Skookum Studios

Pingfold

Privacy Policy

studiosskookum@gmail.com +92 303 0156789

Last updated:

This Privacy Policy explains how Skookum Studios handles information when you use the Pingfold Android application ("Pingfold"). Pingfold is built from the ground up to protect your privacy: core notification management is local-first, requires no user account, has no cloud synchronization, and operates without an internet connection.

Pingfold does not display advertising, does not sell your personal data, and does not use advertising identifiers or advertising SDKs.

Our Core Privacy Promise: On-Device Processing

Your notifications stay on your device. Notification content is never uploaded.

Pingfold uses Android Notification Access to see incoming notifications and apply the delivery choices you configure, including Immediate delivery, scheduled Digests, blocking, custom exception rules, Focus sessions, and Profiles.

All notification content handled by Pingfold—including notification titles, messages, bodies, sender names, verification codes, app names, and notification identifiers—stays on your physical device. Pingfold does not upload, synchronize, transmit, or back up your notification content to any server, cloud service, or external provider.

  • Recent Content & search: Pingfold can keep recent notification titles and messages locally in app-private storage so you can review recent alerts, search your history, and build precise exception rules. Recent Content is excluded from device backup, can be disabled and deleted from Settings at any time, and offers a user-selectable retention window of 1, 7, or 30 days (defaulting to 30 days).
  • Structural notification history: Pingfold stores structural metadata (such as delivery disposition, timestamps, and rule matches) in a private local database to power your Activity windows, Inbox, and Noise Insights. This structural history contains routing information rather than notification text and supports retention options of 7 days, 30 days, 90 days, or keep-until-deleted. Clearing structural history automatically removes linked Recent Content.
  • Digest previews: Queued notifications and delivery previews are stored in a separate, bounded local store (queued previews remain up to 72 hours and delivered previews up to 24 hours). You can clear Digest previews at any time via the Clear Digest control in Settings.
  • Backup and device transfer disabled: Android cloud backups (Google Drive backup) and device-to-device transfers are explicitly disabled in Pingfold's manifest. App-owned data and notification history are never included in system backups.

Information We Process and Collect

Pingfold is designed with strict data minimization. We process and collect only the data necessary to provide notification management, maintain stability, and support optional features:

  • Notification data (local only): notification titles, messages, sender names, package names, channels, timestamps, and delivery decisions. Processed in real time on-device and stored solely in local app-private storage. Never uploaded.
  • App configuration & rules (local only): your per-app preferences (Immediate, Digest, Block), exception rules, phrase matchers, schedules, Focus sessions, and saved Profiles. Stored strictly on your device.
  • Usage analytics (optional, user-controlled): when enabled in Settings › Privacy & diagnostics, Pingfold sends a bounded catalog of 17 privacy-limited feature-use events to Google Analytics for Firebase (such as navigating screens, creating an exception, or toggling a filter). Pingfold's custom analytics events never contain notification content, app names, exception names, rule names, notification identifiers, or user identifiers. Advertising ID collection, automatic screen reporting, and ad personalization are disabled in the manifest. Google may derive approximate (coarse) location from masked IP addresses.
  • Crash diagnostics (optional, user-controlled): when enabled in Settings › Privacy & diagnostics, Firebase Crashlytics collects technical crash stack traces, device metadata, OS version, and a single custom diagnostic flag (whether the notification listener was connected). Pingfold does not attach notification content, app names, exception names, or user text to crash reports.
  • Lifetime Supporter purchase data (optional feature): if you purchase or restore the optional Lifetime Supporter / PRO tier, Google Play Billing processes the transaction. Pingfold does not collect, handle, or store credit card or payment information. Our isolated supporter service (hosted on Cloudflare) receives the Play purchase token, an obfuscated claim identifier, and session tokens to verify entitlement and prevent fraud or replay.
  • Supporter display name (optional): Lifetime Supporters may optionally enter a public display name and phrase for the Founding 1,000 Supporter Roll. This is subject to automated moderation. No real name or email is required. You can edit, unpublish, or delete your display name at any time directly in the app, which automatically anonymizes your supporter entry.

How We Use Information

We use information solely to:

  • intercept, organize, schedule, and quiet notifications according to your preferences;
  • deliver scheduled Digest summaries and reminders on your device;
  • display local notification history, Noise Insights, and Rule Activity on-device;
  • verify, activate, and restore optional Lifetime Supporter purchases;
  • display approved display names on the public Founding 1,000 Supporter Roll when explicitly published by the user;
  • diagnose technical issues, investigate crashes, and improve app stability when optional diagnostics are enabled; and
  • protect the supporter backend from abuse, replay attacks, and unauthorized access.

