1. Scope
This notice covers pipipong.com, community.pipipong.com, studio.pipipong.com, direct desktop-app installer delivery, the current macOS technical preview, public Pet Community pages, authenticated community features, and PPAS Studio. Pipipong is a technical preview, so users should review the version-specific Status and Safety information before using it with important files.
2. Website access and downloads
Hosting, security, and file-delivery providers may process necessary technical logs such as request time, page or file requested, IP address, browser and device information, referrer, errors, and security events. These records are used to deliver the site and installer, diagnose faults, and prevent abuse.
Pipipong also operates a first-party anonymous website audience-measurement system on a fixed list of public pages. It counts page-family views, broad entry-source categories, adjacent public-page transitions, visible-time buckets, fixed call-to-action categories, language, coarse screen-size device class, edge-derived country code, page-load buckets, and fixed client-error categories. The event payload does not contain a visitor, session, advertising, or account identifier; an IP address; a raw user-agent; a full referrer; a URL query or hash; form content; or free text.
This measurement does not set or read cookies, LocalStorage, SessionStorage, or another persistent browser identifier. Login, sign-up, verification, account, administration, upload, moderation, legal, API, and PPAS Studio work areas are excluded. The client and collector do not record an event when Global Privacy Control or Do Not Track is enabled. These limits let Pipipong operate the aggregate measurement without an audience-analytics consent banner; where applicable law requires a different result, collection must remain disabled for that context.
Accepted events are combined directly into daily counts by host, public page family, and a fixed category. The analytics store does not retain a raw event stream, a complete browsing journey, or unique-visitor records, and the reports show approximate activity counts rather than counts of people. Necessary hosting and security infrastructure may still process the request information described in the first paragraph, but the analytics tables do not persist an IP address, raw user-agent, or full referrer.
The macOS installer can be downloaded without giving Pipipong a name, email address, or application form. Public Pet Community pages and published creator profiles can also be browsed without an account. Signing in, saving a favourite, downloading a pet package, reporting content, creating a hosted draft, submitting a pet, reviewing content, or changing an account creates the separate account and community records described below; those records are not linked to the anonymous website aggregates.
3. Verified community account and sessions
Community sign-in uses a one-time email code delivered by Clerk, Pipipong's authentication provider. Clerk verifies control of the address and supplies the verified primary email and, when available, a display name. Pipipong stores the normalised email, a one-way provider-subject digest, profile fields, locale, role, account state, notification preferences, legal-acceptance records, and security audit events. Pipipong does not receive or store the one-time code, an email-account password, or a Clerk session token in D1.
After sign-in, Pipipong creates its own opaque, revocable server session. Only token hashes are stored in D1; the browser receives a secure session cookie and a separate CSRF token. Session rotation, expiry, account state, verified-email state, role and ownership are checked on the server. Administrator and moderator tools are not unlocked by client-side UI state.
4. Desktop-client task data
Depending on the task and settings, the desktop client may process voice input, local transcripts, task descriptions, edited instructions, selected file names or contents, application context, execution plans, permission choices, confirmations, action logs, results, and errors.
Speech transcription is performed locally in the current build. Computer and fixed-project task execution currently requires a configured Codex executor. Content needed for that execution may be sent to the configured provider under its own terms; users should not assume every task is fully offline.
The release-pending v0.9.7 external-pet importer runs only after the user selects a local folder or ZIP, or explicitly asks the app to inspect the direct children of the local .petdex/pets and .codex/pets directories. It does not scan at startup, create a directory watcher, contact an online Petdex catalogue, upload the package, or modify the source. A compatible package is converted into a private Pipipong-managed copy that continues to work if the source is later removed.
The managed copy may retain local provenance needed for duplicate detection, updates, safety review, and licence display: a bounded source-format and source-confidence value, original ID, display name and description, explicitly declared author and licence information, package and normalised-asset digests, import time, adapter version, and the fact that the source was copied without automatic synchronisation. The app does not retain the absolute source path in that provenance record or expose it to the renderer.
5. Release-pending v0.9.7 updates and optional telemetry
The current public desktop release remains v0.9.6. Automatic updates, optional crash and reliability diagnostics, optional limited product analytics, and the one-time problem-report flow described in this section are release-pending v0.9.7 candidate capabilities, not enabled services in the current public build.
