privacy — pip
← pip

privacy

last updated: 23 july 2026 · plain-language draft describing how the app actually works. before you publish it, replace the bracketed placeholders (legal name, contact email, jurisdiction) and have a qualified lawyer review it. this is not legal advice.

pip is built privacy-first. the short version: your full conversation history, memories, and journals live encrypted on your own computer. paid features send only the bounded context needed for a particular operation to our hosted proxy and its AI provider; we do not keep a second copy of your local stores.

what stays on your device

this data is written as AES-256-GCM encrypted files in your operating system's app-data folder. the encryption key and your sign-in secrets are kept in your operating system's credential vault (Keychain on macOS, Credential Manager on Windows), not in plain text. you can delete all of it any time from settings → "forget everything", or by removing the app. typical locations:

what pip notices on your screen

to power focus sessions, gentle proactive presence, and build mode, pip can look at which application is in the foreground and that window's title, plus how long you've been idle. this observation is off by default — nothing is observed until you turn it on in the workshop, and you can turn it back off at any time. it is metadata only: pip never takes screenshots, never reads your keystrokes, and never reads the contents of your files, messages, or pages.

window titles are sanitised on your device before pip ever uses them: email addresses, links, file paths, anything that looks like a password or key, and probable personal names are stripped out. this signal stays on your machine. sending anything to the model is a separate, second choice: only if you also switch on "include a coarse activity summary in hosted replies" will a short category summary (for example, "about 40 min in a coding tool today") travel with a reply. it never includes window titles, filenames, project names, or commands. both switches are yours to revoke whenever you like.

the weather

pip reacts to the weather where you are: it holds an umbrella when it's actually raining on you, goes quiet in fog, watches the snow. your app never sends us a location. it doesn't read GPS, it doesn't look your address up, and it never asks you for a city.

instead, when pip asks our service for the weather, we use the approximate location that request already arrives with (the same rough area any website can see from a connection), rounded to about 11 km before it is used. that rounded area is all we ever handle: it isn't stored, isn't logged, and isn't attached to you. everyone in the same rounded area shares one cached answer, so we usually don't look anything up at all. you can switch the whole thing off in the workshop.

that guess is wrong for anyone on a vpn or a work connection, so the workshop shows you the area pip is using and lets you correct it by typing a town. if you do: the name you type is sent to our service to look up, and the town you pick is saved on your machine and sent with each weather request — rounded to the same ~11 km, never more precise than the automatic guess. it is not stored on our side, and "use my connection instead" clears it. pip never reads your gps and never asks your operating system where you are.

what leaves your device

when your plan is active and you send a message, pip sends the current turn plus up to 20 recent turns and a small, locally selected context bundle (for example, up to five relevant memories, your profile, agenda, writing preferences, and optional activity/weather summaries). the complete local history and memory files are not uploaded; selected excerpts can be sent because they are what makes a personalised reply possible. free preview replies are generated locally and do not use this hosted path.

paid background features are separate operations. when enabled, bounded conversation windows, selected memories, theories, reflections, people notes, predictions, or dreams may be sent to extract memories, write reflections, or make a gentle synthesis. if you enable "almost-said", a deleted draft can be sent for a short topic-only extraction; turn that feature off and deleted drafts are not kept. these operations run only with an active plan.

the hosted proxy runs on Cloudflare, keeps the AI key server-side, calls Anthropic's Claude, and returns the result to your machine. we do not retain prompts or replies beyond what is needed to deliver a request and operate the service (for example, short-lived request logs and abuse/usage metering).

pip social (optional)

if you choose to add a friend, pip passes short notes between your desktops through short-lived mailboxes on our Cloudflare service. to do this we relay: a random per-install id, your friend code, the display name and creature look you chose, and the short notes you send. these are kept only briefly — messages for up to 7 days (max 50, up to 240 characters each), friend cards for up to 180 days, and a "last seen" timestamp for up to 30 days — then they expire automatically. the conversation threads themselves live encrypted on your device; "forget everything" wipes your local social data. if you never add a friend, nothing social ever leaves your machine.

the playground (optional)

the playground is a shared outdoor map you can walk your pip into. it is the one part of pip where strangers can see you, so it is worth being precise: while you are connected, the display name you chose, your creature look, and your pip's live position on the map are relayed through our Cloudflare service to the other pips in the same area, and theirs to you. nothing from your conversations, memories, reflections, or activity is ever sent to the playground — it carries movement and appearance only.

your desktop is not identified to anyone. the id used in a playground area is a one-way scramble of your install id, and joining uses a single-use ticket that expires in sixty seconds, so your licence and device credentials never travel with it. if you claim a plot, we keep one row — that scrambled id, the plot number, and the name and look you chose — for up to 180 days after your last visit, then it is deleted and the plot is freed. if you never open the playground, none of this ever leaves your machine.

updates

the app may check a versioned update endpoint so it can offer you new versions. that check does not send your personal data.

purchases

payments are handled by our reseller, Dodo Payments, who acts as merchant of record. when you buy, they process your payment and email you a licence key. we receive limited order information (such as your email and which plan you bought) to provide support and manage your subscription. we do not see or store your card details. Dodo Payments' own privacy terms apply to checkout.

who processes data for us

we keep third parties to a minimum. they are: Anthropic (generates AI replies from the context described above), Cloudflare (hosts our proxy, metering, downloads, pip-social mailboxes, and the playground areas, and supplies the approximate network location used for weather), Open-Meteo (receives only the Worker-rounded weather coordinate, and — if you correct your area — the town name you typed), Dodo Payments (payments and licensing), and Google Fonts (fonts loaded by this website). each receives what it needs for its function. their own privacy terms apply to those requests.

the website

this site uses no advertising trackers. if we use basic, privacy-respecting analytics to count visits, it is aggregate only and never tied to an individual.

children

pip is designed to be safe and age-appropriate, and its companion behaviour is platonic by design. if you are under the age of digital consent in your country, please use pip with a parent or guardian's permission.

your rights & contact

because your data is local, you already hold and control it — you can inspect it in the app and erase it with "forget everything" or by uninstalling. for anything related to a purchase, a data request, or a question, contact support@doorado.in. pip is provided by doorado, based in new delhi, india.

terms of service →