Privacy Policy
What Pinily collects, why, who else sees it, and what you can do about it. Written for Swiss law — the Federal Act on Data Protection (FADP).
1. Who is responsible
Pinily decides why and how your personal data is processed, which makes it the controller under Article 5(j) FADP. The full legal identity and address are on the Legal Notice page.
To be completed Legal company name, legal form and registered Swiss address — see the Legal Notice.
For anything about your data, write to privacy@pinily.com. There is no legal requirement for Pinily to appoint a data protection advisor under Article 10 FADP, and none has been appointed. That email reaches a person, not a queue.
2. Who this covers
This policy covers the Pinily app on iOS and Android, and the pinily.com website. Pinily is built for people in Switzerland. It is not offered to people in the EU or EEA, so this policy is written around Swiss law and does not repeat rights the EU GDPR grants that Swiss law does not.
3. What Pinily collects
Almost everything here comes from you directly. Where it does not, the source is named.
Your account
- Email address. Required — it is how you sign in.
- Username. Required, and public.
- Display name, bio, profile photo. Optional.
- Date of birth and gender. Optional. Date of birth is used to check the minimum age and to let hosts set an age limit on an event.
- Country, canton and city. Optional. They decide which events the feed shows you.
- Interests, chosen from a fixed list of thirteen. There is no free-text field, so there is nothing here that can accidentally say more about you than you meant.
- Language and time zone, read from your phone so notifications arrive in a language you read.
- If you turn on two-factor authentication: a secret shared with your authenticator app, hashed recovery codes, and — only if you choose to give one — a recovery phone number. Pinily never sends SMS; the number is a fallback contact and nothing else. You can leave it blank.
How you sign in
You can sign in with a six-digit code emailed to you, or with Apple, Google or Facebook. Pinily has no passwords at all, so there is no password to store or leak. If you use a social sign-in, that provider tells Pinily your account identifier, your email address, and — if they have one — your name and picture. Pinily never receives your password for those accounts.
What you make and do
- Events you create: name, description, date and time, venue name and its coordinates, category, photo, price, capacity, what to bring, dress code, and any age limit.
- Events you join, ask to join, are invited to, vote on a date for, or claim an item for.
- Who you follow, who follows you, who your friends are, who you have blocked, and the groups you are in.
- Your availability, if you mark days free.
- Stories, event album photos, reviews you write and receive, poll votes, and the days you keep a streak.
- Your level and the activity that earned it.
Your messages
Direct messages, group chats and event chats are end-to-end encrypted. Pinily holds ciphertext and nothing else — not the words, not the photos, not the voice notes. The keys live on your devices. This is not a promise about how carefully the servers are guarded; it is a statement about what is on them.
What the servers do hold for those chats is the outside of the envelope: who sent a message, in which conversation, when, whether it was edited or deleted, and what type it was. That is what makes an inbox work, and it cannot be encrypted away.
Two deliberate exceptions. Event album photos are encrypted with a key shared among the event's participants, because the album has to be openable by everyone who was there. And if you report a message, the text of that one message is revealed to Pinily by you, along with a cryptographic proof that it really was sent — otherwise a report would be one person's word against another's with nothing behind it.
Money
- Pinily+ subscriptions: your Stripe customer and subscription identifiers, plan, status, and when the current period ends.
- Boost credits: what you bought, what it cost, and the Stripe payment reference.
- Event tickets: the ticket, the amount, the platform fee, the payment and attendance status, and the Stripe references. Refunds, disputes and payouts alongside them.
- If you host paid events: your Stripe Connect account identifier and whether Stripe has cleared you to take charges and receive payouts.
Card numbers never reach Pinily. Stripe's own component collects them on your device and sends them straight to Stripe. Pinily stores references, never payment credentials.
Your device
- A push token, so notifications can reach you, together with the platform (iOS or Android) and when the device was last seen.
- Public encryption keys for each device you sign in on. The private halves never leave the phone that made them.
- A device identifier Pinily generates itself and keeps in secure storage. It is not your phone's advertising ID — Pinily does not read or use advertising identifiers at all.
- App version, and crash and error reports when something goes wrong.
Location
When you let it, the app reads your position to show what is near you and to sort events by distance. That reading stays on your phone. It is not sent anywhere and not stored.