In the candidate, automatic update checks are separate from telemetry consent and are on by default. A check contacts a fixed HTTPS update feed with the technical request data needed to serve a compatible release; it does not include an analytics identifier, account identifier, task content, or tracking query. Users can turn off automatic checks and still check manually. The production feed and its access-log settings have not yet been publicly configured or verified.
Continuous crash and reliability diagnostics and limited product analytics remain two separate, optional choices. The candidate's first-run privacy prompt initially displays both choices selected, but that preselection is only a proposed choice and is not consent. Until the user explicitly saves the two choices with the confirmation action, persisted consent remains false for both choices, both anonymous identifiers remain null, their SDKs and external clients remain uninitialised, and no diagnostic or analytics network request may be sent. Choosing “Keep both off” saves false/false. If the user explicitly saves an enabled choice, the two systems use different random identifiers that are not linked to a community account or to each other. Turning a choice off stops its sending and removes its local identifier; users can also reset or copy the relevant identifier for a deletion request.
6. Candidate data limits and local retention
Automatic reliability data is limited to sanitised app and process health, app version, coarse operating-system and architecture fields, safe error codes, bounded stack information, result states, counts, and duration buckets. Optional product analytics uses a fixed 24-event schema: the existing 19 content-free product events plus five local external-pet import lifecycle events. Those five events use only fixed source/format/result enums, booleans, and count or duration buckets. They do not contain a pet name, slug, author, licence, path, URL, image, package manifest, description, or digest. Consent policy version 2 requires a renewed choice instead of treating an earlier analytics opt-in as permission for the expanded catalogue.
Automatic update, diagnostic, and analytics payloads must not contain voice recordings, transcripts, AI prompts, conversations or responses, commands, file contents, file or folder names, paths, clipboard data, screenshots or screen recordings, browser history, window titles, contact details, API keys, tokens, passwords, cookies, secrets, provider endpoints, or arbitrary interface text. A shared redaction and size-limiting pipeline rejects prohibited or unbounded fields before local support logs or outbound payloads are created.
The candidate limits local rolling sanitised diagnostic logs to the earlier of seven days or 20 MiB and keeps the product-analytics delivery queue only for the current app session. Users can clear local diagnostic data and export a previewed diagnostic package. Unsent problem-report drafts are not saved by default.
For reliability diagnostics that a user explicitly enables, the candidate is configured to send sanitised events to Sentry's EU region. Error events ingested during the current Business trial may be retained for up to 90 days. After the organization returns to the Developer plan, newly ingested error events use 30-day retention; the change does not shorten the expiry already assigned to trial-era events. A separately authorised one-time report event follows the applicable event retention, and a Sentry binary attachment is retained for up to 30 days.
For product analytics that a user explicitly enables, the candidate is configured to send only the fixed 24-event, content-free catalogue to PostHog EU Cloud. The current Free plan retains accepted events for up to one year. Pipipong has configured PostHog not to store client IP addresses, and the app disables GeoIP enrichment and person-profile processing. Autocapture, session replay, heatmaps, exception autocapture, feature flags, and account linkage are not used.
7. One-time problem reports
A user may choose to prepare one problem report even when continuous diagnostics are off. The app shows the exact user description, system summary, sanitised logs, update state, and selected attachments before the final send action. Sending authorises only that displayed report and does not enable continuous diagnostics or product analytics.
A contact email, description, screenshot, or other permitted attachment is included only when the user deliberately supplies or selects it. The app does not automatically attach a screen or microphone capture, transcript, AI content, command, file content, file name, full path, clipboard, browser content, provider endpoint, secret, window title, imported pet image, pet.json file, provenance record, or licence text. An external-pet file can be included only if the user selects it through the report attachment picker and confirms the final preview. If no reviewed production report transport is configured, sending remains unavailable and the user may export the sanitised diagnostic package locally instead.
8. Scope, permissions, and user control
Pipipong is designed to show the task scope and plan before acting, request only the permissions needed for the chosen action, and require confirmation for sensitive changes. Users can edit a transcript, decline a permission, cancel before confirmation, and review the resulting action record where the build supports it.
Users should avoid including unnecessary sensitive information in prompts, files, or pet packs and should keep independent backups of important work.
9. Third-party services and release-pending processors
Installer delivery, website hosting, community authentication, private object storage, forwarding of support mail, and a user-configured executor may be provided by third parties. Information required for a chosen function is processed under the relevant provider's terms and privacy rules. Pipipong does not claim support for an executor that is not listed on the current Status page.
