What we need to run the service
ZipPigeon handles account details, recipient details, transfer status, encrypted files, encrypted manifests, audit events, IP addresses, and user agents so files can be delivered and abuse can be blocked.

Privacy
Learn what ZipPigeon stores, what is encrypted, and what the service still needs in order to deliver files.
ZipPigeon handles account details, recipient details, transfer status, encrypted files, encrypted manifests, audit events, IP addresses, and user agents so files can be delivered and abuse can be blocked.
Plaintext file contents, raw file keys, private account keys, recovery codes, and secure-link URL fragments should not reach our servers during normal use.
Transfers can expire or be archived. Revoking access stops future opens through ZipPigeon, but it cannot pull back a file someone already downloaded. Encrypted objects are deleted during archive where storage deletion succeeds; operational metadata, logs, and backups can have separate retention.
Infrastructure, object storage, database, email, payment, analytics, and abuse-prevention providers may process operational data where configured. A named subprocessor list, data-residency commitment, and DPA are not yet published as formal enterprise materials.
Client telemetry is intended for security and reliability and is scrubbed for tokens, URLs, email addresses, file names, canaries, and key material before logging. File contents should not be sent as analytics data.
Contact privacy@zippigeon.com for access, deletion, subprocessor, retention, or DPA questions. Include the account email and request type only when that context is safe to share.
Use ZipPigeon when a file needs to reach the right person without becoming another attachment or shared folder to clean up later.
Open signed-in sender