Privacy Policy

Last updated: July 26, 2026

PidgeIoT is operated by Justin's Engineering Services LLC, a Massachusetts limited liability company. This policy describes what data the platform collects, where it lives, and what we do — and deliberately don't do — with it.

Questions about anything here: info@jes.contact.

What we collect

Account data. When you register a dashboard account, our self-hosted Ory Kratos identity system stores your email address and a hash of your password. We never store your password in plain text.

Device data. The platform exists to hold the data your devices send it: telemetry values, device configuration (shadow state), and device log uploads, along with the metadata you enter when creating flocks and pigeons (names, descriptions, connector settings). You control what your devices report.

Web logs. Like nearly every web service, our infrastructure records standard request logs — IP address, user agent, timestamps, and the routes requested — used for debugging and abuse prevention.

Where your data lives

Account, device, and platform data are stored in managed PostgreSQL and on Cloudflare's edge infrastructure (Workers, Durable Objects, and object storage). All traffic between your browser or devices and the platform is encrypted in transit with TLS.

Device credentials are handled asymmetrically: only a device's public key is ever persisted. The platform cannot recover a device token after it is first shown to you.

What we don't do

  • We do not sell your data. Not account data, not telemetry, not anything.
  • We do not run third-party advertising or ad-tracking scripts on this site.
  • We do not use tracking cookies. The only cookie we set is a session cookie, strictly for keeping you signed in.

Telemetry forwarding you configure

PidgeIoT lets you configure a forwarding endpoint for a pigeon's telemetry. If you do, we send that pigeon's telemetry to the endpoint you configured instead of storing its history with us. That endpoint is chosen and controlled by you — data sent there is governed by whoever operates it, not by this policy.

Email

We send transactional email only: account verification, password recovery, and the alert notifications you configure. Delivery goes through a third-party SMTP provider, which necessarily processes the recipient address and message content in order to deliver it. We do not send marketing email.

Deleting your data

You can delete your pigeons and flocks directly in the dashboard at any time; deleting a pigeon removes its stored shadow, telemetry, and logs from the platform.

There is no automated account-deletion flow yet. To delete your account, email info@jes.contact from your account's address and we will remove it.

Changes to this policy

As the platform evolves we may update this policy. Changes will be posted on this page with a revised "Last updated" date.