Pigeoneer privacy policy
Last updated: 17 September 2026
This policy covers two groups of people:
- Visitors to pigeoneer.app, including anyone who uses the early access form.
- Clients, meaning game studios who are given access to the Pigeoneer app, and the people at those studios who use it. Where this policy says "your studio" or "a client" it means the same thing. The word is used more broadly here than in the Terms of Service, which use it for one named counterparty.
Creators and journalists are covered by a separate notice: pigeoneer.app/creators. A studio emails them from its own mailbox using Pigeoneer; we provide the contact database and process the campaign on the studio's behalf. If you are a creator or a journalist and you want your data removed, that notice is the right place to start, and [email protected] works too.
Who we are
Pigeoneer is operated by Pigeoneer LLC, a limited liability company registered in California, United States. Write to us at [email protected]; we will give you our registered postal address and our agent for service if you ask. That company is the data controller for the processing described in this policy, except where this policy says we act as a processor for a client.
Privacy contact, and the only address you need for anything on this page including opting out: [email protected].
Representatives. We are appointing a representative in the European Union under Article 27 GDPR and one in the United Kingdom under Article 27 UK GDPR, and we will name them here as soon as they are in place. Until then, exercise any right directly with us at [email protected]. We have not appointed a data protection officer, and our current view is that we are not required to; we will say so here if that changes.
The terms every studio agrees to are shown in the app during onboarding and accepted there; they are not published on this website.
What the website loads
- No analytics. There is no Google Analytics, no tag manager, no Plausible, no pixel, no telemetry of any kind on pigeoneer.app.
- No advertising or tracking cookies. Our own site code sets no cookies at all.
- One browser storage item. If you switch the site between light and dark, we save the single value
themein your browser's local storage so the page does not flash on your next visit. It is not an identifier and it never leaves your browser. - One third party script. The early access form is protected by Cloudflare Turnstile, an anti bot check. Its script loads from challenges.cloudflare.com on the home page, in both languages, and it can set its own cookies or storage in that context. It loads when the page loads, before you interact with the form.
That is the whole list.
What the early access form collects
If you submit the form, we receive and store:
| Field | Where it comes from |
|---|---|
| Your email address | You type it |
| Your description of your game | You type it, 40 to 2000 characters |
| Timestamp of submission | Generated on submission |
| Your browser's User Agent string, first 256 characters | Sent automatically by your browser |
| The page language you submitted from, EN or ES | Derived from the page |
| A flag recording whether we have emailed you back | Set by us |
There is also a hidden "leave this field empty" field. It is a spam trap. If it is filled in, the submission is dropped and nothing is stored. A submission that fails the Cloudflare bot check is rejected before anything is written. Everything else is stored.
Your IP address is sent to Cloudflare Turnstile as part of the bot check, together with the challenge response. We do not store your IP address in our own record.
Where it goes:
- The record is written to Cloudflare Workers KV, our hosting provider's storage.
- If the submission looks genuine, a notification email is sent through Resend to our own inbox, containing your email address, the timestamp, the page language and the full text you wrote. Your address is set as the reply address so we can answer you.
Legal basis. Legitimate interests, Article 6(1)(f), specifically responding to an enquiry you sent us and defending the form against automated abuse. If we later add you to any mailing list, we will ask first.
Retention. We delete a signup record, and the notification email that carried it, within 30 days of your request, and in any event we do not keep them more than 24 months after the last contact with you.
Access. The stored signups can be read by the founder through a token protected admin endpoint. Nobody else has that token.
Server logs
We do not run our own web server and we do not keep our own access logs. Cloudflare, as our hosting provider, processes connection data including your IP address in order to serve the page and to protect it, under its own retention settings.
This part applies once your studio is given access to the Pigeoneer app.
Account records, where we are the controller
For running your account and the business relationship, we hold as controller:
- Your login identity, an email address, authenticated through Cloudflare Access, and the legal name, establishment country and registered address of your studio.
- Support correspondence with us.
- The record of what you accepted: the Terms of Service, the Data Processing Agreement where it applies, and each campaign order, with who accepted it and when. We keep those for as long as a claim under the agreement could be brought.
- Usage and cost records: which model was called for which operation, token counts and cost, tied to project and, today, to creator handle. That ledger is our own business record, held under Article 6(1)(f) for as long as we operate the platform; we remove the creator handle from it when your account closes.
