Back to home
Static page Featured page

Privacy Policy

Ping Privacy and Personal Data Processing Policy for users in the Russian Federation and the European Union. Clear information on data use, security, retention, user rights, and contacts.

Ping Privacy and Personal Data Processing Policy

For users in the Russian Federation and the European Union

Version: 1.0

Effective date: June 21, 2026

Contents

  1. Who we are
  2. A brief overview of Ping’s principles
  3. What data we process
  4. Data sources
  5. Purposes of processing
  6. Legal bases for the EU/EEA
  7. Legal bases for the Russian Federation
  8. Special categories of data
  9. Who we disclose data to
  10. Cross-border transfer and localization
  11. Retention periods
  12. Account deletion and data export
  13. Rights of users from the EU/EEA
  14. Rights of users from the Russian Federation
  15. How to submit a request
  16. Security
  17. Local storage on the device
  18. Device permissions
  19. Children
  20. Policy changes
  21. Contacts and supervisory authorities
  22. Appendix: brief data table

1. Who we are

This Policy describes how the Ping project ("Ping", "we", "Operator", "Controller") collects, uses, stores, transfers, and protects the personal data of users of the Ping mobile and web application, the my-ping.app website, and related services.

Operator / Controller details:

  • Project operator and controller of personal data: Ilya Yuryevich Serdyukov, founder of Ping.
  • Headquarters / main place of project management: Barcelona, Spain.
  • Email for privacy and personal data matters: info@my-ping.app.
  • Postal correspondence on personal data matters is accepted by prior arrangement via info@my-ping.app.
  • Data protection contact: info@my-ping.app.

This Policy applies together with the Ping user terms published in the Ping app or on my-ping.app. If separate Ping features have additional terms, they apply only to the relevant features and do not override this Policy.

For users from the Russian Federation, this Policy also serves as the Operator’s personal data processing policy within the meaning of Federal Law of the Russian Federation No. 152-FZ of 27.07.2006 "On Personal Data".

For users from the European Union and the European Economic Area, this Policy serves as a privacy notice within the meaning of Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR").

2. A brief overview of Ping’s principles

Ping is built as a private messenger and workspace for communication. We design the service according to principles of data minimization, encryption, access control, and transparent user settings.

Key principles:

  • we do not sell users’ personal data;
  • we do not use the contents of private messages for advertising profiling;
  • we do not require a real name, gender, age, interests, or other data unless they are needed for the selected feature;
  • push notifications for private and secret chats are generated without the message text, attachments, or sensitive details, except where the user enables detailed previews for supported notification types;
  • private messages and private spaces are processed in encrypted form, and the server stores only the data necessary for the service to work and for message delivery;
  • secret chats with end-to-end encryption operate as a separate mode for the specific devices of the participants; the contents of such chats are intended to be accessible only on devices that hold the relevant keys;
  • where technically possible, we provide settings that let the user control visibility, synchronization, contacts, notifications, and data deletion.

3. What data we process

We process only the data needed for Ping to operate, secure accounts, deliver messages, comply with the law, and support users.

3.1. Account data

We may process:

  • phone number and/or email used for registration, login, access recovery, and security notifications;
  • username, display name, surname, avatar, profile description, language settings, and visibility settings;
  • account status, creation date, deletion request date, restoration date, and related technical markers;
  • privacy settings, including phone visibility, read receipts, warnings about unknown contacts, and blocked users;
  • contact lists and connections within Ping, if the user adds them to the service or interacts with other users.

If a user allows access to the device contacts, Ping uses such data only to find acquaintances, display names, and enable connections within the service. We do not request more address book data than is necessary for this function. The user can turn off contact synchronization and delete synchronized contacts from Ping’s server-side storage in the app privacy settings or by contacting info@my-ping.app.

3.2. Device and session data

We may process:

  • device identifiers within Ping;
  • platform, app version, device name, trusted status details;
  • technical device data needed to confirm device trust and operate protected features;
  • for secret chats: technical information about which devices can participate in such a chat, and data needed to establish a protected connection; secret chat decryption keys are not transmitted to the Ping server;
  • technical session data, creation time, expiration time, and access revocation time;
  • data needed to deliver push notifications, in protected form;
  • data about passkey/Face ID/Touch ID in the form of technical login confirmations, but not the user’s biometric data;
  • data about access recovery methods in protected form, when the user enables such recovery methods.

