Privacy at Pinamily

Privacy Policy

This policy explains what information Pinamily processes, why it is needed, and the controls available to you when you use the app and this website.

Last updated September 16, 2026

Introduction

Pinamily is a family organizer that brings household calendars, lists, chores, recipes, meal plans, birthdays, and support into one shared service. This policy applies to the Pinamily mobile app, related services, and pinamily.app.

The public website is a static site. It has no account area, contact form, advertising, analytics, tracking pixels, or non-essential cookies, and it does not collect family content.

Information You Provide

When you create and use an account, Pinamily processes information such as your name, email address, email-verification status, password credential, account status, and the settings or actions associated with your account. Passwords are stored as password hashes, not as readable passwords.

You may also provide household names, invitations and memberships, and the content needed for features you choose to use, including shared calendar entries, lists and list items, chores, recipes, birthdays, and meal-plan entries. Support requests include the subject, message, category, and replies that you submit.

Information Collected Automatically

Pinamily processes limited technical and operational information needed to authenticate requests, maintain sessions, synchronize data, protect the service, diagnose failures, and operate product features. This can include timestamps, session lifecycle information, IP address and user-agent information associated with authentication sessions, app version, platform, operating-system version, locale, time zone, request or correlation identifiers, and service health or error signals.

The app also maintains local data needed for offline use and synchronization. Information held only on your device is subject to your device controls and may be cleared when you sign out or after account deletion is confirmed.

Family and Household Data

Household features are cloud-connected. Pinamily stores the account, membership, invitation, entitlement, and shared feature data needed to synchronize the service across household members and their devices.

People in the same Household can see and work with shared Household content according to their role and the product rules. Invite only people you intend to share that space with. Pinamily does not use family content to target advertising.

Calendar Data

The Pinamily shared calendar stores the event details, timing, recurrence, reminder settings, and change information needed to provide and synchronize calendar features for a Household. Calendar reminders are delivered as local device notifications; remote consumer push is not active in the current release architecture.

External Device Calendars

External calendar integration is optional and read-only. If you enable it, Pinamily reads events from calendars you select on the device and displays them as a local overlay. External event content is not imported into the Pinamily Household calendar, sent to the Pinamily backend, or persisted there.

Pinamily does not connect to Google Calendar or Microsoft Calendar through cloud OAuth and does not write to device calendars. On iOS, the operating system may describe the required permission as Full Calendar Access even though Pinamily uses that access only for this read-only view. On Android, Pinamily requests calendar read access, not calendar write access.

Notifications

Calendar and birthday reminders are scheduled locally on your device when you enable them and grant notification permission. Birthday reminder preferences are device-local. Disabling permission, changing the relevant setting, signing out, or removing app data can affect scheduled reminders.

Invitations and certain account, recovery, support, or operational messages may be sent by email. Remote APNs or FCM consumer push notifications are not active in the MVP.

Subscriptions and Billing

Purchases are completed through the Apple App Store or Google Play. The Store handles your payment method. Pinamily does not receive your full payment-card details.

To provide and maintain subscription access, the Pinamily backend receives and verifies the Store transaction or subscription evidence needed for entitlement status, renewal, expiration, cancellation, restore, and reconciliation. Sensitive Store evidence is excluded from product analytics and is not exposed through ordinary client responses.

Advertising

The Free plan may show Google AdMob adaptive banner ads only on Home and the Lists hub. Gold does not show ads. Pinamily requests non-personalized ads only, does not use family content for ad targeting, does not request Apple App Tracking Transparency permission, and does not use advertising for cross-app tracking by Pinamily.

The AdMob SDK may process limited device, network, consent, and advertising-delivery information needed to request, display, protect, and measure a non-personalized ad. Where applicable, Google User Messaging Platform provides the privacy or consent flow. If the required consent, market, entitlement, provider, or configuration state is not ready, Pinamily does not request an ad.

Analytics

Pinamily uses first-party product and operational analytics. Events use an allow-listed name and limited metadata, with a pseudonymous actor identifier derived for analytics. Pinamily analytics do not include family message or content payloads, email addresses, raw user or household identifiers, support-message text, or Store purchase evidence.

Raw analytics event records are retained for 90 days and then removed. Aggregated operational or product reporting may remain where maintained by the current architecture, without the underlying family content or raw pseudonymous actor event history. No third-party analytics provider is active.

