Pigeon Messenger privacy policy

Operator: Kastia · Contact: [email protected] · Last updated 25 August 2026

Formatted copy, terms of use, and account deletion: kastia.net/privacy.html · kastia.net/terms.html. This is not legal advice. Applies to iOS, Android, Windows, macOS, and kastia.net.

Who we are

Pigeon is a messenger operated for closed beta by Kastia. Contact: [email protected].

What we never see

Private messages, group messages, channel posts, stickers, GIFs, and file attachments are end-to-end encrypted on your device before they leave it. The server stores opaque envelopes and encrypted media blobs. We cannot read that content. Push notifications say only “New message” — never the text. Encrypted backups are sealed with a passphrase that never leaves your device. We do not sell personal information, use chats for ads, or collect precise location.

Account information

To run the service we store: username, display name, optional profile photo, email or phone number used for one-time sign-in codes, Google or Apple sign-in identifiers if you use those buttons, device names, push tokens, and public keys, group/channel membership and roles, and plan entitlements (Free or Plus). Display names, usernames, and profile or channel pictures are visible to people you chat with. They are not end-to-end encrypted.

Delivery metadata

Like most messengers, the service can see that a device sent or received an envelope, which conversation it belongs to, approximate size, and time. We use this to deliver mail, apply plan limits, and fight abuse. We do not sell it. We are not a mixnet.

Apple, Google, and Microsoft

Apple may receive Sign in with Apple data, a generic APNs wake-up, and App Store purchase receipts. Google may receive a sign-in ID token, an FCM push token, and Play billing data if you install from Play. Microsoft may receive Windows notification and Store data if you install from the Store. Email or SMS providers send sign-in codes. Hosting stores sealed blobs. They do not receive message plaintext.

Nearby (Bluetooth)

When you turn Nearby on, your device advertises a short identity beacon over Bluetooth so other Pigeon users can find you. People (and radios) nearby can observe that traffic, including proximity and timing. Message bodies on Nearby are still end-to-end encrypted. Relays forward opaque bytes only.

On your device

Decrypted messages, keys, and contacts you save live in app storage on the device. Contacts are not a server address book. Encrypted backups may include your contact list, sealed with the same passphrase. Optional biometric lock stays on the device.

Deleting your account

In the app: Settings → Delete account (type your username). If you cannot open the app, email [email protected] from the address on the account. We complete email requests within 30 days. Details: kastia.net/privacy.html#delete-account.

Children

Pigeon is not directed at children under 13. You must be at least 13, or the higher age required in your country. If you believe a child has an account, email [email protected].

Permissions

Optional: notifications, Bluetooth (Nearby only), camera or files for a profile picture or attachment, and an in-app biometric lock. Precise GPS is not required.

Safety

You can report an account in the app. A report emails [email protected] with username, user id, conversation id, and a short reason — not message plaintext. We cannot moderate private chats because they are end-to-end encrypted. Block is local to this device.

Your choices

Changes

We will update this policy when the product changes. The in-app copy ships with your build.