3.3. Messages, chats, and spaces

We may process:

  • identifiers of conversations, spaces, topics, participants, and access rights;
  • message metadata: sender, recipients, sender device, creation time, delivery, read, edit, and deletion time;
  • encrypted message content and technical indicators needed for delivery, integrity verification, and app version compatibility;
  • reactions, replies, pins, technical deletion records, and delivery statuses;
  • attachments and media as storage objects: file type, size, duration, width/height, integrity checks, upload status, and links to messages;
  • space, topic, announcement, event, poll, and RSVP data, including titles, descriptions, locations, and links, if the user uses such features.

Ping is designed so that the server does not store plaintext messages with end-to-end encryption. In ordinary private chats and private spaces, the server needs technical metadata for delivery, synchronization, notifications, and security. In secret chats with end-to-end encryption, the server does not have the keys to decrypt the content of the secret chat.

Ordinary private chats, private spaces, and group features may be synchronized across the user’s devices. For such synchronization, the server stores encrypted content, attachments, delivery statuses, and other technical data needed to restore history on trusted devices.

Secret chats are separated from the regular cloud message history. Their contents are not shown to administrators as plaintext, are not included in normal server-side message synchronization, and are not exported by Ping in plaintext, because Ping does not hold the decryption keys.

If a user publishes information in a public space, public topic, public profile, or another feature with expanded visibility, such information may be available to other users within the visibility setting selected by the user. It is important to remember that recipients may save or distribute the received information outside Ping.

3.4. Secret chats with end-to-end encryption

A secret chat is a higher-privacy mode with end-to-end encryption between the specific devices of the participants. The content of such a chat is protected so that Ping does not store decryption keys and cannot restore plaintext messages or media.

In secret chats, Ping processes only the limited server-side data needed for the feature to work:

  • information about the creation and status of the secret chat;
  • identifiers of the participants and devices between which the secret chat was created;
  • technical device data needed to establish a protected connection;
  • encrypted messages, encrypted media, and technical delivery or read statuses;
  • technical delivery and push-notification events. For a secret message, the push notification is generated without the message text and attachment contents;
  • service events within the secret chat, such as reactions, message deletion, or location updates, in encrypted form.

The following rules apply to secret chats:

  • decryption keys are stored on the participants’ devices, not on Ping servers;
  • the history of a secret chat is not regular cloud history and may not be available on other devices of the same user;
  • Ping cannot restore the plaintext of a secret chat if the user loses the device, deletes local data, or revokes the device;
  • server-side data export may include only the server records Ping has: metadata, device information, delivery statuses, and encrypted data, but not the plaintext of secret messages;
  • participants in a secret chat may save, forward, photograph, or otherwise disclose content from their devices; Ping cannot fully prevent such actions on the participant’s side.

3.5. Location

Ping may process location only when the user explicitly uses location-related features, such as sending a location or enabling live location sharing.

In that case, we may process:

  • coordinates, accuracy, update time, and expiration time of the live location;
  • the message or attachment the location is linked to;
  • the status of stopping or expiring the live location.

If location or live location is used in a secret chat, the location content is transmitted as part of the encrypted content. Ping may still process technical delivery metadata for that message.

We may also use approximate IP-based location for account security, confirming a new device, detecting suspicious login activity, and showing warnings to the user. In such events, limited network security data is processed, such as an approximate region and risk indicators.

3.6. Calls

If the user uses audio or video calls, we may process:

  • call ID, call type, conversation, participants, and connection statuses;
  • technical connection data needed to establish and maintain the call;
  • connection, reconnection, end, missed, or declined call events;
  • technical quality indicators: latency, connection stability, route type, audio/video track counters, and connection statuses.

Ping does not record or store the audio or video content of calls. We process only the technical data needed to establish, deliver, maintain quality, secure, and end the call.

