Privacy Policy
Last updated: 2026-09-04
This policy describes what the PidgeIoT platform collects, where it lives, how long we keep it, and what we do (and deliberately don't do) with it.
Questions about anything here: info@jes.contact.
Who is responsible for your data
PidgeIoT is operated by Justin's Engineering Services LLC, a Montana limited liability company registered to do business in Massachusetts. For the account you create, the messages you send us, and the diagnostics your browser sends us, we are the controller of your personal data.
For the data your devices and your team put into the platform, you (or the organization you belong to) are the controller and we process it on your instructions under our Data Processing Agreement, which any customer can countersign by emailing info@jes.contact.
What we collect
Account data. When you register a dashboard account, our self-hosted Ory Kratos identity system stores your email address and a hash of your password. We never store your password in plain text.
Device data. The platform exists to hold the data your devices send it: telemetry values, device configuration (shadow state), and device log uploads, along with the metadata you enter when creating flocks and pigeons (names, descriptions, connector settings). You control what your devices report.
Web logs. Like nearly every web service, our infrastructure records standard request logs (IP address, user agent, timestamps, and the routes requested) used for debugging and abuse prevention.
Error diagnostics. If the dashboard hits a bug, your browser sends us a technical report: the error message, the place in our code where it happened, the app build, the page's route template, your browser's user agent string, and a short trail of recent in-app actions recorded as request method, route template, and status code. These reports are anonymous by design. They carry no account identity, no full URLs, no query strings, no form contents, and no request or response bodies, and we do not link them to your session. If you choose to send us a problem report yourself, we attach your account identity to that report so we can follow up with you, and identified reports are deleted with your account. Error reports are kept for 90 days; the long-lived statistics we keep about error patterns contain no personal data.
What we don't do
- We do not sell your data. Not account data, not telemetry, not anything.
- We do not run third-party advertising or ad-tracking scripts on this site.
- We do not use cookies, browser storage or analytics to profile you or to follow you to other sites. The next section lists everything we do set, and why.
Do Not Track and Global Privacy Control
Some browsers send a Global Privacy Control or Do Not Track signal on your behalf. There is nothing here for either signal to switch off: we sell no personal data and share none for cross-context advertising, we serve no advertising and no cross-site tracking, and the one analytics script we run is not served at all to visitors in the European Economic Area, the United Kingdom or Switzerland. If that ever changes, honoring the signal becomes something we have to build rather than something we can simply state, and this section will say so.
Where your data is processed, and how transfers are protected
We are a United States company, and the platform runs on infrastructure in the United States and on a global edge network. All traffic between your browser or your devices and the platform is encrypted in transit with TLS. In plain terms:
- Each device's own state (its configuration, its latest readings and its log buffer) lives in a Cloudflare Durable Object that is created near whoever first set the device up, and stays there. For a team in Europe that is usually a European data center, but we do not guarantee it.
- Our relational database and our identity database are hosted by Crunchy Bridge on AWS in Northern Virginia (us-east-1).
- Our identity server and our device-transport terminators run on a server in Vint Hill, Virginia.
- Our edge provider runs our code in whichever of its data centers receives a request, and its queues and caches have no fixed location.
- Billing is handled by Stripe in the United States. Transactional email is sent by a third-party email provider.
If you are in the European Economic Area, the United Kingdom or Switzerland, this means your personal data is transferred to the United States. We rely on the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two), together with the UK International Data Transfer Addendum for UK data and the Swiss adaptations for Swiss data, as the legal basis for that transfer. Those clauses are part of our Data Processing Agreement. We are not certified under the EU-U.S. Data Privacy Framework; some of our service providers are, and we rely on their certification for the part of the processing they do.
We do not offer EU data residency today. If you need it, contact us and tell us the requirement.
Device credentials are handled asymmetrically: only a device's public key is ever persisted. The platform cannot recover a device token after it is first shown to you.
Service providers we use
We use a small number of service providers to run the platform. The current list, with what each one does, where it processes data, and the transfer safeguard that covers it, forms part of our Data Processing Agreement and is available on request from info@jes.contact. We give customers thirty days' notice by email before we add or replace one.