Advertising and Tracking

Pingfold does not display advertisements. Advertising ID collection, ad tracking, and ad personalization signals are disabled in the app. We do not sell, rent, or trade your personal information with data brokers or third-party advertisers.

Device Permissions

Pingfold requests only the permissions necessary to operate:

  • Notification Access (BIND_NOTIFICATION_LISTENER_SERVICE): Required for Pingfold's core purpose—inspecting incoming notifications to organize, schedule, or block them according to your preferences. All notification content remains on your device.
  • Post Notifications (POST_NOTIFICATIONS): Required on Android 13 and newer to deliver scheduled Digest summaries, reminders, and service health alerts.
  • Exact Alarms and Boot (SCHEDULE_EXACT_ALARM, RECEIVE_BOOT_COMPLETED): Required to deliver Digest summaries at your exact scheduled times and maintain notification listener reliability after your device restarts.
  • Internet Access (INTERNET, ACCESS_NETWORK_STATE): Used exclusively for the optional telemetry services (when enabled) and the optional Lifetime Supporter verification service. Core notification management functions completely without internet access.
  • In-App Purchases (BILLING): Required by Google Play Billing to process the optional Lifetime Supporter purchase.

Pingfold does not request access to your contacts, precise location, camera, microphone, photos, media storage, phone calls, SMS messages, or Accessibility Services.

Third-Party Services

Pingfold integrates with a limited number of third-party services:

  • Google Play Services: for app distribution, updates, and in-app purchase processing.
  • Google Analytics for Firebase: for privacy-limited usage analytics (optional, user-controlled in Settings).
  • Firebase Crashlytics, Installations, and Sessions: for crash diagnostics and stability metrics (optional, user-controlled in Settings).
  • Cloudflare Infrastructure: hosts the isolated supporter verification backend and database for Lifetime Supporter verification and the Founding 1,000 Supporter Roll.

These providers process data according to their own privacy policies and terms of service.

Data Storage and Security

All notification content, structural history, and app preferences are stored in app-private SQLite databases on your device. Android cloud backups and device-to-device transfers are disabled so notification data is never backed up off the device.

All network communication for approved telemetry, Google Play, and supporter services uses encrypted HTTPS/TLS transport. Supporter session credentials on the device are secured using Android Keystore with an automatic 30-day lifetime limit. Pingfold's architecture strictly isolates notification processing from network code so notification-derived data cannot enter network request paths.

Data Retention and User Controls

You have full control over your data within Pingfold:

  • Notification Content & History: You can adjust Recent Content retention (1, 7, or 30 days) and structural history retention (7, 30, 90 days, or keep until deleted), or clear them immediately via Settings.
  • Rules & Profiles: You can edit, pause, or delete exception rules, reset app modes, and delete saved Profiles at any time.
  • Analytics & Crash Diagnostics: You can independently toggle Usage analytics and Crash diagnostics off in Settings › Privacy & diagnostics. Disabling analytics invokes resetAnalyticsData(). Disabling crash diagnostics closes the reporting gate and requests deletion of unsent local reports.
  • Supporter Profile & Anonymization: Lifetime Supporters can edit, unpublish, or delete their stored display name at any time directly from the Supporter Profile screen in the app. Deleting the display name immediately removes it and automatically anonymizes the supporter entry without requiring a manual request.
  • Local Data Deletion: You can delete all local data at any time by clearing app data in Android system settings (Settings › Apps › Pingfold › Storage & cache › Clear storage) or by uninstalling Pingfold.
  • Supporter Ledger Records: Purchase, entitlement, and fraud-prevention records on the supporter service are retained to verify lifetime purchases, honor refunds or revocations, preserve Founding-rank integrity, and meet legal and accounting obligations.

Data Deletion and Anonymization

Because Pingfold does not require accounts, passwords, or emails to use the app, all your notification history and configuration data reside exclusively on your physical device and are completely erased when you clear app storage or uninstall the application.

Lifetime Supporters can delete or unpublish their display name directly from the Supporter Profile screen in the app at any time, which immediately removes the name and automatically anonymizes their supporter entry. You do not need to contact us to delete or anonymize your data.

If you have any questions about data privacy or purchase verification records, you can contact us at studiosskookum@gmail.com.

Children's Privacy

Pingfold is not directed to children under the age of 13 (or 16 in applicable jurisdictions). We do not knowingly collect personal information from children.

Changes to This Privacy Policy

We may update this Privacy Policy as Pingfold evolves. The "Last updated" date at the top of this policy will reflect any revisions.

Contact Us

If you have questions about this Privacy Policy or data privacy in Pingfold, please contact Skookum Studios: