English

Privacy Policy

Effective 2026-09-09 (first published 2026-08-12)

1. What we collect and how

Account — the account identifier and display name your sign-in provider (Google or Apple) passes to us. We do not receive your email address, phone number or date of birth.
Device — push token, platform (Android/iOS), app version, device language, installation identifier, last-seen time. The app registers these with our server so it can receive notifications.
Usage records — poke records (sender, receiver, effect, time, tap count), connections and invites, notification settings (quiet hours and time zone), blocks and reports (reason category), and service usage events (event name plus minimal properties). These are generated automatically as you use the service.

2. What we do not collect

No location, contacts, photos or message content — Pictie has nowhere to type text. No advertising identifiers, no third-party tracking SDKs, no external analytics services.

3. Purposes and legal basis

Providing the service (delivering pokes, keeping connections, notifications) — performance of our contract with you.
Safety (block, report, sending limits, abuse prevention) — performance of the contract and our legitimate interest in protecting users.
Improving the service — our legitimate interest in producing statistics that identify no one.
We never sell personal data and never use it for marketing.

4. Retention

Account, device and connection data — until you delete your account. On deletion your display name is anonymized immediately, the sign-in link is deleted, every session is revoked, push tokens are removed from your devices, and all connections are disconnected.
Sign-in sessions — expire after 30 days; logging out revokes them at once.
Individual poke records — deleted automatically after 90 days; only monthly counts that identify no one remain.
Per-connection poke history (effect, direction and time only — no user identifiers) — kept while the connection lasts, deleted 90 days after it is disconnected or an account is deleted.
Usage events — aggregated and deleted after 90 days.
Reports and blocks — kept after account deletion to prevent abuse.

5. Processors and international transfers

We entrust processing to the providers below. All of them are in the United States, so your data is transferred abroad, over the internet (TLS-encrypted), each time the service is used.
Cloudflare, Inc. (US) — runs our server and stores the database. Everything in section 1, for the periods in section 4.
Google LLC (US) — Android push delivery (Firebase Cloud Messaging) and Google sign-in verification. Push token, poke identifier, effect identifier; held for as long as delivery requires.
Apple Inc. (US) — iOS push delivery (APNs) and Apple sign-in verification. Push token, poke identifier, effect identifier; held for as long as delivery requires.
You may object to these transfers by writing to us. Because the service cannot run without them, we would then help you delete your account.

6. Disposal

Data is disposed of without delay when its retention period ends or its purpose is fulfilled. Electronic records are deleted irreversibly; the automatic deletions in section 4 run daily. Aggregate statistics retain nothing that identifies a person.

7. Your rights and how to exercise them

You can request access, correction, deletion or suspension of processing at any time. Your display name can be changed in the app's settings, and your account and data can be deleted there (Settings → Delete account & data). For anything else, write to the address below; after verifying your identity we act without delay and within 10 days. The legal guardian of a child under 14 may exercise the same rights.

8. Safeguards

Sign-in and invite tokens are stored only as hashes, and push tokens are never written to logs. All traffic is encrypted with HTTPS. We collect the minimum needed, restrict database access to the operator, and keep personal data and tokens out of operational logs.

9. Children under 14

Pictie is for people aged 14 and over. We do not collect dates of birth and so do not verify age automatically; if we learn that a child under 14 has signed up, we delete the account and its data immediately.

10. Cookies and automatic collection

The pictie.app web pages set no cookies; the language comes only from the lang value in the address. The app automatically sends its version, platform and device language to our server so that notifications are delivered and stay compatible.

11. Data protection officer and remedies

Data protection officer: the Pictie representative · hello@pictie.app
Send privacy questions, complaints and requests for remedy to that address. In Korea you can also contact the Personal Information Infringement Report Center (privacy.kisa.or.kr · 118) or the Personal Information Dispute Mediation Committee (kopico.go.kr · 1833-6972).

12. Additional notice for users in the EU/EEA

The controller is Pictie, located in the Republic of Korea. The legal bases are GDPR Art. 6(1)(b), performance of a contract (providing the service), and Art. 6(1)(f), legitimate interests (safety, aggregate statistics). You may exercise your rights of access, rectification, erasure, restriction, portability and objection by writing to us, and you have the right to lodge a complaint with the supervisory authority in your country. The transfers in section 5 are transfers from Korea to the United States.

13. Changes to this policy

Changes are posted on this page. For material changes — what we collect, why, for how long, or whom we entrust it to — we give notice in the app or on this page 7 days before they take effect.

Questions? Write to hello@pictie.app.