Privacy

What ZipPigeon keeps private

Learn what ZipPigeon stores, what is encrypted, and what the service still needs in order to deliver files.

What we need to run the service

ZipPigeon handles account details, recipient details, transfer status, encrypted files, encrypted manifests, audit events, IP addresses, and user agents so files can be delivered and abuse can be blocked.

What we do not want

Plaintext file contents, raw file keys, private account keys, recovery codes, and secure-link URL fragments should not reach our servers during normal use.

Retention and deletion

Transfers can expire or be archived. Revoking access stops future opens through ZipPigeon, but it cannot pull back a file someone already downloaded. Encrypted objects are deleted during archive where storage deletion succeeds; operational metadata, logs, and backups can have separate retention.

Subprocessors and residency

Infrastructure, object storage, database, email, payment, analytics, and abuse-prevention providers may process operational data where configured. A named subprocessor list, data-residency commitment, and DPA are not yet published as formal enterprise materials.

Analytics boundary

Client telemetry is intended for security and reliability and is scrubbed for tokens, URLs, email addresses, file names, canaries, and key material before logging. File contents should not be sent as analytics data.

Privacy requests

Contact privacy@zippigeon.com for access, deletion, subprocessor, retention, or DPA questions. Include the account email and request type only when that context is safe to share.

Send the file. Keep control of the link.

Use ZipPigeon when a file needs to reach the right person without becoming another attachment or shared folder to clean up later.

Open signed-in sender