Privacy Policy
Effective date: August 16, 2026
Carrier Pigeon (“the App,” “we,” “us”) is a messaging app where messages travel as “pigeons” across a real map at true pigeon speed. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. By using the App, you agree to this policy.
When you create an account (with an email and password, or with Sign in with Apple), we collect your email address, a display name, and a username. If you use Sign in with Apple, Apple may share a relay email address instead of your real one.
We store the messages you send and receive so they can be delivered — including message text, any photos you attach, and the map coordinates a pigeon flies between for a given message. New messages are end-to-end encrypted (see “End-to-end encryption” below).
Because pigeons fly across a real map, the App uses an approximate, privacy-reduced location to determine where your pigeons depart from and how long they take to arrive. Locations are obfuscated (“snapped”) rather than stored as your exact position. You can choose “live” mode (device location) or “manual” mode (a pin you place yourself), and you can change this at any time in the App.
We store your friend connections and friend requests so you can send pigeons to people you choose.
If you enable notifications, we store a push-notification token so we can alert you when a pigeon arrives. We also process basic device information needed to operate and secure the App.
In-app purchases (pigeons) are processed by Apple. We receive a record that a purchase occurred and update your in-app balance. We never see or store your payment card details.
We use Google Firebase Analytics to understand how the App is used (for example, feature usage, app version, device type, and general, non-precise usage events) so we can improve it. The App does not use an advertising identifier and does not track you across other companies’ apps or websites for advertising.
For new messages between people using a supported version of the App, the message text and its map coordinates are end-to-end encrypted. Encryption keys are generated on your device; your private key is stored securely on your device and never leaves it. This means neither we nor our infrastructure provider can read the contents of those encrypted messages — only you and the person you’re messaging can.
Other users can see information you choose to share with them — such as your display name and username, the messages and photos you send them, and the approximate departure/arrival points shown on a pigeon’s flight.
We rely on trusted providers to run the App. They process data on our behalf under their own terms:
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
We may disclose information if required by law, or to protect the rights, safety, and security of our users, the public, or the App. Note that end-to-end encrypted message contents are not readable by us and therefore cannot be disclosed in readable form.
We keep your information for as long as your account is active or as needed to provide the App. When you delete your account, we delete or de-identify your personal information within a reasonable period, except where we must retain it to comply with legal obligations, resolve disputes, or enforce our agreements.
Depending on where you live (for example, the EEA/UK under GDPR, or California under the CCPA/CPRA), you may have additional rights — such as to access, correct, delete, or port your data, and to object to or restrict certain processing. To exercise any of these rights, contact us at noahiarrobino@yahoo.com. We will not discriminate against you for exercising your rights.
The App is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
We use industry-standard safeguards — including encryption in transit, access controls, and end-to-end encryption for new message contents — to protect your information. No method of transmission or storage is 100% secure, but we work to protect your data and continually improve our safeguards.
Your information may be processed and stored on servers operated by our providers in countries other than your own, including the United States. Where required, we rely on appropriate safeguards for such transfers.
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Effective date” above and, where appropriate, notify you in the App. Your continued use of the App after changes take effect means you accept the updated policy.
Questions, concerns, or requests? Reach us at noahiarrobino@yahoo.com.