agent tool may access Content and account resources within its authorized scope and permissions. Managed-Agent Pings carry an AI-generated label and machine-readable provenance on supported PingRoom surfaces. Connected-agent and externally exported Content may be labeled where the applicable interface supports it. Section 6.4 describes sharing with integrations and Model Providers; Section 6.5 describes analytics processing.
6.2 Push Notification Delivery Providers (PingRoom Only)
To deliver push notifications to your device, we transmit your device push token and notification payload to the following platform services:
- Apple Push Notification service (APNs): For iOS devices. Governed by Apple's Privacy Policy.
- Firebase Cloud Messaging (FCM): For Android devices. Governed by Google's Privacy Policy.
These are the official push notification services provided by Apple and Google respectively. We communicate with them directly from our own infrastructure. We do not use any third-party push notification aggregators or intermediary services.
6.3 Subscription & Payment Processing
Mobile purchases made through an App are processed by Apple (App Store) or Google (Google Play) under their terms. We use RevenueCat to manage and verify mobile subscription entitlements. RevenueCat receives your unified PingRoom account identifier and app-store receipt, transaction, product, and subscription-status data. We do not send RevenueCat your email address, room or notification content, or managed-agent content.
Web subscriptions are processed by Stripe. When you start web billing, we send Stripe your name, email address, and PingRoom user ID, together with the selected plan, and create or reuse a Stripe customer and subscription. Stripe processes your payment method and returns customer, subscription, invoice, and payment-status identifiers and billing events. Mindzone does not receive or store your full payment-card number.
6.4 Integrations & Model Providers
PingRoom lets you connect a room to external services, and PingRoom Agents can use either PingRoom AI or a Model Provider connection you configure. Relevant Content and metadata are sent only for the integrations, provider mode, agents, tools, and triggers you enable. Independent destination and BYOK providers apply their own privacy, retention, security, content, and model-training terms. Providers Mindzone selects for PingRoom AI process data on our behalf or as otherwise identified in the just-in-time notice; Mindzone remains responsible for selecting and overseeing those providers as required by applicable law.
- Chat channel mirroring: If you connect a room to Telegram, Slack, Discord, or Microsoft Teams, notifications posted in that room are mirrored (delivered as messages) to the channel or chat you link. The notification title, body, sender name, and room name are sent to that platform.
- Maps and place services: When you choose, preview, open, navigate to, or share a place, the App and operating system may provide its coordinates to the map, geocoding, navigation, or sharing provider you select. That provider receives the information under its own terms.
- Outgoing webhooks: If you configure an outgoing webhook on a room, we forward notification events (including the notification content, room identifier, and any structured data or precise Location Ping attached to the notification) to the URL you specify. Delivery is performed on our behalf by Cloudflare, Inc., which signs and relays the request to your endpoint.
- Connected Agents: If you authorize a third-party agent or application through OAuth, MCP, or another supported interface, it can act within its authorized scopes and the Rooms and resources your account may access. The agent operator is an independent third party; grant access only to agents you trust.
- PingRoom AI: If you choose PingRoom AI, Mindzone supplies the model connection and selects a third-party Model Provider. Before the first transfer, the App identifies the current provider and the data categories a run may send and requests your permission. Depending on the builder, run, trigger, and tools you configure, those categories may include your builder description and history; a limited list of accessible Room names and IDs; agent instructions and settings; manual tasks; schedule, signed-webhook, or watched-Room inputs; relevant Room or account Content; prior model messages; tool arguments and results; approval context; and request metadata. We record provider usage by account to enforce plan and safety limits. The current provider may change; we will identify a replacement before it receives data where a new permission is required.
- Provider connections you add (BYOK): If you add your own compatible provider credential, you direct us to send the same categories needed for your configured runs to the API host you choose. We use the encrypted credential server-side and do not include it in the prompt. Review that provider's terms, retention, security, and training practices; Mindzone cannot control or make promises for an independent host you select.
- Managed-agent tools: A model may request a supported tool within the permissions and limits you configure. Our runtime sends tool results back to the Model Provider so it can continue the run. Some sensitive actions pause for an authorized person to approve or reject them; other permitted actions may execute without an additional prompt.