3.7. Notifications

We may process:

  • notification settings for private messages, main chat, topics, announcements, events, reactions, moderation, and security;
  • quiet hours, time zone, sounds, badges, delivery modes;
  • notification logs, push delivery statuses, opens, and provider errors;
  • push tokens in encrypted form and their hashes.

Push notifications for private and secret chats are generated without the message text, attachment name, or sensitive details unless the user has enabled detailed previews for supported notification types. For secret chats, push notifications do not contain the plaintext of the secret message.

3.8. Security, logs, and diagnostics

To protect the service, we may process:

  • login events, new device confirmations, account recovery, phone number changes, and the use of additional account protection methods;
  • limited request, connection, error, and diagnostic details;
  • limited network risk indicators and approximate connection region data;
  • message delivery logs, delivery errors, queue statuses, and technical delivery events;
  • administrative audit logs with redacted or hashed values where possible.

Diagnostic data is limited to information necessary for the security and reliability of the service and is not used to read the contents of correspondence.

3.9. Moderation, complaints, and lawful access

We may process complaints, violation details, restriction statuses, appeals, and moderation decisions. When reviewing complaints, we use only the information needed to verify the request, protect users, and secure the service.

If the law requires disclosure of information to an authorized government authority, court, law enforcement agency, security authority, or another body with lawful authority to request such data, we may provide only the data we have, that we can technically extract from our systems, and that we are required to provide under applicable law. If correspondence is stored only in encrypted form and Ping does not have the decryption keys, we cannot provide its plaintext. For end-to-end encrypted messages and secret chats, this usually means account data, device data, chat metadata, technical logs, delivery statuses, and encrypted data, but not plaintext content.

3.10. Cookies and web sessions

If the user uses the Ping web version or website, we may use cookies and similar local technologies only for service operation: login, session security, interface language, abuse prevention, and saving basic settings. We do not use cookies for advertising profiling. If the user disables cookies in the browser, some web features, including login, may not work correctly.

4. Data sources

We receive data:

  • directly from the user during registration, profile setup, message sending, calls, media uploads, support requests, and privacy settings;
  • from the user’s devices and the Ping app during synchronization, message delivery, device confirmation, and diagnostics;
  • from other users when they add the user to contacts, a space, a topic, a call, an event, a complaint, or a message;
  • from technical providers such as notification, login message, call, hosting, storage, anti-spam, and security providers;
  • from public or internal sources only if necessary for security, legal compliance, or protection of the rights of users and Ping.

5. Purposes of processing

We process personal data for the following purposes:

  • registration, authentication, and account maintenance;
  • phone number/email verification, login, access recovery, trusted device confirmation, and account takeover protection;
  • delivery of messages, attachments, media, reactions, and delivery/read statuses;
  • creation and maintenance of secret chats between specific devices, including processing of technical data for a protected connection and delivery of encrypted secret chat messages and media;
  • operation of spaces, topics, announcements, events, polls, and access roles;
  • operation of audio and video calls;
  • sending notifications, including security notifications;
  • storing local and server-side synchronization states, outgoing message queues, and technical deletion records;
  • supporting user privacy and security settings;
  • handling support requests, complaints, blocks, and moderation;
  • preventing spam, fraud, abuse, and unauthorized access;
  • diagnosing failures and ensuring service reliability, performance, and security;
  • complying with legal obligations, responding to lawful requests, maintaining audit logs, and protecting the rights of Ping, users, and third parties;
  • data export and account deletion at the user’s request.

6. Legal bases for users from the EU/EEA

Where GDPR applies to processing, we use the following legal bases:

  • Contract performance: account creation, login, message delivery, calls, synchronization, settings storage, space operation, and service support.
  • Legitimate interest: security, abuse prevention, diagnostics, rights protection, technical logs, and improving service reliability, where such interests are not overridden by the user’s rights and freedoms.
  • Consent: optional features where consent is required, such as access to device contacts, location, camera, microphone, expanded push previews, marketing communications, or optional analytics settings.
  • Legal obligation: storing and disclosing data when required by applicable law, a court order, or a lawful request from a competent authority.
  • Vital interests: only in rare cases where processing is necessary to protect a person’s life or safety.