The first-party anonymous website measurement is received by the Pipipong Cloudflare Worker and stored as daily aggregate counts in Cloudflare D1. Cloudflare may process the technical request information needed to provide, route, and protect that infrastructure under its own terms. Pipipong derives only a two-letter country code at the network edge for the analytics record and does not write the request IP address, raw user-agent, or full referrer to the analytics tables.
The release-pending v0.9.7 candidate uses separate configured EU destinations for optional telemetry: Sentry's EU region for reliability diagnostics and PostHog EU Cloud for limited product analytics. Sentry error-event retention is up to 90 days for events ingested during the current Business trial and 30 days for new events ingested after the Developer-plan downgrade. PostHog's current Free plan retains accepted product events for up to one year. The current public v0.9.6 build does not send desktop diagnostics or product analytics to either service.
Regional routing and storage do not mean every provider operation is confined to one country. Account administration, security, support, subprocessors, backups, or deletion handling may involve other locations as described in the providers' current terms, data-processing agreements, and subprocessor disclosures. The candidate remains release-gated until its exact public build, consent boundary, raw-event minimisation, revocation, deletion, and service receipts have been verified; an unverified update-feed or online-report path remains disabled.
10. PPAS Studio, private drafts, and package validation
Local PPAS Studio preview still reads, hashes, validates, previews, and prepares reports in browser memory. Selecting a file for local preview alone does not upload its bytes or persist them in LocalStorage, IndexedDB, or a service-worker cache.
When the current Status page and deployment gates show hosted drafts enabled, an authenticated creator may separately choose to upload a confirmed package. That package is stored under a non-public quarantine key, checked again for size, hash, archive paths, forbidden files, integrity, schemas, semantics, permissions, assets and deterministic conformance, and then retained privately for review. The current validator has no filesystem and no exposed network adapter; it runs in the same Cloudflare Worker deployment rather than a separately isolated service. Approved package objects remain private and are delivered only through short-lived, one-time account tickets.
11. Community activity, moderation, and notifications
Pipipong stores favourites, download-library entries, one-time ticket and download events, creator onboarding and agreement acceptance, draft and package metadata, frozen submission snapshots, review decisions, reports, moderation actions, appeals, account-status changes, in-app notifications, and append-only audit records needed to operate and secure the community. Public pet and creator pages expose only approved listing information, not private package keys, email addresses, internal notes, reporter identity, or raw audit metadata.
One-time account verification codes are sent by the authentication provider. Security, review, report, and service workflow notifications otherwise appear in the signed-in account when relevant. Marketing is a separate preference and is off by default. Support, privacy, and copyright addresses are monitored forwarding channels.
12. Retention, access, export, and deletion
Account settings provide a JSON export and an authenticated deletion request. A deletion request immediately revokes Pipipong community sessions and records the request for processing; it does not invent or promise a fixed completion period. Published content, abuse-prevention records, audit evidence, legal acceptances, backups, provider logs, and material subject to a safety or legal hold may require limited retention. The applicable period depends on the operational or legal reason and is not stated as a fixed number here.
Anonymous website aggregate rows are retained for up to 400 days and older rows are removed automatically. Because the analytics system creates no visitor record and cannot associate an aggregate count with a person, account, or device, there is no individual website-analytics profile to export or selectively delete. Global Privacy Control and Do Not Track prevent future collection by this system, as described above.
Turning off desktop diagnostics or product analytics stops future sending and removes that system's local anonymous identifier. Events already accepted by a provider are not necessarily erased at that moment: they remain subject to the Sentry 90-day/30-day ingestion-time lifecycle or PostHog's up-to-one-year lifecycle unless Pipipong completes the applicable provider deletion process; provider backups, security records, or legal holds may follow separate documented handling. To request access or deletion, copy only the relevant anonymous privacy identifier from the app and send it through the privacy contact. The two optional systems remain separate from each other, the community account, and the identifier-free website aggregates.
Depending on applicable law and context, a person may have rights to access, correct, delete, or export personal information, restrict or object to processing, or complain to a regulator. Unnecessary identity documents are not required. Use the same contact for other privacy requests, and do not send identity documents or other sensitive records unless Pipipong specifically requests them through a confirmed process.
Privacy contact
Privacy, access, or deletion requests: phzhertzpeng@gmail.com