Support and Diagnostics

When you contact support, Pinamily stores your ticket, its status, messages and replies, and limited operational diagnostics. Diagnostics use an allow-list of technical fields such as app and operating-system versions, locale and time zone, capability state, sync health, notification or secure-storage state, billing state, and request identifiers. Family content is not attached automatically.

The MVP does not accept support attachments. Internal support notes are visible only to administrators, not in My Requests. Email notifications about a support update do not include the support-message body.

Data Export

From More > Privacy and data, you can request an export of personal account data. Exports can include account profile information, Household memberships and roles, privacy-request history, your user-visible support requests and messages, safe diagnostics, and in-app inbox records.

Household-owned content such as shared calendars, lists, chores, recipes, birthdays, and meal plans is not part of a personal account export. The export is a private ZIP containing JSON files. Its download link is signed for 15 minutes, and the export artifact is retained for 7 days before deletion. You can generate a fresh signed link while the artifact remains available.

Account Deletion

Account deletion is requested in More > Privacy and data and requires fresh authentication and explicit confirmation. It is processed by the service as a lifecycle request, so the app may show Pending or Processing before completion rather than reporting instant deletion.

A Member can delete their account and leave the Household while shared Household content remains. An Owner of a Household with other members must first transfer ownership to an existing Member of that Household. A sole Owner and sole member must explicitly choose Delete account and family, which also removes the Household and its shared content. Sessions are revoked during processing, and local app data is cleared after the server confirms completion.

Some sanitized security, operational, or audit records and de-identified technical links may remain where needed to protect the service, preserve system integrity, or meet applicable requirements. See the separate Delete Account page for step-by-step instructions.

Data Retention

Pinamily does not apply one universal retention period to every record. Account and Household information is generally kept while needed to provide the service and then handled through the relevant membership, Household, deletion, security, and operational lifecycle.

Specific current periods are: 90 days for raw first-party analytics events and 7 days for completed privacy-export artifacts. Authentication, billing, support, security, audit, and operational records may be retained for the time needed for their purpose, service integrity, dispute handling, fraud prevention, or applicable legal requirements. Pinamily minimizes or sanitizes retained references where the deletion lifecycle requires it.

Service Providers

Pinamily uses or is designed to use a limited set of providers for release functions. Availability and configuration can vary by platform, market, and environment:

  • Apple: App Store purchasing, subscription administration, and Store transaction verification for iOS.
  • Google: Google Play purchasing and subscription administration for Android; Google AdMob and User Messaging Platform for eligible Free-plan banner ads and related privacy choices.
  • Mailgun: delivery of verification, account and recovery, invitation, support, and operational email.
  • Cloudflare R2: private object storage for completed privacy-export artifacts.

Pinamily does not list an observability vendor because no concrete third-party analytics or OTLP vendor is selected. This policy also does not name a hosting or database vendor that has not been ratified for release.

Security

Pinamily uses technical and organizational safeguards appropriate to the service, including authenticated and role-authorized access, verified sessions, hashed passwords, protected device credential storage, data minimization, private export storage, short-lived export links, and controls intended to keep secrets and sensitive evidence out of logs and analytics.

No online service can guarantee absolute security. Keep your credentials private, use your device security controls, and report suspected unauthorized access through Help and support.

International Use

Pinamily is designed for use in multiple markets. When you use the service, information may be processed in locations where Pinamily operations or the providers described above handle the relevant function. Privacy rights and provider disclosures can vary by location, and market-specific consent controls are applied where the product is configured to require them.

Children and Family Use

Pinamily is a family organizer, but the current account model does not include child accounts or parent-managed child profiles. Each account is an individual account with its own authentication, and the account holder is responsible for the account, the people they invite, and the information they choose to share in a Household.

Account holders should use Pinamily in a way that is appropriate for their family and consistent with applicable requirements. This policy does not state a minimum account age or represent that Pinamily offers managed accounts for children.

Your Choices and Rights

You can choose what Household content to add, who to invite, whether to enable external device calendars, which calendars to display, and whether to allow local notifications. Store controls let you manage subscriptions. Eligible advertising flows provide the privacy choices required for the relevant market.

The app provides personal data export, account deletion, active-session controls, and support. Depending on where you live, applicable law may also give you rights concerning access, correction, deletion, restriction, objection, or portability. Use More > Help and support to make a privacy request or ask about the rights available to you.

Changes to This Policy

This policy may be updated as Pinamily changes or as legal and operational requirements evolve. The updated version will be posted at this URL with a revised date, and additional notice may be provided in the app when appropriate.

Contact

For privacy questions or requests, open Pinamily and go to More > Help and support.