7. Legal bases for users from the Russian Federation

If Russian law applies to the processing, we process personal data on the grounds provided by Russian law, including:

  • the personal data subject’s consent;
  • conclusion and performance of an agreement with the user;
  • fulfillment of obligations imposed on the Operator by law;
  • exercise of the rights and legitimate interests of the Operator, users, or third parties, provided that the rights of the personal data subject are respected;
  • other grounds provided by Federal Law No. 152-FZ.

If the user refuses to provide data needed for the service to work, some Ping features may be unavailable. For example, without a phone number or another supported identifier, login may be impossible, and without a push token the app cannot deliver push notifications.

8. Special categories of data

We do not ask users to provide special categories of personal data specifically, such as health information, political views, religion, biometric data for identification, criminal record information, or similar sensitive data.

The user may send such information themselves in messages, attachments, profiles, or complaints. In end-to-end encrypted chats, such information is processed as part of the encrypted user content. The user is responsible for what information they disclose to other participants.

Ping does not receive or store Face ID, Touch ID, or biometric templates. If the user uses a passkey or the device’s system biometrics, Ping receives only the technical confirmation needed to verify the login.

9. Who we disclose data to

We do not sell personal data, do not share it with advertising networks, and do not disclose correspondence, profiles, contacts, media, technical logs, or other data to third parties for their independent use.

Data may become available to other users only within the user’s own actions in Ping: for example, when the user sends a message, makes a call, adds a participant to a chat, joins a space, sends a location, reacts to a message, or publishes profile details visible to other participants under privacy settings.

The only external disclosure as a standalone recipient is a lawful request from an authorized government authority, court, law enforcement agency, security authority, or another body entitled to require such data under applicable law.

In that case, we disclose only the amount of data that:

  • is expressly required by the lawful request;
  • is in Ping’s possession;
  • can be technically extracted from our systems;
  • must be disclosed under applicable law.

Before disclosing data, we perform a legal and technical review of the request. We reject or challenge excessive, unclear, or unlawful requests whenever possible under applicable law. If applicable law does not prohibit notifying the user and such notification does not create a risk to an investigation, security, or the rights of others, we may notify the user about the request. Ping may publish aggregated statistics on lawful requests without disclosing users’ personal data.

If a competent authority requests correspondence, we may provide it only to the extent that we have it and can extract it. If a message, media file, or secret chat is stored only in encrypted form and Ping does not have the decryption keys, we cannot provide the plaintext of such content. In that case, only metadata, account data, device data, technical logs, delivery statuses, and encrypted data may be available, if their disclosure is required by law.

Separate from disclosure to standalone recipients, Ping may outsource technical data processing to infrastructure providers that act only on our instructions and may not use the data for their own purposes. Such processors may include hosting, database, object storage, notification, login message, call, network infrastructure, security, anti-spam, monitoring, logging, and diagnostics providers.

These processors receive access only to the data needed to perform their technical function and must comply with confidentiality, security, contractual restrictions, applicable law, and Ping’s instructions. They do not receive the right to read, sell, analyze, or disclose the contents of correspondence for their own purposes.

Third-party integrations available in Ping receive data only through the user’s action or with a separate notice in the interface. A third-party developer, payment provider, or feature provider may be an independent operator/controller of data and apply its own terms and privacy policy.

If a third-party integration receives access to a chat, file, audio, link, button, payment, delivery address, or other content through the user’s action, Ping is not responsible for that third party’s further use of the data outside Ping’s instructions if that party acts as an independent data recipient. Before using such features, the user reviews their terms.

10. Cross-border transfer and localization

Ping uses regional data segregation to ensure speed, availability, security, and compliance with local legal requirements. Personal data of users from the Russian Federation is stored on Russian servers. Personal data of users from the European Union and the EEA is stored on European servers.

For users from the EU/EEA, personal data may be transferred outside the EU/EEA only if there is a legal mechanism under the GDPR, such as an adequacy decision, standard contractual clauses, technical and organizational safeguards, necessity for contract performance, or another permitted basis. Requests from public authorities of third countries are reviewed in light of GDPR requirements for international disclosures and transfers.

