Privacy Policy
Last updated: February 2026
1. Information We Collect
Account information: When you create an account, we collect your username and email address. If you register with a password, it is stored as a one-way hash — we never store it in plain text. If you sign in with Google, we receive your Google account ID, name, email, and profile picture.
Message information: When visitors send you a paid message, we collect their name, email address, and message content. Messages are encrypted at rest using AES-256-GCM and can only be decrypted by our application when displayed to the intended recipient.
2. How We Use Your Information
- To create and manage your Pingry account
- To display your public profile page
- To process payments through Flutterwave and the Bitcoin Lightning Network (via Blink)
- To deliver paid messages to your dashboard
- To process withdrawal requests via bank transfer or Lightning
- To send transactional emails (welcome messages, payment notifications, withdrawal updates)
3. Payment Processing
Flutterwave: Card payments, bank transfers, and mobile money are processed by Flutterwave. We do not store credit card numbers, bank account details, or any sensitive financial information. See Flutterwave's Privacy Policy.
Bitcoin Lightning: Lightning payments are processed via Blink. We store the payment hash and invoice for transaction verification. Lightning transactions are pseudonymous by nature.
4. Data Sharing
We do not sell, rent, or trade your personal information. We share data only with:
- Flutterwave — to process fiat payments and bank payouts
- Blink — to process Bitcoin Lightning payments and payouts
- Google — only if you choose to sign in with Google (OAuth authentication)
- Resend — to deliver transactional emails (your email address only)
- Message recipients — sender name, email, and message content are shared with the profile owner
5. Data Security
We use industry-standard security measures including:
- Encrypted connections (HTTPS / TLS)
- AES-256-GCM encryption for message content at rest
- One-way hashed passwords (bcrypt)
- CSRF protection on all forms
- Rate limiting to prevent abuse
- Row-level database locking to prevent double-crediting
6. Cookies and Local Storage
We use session cookies to keep you logged in and OAuth state cookies for Google sign-in. We also use browser local storage to remember your dark mode preference. These are essential for the service to function and are not used for tracking or advertising.
7. Transactional Emails
We send emails for important account events: welcome messages, payment receipts, and withdrawal status updates. These are delivered via Resend. We do not send marketing or promotional emails.
8. Your Rights
You can update your profile information at any time from your Settings page. To request account deletion or a copy of your data, contact us at the address below.
9. Contact
If you have questions about this policy, reach out to us at privacy@pingry.me.