The one time location is recorded is when you scan a QR code to check in to a ticketed event. Then the coordinates, their accuracy, and how far you were from the venue are saved with the check-in, so a host can prove who actually turned up and Pinily can spot tickets being passed around. You can always be checked in by hand instead.
How you use the app
If you leave the analytics switch on, Pinily records which screens you open and a small set of named actions — a paywall shown, a plan picked, an event created or joined, a boost bought, a help article opened, a search that found nothing. Those events carry your Pinily user ID and nothing else about you: no username, no display name, no email. Turn the switch off in Settings → Privacy → Data & privacy and it stops, and the events already queued on your phone are thrown away rather than sent on the way out.
Security events
Signing in, turning two-factor on or off, changing your email or username, signing out everywhere, and deleting your account are each written to a log you can read in the app under Account & security → Security activity. IP addresses are not recorded there.
4. Why Pinily processes it
Swiss law does not ask a private company to name a "legal basis" for each purpose the way EU law does. Under Article 31 FADP, processing personal data of someone you have a contract with, in direct connection with that contract, is justified. Almost everything below is that: you asked for an events app, and this is an events app working. Where something rests on your consent instead, it says so.
| What for | What it uses |
|---|---|
| Letting you in and keeping the account yours | Email, sign-in provider, two-factor factors, recovery codes, security log |
| Showing you events worth going to | City and canton, interests, who you follow and are friends with, distance |
| Running an event | Attendance, invitations, join requests, date votes, bring lists, contributions |
| Delivering messages | Encrypted payloads, sender, conversation, timing, device keys |
| Taking payment and paying hosts | Stripe identifiers, amounts, fees, ticket and payout status |
| Notifying you | Push token, your per-category notification switches, quiet hours, language |
| Keeping people safe | Reports, blocks, revealed reported messages, fraud signals, check-in records |
| Meeting legal duties | Payment and accounting records |
| Improving the product (consent — you can switch it off) | Screen views and named product events tied to your user ID |
| Telling you about promoted events (consent — off unless you turn it on) | Your city |
Pinily does not use your data to build an advertising profile, does not sell personal data, and does not share it with data brokers. There is no advertising network in the app.
5. What other people can see
This is the part that matters most day to day, and it is under your control in Settings → Privacy.
- Your username, display name, photo and level are visible to people who can see your profile.
- Your profile is public by default. You can make it private, require approval before someone follows you, and hide your followers, your events, your past events, your interests and your reviews individually.
- A public event is visible to everyone, including on a shareable link that works without an account. A private event is visible only to people invited or holding the link.
- Turn off "discoverable" and you stop appearing in search. Turn off "show location" and your city stops being shown.
- Turn on incognito viewing and you can look at profiles without leaving a trace. That one is free — declining to leave a footprint should not cost anything.
- Blocking someone cuts the connection in both directions.
Two things are more public than they look. Profile photos, event photos and stories are served from public storage, which means anyone holding the exact link can open the file even if they could not open the app screen it came from. Do not put anything in a story you would mind a stranger seeing.
6. Who else processes your data
The complete list. Nothing is omitted, and there is no "and similar partners" clause hiding anything.
| Provider | What it does | What it gets | Where |
|---|---|---|---|
| Supabase | Database, sign-in, file storage, server functions | Everything in this policy except the contents of your chats, which it holds only as ciphertext | Stockholm, Sweden |
| Infomaniak | Sends the emails — sign-in codes, security notices, event mail | Your email address and the message | Switzerland |
| Google / Firebase | Push notifications, app-integrity checks, Google sign-in, Play billing | Push token, device attestation, and if you use Google sign-in, your Google account ID and email | United States and worldwide |
| Apple | Sign in with Apple, App Store purchases, Apple Pay | Your Apple identifier and purchase records | United States and worldwide |
| Stripe | Card, TWINT, PayPal, Apple Pay and Google Pay; paying hosts out | Email, payment method, amounts; for hosts, identity documents Stripe needs by law | Ireland and the United States |
| RevenueCat | Keeps track of whether your Pinily+ is active when you bought it in an app store | Your Pinily user ID and the purchase receipt | United States |
| PostHog | Product analytics — only if you leave the switch on | Your user ID, screen and event names, device and app details, IP address | European Union |
| Klipy | GIF, sticker and meme search in chats | What you typed, and a one-way hash of your user ID that cannot be turned back into it | To be confirmed — see below |
| Komoot (Photon) | Address and place search when you set an event location | What you typed, or coordinates for a reverse lookup | Germany |
| Open-Meteo | The weather forecast on an event | The event's coordinates and date — never a person's location | Germany |
To be completed Klipy's legal entity and country of processing are still being confirmed. Until they are, treat GIF search as leaving Switzerland.
