Pingr privacy notice
23 September 2026
What Pingr does
Pingr provides a managed online push-notification service for an iPhone installation. A sender calls the installation's personal URL with a title, body, and optional JSON payload. The backend stores the message and asks Apple Push Notification service (APNs) to deliver it. A backend response that accepts a request does not guarantee a notification will arrive: Apple, a device, its network connection, notification settings, and other service conditions can affect delivery. Pingr does not promise an offline queue or guaranteed delivery.
Service and message data
Pingr processes an APNs device token, generated URL key, hash of a separate device secret, plan and entitlement state, plus each message’s title, body, optional JSON payload, time, and status. The backend runs on Hetzner in Germany with SQLite; APNs receives the notification payload. Messages are retained for up to 30 days plus up to one hour before the hourly purge. Free users see the latest 7 days. A URL key can send alerts only; reading history or changing an installation requires the separate device secret.
History and deletion
Installation records have no automatic expiry. Reset URL and clear history deletes the installation’s live record (including its APNs token, secret hash and purchase binding) and all associated messages, and invalidates its old sending URL and secret. The app can then register a replacement installation. Purchase-wide refund/revocation state, keyed by the original transaction identifier, is retained without an automatic expiry to enforce entitlements and prevent a reset from bypassing a refund. Contact support for deletion requests or if you cannot access an installation. Hetzner keeps seven rotating daily backup slots. Root-only deployment rollback snapshots are eligible for deletion after seven completed days, with up to one additional day before cleanup. Deleted data may remain in those backups until replaced or removed; backups are for recovery rather than normal history access.
Request data and protection
The server processes source IP addresses to accept connections. Registration rate limits use the trusted source IP in a bounded in-memory cache, with entries eligible for removal after an idle hour and cleared on restart; IPs are not written to the app database. Request access logging is disabled to avoid recording secret URLs or message contents. Node service status and error labels go to the host’s operational journal. Separately, reverse-proxy error entries may contain the source IP and requested URL, including query data or a sending key, when a request fails. Operational-log retention follows host settings rather than the message-history schedule.
Optional product analytics
Pingr uses TelemetryDeck for optional analytics, enabled by default and switchable off in Settings. Allow-listed signals describe product interactions, session starts, purchase or restore outcomes, and bounded technical-failure categories. The SDK adds app/build and SDK versions, device model and screen characteristics, OS version, language/region/time zone, appearance and accessibility settings, run context (such as TestFlight), and a pseudonymous hashed device identifier and a random session identifier. No notification titles, bodies, JSON payloads, sending URLs, keys, secrets, APNs tokens, purchase identifiers, raw error messages, support-message contents or support diagnostic attachments are sent to analytics. These measurements help us understand use and reliability; they do not control recording, purchase verification or delivery.
Purchases and support
Apple processes Pro payments at the localized price shown in the App Store. Pingr verifies signed Apple transaction data and receives signed App Store Server Notifications for entitlement, refund and revocation handling. The backend stores the original transaction identifier and verification time on an installation, plus purchase-wide original transaction identifier, notification UUID, signed date and free/Pro state; these support restoration, the three-installation limit and refund enforcement. It does not store full signed receipts, decoded transactions or payment-card details. A support message and any diagnostics you choose to include are handled by your email provider and received by our support mailbox; handing a draft to an email app does not prove delivery.
This website
This static website is hosted on Cloudflare. It has no contact form, browser analytics, account system, or application-message database. Cloudflare may process request data, such as IP address, browser information, and request logs, to provide and protect the site under its own terms.
Contact
For privacy questions, contact Pragmatiq at arthur.kuehn@pragmatiq.io.