Privacy Policy
Last updated
This policy covers the website, your account and payments. It is separate from the per-product pages in the documentation, which describe what each application stores on your own machine — those are technical notes, this is the policy.
Who we are: Pioneering, New Zealand. Contact: hello@pioneering.app.
The short version#
- The applications check your subscription and nothing else. That request carries a salted device hash,
macosorwindows, and the app version. No telemetry, no analytics, no usage counters, no record of what you did. - The one thing an application can send besides that check is a crash report, and only when you press Send. There is no background uploader: Perch shows you the exact text first, sends a summary rather than the crash file, and sends nothing if you do not choose to. What is in it.
- That check is cached with a week of grace, so being offline is never treated as not being allowed.
- The website and account system collect the minimum needed to sell you a subscription and let you sign in: an email address, a password hash, and identifiers from our payment processor.
- We do not sell anything to anyone, and there is no advertising.
What we collect, and why#
| What | Why | Where it comes from |
|---|---|---|
| Email address | To identify your account and send receipts | Your payment, via Stripe |
| Password hash | To let you sign in | Set by you, never stored as a password |
| Stripe customer and subscription id | To know what you have paid for | Stripe |
| Plan and billing period | To decide what your account can download | Our own records |
| A salted hash of a device identifier | To stop one subscription being shared across unlimited machines | Your computer |
| Platform and app version | To answer "is this build still supported" | Your computer |
| IP address, temporarily | To rate-limit sign-in and password reset | Your request |
| A short account log | To answer "why did I lose access" | Our own records |
What we deliberately do not collect#
- Payment card details. These are entered on our payment processor's own systems and never reach ours. We can see the last four digits and the card brand; we cannot see the number.
- Raw device identifiers. Your machine's identifier is salted and hashed before it leaves your computer. We store the hash. We cannot reverse it into a device.
- Anything you do in the applications. Which files you opened, which windows you shared, what you typed. The subscription check carries a device hash, a platform and a version number, and there is nowhere in that request for any of the rest.
Cookies and local storage#
The site sets no tracking cookies and uses no analytics.
Two things are stored in your browser, locally, and never transmitted:
- your light/dark theme choice;
- the email address you typed at checkout, so a return trip does not ask twice.
Both are cleared when you clear site data.
How long we keep it#
| Data | Kept |
|---|---|
| Account and email | Until you ask us to delete it |
| Password reset and activation tokens | 1 hour and 24 hours, then discarded |
| Sign-in sessions | 90 days, refreshed as used |
| IP rate-limit records | 24 hours |
| Account log | 24 months |
| Payment records | 7 years, because tax law requires it |
Payment records are the one thing we cannot delete on request — the retention period is a legal obligation, not a choice.
Who else sees it#
Two processors, both because the service cannot work without them:
- Stripe — payments. They receive your email and card details. Their privacy policy governs what they do with them.
- Resend — transactional email. They receive your email address and the contents of the messages we send you.
Neither is permitted to use your data for their own purposes. We use no advertising networks, no analytics providers and no data brokers.
Data is stored on Cloudflare infrastructure, with the account database located in Oceania.
Your rights#
Under the New Zealand Privacy Act 2020 you can ask us to:
- tell you what we hold about you;
- correct anything that is wrong;
- delete your account and personal data, subject to the payment-record retention above;
- export your data in a readable format.
Email hello@pioneering.app. We will respond within 20 working days, which is the statutory limit.
If you are in the UK or EU, the equivalent rights under UK/EU GDPR apply and the same address reaches us.
If you are unhappy with our response, you can complain to the New Zealand Office of the Privacy Commissioner.
Breach notification#
If we discover a breach likely to cause you serious harm, we will notify you and the Privacy Commissioner as required by the Privacy Act. We will tell you what happened, what was exposed, and what to do about it — in that order, and without waiting until we have a complete picture.
Changes#
If this policy changes materially, the change appears here with a new date, and account holders are emailed. A privacy claim is only worth something if it is specific enough to be caught being wrong, so we would rather notify you than quietly edit.