Skip to main content

Privacy & Security

Private by architecture, not by promise.

PingRoom limits collection, protects what it needs, and explains where data goes. Privacy is built into the product and backed by controls you can use.

The data we hold is the data we need.

PingRoom collects each category of data for an identified product, safety, reliability, or legal need. Data that does not support one of those needs is excluded.

Six privacy and security principles.

No continuous location tracking

For geofence triggers, PingRoom stores the boundary while iOS or Android monitors it locally and sends the trigger ID when it fires. That event reveals entry to or exit from the saved area without sending a live GPS sample. A precise place is stored only when you deliberately attach it to a Ping.

Direct delivery. No push broker

Our notification service sends directly to Apple Push Notification service or Firebase Cloud Messaging. No third-party push aggregator sits between PingRoom and those platform services. Analytics is separate and disclosed in our Privacy Policy.

Tokens are minimal and self-cleaning

We store the native push token, device platform, and app version needed for delivery. Invalid tokens are removed when the platform reports them unusable, and we do not use them for advertising.

Start without an account

Start with a system-generated guest account and no email address. Upgrade later with a one-time code or social login. PingRoom accounts have no password of their own, and room passwords are stored as one-way hashes.

Security controls by default

Public endpoints are rate-limited. APIs whitelist allowed fields and hide sensitive fields, and webhook logs filter secrets. Rooms can be password-protected.

Limited data collection

Every stored field must support a product, safety, reliability, or legal need. AI provider transfers, analytics, integrations, retention, and deletion exceptions are disclosed in the Privacy Policy.

What we don’t collect

Limits we design around.

  • Continuous location feeds or automatically recorded travel paths
  • Third-party trackers in the notification path
  • Advertising identifiers or cross-app profiles
  • Sale or sharing of personal data for behavioral advertising

The Privacy Policy lists what we collect, why we use it, where it goes, and how long we keep it.