For users who are citizens of the Russian Federation, when collecting personal data, including via the internet, recording, systematization, accumulation, storage, clarification, and extraction of personal data must be carried out using databases located in the territory of the Russian Federation, except in cases permitted by Russian law. Cross-border transfer of personal data from the Russian Federation is carried out only on a legal basis and in compliance with Russian law.

Actual storage and processing regions:

  • RF: personal data of users from the Russian Federation is stored and processed on Russian servers in the Yandex Cloud cluster within the territory of the Russian Federation. Yandex Cloud acts as a technical infrastructure provider and processor on Ping’s instructions; use of cloud infrastructure does not relieve Ping of its obligations as the personal data operator. According to Yandex Cloud’s official information, the platform is hosted in Yandex data centers in the Russian Federation and provides solutions for processing personal data under 152-FZ. Sources: 152-FZ Cloud, Data privacy in Yandex Cloud, Yandex Cloud data centers.
  • EU/EEA: personal data of users from the European Union and the EEA is stored and processed on European servers within the EU/EEA.
  • Other countries: primary storage of personal data of users from the RF and EU/EEA outside the respective regions is not used, except in cases expressly described in this Policy and permitted by applicable law.

11. Retention periods

We retain personal data no longer than necessary for the purposes of processing, unless a longer period is required by law, security, dispute resolution, rights protection, or backup technical limitations.

Retention periods and criteria:

  • account data is retained while the account is active;
  • after a deletion request, the account may remain in a recovery period of up to 30 days; after that, the data is deleted or anonymized if there is no legal basis for further retention;
  • sessions, technical access data, notification data, and device data are retained until expiration, revocation, device removal, or account deletion;
  • messages, attachments, and chat metadata are retained until deleted by the user, expired, the account is deleted, or while they are needed for conversation operation and legal compliance;
  • encrypted secret message data, delivery/read statuses, technical device data, and secret chat media records are retained for as long as needed for delivery, secret chat operation, security, deletion, disaster recovery, and legal compliance;
  • unfinished secret chat media upload sessions have a limited lifetime and are deleted or become unavailable according to technical retention policy;
  • live location sharing is retained until stopped, expired, or the related message is deleted;
  • security metadata, such as session details, device details, approximate connection region, and abuse indicators, is retained for up to 12 months unless a longer period is required for incident investigation, rights protection, legal compliance, or preventing repeated abuse;
  • technical logs are retained for up to 90 days unless a longer period is required for security, incident investigation, legal compliance, or rights protection;
  • security and administrative audit logs are retained for up to 12 months unless a longer period is required by law, incident investigation, or rights protection;
  • backups may retain deleted data for up to 90 days before being overwritten in the standard backup retention cycle;
  • legal and compliance records are retained for the period required by law or for as long as needed to protect the rights of Ping, users, and third parties.

12. Account deletion and data export

The user may request an export of their data and deletion of their account through Ping app settings or by contacting privacy support.

Before export or deletion, we may require re-authentication, confirmation of a trusted device, or another trust check. This is to protect the account from unauthorized access.

The data export may include only data that is in Ping’s possession and technically extractable from server systems. Plaintext secret chats and secret chat media are not accessible to Ping and are not guaranteed in server export; such data may exist only locally on participants’ devices after decryption.

When deleting an account:

  • active sessions and devices are revoked;
  • push tokens are cleared or revoked;
  • the profile is deleted or moved to a technical deleted-account state;
  • the account may enter a pending-deletion state with the possibility of restoration for up to 30 days;
  • history in group spaces may be preserved as a technical deletion record or metadata so as not to disrupt the history of other participants;
  • server records of secret chats, if retained, remain encrypted and do not allow Ping to restore plaintext without device keys;
  • data that we are required to retain by law, for security, audit, or dispute resolution may be retained for a limited period;
  • the contents of secret chats, whose keys exist only on devices, may become unrecoverable after local keys are deleted.