How long we keep data
We keep data for as long as it serves the purpose it was collected for, and no longer. The concrete periods are:
| Data | How long, and what happens then |
|---|---|
| Your account (email, name, phone if you give one, credentials) | While your account exists. Deleted when you ask us to delete it. |
| Sign-in sessions | 4 hours, then they expire. |
| Verification and recovery codes | Minutes to hours, and single use. The record that the message was sent stays in the identity system's own log. |
| Organization invitations | 7 days, and single use, then they expire. |
| Device configuration, latest readings, device log buffer | While the device exists, and the log buffer keeps only the newest 200 chunks. Erased when you delete the device. |
| Telemetry history | 7 days on the free tier, 30 days on Builder, 90 days on Growth, 13 months on Scale and Fleet. Deleted automatically after that. |
| Saved dashboard graphs | While your account exists. Deleted when you delete the graph, and with the rest of your account when you ask us to delete it. |
| Firmware images | While the fleet exists. Removed by us on request. |
| Billing records (invoices, subscription history) | As long as tax and accounting law require, held by our payment processor. Deleted at the end of the statutory period. |
| Contact-form and support messages | Kept as correspondence you addressed to us. Deleting your account detaches your account identifier from the message rather than deleting the message itself. |
| Dashboard error reports | 90 days, then deleted automatically. The statistics we keep about error patterns contain no personal data. |
| Web and API request logs | 7 days, then deleted automatically by our edge provider. |
| Backups of our databases | Rotated on our database host's own schedule. Deleted data disappears from a backup when that backup expires. |
Why we are allowed to process your data
If you are in the EEA, the UK or Switzerland, the law requires us to tell you the legal basis for each kind of processing:
- To provide the service you signed up for (creating and securing your account, running your devices, sending you the alerts you configure, billing your organization): performance of a contract (GDPR Article 6(1)(b)).
- To keep tax and accounting records, including validating an EU VAT number you give us against the European Commission's VIES register: a legal obligation (Article 6(1)(c)).
- To keep the platform secure and working (request logs, rate limiting, anonymous error diagnostics, notifying ourselves of failures): our legitimate interest in running a secure service (Article 6(1)(f)). We have designed these to carry as little personal data as possible; error reports carry no identity unless you choose to attach one.
- To answer your messages when you use the contact form or send feedback: our legitimate interest in responding to you, and, where you are asking about becoming a customer, steps you ask us to take before a contract (Article 6(1)(b) and (f)).
- Email updates: only with your consent, which you can withdraw at any time (Article 6(1)(a)). We do not send marketing email today.
Product updates by email
If you tick the box for product updates, we send you occasional email about PidgeIoT. We do that only because you asked us to, which in legal terms means we rely on your consent (GDPR Article 6(1)(a)), and you can withdraw it at any time in your account settings without giving a reason and without affecting anything else about your account. Withdrawing takes effect for anything we have not already sent. We do not send this email unless you have asked for it, we do not share your address with anyone else for their own marketing, and every message we send includes a link to stop them.
Objecting to how we use your data
You can object at any time to our sending you marketing email, and we will stop; this is an absolute right and we do not weigh it against anything (GDPR Article 21(2) and 21(3)). For the smaller number of things we do because we have a legitimate interest in them, such as keeping the service secure and diagnosing faults, you can also object, and we will stop unless we can show compelling grounds that override your interests. In either case, email us at the address in this notice, or use your account settings for the marketing choice. You do not have to explain why, and objecting costs you nothing.
Your rights
If you are in the EEA, the UK or Switzerland, you have the right to ask us for access to the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we process it, to receive it in a portable format, and, where we rely on consent, to withdraw that consent. You also have the right to complain to your data protection authority.
Much of this you can do yourself:
- See and correct your email, name and phone number in account settings.
- Delete devices, empty organizations, and your own identified error reports in the dashboard.
- Take your data with you: every fleet, device, configuration and telemetry history you can see in the dashboard is available as JSON through the API documented on our API reference page, and you can configure a forwarding endpoint to receive your telemetry continuously.
For anything else, including deleting your account, email info@jes.contact from the address on your account. We will confirm receipt within five business days and answer within one month; if a request is complex we may take up to two further months and will tell you why. We do not charge for this unless a request is clearly unfounded or excessive.
If your data reached us through a customer's use of the platform (for example your organization's account, or a device your employer operates), that customer is the controller and we will pass your request to them.
Deleting your data
You can delete your pigeons and flocks directly in the dashboard at any time; deleting a pigeon removes its stored shadow, telemetry, and logs from the platform.
There is no automated account-deletion flow yet. To delete your account, email info@jes.contact from your account's address and we will remove it.
Automated decisions
We do not make decisions about you by automated means that have legal or similarly significant effects. Two automated checks exist and you should know about them: when an organization saves an EU VAT number we validate it against the European Commission's VIES register and will not accept a number the register says is invalid; and when a free-tier account exceeds its monthly message allowance, its devices' uploads are paused until the next period. Both are about the organization's account rather than about you as a person, and either can be raised with us by email.
Telemetry forwarding you configure
PidgeIoT lets you configure a forwarding endpoint for a pigeon's telemetry. If you do, we send that pigeon's telemetry to the endpoint you configured instead of storing its history with us. That endpoint is chosen and controlled by you: data sent there is governed by whoever operates it, not by this policy.
We send transactional email only: account verification, password recovery, and the alert notifications you configure. Delivery goes through a third-party SMTP provider, which necessarily processes the recipient address and message content in order to deliver it.
We do not send marketing email today.
Changes to this policy
As the platform evolves we may update this policy. Changes will be posted on this page with a revised "Last updated" date.