These connections and agents are optional. PingRoom Room integrations apply only where enabled. A Managed Agent may continue sending data in the background while an enabled schedule, signed hook, or watched-Room trigger remains active. Pause the agent or disable its triggers to stop new runs. Disconnecting an integration, withdrawing PingRoom AI permission, or removing a BYOK connection stops future transfers through that connection but cannot retract data already processed by a provider. Mindzone does not use Agent Content to train a model operated by Mindzone.
6.5 Analytics & Website Measurement
PostHog processes the optional App feature, screen, engagement, and bounded diagnostic events described in Section 2.7 while optional App analytics is enabled. Google Analytics for Firebase is deactivated in the current native Apps and does not receive App events. Product-event fields are filtered to exclude Content, precise location, codes, credentials, raw errors, and raw URLs. You can turn optional App analytics off in the applicable App settings. Vercel Analytics processes Website usage measurements only after we replace invite and activation codes, Room codes, and public handles; remove fragments; and remove every query parameter except a short list of sanitized campaign labels.
Google Analytics 4 is disabled on the Website. We do not load the Google tag or send Website page-view or interaction events to GA4. A prior consent choice saved in your browser is not used while the integration remains disabled. If we reintroduce GA4 or another optional Website analytics service, it will remain off until you make a new affirmative choice and this Policy is updated before collection begins.
On your first Website visit, PingRoom temporarily holds a sanitized attribution record in the page's memory while you choose whether to allow account-linked attribution. It updates the record when you later arrive through a supported campaign parameter, ad-click identifier, or external referring site. If you allow attribution, your browser stores the record and may link a copy to your PingRoom account when you sign in. The browser record contains random installation and touch IDs, timestamps, a channel classification, normalized landing-page paths, campaign labels, at most one supported ad-click identifier per touch, referring hostnames, and a short checksum used to prevent duplicate uploads. The record expires 90 days after it is created or last updated. The filter replaces known Room, activation, and public-handle path values; omits referral reward codes; and rejects campaign values containing email addresses, URLs, or secret-like fields. Choosing “Keep off” or later withdrawing consent clears the pending and browser-stored record, stops future account linkage, and requests deletion of the account-linked attribution copy from PingRoom when you are signed in. If that request is temporarily unavailable, the Website retries it on a later authenticated session before sending new attribution.
When a PingRoom install link sends a visitor to an app store, our server records an aggregate store-handoff event so we can compare campaign traffic with later aggregate results. That event contains a random event ID, timestamp, destination platform, and sanitized source, medium, campaign, and campaign-ID labels. The campaign event record does not contain a cookie, PingRoom user or installation ID, advertising or ad-click ID, IP address, user agent, raw URL, referring URL, Room or invite code, or referral reward code. Ordinary security and request logs remain governed by the separate log practices described in this Policy.
Subject to the applicable App measurement setting and consent requirements, Android can read Google Play's Install Referrer once after a Play Store install. PingRoom immediately filters that value to the same bounded campaign fields, discards the raw value, and may link the filtered first- and last-touch record to your account. Installed Apps on both platforms can similarly read sanitized campaign fields from PingRoom links you open. We do not use an advertising identifier or fingerprinting for this. Apple does not provide an equivalent person-level web-to-App-Store referrer for general campaigns, so those iOS campaign results are measured only through aggregate App Store campaign reporting unless you open a PingRoom link after installation.
On iOS, subject to the same measurement setting and an authenticated PingRoom session, the App may request a short-lived Apple Ads AdServices attribution token after App open. The App sends that token over an encrypted connection only to PingRoom. Our server temporarily retains an encrypted copy solely while exchanging it with Apple's AdServices API, stores a cryptographic fingerprint for duplicate prevention, and removes the raw token when the exchange reaches a final result or the token expires. The raw token is not displayed in our administration tools. We retain only the bounded Apple response fields needed for internal campaign measurement, such as whether Apple attributed the install and the available organization, campaign, ad-group, keyword, ad, conversion, claim, country, placement, and rounded click- or impression-date fields. PingRoom may associate that result with your account, App-scoped installation ID, and campaign event history. This integration uses Apple's first-party App Store advertising data; it does not request App Tracking Transparency permission, access IDFA, identify activity outside the App Store, or enable cross-company behavioral tracking. Withdrawing the applicable measurement choice requests deletion of this non-financial account-linked record and places an account-level collection block. The block remains effective after logout and on other signed-in devices until you explicitly turn measurement back on.
We deny advertising storage, advertising user data, ad personalization, and Google Signals for Website measurement. We do not use PostHog, Vercel Analytics, or Google Analytics to serve targeted advertisements, and we do not sell or share personal data for cross-context behavioral advertising.