12.1. Deleting messages and chats

Message deletion depends on the chat type and the selected action:

  • in secret chats, deleting a message triggers deletion on participants’ devices, to the extent technically possible for the relevant app version and connection state;
  • for "delete for everyone" in a secret chat, Ping sends an encrypted service event; the server does not receive the plaintext of the deleted message and may retain technical delivery metadata for that event;
  • in ordinary private chats, the user may delete a message for themselves; delete for everyone is available for supported message types;
  • in group spaces, topics, and public sections, deletion may leave a technical deletion record to preserve the integrity of history, counts, moderation, and audit logs;
  • if a recipient has already saved, forwarded, exported, copied, or photographed the content, Ping cannot delete that external copy;
  • deleted messages and old versions of edited messages may be retained in system logs, backups, moderation queues, or audit logs within the periods specified in section 11, if needed for security, recovery, a lawful request, or rights protection.

12.2. Data management in the app

The user can manage individual data categories in Ping settings: synchronized contacts, phone visibility, read receipts, push previews, blocked users, linked devices, local cache, data export, and account deletion. If the needed setting is not available in the user’s app version, the request can be sent to info@my-ping.app.

13. Rights of users from the EU/EEA

If GDPR applies to the processing, the user has the right to:

  • access their personal data;
  • request correction of inaccurate data;
  • request deletion of data;
  • request restriction of processing;
  • receive data in a portable format in cases provided by the GDPR;
  • object to processing based on legitimate interest;
  • withdraw consent if processing is based on consent;
  • lodge a complaint with the data protection supervisory authority in their country.

We usually respond to GDPR requests within one month. This period may be extended by up to two additional months in cases permitted by the GDPR if the request is complex or there are many requests; in such case, we inform the user of the extension and the reasons for the delay within the first month.

Ping does not use solely automated decision-making, including profiling, that produces legal or similarly significant effects for the user. Automated security tools may help detect spam, fraud, suspicious logins, or abuse, but the user may submit a request for human review of a restriction or moderation decision.

14. Rights of users from the Russian Federation

If Russian law applies to the processing, the user has the right to:

  • receive information about the processing of their personal data;
  • request clarification, blocking, or destruction of personal data if they are incomplete, outdated, inaccurate, unlawfully obtained, or not needed for the stated purpose of processing;
  • withdraw consent to the processing of personal data;
  • appeal the actions or inaction of the Operator to Roskomnadzor or a court;
  • exercise other rights provided by Russian law.

After consent is withdrawn, we stop processing based on consent if there is no other lawful basis to continue processing, such as contract performance, a legal obligation, rights protection, or service security.

Requests from users in the Russian Federation are reviewed within the time limits established by Russian law. Usually, a response to a personal data subject request is provided within 10 business days from receipt of the request; this period may be extended by no more than 5 business days if permitted by law. If inaccuracy, unlawful processing, or the achievement of the processing purpose is confirmed, we take measures to clarify, block, stop processing, or destroy the data within the time limits established by applicable law.

15. How to submit a request

A request can be submitted:

  • in the Ping app through privacy, account, or support settings;
  • by email: info@my-ping.app;
  • for postal correspondence on personal data matters: by prior arrangement at info@my-ping.app.

To protect the account, we may ask you to confirm your identity, device, or ownership of a contact channel. We will not ask for a password, OTP code, or secret keys in plain text by email.

16. Security

We use technical and organizational safeguards, including:

  • encryption of data in transit;
  • end-to-end encryption for supported types of private messages, private spaces, and secret chats;
  • secret chats with end-to-end encryption between the specific devices of participants;
  • protection of messages, media, and attachments according to the selected chat type;
  • storing sensitive access and security data in the device’s secure storage, when supported by the platform;
  • secure local storage of app data;
  • storing sensitive secret chat data in the device’s secure storage, when supported by the platform;
  • hashing or encryption of tokens, access recovery data, and other sensitive technical data;
  • confirming new devices through trusted devices, QR, passkey, recovery code, or other supported factors;
  • separating administrative access, re-authentication for risky actions, audit logs, redaction of sensitive fields, and preventing administrators from restoring plaintext end-to-end encrypted content;
  • security monitoring, detection of suspicious activity, and revocation of sessions/devices when needed.