Legal basis: performance of our agreement with you, Article 6(1)(b), where you are an individual; where the client is a company, the personal data is that of the people who act for it, and the basis is our legitimate interest in administering the contract and in establishing or defending a claim under it, Article 6(1)(f). Running, securing and improving the service is also Article 6(1)(f).
Your onboarding intake answers (game title, studio name, localisation, platforms and storefronts, target creator languages, campaign goal and headline, your name and role, the writing samples the tool learns your voice from, your timezone, your key access model and budget stance) belong to your project, and for them we are your processor under the next sections and the Data Processing Agreement, not the controller.
Mailbox credentials
What we hold. To send your campaign from your own address and to read the replies, Pigeoneer stores your SMTP host and port, your IMAP host and port, your mailbox username, the sender display name, and the mailbox password itself.
How it is stored. The mailbox password is encrypted at rest, using Windows DPAPI, on the machine that runs your campaign. That machine is under our physical control in California and is not a shared or public cloud server. Our off-site backups are themselves encrypted and exclude mailbox passwords entirely, so a copy of a backup carries no credential of yours at all.
Scope of access. The credentials give Pigeoneer the ability to send mail as your address and to read incoming mail in that mailbox, which is what the product does: it sends your pitches and follow-ups, reads incoming mail to find replies to your campaign and draft answers, and notifies you from your own mailbox when a contact opts out. An incoming message it cannot match to your campaign is held for you to look at and is not answered; if you have not acted on it within 30 days we delete our copy, and it stays in your mailbox. The app never displays the password back through its interface, and it is deliberately blanked in the settings screen after saving. You can revoke our access at any moment by changing the mailbox password, which locks the tool out of both sending and reading immediately; that does not close your account or stop coverage tracking.
Our advice. Use a dedicated press or outreach mailbox, not a personal or an admin one, and not one that shares a password with anything else.
Project data, mailbox contents and reply correspondence, where we are a processor
For your intake answers and campaign configuration, the contents of your mailbox, the pitches sent under your name, the replies creators send you, the drafts, the activity logs of your campaign, the summaries of coverage of your game, and the creator records tied to your specific project, we act as your processor. You are the controller. We process that material on your documented instructions, in order to run your campaign.
The detail of that relationship, including security, subprocessors, assistance with data subject requests, breach notification and deletion when your account closes, is in the Data Processing Agreement that forms part of your contract with us. Where this policy and that agreement disagree about that material, the agreement governs.
Practically, verbatim reply text from your campaign is stored in several places, all of them inside your project's records: a short snippet on the per-project creator state, the full inbound body on the hold record and its classification, your project's daily activity log, and the draft files on disk that carry the creator's real email address. None of it is on the shared creator record.
The creator pool, where we are an independent controller
Pigeoneer maintains its own database of publicly discoverable creators and journalists, built from YouTube, Twitch and other public sources. That pool is reused across clients, and for it Pigeoneer is an independent controller, not your processor. You do not own it, it does not leave with you, and we answer to the creators in it directly. The notice we give those people is at pigeoneer.app/creators.
A creator who replies "stop" to your campaign is out of your project: the system records that without waiting on a person, no later import or re-scoring clears it, and we do not lift it at your request. Recognition of an opt-out written in someone's own words is automated and can miss an unusual phrasing; if you see one the system did not catch, forward it to us and we record it. The scope follows what the creator asked for, not which mailbox it arrived in: naming your game takes them out of every campaign for that game from any studio, naming your studio out of every campaign of yours, and asking for no contact through Pigeoneer or no marketing at all out of every client including yours and out of every other marketing use of their record, including scoring and being shown to a studio. Unclear wording is read the wider way. The single-project stop is applied by the software; the three wider scopes are applied by a person and kept on a written list we check before every import, scoring pass and send. Both routes are offered to them at pigeoneer.app/creators.
Where the line between the two roles falls: reply text and everything derived from it live only in your project's records. The shared creator record holds public profile data, the research notes and scores we generate, and the minimum record of any opt-out.
Coverage tracking and campaign reporting
Separately from the outreach, Pigeoneer looks for videos and streams published about your game and turns them into something you can read.
What we process. For a piece of coverage about your game we take the public information the platform provides, including its title, publication date, view count and comment count, and a transcript of it. We use the transcript to produce a written summary: how the piece received the game, and the moments in it worth your attention.