6.6 Authentication & Transactional Email
If you choose Apple, Google, or Telegram sign-in, that provider processes your authentication request and shares the account identifiers and basic profile information described in Section 2.1. We use Resend to deliver transactional email, including OTP codes and account or access messages. Resend receives the destination email address and the content and delivery metadata of the message.
6.7 Infrastructure Providers
Our Service runs on third-party cloud infrastructure that processes data on our behalf under contractual data-protection obligations, processing it only according to our instructions. These sub-processors include DigitalOcean for API and administration hosting, Vercel for Website and web-application hosting, and Fly.io for notification service hosting. We also use Cloudflare, Inc. for content delivery, security, and webhook relay; Cockroach Labs for our PostgreSQL-compatible CockroachDB database; Upstash for Redis-compatible cache and queue services; and an S3-compatible object-storage provider for uploaded files. Push delivery, payment processing, analytics, and the integrations described above are handled by the providers named in this Section 6.
6.8 Law Enforcement & Legal Requirements
We may disclose your personal information if required to do so by UAE law, regulation, legal process, or enforceable government request. We may also disclose information when we believe in good faith that disclosure is necessary to:
- Comply with a legal obligation or lawful request from a competent authority in the UAE
- Protect and defend our rights or property
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of users of the Service or the public
6.9 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you via a prominent notice within either App or by email before your personal information becomes subject to a different privacy policy.
7. Data Storage & Security
We use these technical and organizational safeguards:
- Database Security: Your data is stored in a PostgreSQL-compatible CockroachDB database using encrypted connections (TLS/SSL). Access to the database is restricted to authorized services only.
- Authentication Security: User sessions are managed via JSON Web Tokens (JWT) with HMAC SHA-256 signing and are validated on authenticated requests. Each App maintains its own local session copy. App-specific session copies are cleared or revoked as applicable when you sign out, and account deletion invalidates the active account session.
- On-Device Security: Authentication sessions, credentials, and sensitive recovery records are stored through the operating system's secure storage mechanisms, such as iOS Keychain and Android Keystore-backed storage. Ordinary preferences, cached interface state, analytics or retry queues, and other non-credential App data use normal App storage and rely on the device and operating system's protections; they are not all separately encrypted by the Apps.
- Model Credential Security: Managed model-provider credentials are encrypted at rest on our servers, used server-side only for the connection you configure, and are not returned to PingRoom Agents after they are saved. Arguments for pending sensitive tool actions are also encrypted at rest until the action is decided or expires.
- Transport Security: All communication between the Apps and our servers is encrypted using HTTPS (TLS 1.2 or higher).
- Notification Delivery Security: Communication with APNs uses HTTP/2 with JWT-based authentication. Communication with FCM uses OAuth 2.0 service account authentication. This applies to PingRoom push delivery only.
- Access Control: Internal access to user data is restricted on a need-to-know basis and protected by authentication and authorization controls.
No transmission or electronic-storage method is completely secure, so we cannot guarantee absolute security. We investigate and address identified security incidents.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law:
- Account Data: Retained for as long as your account is active. When an in-App account deletion succeeds, we remove the active account and its managed-agent graph. An email deletion request may take up to 30 days to verify and process. Limited records may remain where necessary for legal, tax, accounting, security, fraud-prevention, or dispute purposes.
- Device Identifiers & Push Tokens: The random App-scoped anti-abuse identifier is independent of an account and is not cleared by sign-out or account change. Android removes its local value on uninstall; an iOS Keychain value may survive reinstall. Account deletion does not necessarily erase the local value from every installed App. Associated gift, referral, redemption, or fraud-prevention records may be retained as needed to enforce abuse limits. On account deletion, we request the purge of active PingRoom push tokens; tokens are also removed when reported invalid by Apple or Google.
- Room & Notification Data: Active room configurations, memberships, notification content, and delivery records are retained as needed to provide and monitor PingRoom. A precise place attached to a Location Ping remains with that notification. Direct Room deletion removes user access, connector credentials, attachments, and active operation. If a Room is instead made inactive during account deletion, the deleting user’s membership, connector credentials, and attachments are removed, but limited internal rows such as notification history (including any embedded Location Ping), other members’ membership records, Quick Actions, or location and time trigger records may remain. Users can no longer access or operate that Room. We do not promise a fixed 90- or 365-day deletion period unless the applicable product interface expressly provides one.