Supabase, Infomaniak, RevenueCat, PostHog and Klipy act on Pinily's instructions (processors, Article 9 FADP). Stripe, Apple, Google, Komoot and Open-Meteo also decide things for themselves — Stripe because financial law obliges it to, the others because they run their own services.
7. Where your data goes
Pinily is Swiss and its users are in Switzerland, but the servers are not all here. Article 19(4) FADP says you get told where.
- The database, the files and the sign-in system are hosted in Stockholm, Sweden. Sweden is on Annex 1 of the Swiss Data Protection Ordinance as a country with adequate protection, so nothing further is needed for that.
- Emails are sent through a Swiss provider and do not leave the country on Pinily's side.
- Analytics are ingested in the European Union.
- Push, sign-in with Apple or Google, app-store billing and payments involve providers in the United States. Since 15 September 2024 the United States is on Annex 1 too, but only for companies certified under the Swiss–U.S. Data Privacy Framework. Stripe and Google are certified. For the others, transfers rest on the contractual safeguards in Article 16(2) FADP.
To be completed The transfer mechanism for Apple, RevenueCat, PostHog and Supabase is being confirmed with each provider.
8. How long things are kept
Article 6(4) FADP says data must be destroyed or anonymised once it is no longer needed. This table is what the system actually does today, not an intention.
| What | How long | What ends it |
|---|---|---|
| Your profile and everything hanging off it | Until you delete your account | You delete it — most rows go with it immediately |
| A deactivated account | Hidden but kept, indefinitely | You sign in again and it comes back, or you delete it |
| Stories | Removed from view after 24 hours (48 with Pinily+); the row and the file are deleted within the hour after that | Automatic hourly cleanup |
| Event chats and their media | Deleted after the event finishes — except a photo or voice note somebody reported, which is held while the report is open | Automatic cleanup every 15 minutes |
| Direct and group messages | Until you or the other person deletes them, or the account goes | You |
| Your local message history on this phone | Until you sign out and clear it, or uninstall | You |
| Encrypted chat backup | Until you turn it off or delete the account | You |
| Payment, ticket, refund and payout records | Kept after deletion, detached from your profile | Swiss accounting law — see below |
| Security log | Kept while the account exists | Account deletion |
| Reports and moderation records | Kept after they are handled so a pattern is still visible | Owner decision — no period is set yet |
| Check-in records with GPS | Kept with the event | Owner decision — no period is set yet |
| Analytics events | Held by PostHog under its own retention | Turning analytics off stops new ones |
Business records that show money moving have to be kept for ten years under Article 958f of the Swiss Code of Obligations. Those survive account deletion, but they are kept as accounting records and are no longer linked to a profile.
To be completed Retention periods for moderation records and check-in GPS still need to be set.
9. Your rights
Under the FADP you can do all of the following, free of charge, and Pinily has 30 days to answer (Article 25(7)).
| Right | Where it is | Article |
|---|---|---|
| Know what is held about you | Settings → Privacy → Data & privacy → Download your data, or ask by email | Art. 25 |
| Get a copy you can take elsewhere | The same download — it is JSON, and includes the readable messages held on this phone | Art. 28 |
| Correct something wrong | Edit profile, or ask by email | Art. 32(1) |
| Have data deleted | Settings → Account & security → Delete account, or ask by email | Art. 32(2) |
| Object to a particular use | privacy@pinily.com | Art. 30(2)(b) |
| Take back consent | The analytics switch and the promoted-events switch, any time | Art. 6(6) |
| Stop marketing | Settings → Notifications, or the unsubscribe link in any marketing email | Art. 3(1)(o) UCA |
The export is put together on the server, which reaches rows the app itself cannot read, and then the app adds the plaintext of the messages held on the phone you are using. That last part is bounded by what this particular phone has seen — which is the honest answer, and the same limit you live with. The alternative would be servers that can read your messages.
Pinily may have to check who you are before answering (Article 16(5) DPO). If Pinily refuses or delays, it will say why (Article 26(4) FADP).
If you are not satisfied, you can raise it with the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch. You can also go to a civil court under Article 32 FADP.
