Legal
Privacy Policy
Last updated: July 29, 2026
Postal Pigeon is built so that we have as little of your data as possible to protect — or lose. Your messages, files, and calls are end-to-end encrypted on your device before they ever reach our servers, and we never have the keys required to read them. When the last member of a chat leaves, that conversation and everything in it is permanently deleted. What follows is the detailed policy covering the small amount of information we do handle: account, billing, and basic diagnostic data.
Account information. To create a Postal Pigeon account we collect an email address (for sign-in and account recovery) and a securely hashed authentication credential. We do not require your real name, phone number, or a government ID to use the app.
Billing information. If you subscribe to Postal Pigeon Pro, payment is handled by a third-party payment processor. We receive confirmation that a payment succeeded and a subscription status; we do not receive or store your full card number.
Device and diagnostic information. With your permission, the app may send anonymized crash reports and basic device information (macOS version, hardware architecture, app version) to help us fix bugs. This data is not linked to message content and can be disabled in Settings at any time.
Website analytics. Our marketing website may use privacy-respecting, aggregate analytics (e.g. page views, referrers) to understand traffic. This is separate from the app itself and never includes message data, because we don't have any.
We use the limited account and billing information described above to operate your account, process subscription payments, provide customer support, secure the service against abuse, and comply with legal obligations. We do not sell personal information, and we do not use it to build advertising profiles.
Conversations are deleted automatically and permanently the moment the last participant leaves a chat — this isn't a setting you need to enable, it's how the relay is designed. Account information (your email and subscription status) is retained for as long as your account is active. You can delete your account at any time from Settings → Account → Delete Account, which erases your account record and revokes any remaining encryption keys tied to it. Deletion typically completes within 30 days.
We rely on a small number of infrastructure providers to operate Postal Pigeon: a payment processor for subscriptions, and cloud hosting for our message relays. Relays only ever handle encrypted ciphertext in transit — they are never given decryption keys and do not retain message content after delivery. These providers are contractually restricted to using data only to provide services to us.
Depending on where you live, you may have rights to access, correct, export, or delete the personal information we hold about you (for example under the GDPR in the EU/UK, or the CCPA/CPRA in California). Because message content isn't something we hold in the first place, most of these requests apply to account and billing data. To exercise these rights, contact us at privacy@postalpigeon.app.
Postal Pigeon's infrastructure may process data in countries other than your own. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers of personal data.
Postal Pigeon is not directed to children under 16, and we do not knowingly collect personal information from children under that age. If you believe a child has provided us with personal information, contact us and we will delete it.
We may update this Privacy Policy from time to time. If we make material changes, we will notify users in-app or by email before the change takes effect. The "Last updated" date above always reflects the most recent revision.
Questions about this policy or your data can be sent to privacy@postalpigeon.app.