- Managed Agent Data: Agent definitions, encrypted model credentials, builder history, trigger settings, run messages, tool arguments and results, pending-action decisions, token usage, and event timelines are retained while your account exists and as needed to operate, secure, and troubleshoot the Service. Expired pending actions may retain their decision and audit metadata. Archiving an agent changes its status and stops active use; it is not a deletion and retains the definition and run history. Account deletion removes the managed-agent graph and saved provider connections from our active systems, subject to the limited exceptions above and any data already received by a Model Provider under its terms.
- AI Safety Reports: A report can include your selected reason, optional details, and a server-minimized model-output snapshot. Open reports are assigned an original expiry no later than 90 days after submission. If the reporting account is deleted while a report is pending or under review, we remove its reporter identifier and details. We retain the reported agent, version, and run identifiers only when they belong to another account and remain necessary for moderation. If the account that owns the reported agent is deleted, we remove those subject identifiers instead. In either case, the minimized snapshot may remain until the original expiry. Reports already actioned or dismissed are deleted with the related account; while an account remains active, closing a report shortens any remaining retention to 30 days or less. Expired reports are pruned daily.
- Local App Data: Account deletion does not guarantee that every local record is erased simultaneously from every installed App or browser. Session copies, pending creation or run recovery records, preferences, caches, and queues may remain until the relevant App clears them, the recovery flow completes or is discarded, or you clear the App or browser storage. Our servers will reject a deleted account's session.
- Billing & Third-Party Records: Billing, transaction, subscription, and tax records may be kept for the periods required by law and by Stripe, Apple, Google, or RevenueCat under their own policies. A model provider or other integration may also retain data under its own terms. If a paid entitlement expires, Pro-only automation configurations may be disabled but retained so they can be restored after renewal; temporary billing-verification grace does not change their underlying retention lifecycle.
- Usage & Log Data: Identifiable analytics events and server logs are retained only as long as reasonably necessary for analytics, security, abuse prevention, diagnostics, or legal obligations, after which they are deleted or anonymized.
9. Your Privacy Rights
Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), you have the following rights regarding your personal data:
- Right of Access: You have the right to request a copy of the personal data we hold about you and information about how it is processed.
- Right to Rectification: You have the right to request correction of inaccurate or incomplete personal data.
- Right to Erasure: You have the right to request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, or where you withdraw your consent.
- Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to request that it be transferred to another controller where technically feasible.
- Right to Object: You have the right to object to the processing of your personal data where processing is based on legitimate interests.
- Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
- Right to Restrict Processing: You have the right to request that we limit the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
- Rights Concerning Automated Processing: You may object to decisions resulting from automated processing, including profiling, particularly decisions with legal impact or an adverse effect, subject to the PDPL's exceptions. You may request that a human review an automated-processing decision.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the UAE Data Office if you believe your data protection rights have been violated.
If the EEA or UK data-protection laws apply to our processing of you, you may also request access, correction, erasure, restriction, portability, or object to processing; withdraw consent; and complain to the data-protection authority where you live or work. Where we rely on legitimate interests, you may ask us to explain and reconsider that balancing. These rights are subject to applicable exceptions. Nothing in this Policy limits rights that cannot lawfully be waived in your jurisdiction.
Mindzone does not use managed-agent output to make solely automated decisions about users that produce legal or similarly significant effects. If you configure or use a managed agent for employment, credit, health, legal, eligibility, safety, or another consequential purpose affecting someone else, you are responsible for having an appropriate legal basis, providing required notices and safeguards, obtaining any necessary consent, and ensuring meaningful human review and compliance with applicable law.
To exercise any of these rights, please contact us at privacy@pingroom.io. We generally respond within 30 days or one month, as applicable, and will tell you if the law permits additional time. We may ask you to verify your identity before processing your request.
10. Children's Privacy
The Service is not intended for anyone under the age of 16, and we do not knowingly permit a person under 16 to create or keep an account. Parent or guardian consent does not make an under-16 account eligible. If we learn that an account belongs to a person under 16, we will restrict or disable it and take steps to delete the associated personal data, subject to safety, legal-preservation, and reporting duties.