No system can be absolutely secure. The user is responsible for protecting their device, passcode, credentials, passkey, recovery codes, and not sharing device or account access with others.

17. Local storage on the device

The Ping app may store on the device:

  • local secure storage for messages, attachments, sending queues, notifications, synchronization, and caches;
  • local secret chat data needed to display history on a specific device;
  • media and thumbnails in the cache after the user opens or sends files;
  • sensitive access, local storage, and device trust data in system secure storage;
  • sensitive secret chat data in the device’s system secure storage;
  • a local notification log and diagnostic records.

The user may clear app caches, but clearing the cache does not always delete the account, server data, or data held by other participants in a conversation. Deleting the app, resetting the device, or deleting local keys may make secret chats unrecoverable on that device.

18. Device permissions

Ping may request device permissions only for the relevant features:

  • Contacts: finding acquaintances and creating contacts, if the user allows it.
  • Camera and microphone: photos, video, video messages, and calls.
  • Photos/files: selecting and saving media or documents.
  • Location: sending a location or sharing live location.
  • Push notifications: delivery of notifications.
  • Device biometrics: local confirmation of an action through Face ID, Touch ID, or the system passkey; Ping does not receive biometric templates.

The user can change permissions in the device settings. Some features may stop working without the relevant permission.

19. Children

Ping is not intended for users under 16 years of age or another age required by applicable law. If we learn that we are processing a child’s data without the necessary consent of a parent or legal guardian, we will take steps to delete or restrict such data.

20. Policy changes

We may update this Policy if Ping’s features, legal requirements, providers, storage regions, encryption methods, or data processing methods change.

If the changes are material, we will notify users in an available way: through the app, website, email, push notification, or another message in the service. Continued use of Ping after the changes take effect means acceptance of the updated Policy, unless otherwise required by law. If separate consent is required for new processing, we will request it separately.

21. Contacts and supervisory authorities

For privacy and personal data matters:

  • Email: info@my-ping.app
  • Headquarters / main place of project management: Barcelona, Spain
  • Postal correspondence on personal data matters: by prior arrangement at info@my-ping.app
  • Data protection contact: info@my-ping.app

Users from the EU/EEA may contact their national data protection authority. Users from the Russian Federation may contact Roskomnadzor or a court in the manner established by Russian law.

22. Appendix: brief data table

Category Data examples Purposes EU/EEA basis RF basis
Account and profile Phone, email, username, display name, avatar, language, settings Registration, profile, privacy, access recovery Contract, consent, legitimate interest, legal obligation Contract, consent, legitimate interest, law
Devices and security Device ID, device trust data, session status, security logs Login, trusted devices, account protection, incident investigation Contract, legitimate interest, legal obligation Contract, legitimate interest, law
Syncable messages and chats Encrypted content, delivery/read statuses, reactions, attachment metadata, conversation participants Message delivery, synchronization, history, private spaces Contract, legitimate interest Contract, legitimate interest
Secret chats Secret chat and participant device details, encrypted messages and media, delivery/read statuses, necessary technical metadata Private communication with end-to-end encryption between specific devices, message and media delivery, reactions, deletion, and location updates in encrypted form Contract, legitimate security interest Contract, legitimate security interest
Location Sent location, live location sharing, approximate GeoIP security data Location features, login and device security Consent, contract, legitimate security interest Consent, contract, legitimate security interest
Calls Call ID, participants, connection state, technical quality metrics Audio/video calls, quality and reliability diagnostics Contract, legitimate interest Contract, legitimate interest
Notifications Notification settings, protected push tokens, delivery logs Push and in-app notifications, security, quiet hours, notification counters Contract, consent, legitimate interest Contract, consent, legitimate interest
Moderation and lawful access Complaints, report metadata, moderation actions, lawful access cases, administrative audit logs Community safety, legal compliance, rights protection Legitimate interest, legal obligation Legitimate interest, law
User-selected integrations Data sent by the user to a bot, payment provider, translator, transcription service, or other feature Performing the user-selected feature Consent, contract, legitimate interest Consent, contract, legitimate interest