Legal
Privacy Policy
Last updated · August 17, 2026
Pingr is built privacy-first, and this policy is written to be exact. Your notifications are fetched by the App directly from the services you connect and are stored on your Mac. Using Pingr requires a Pingr account, and the optional AI features send the content you ask about to our server. Everything that leaves your Mac is spelled out below.
1. Overview
Pingr (“the App”) is a macOS menu bar application that aggregates notifications from the third-party services you connect. Notification collection happens on your device: the App talks to each provider's API directly, and your notification history lives in a local database on your Mac.
We also operate a small backend (“the Service”) that handles sign-in, subscription status, the optional AI features, and the OAuth handshake for two providers. This policy covers both the App and the Service.
2. Your Pingr Account
Using Pingr requires a Pingr account. Sign-in is passwordless: you enter your email address and we email you a one-time magic link. We never ask for, use, or store a password.
The account data held on our servers is limited to:
- Your email address
- The name and platform of each device you sign in from
- Session and refresh tokens for those devices, with the time they were issued and last used
- Your subscription status — plan, current period end, and whether a cancellation is scheduled
- AI usage counters, so that plan quotas can be enforced
Your email address is used to send sign-in links and, when necessary, service messages about your account or subscription. We do not send marketing email and we do not share your address with anyone other than the email provider that delivers those messages.
3. What We Do Not Collect
Pingr does not:
- Run analytics, tracking, advertising, or telemetry SDKs in the App (for the website, see section 12)
- Store your notifications, messages, or notification history on our servers
- Store the access tokens or credentials of the services you connect — they stay in the macOS Keychain on your Mac
- Receive your payment card details
- Profile your usage or sell data to anyone
4. Data Accessed From Connected Services
To surface notifications, the App reads data from the third-party services you choose to connect, using each provider's official API over secure HTTPS connections, directly from your Mac. The data accessed is limited to what is needed to display notifications:
- GitHub, GitLab — notifications, issue and pull/merge request activity, repository metadata, and your user profile
- Jira, Linear, Plane, Notion — issues, tickets, and pages assigned to you or mentioning you, plus their status updates
- Slack, Discord, Telegram, WhatsApp, Messenger — message notifications from the conversations your account can already see
- IMAP email — message metadata (subject, sender, date) and content from the mailbox you connect
This data is fetched by the App on demand, rendered as notifications, and stored locally in your notification history. It is not relayed through our servers and we do not store it, with one exception: if you use the optional AI features, the specific notifications involved in that request pass through our server, exactly as described in section 7.
5. Third-Party Service Policies
Each provider you connect has its own privacy policy governing the data held on its servers:
6. Local Data Storage
The following is stored on your Mac and nowhere else:
- Notification history, thread state, and read/unread status, in an on-device SQLite database
- The full-text search index
- API tokens and OAuth credentials for the services you connect, in the macOS Keychain
- App preferences, filters, and snooze settings
There is no cloud sync of your notifications between devices. If you sign in on a second Mac, that Mac builds its own local history from the services you connect there.
7. AI Features
Pingr's AI features (the daily brief and the Ask Pingr chat) are opt-in and run through our servers. They are the only part of Pingr that sends notification content off your Mac.
When you request a brief or ask a question, the App sends the content of the notifications relevant to that request to our server. Our server forwards it to OpenRouter, which routes it to the language-model provider serving the selected model. Every request we send carries a zero data retention flag and an explicit opt-out of data collection and model training, so the provider does not retain the content or use it to train models.
We do not store your prompt or the model's response once the request has completed. What we keep is a usage counter, so your plan's quota can be enforced. If you never use an AI feature, no notification content ever leaves your Mac.
8. Connecting Accounts and the OAuth Broker
Most providers are connected straight from the App, with no involvement from our server. Slack and Messenger are the exception: they require an OAuth application secret that cannot safely be shipped inside a desktop app, so their OAuth handshake runs through our server.
In that flow our server exchanges the authorization code for an access token and hands it to your Mac through a single-use, encrypted record that expires after 60 seconds and is deleted as soon as it is collected. We do not store the resulting access token. On your Mac it is kept in the macOS Keychain, like every other credential.
9. Payments
Subscriptions are sold and processed by Paddle, which acts as the Merchant of Record for every purchase: Paddle is the seller, runs the checkout, and issues the invoice and any applicable tax.
Your card details never reach us. They are entered on Paddle's checkout and held by Paddle under its own privacy policy. What we receive and store is your subscription status: the plan, the end of the current billing period, and whether a cancellation has been scheduled.
10. Sub-processors
We use the following providers to run the Service. Each processes only the data described here:
- Paddle — payments, invoicing, and tax, as Merchant of Record
- Resend — delivery of sign-in and account emails
- OpenRouter, and through it the provider of the selected language model — AI requests only
- Hetzner — server hosting in Nuremberg, Germany
- Cloudflare — DNS and email routing
11. Hosting and International Transfers
Our server runs on infrastructure operated by Hetzner in Nuremberg, Germany. Account data, subscription status, and OAuth handovers are therefore processed within the European Union.
AI requests are the exception: the content of an AI request is forwarded through OpenRouter to the provider serving the selected model, which may process it outside the EU. The zero-retention and no-training flags described in section 7 are sent with every such request, wherever the model runs.
12. Analytics, Cookies, and Server Logs
The App contains no analytics, tracking, crash-reporting, or advertising SDKs at all. Nothing about how you use Pingr is reported back to us from your Mac.
This website counts visits using Umami, which we run on our own server in Germany. It stores nothing on your device, sets no cookies, and cannot follow you to any other site. There is no consent banner for it because there is nothing to consent to.
One cookie needs your permission, and is only written if you give it. When you arrive from an advertisement or a link we are measuring, the address you land on carries a campaign identifier. If you accept the banner, we store that identifier in a cookie named pingr_attr for up to 90 days, and attach it to your account if you later sign up. It tells us which advertisements are worth paying for. It contains no name, address, or browsing history, and it is never shared with anyone except the advertising platform the click came from, which receives only its own identifier back alongside the fact that a signup or purchase followed.
Your answer itself is remembered in a cookie named pingr_consent for one year, so we do not ask again. If you decline, nothing is stored and any earlier pingr_attr cookie is deleted. You can change your mind at any time by clearing this site's cookies in your browser; the banner will reappear.
Our server keeps ordinary operational logs of the requests it receives, including IP address, timestamp, endpoint, and response status. These are necessary to run the Service securely, diagnose faults, and detect abuse. They are not used for analytics or profiling, and are retained only as long as they are needed for those purposes.
13. Children's Privacy
The App is not intended for use by children under the age of 13. We do not knowingly collect personal information from children.
14. Your Rights and Data Deletion
You can delete everything Pingr stores on your Mac at any time from the App's settings, or by uninstalling the App and removing its application-support folder.
To delete your Pingr account, email info@pingrhub.com from the address on the account. We delete the account and every piece of data tied to it on our servers: email address, device records, sessions, subscription status, and usage counters. If you have an active subscription, cancel it first or ask us to cancel it for you. Invoice records that Paddle is legally required to keep for tax purposes remain with Paddle and are outside our control.
If you are in the European Economic Area or the United Kingdom, you also have the right to access, correct, export, or restrict the processing of your personal data, and to object to it. Write to the same address and we will respond.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date.
16. Contact
If you have questions about this Privacy Policy, contact us at info@pingrhub.com.