When it runs. Your terms limit it to the weeks of tracking in your campaign order, starting when you get access to your project, and what we found stays in your account afterwards. The software does not yet stop discovery at the end of that window: today it runs for as long as your project is active.
What you see. Coverage reports contain summaries, not transcripts. Transcripts are not available through the product, and your terms forbid attempting to reconstruct or extract them.
Who this covers. This runs against coverage of your game, whoever published it. That includes people you never approached and who published entirely on their own, because we are looking for coverage of the game rather than coverage by particular people. We process it for you, as your processor; those people are told about it at pigeoneer.app/creators.
Attribution. We also report which of the contacts you approached went on to publish. That is a correlation and not proof that your message caused a publication, and your terms say so. A summary that does not mention a free key is likewise not evidence that anything was withheld from an audience.
What you may not do with it. Your terms restrict these outputs to running and judging your campaign and improving your game. They may not be republished or redistributed, used to harass, coerce or retaliate against anyone or to condition keys or access on favourable coverage, or fed into unrelated profiling, model training or dataset building.
Lawful bases at a glance
| What we process | Role | Lawful basis |
|---|---|---|
| Early access form submissions | Controller | Art. 6(1)(f), answering your enquiry and blocking abuse |
| Your account and login, and the record of what you accepted | Controller | Art. 6(1)(b), our agreement with you; Art. 6(1)(f) for the people who act for a company client |
| Intake answers, project and game details, mailbox credentials | Processor | Your basis as controller, recorded in the Data Processing Agreement |
| Mailbox contents, replies, campaign records and activity logs | Processor | Your basis as controller, recorded in the Data Processing Agreement |
| Usage and cost records (the model-call ledger) | Controller | Art. 6(1)(f), running, costing and securing the service |
| Creator pool and profiling of creators | Independent controller | Art. 6(1)(f), see pigeoneer.app/creators |
| Coverage summaries and attribution reports for your campaign, whoever published the coverage | Processor | Your basis as controller, recorded in the Data Processing Agreement |
| Support correspondence | Controller | Art. 6(1)(b) and Art. 6(1)(f) |
Subprocessors and other recipients
We use three third party services to run Pigeoneer: hosting and access control, our own service email, and a single AI model provider. The current list, with what each one does, where it is located and the data protection terms in place, is at pigeoneer.app/subprocessors. We will give notice before adding a new subprocessor that handles client or creator personal data, on the terms set out in the Data Processing Agreement.
Two sources we read, which are not subprocessors because they process our requests for their own purposes and not on our instructions: YouTube and Twitch, whose APIs we query with search terms (a genre, a tag, and your game's name when looking for coverage) and with the identifiers of the public channels and videos we look up, and from which we fetch the caption tracks and audio of published videos and streams. They receive no reply text and nothing else you entered.
We do not share personal data with advertisers or data brokers. What we disclose, to whom and under what restrictions is described above and on the creator notice.
AI processing
Pigeoneer is an AI product.
Which providers get what.
- Anthropic, the Claude API, on business terms. This is the only external model provider. It receives the drafting and classification prompts, which contain the contact's public profile information, our derived notes about their channel, your game and campaign details, your writing samples, and the text of inbound replies when a reply is being classified or answered. It also receives the transcript of a piece of coverage when we summarise it.
- Local tooling. Obtaining a transcript happens on our own machine: for a YouTube video we fetch the caption track published with it where there is one; otherwise, and for every Twitch stream, we download the audio and run speech-to-text locally. The caption or audio file lives in a temporary folder for the length of the transcription and is deleted when it finishes, whether or not it succeeded; the transcript text is held in memory for the summarising call and is not stored by our application. No audio or video leaves the machine; the finished transcript text goes to the provider above for the summary, a step we intend to bring in-house too. What we keep is the summary, with the transcript's source, length and language.
Provider retention. Anthropic keeps what we send it, for every drafting, classification and summarising call, for up to thirty days under its commercial terms and then deletes it. We have no zero-retention arrangement with it.
Training. The Claude API is used through a paid business key, whose standard commercial terms do not use API inputs to train models. We do not train any model of our own on your data. No path runs on a personal or consumer subscription.