We use a global minimum of 16 because UAE child-digital-safety rules require age assurance and, where the social-media rules apply, enhanced safeguards for users aged 15 to under 16. The Service does not offer a reduced-access account tier for that age group. We may use proportionate, reliable age-assurance measures rather than relying only on self-declaration. We will explain any additional information and retention at the point of collection, and access may be limited where reliable age assurance is unavailable.
If you are a parent or guardian and believe that a person under 16 has provided us with personal data, please contact us at privacy@pingroom.io so that we can take appropriate action.
11. International Data Transfers
Mindzone Technologies LLC is based in the United Arab Emirates. Your data may be processed in the UAE and in other countries where we, our service providers, or a Model Provider operate. These destinations may include the United States, the European Economic Area, the United Kingdom, and other jurisdictions used by our infrastructure, database, security, analytics, email, authentication, billing, app-store, and support providers. Model Providers selected by Mindzone for PingRoom AI, providers and API hosts you configure, integrations, and webhook endpoints may process data in any country in which they or their processors operate.
Where Mindzone controls a transfer of personal data outside the UAE, we use safeguards appropriate to the transfer and the UAE PDPL, which may include:
- Ensuring the receiving jurisdiction provides an adequate level of data protection as determined by the UAE Data Office
- Implementing appropriate contractual safeguards with our service providers
- Applying supplementary technical and organizational measures to protect your data during transfer and processing
PingRoom push delivery involves transmitting your device token and notification content to Apple (for APNs) or Google (for FCM), whose systems are distributed globally. Other cross-border transfers may occur through Stripe, RevenueCat, the app stores, PostHog, Vercel, Resend, sign-in providers, or the Model Providers and integrations described in Section 6. Google and these other providers may process data in the United States or other countries where they or their processors operate. Data protection laws in a destination may differ from those in the UAE.
12. Cookies & Tracking Technologies
12.1 Website (pingroom.io)
Our marketing website at pingroom.io may use the following technologies:
- Essential Cookies: Minimal cookies necessary for the website to function correctly, such as session management.
- Analytics: Vercel Analytics measures Website usage using normalized URLs as described in Section 6.5. Google Analytics 4 is disabled: the Website does not load its tag, set GA4 measurement cookies, or send it page-view or interaction events. We do not run an advertising pixel or enable Google advertising signals or personalization on the Website.
- Optional account-linked attribution: If you allow it, browser storage keeps the attribution record described in Section 6.5 until 90 days after the record is created or last updated. Choosing “Keep off” or withdrawing consent removes the browser record and, when authenticated, requests erasure of its account-linked copy.
12.2 Mobile Applications
The native mobile Apps do not use browser cookies. They store authentication sessions, credentials, and sensitive recovery data through operating-system secure storage such as iOS Keychain or Android Keystore-backed storage. Ordinary preferences, cached application state, offline or retry queues, and analytics queues use regular App storage and are not all separately encrypted by the Apps. While optional App analytics is enabled, PostHog may store an analytics identity, preference, and pending event queue in App storage. Google Analytics for Firebase is deactivated in the current Apps and does not collect analytics events or assign an Analytics App Instance ID. You may withdraw the optional-analytics choice in the applicable App settings. The Apps contact our servers for service configuration, authenticated features, security checks, and required-update or maintenance status. These requests may include the random App-scoped identifier described in Section 2.3 but do not use an advertising identifier. While optional App analytics is enabled, the Apps send the account-linked usage and bounded diagnostic events described in Sections 2.7 and 6.5 to PostHog. On Android, PingRoom may also read Google Play's Install Referrer once and retain only the privacy-filtered campaign record described in Section 6.5; the raw referrer is discarded and this process does not request the Android advertising-ID permission. On iOS, PingRoom may obtain and submit the short-lived Apple Ads AdServices token described in Section 6.5. Its raw value is kept only temporarily for the server-to-Apple exchange and is never exposed in the administration panel; the resulting bounded Apple campaign record may be linked to your PingRoom account and App-scoped installation ID. This process does not access IDFA or request App Tracking Transparency permission.
13. Changes to This Policy
We may update this Privacy Policy when our practices, technology, or legal requirements change. For material changes, we will:
- Update the "Last updated" date at the top of this page
- Notify you through a prominent notice within either App or on our Website
- For significant changes that affect how we process your personal data, we may also send a notification to the email address associated with your verified account
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.
14. Contact Information
For questions or requests about this Privacy Policy or our data practices, contact us:
For requests concerning rights under the UAE PDPL, include "PDPL Request" in the email subject line.