← Pipit

Privacy Policy

Last updated: [DATE] · Data controller: Samarkand Industries OÜ ([address])

Pipit is privacy-first. Sealed messages are end-to-end encrypted — we only ever hold ciphertext for those, and the keys never leave your devices. This policy explains the limited data we do process to run the service.

What we collect and why

DataWhyLegal basis (GDPR)
Waitlist emailTo tell you when Pipit opensConsent
Account identity: your @pipit.email handle + password hash (or OAuth identity)To create and secure your accountContract
Connected mailbox tokens (encrypted at rest)To show your existing mail in PipitContract
Payment detailsSubscriptions, handled by Stripe — we never see full card dataContract
Hosted mail: message ciphertext + minimal envelope metadata (from / subject / date)To deliver mail to your @pipit.email addressContract
Anonymous, no-PII product analytics (respects Do-Not-Track; opt-out in Settings)To improve PipitLegitimate interest

What we cannot read

Sealed message bodies and attachments are end-to-end encrypted with keys held only on your devices. The server stores ciphertext and cannot decrypt it.

Honest limits (the bridge)

For a hosted @pipit.email address, mail from the outside world passes through our email provider (Mailgun) in the clear on the way in — the instant before it is sealed to your key — and, if you have not yet set up a device key, is held in a form our server can read until your first sign-in, then re-sealed to you and the readable copy deleted. These windows are inherent to bridging ordinary email and are disclosed here plainly.

Sub-processors

We use: Cloudflare (hosting, storage), Mailgun (hosted-mail send/receive), Stripe (payments), Vercel (web hosting), and our database provider. Each processes only what its function requires.

Retention

Account data for the life of your account; waitlist emails until launch or opt-out; hosted mail per your plan's storage terms. [Specify concrete periods.]

Your rights

Access, correction, deletion, export, and objection. Contact privacy@pipit.email. You may also complain to your local data-protection authority.