Automated decisions. The tool scores creators for fit and classifies replies. Those are decisions about creators, not about you, and they are described in the creator notice. Nothing in the product makes an automated decision with legal or similarly significant effect about a client.
International transfers
Pigeoneer is a United States company and the platform is operated from the United States (California). Its infrastructure and the providers listed above are United States based. If you or your data subjects are in the EEA or the UK, personal data will be transferred to and processed there, and potentially in other countries where our subprocessors operate.
If your studio is established in the EEA, the UK or Switzerland, you accept a Data Processing Agreement with us in the app, on the second screen of onboarding, alongside the Terms of Service, before you enter anything about your campaign or your mailbox; by then we hold your studio's name, establishment country and address, and what we read from your game's public store page, and nothing else. It incorporates the 2021 European Commission standard contractual clauses, with the UK Addendum for a UK studio and the Swiss adjustments recognised by the FDPIC for a Swiss one. Establishment is not the only thing that can make that law apply to you; if it applies for another reason, tell us at setup and we show you the same agreement. We hold a transfer impact assessment under Clause 14 of those clauses and will give you a summary on request. Its present conclusion is that the transfers may proceed, on conditions it records and re-checks at each reassessment.
We have also adopted a written procedure for what happens if any government asks us for data, covering recording the request, telling you, seeking permission to tell you where we are forbidden to, and challenging it where there are grounds. Ask and we will send it to you.
For our own transfers onward to our providers, all three carry the standard contractual clauses, and two of the three are additionally certified under the EU-US Data Privacy Framework. Details for each are on the subprocessor page. Pigeoneer itself is not certified under that Framework and does not rely on it.
Retention
The rule is the one in your Terms of Service: your campaign records stay in your account for as long as it is open, including the replies you received, and using up your send allowance or a tracking window ending does not change that. Export and erasure are performed on request, by hand, within the periods below. The product does not yet record sign-ins, so the twelve months in the dormancy rule below run from the day it does; nothing is deleted under that rule before then.
| Data | Commitment |
|---|---|
| Early access signups | Deleted on request within 30 days; otherwise not kept beyond 24 months after last contact |
| Your account and project data | Kept while your account is open. When it closes you have 30 days to ask for an export, delivered within 30 days of the request, and nothing covered by a pending export is deleted; live data is deleted within 30 days of the later of the end of that window and any deletion request from you, and backup copies go at the next rotation and in any event within a further 30 days. Where the standard contractual clauses require immediate return or deletion, they govern |
| A deletion request while your account is open | Completed within 30 days of the request, not held back by anything else; backups at the next rotation and within a further 30 days |
| Mailbox credentials | Deleted within 7 days of your account closing, or immediately on request at any time |
| Incoming messages we could not match to your campaign | Held for you to look at; deleted after 30 days unless you act on them sooner |
| Verbatim reply text | Kept while your account is open. If nobody from your studio signs in for 12 months we email you; if we hear nothing within 30 days we delete the text of the replies and keep the record that they happened; if we do hear from you the 12 months start again. The 12 months run from the day the product starts recording sign-ins. You can ask us to delete any reply at any time, and we do it within 30 days |
| Campaign activity logs and draft files | Kept while your account is open, then deleted with the rest of your project data. When a reply's text goes under the dormancy rule above, it is removed from every copy: snippet, held message, log and draft, and only the derived sentiment and intent assessment stays. At your request we delete whatever you ask, assessment included |
| Usage and cost records | Kept as a business record for as long as we operate the platform, with the creator handle removed when your account closes |
| What we keep after deletion | The minimum record needed to keep honouring an opt-out (the contact and the fact, date and scope of the objection, not the message), records a law we are subject to requires us to keep, the record of what you accepted, and our own usage and cost records; each only for its purpose |
| Creator pool records | Covered by pigeoneer.app/creators |
Deletion on request
Write to [email protected]. We will confirm within 5 working days and complete the deletion within 30 days of the request while your account is open, or on the closure timetable in the table above if you are closing it, and the mailbox credentials immediately on request. On request we delete everything we hold for you: the trained voice, the project database, the drafts, the research, the activity logs, any incoming messages we held for you, and the mailbox credentials, keeping only the four things named in the table above. Backup copies are deleted, or overwritten, at the next backup rotation after the deletion, and in any event within 30 days of it.
A deletion is final. A later campaign starts from zero, not from where you left off.