10. Deleting your account
Settings → Account & security → Delete account. It asks for your second factor first, because deletion is not something anyone should be able to do with a borrowed phone.
What goes
- Your profile, and everything that hangs off it — attendance, follows, friendships, availability, invitations, votes, levels, streaks, notifications, security log.
- Every file you uploaded, in every bucket: avatars, stories, event images, chat media, album photos, report screenshots and your encrypted chat backup.
- Your device keys, so nobody who signs in on that handset afterwards inherits an identity your contacts are still sending to.
- The sign-in record itself.
What stays
- Payment, ticket, refund and payout records, for the ten years Swiss accounting law requires.
- Messages you sent to other people. They are on their devices and in their history, and Pinily cannot reach into someone else's conversation any more than it could read it.
- Reports other people filed about you, so a pattern does not disappear by deleting an account.
- Anything already anonymised, which is no longer personal data.
Deletion is blocked if you are hosting a future event other people have already joined. Cancel or finish those first — this stops a host vanishing on the guests. If you only want a break, deactivate instead: your account disappears from view and comes straight back the next time you sign in.
11. Age
You must be at least 13 to use Pinily. If you are under 16, you need a parent or guardian to agree before you buy anything — Article 19 of the Swiss Civil Code says a minor needs their legal representative's consent to take on obligations.
Pinily does not verify age, and says so rather than implying a check that does not happen. If you believe a child under 13 has an account, write to privacy@pinily.com and it will be removed.
A host can set a minimum age on an event. That is the host's rule for their event, checked at the door by them, not by Pinily.
12. How your data is protected
Article 8 FADP requires measures appropriate to the risk. What is actually in place:
- Chats — direct, group and event — are end-to-end encrypted. The server cannot read them.
- The message history on your phone is stored in an encrypted database, with the key in the platform keychain or keystore.
- Every table in the database has row-level security switched on, so a query can only ever return rows the signed-in person is entitled to. Several tables are closed to clients entirely and reachable only through checked server functions.
- Sign-in tokens live in the platform keychain or keystore, not in ordinary app storage.
- There are no passwords, so there is no password database. Two-factor authentication with an authenticator app is available, and sensitive actions ask for it again.
- Everything travels over HTTPS. App Check attests that requests come from a genuine build.
- Private buckets for chat media, albums, backups, support attachments and report screenshots, each with its own access rule.
- Secret scanning on every commit and on every push, so a key cannot quietly reach the repository.
No system is perfect, and this policy will not claim otherwise. If a breach is likely to put you at high risk, Pinily notifies the Federal Data Protection and Information Commissioner as quickly as possible under Article 24 FADP, and tells you where that is needed to protect you.
If you have found a security problem, please write to privacy@pinily.com before publishing it.
13. Automated decisions
Pinily contains no artificial intelligence. No large language model, no machine learning, nothing that generates text or makes a judgement about you. The in-app help assistant is a decision tree somebody wrote by hand.
Some things are automatic: which events the feed puts in front of you, when a reminder fires, and a set of fraud checks that look for patterns like the same device checking in as several different people. None of them decides anything about you on their own. A fraud check raises a flag for a person to look at; a person decides. That means Article 21 FADP, which covers decisions taken by machine alone, is not engaged.
One thing does happen without a person: if a card holder disputes a ticket payment with their bank, the payout for that event is held until it is resolved. That is Stripe and Pinily performing the payment contract, and you will see it in the app when it happens.
14. Notifications and marketing
Three different things, treated differently.
- Service and security messages — your sign-in code, a security alert, a ticket confirmation, a refund. These are part of the service and cannot be switched off while you have an account.
- Activity notifications — someone invited you, the chat has a new message, an event you joined was cancelled. Every one of these has its own switch in Settings → Notifications, plus quiet hours.
- Marketing — promoted events somebody paid to put in front of you, and any promotional email. Under Article 3(1)(o) of the Swiss Unfair Competition Act these need your consent first, so they are off until you turn them on. Every marketing message names Pinily as the sender and carries a free way to refuse.
16. Changes
When this policy changes in a way that matters, you will be told in the app before it takes effect, and the version you accepted is recorded against your account. The date at the top of this page always says when it last changed.
17. Contact
privacy@pinily.com for anything about your data. contact@pinily.com for everything else. Postal address on the Legal Notice page.