Security
In place:
- Your access to the app is authenticated through Cloudflare Zero Trust, with a signed token verified on every request, and reached over a Cloudflare tunnel rather than an open port.
- The website enforces a strict content security policy, denies framing, and sends no cross origin requests other than the bot check.
- The live machine's disk, and with it the database and every project file, is encrypted at rest.
- Mailbox passwords are additionally encrypted using Windows DPAPI, and off-site backups are encrypted and exclude mailbox passwords entirely.
- The app never returns your mailbox password through its interface.
Not in place: other credentials on the live machine, including our hosting provider's API token and third party API keys, are protected by the disk encryption but not by the additional protection your mailbox password has; there is no security event logging, intrusion detection or alerting, so detection of unauthorised access depends on a person noticing; and there is no third party security certification or penetration test.
Your rights, EEA and UK
If the GDPR or the UK GDPR applies to you, you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to processing, to receive the data you gave us in a portable form where the conditions of Article 20 are met (we provide an export of your account data on request in any case), and to object at any time to direct marketing, which is absolute and requires no reason.
Use [email protected]. We answer within 30 days. We do not charge for this.
If you are unhappy with our answer, you can complain to your national supervisory authority, or to the Information Commissioner's Office in the United Kingdom at ico.org.uk. You do not need our permission to do that.
Where we act as a processor for your campaign data, requests from your own data subjects should go to you, and we will assist you as set out in the Data Processing Agreement. Under the standing instruction in your terms we act on four kinds of request ourselves and forward them to you within three business days: an objection to further contact, which we apply at the scope asked for; a request to delete a creator's reply, which deletes our copies of it; an objection to our summarising of a person's published coverage, which stops it; and a request to delete a coverage summary, which deletes it.
California
For readers in California, under the CCPA as amended by the CPRA:
- We do not share personal information for cross context behavioural advertising, and we have never done so.
- What we disclose, and to whom. Studios that use Pigeoneer see, for the creators our scoring matched to their game, the creator's public profile and the score and research notes we generated, and the replies sent to them; every client's terms bind it to use that material only to run its campaign with us, and not to sell it, pass it on or use it for anything else. Our service providers receive what the subprocessor page lists. Whether a disclosure of that kind is a "sale" or "sharing" under the CCPA is a classification we are having assessed; if you are a California resident and want to opt out of any sale or sharing of your personal information, write to [email protected] and we honour the request without asking you to verify your identity.
- Categories collected in the last 12 months: identifiers, meaning email address and login identity; commercial information, meaning your account and campaign details; internet activity information, limited to the truncated User Agent string on a form submission; professional information you tell us about your studio; and, for the separate creator pool, inferences drawn to create a profile of a channel.
- Sources: you, and public sources for the separate creator pool.
- Purposes: to answer your enquiry, to provide the service, to secure it and to bill for it when billing exists.
- Disclosures for a business purpose: to the service providers listed at pigeoneer.app/subprocessors.
- You may request to know, to delete, to correct, and to limit the use of sensitive personal information. The sensitive personal information we handle is your account credentials, used only to provide the service, and, as your processor, the contents of the mailbox you connect, which we read to find replies to your campaign, classify their tone and intent, draft answers and keep your campaign's records, and for nothing else. A request to limit that use does not require identity verification.
- We will not discriminate against you for exercising any of these rights.
Send California requests to [email protected]. For a request to know, delete or correct, we verify you by replying to the email address on the account or on the enquiry; a request to opt out of sale or sharing, or to limit the use of sensitive personal information, needs no verification. Creators in California should read the California section of pigeoneer.app/creators, which covers the pool.
Children
Pigeoneer is a business tool sold to game studios. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, write to [email protected] and we will delete it.
Changes to this policy
We will update this policy when the product changes. The date at the top always reflects the current version.
For a change that materially affects clients, we will email the account contact at least 14 days before it takes effect. For other changes, updating this page is the notice. This page explains our processing; it does not amend the Terms of Service, a campaign order or the Data Processing Agreement, which change only through their own acceptance and notice mechanisms. If you disagree with a material change, you can close your account and ask us to delete your data.
Contact
[email protected] for anything in this policy, including access, deletion and complaints.
It is also the address to use to stop receiving email from us.
Pigeoneer LLC. Write to [email protected], and ask there if you need our registered postal address.