What PingMe! stores, why, and for how long.
PingMe! ("we", "us") is operated by Dataflair Ltda, a company registered in Brazil and based in Pelotas, RS, Brazil. Dataflair Ltda is the data controller for everything described here.
For anything in this policy, including access and deletion requests, contact us at [email protected].
Because we are established in Brazil and we serve users in the EU and the UK, both the Brazilian LGPD and the GDPR / UK GDPR apply to this service. Where the two differ, we follow whichever is stricter.
No account is required to create a link. When you tap "Get My Link" and allow notifications, your browser creates a push subscription and sends it to us. We store:
p256dh and auth) that let us encrypt notifications so only your browser can read them. The endpoint URL identifies your specific browser installation.This is the majority of our users. Data created this way is not anonymous: it is tied to your browser's push subscription, which is a stable identifier for that browser until you revoke notification permission.
Signing in is only needed for the dashboard. We request the scopes
openid, email and profile, and we store what
Google returns for them:
sub value — an opaque id, not your password or anything else from your Google account);We do not request, receive or store access to your Gmail, Drive, Calendar, contacts or any other Google service. These fields are captured the first time you sign in and are not refreshed on later sign-ins, so if your Google name or picture changes, our copy will not follow it — see section 8 on how to correct it.
One thing worth knowing: if you sign in on a browser where you had already created links anonymously, that browser's push subscription and the links under it are attached to your new account, so data that was previously tied only to a browser becomes tied to your Google identity. Deleting your account then deletes those links and their ping history too.
For every ping we store:
We do not ask a visitor for their name, email or anything else, and there is nothing on the ping page that asks them to identify themselves.
session, contains a signed reference to your account, and is marked HttpOnly, Secure and SameSite=Lax, with a lifetime of 30 days. Signing out clears it. This is a strictly necessary cookie: without it we cannot keep you signed in.We set no advertising cookies and no cross-site tracking cookies.
Every page loads an analytics script from analytics.pingme.gg, a host we
operate ourselves, which records page views so we can see how the site is used. The
software is Umami, self-hosted on the same server as the rest of the
service. It is not a third-party analytics product: the data never leaves our own
infrastructure, and nobody else receives it.
For each page view it records the page URL, the referring URL, your browser, your operating system, your device type, your screen size, and an approximate country. The country is derived from your IP address at the moment of the request; the IP address itself is not stored.
It is cookieless. It sets no cookie and no device identifier, and it neither stores anything on your device nor reads anything from it. That is why you do not see a consent banner on this site: the consent requirement in Art. 5(3) of the ePrivacy Directive is triggered by storing or reading data on your device, and this does neither. We rely on our legitimate interest in understanding how the site is used (Art. 6(1)(f) GDPR), and you can object to it — see section 8.
Analytics records are kept for 12 months and then deleted.
Each ping stores SHA-256(secret + ":" + IP address). The secret is a
single value fixed for this deployment — it is not different per user, per
link or per day. Two consequences follow, and we would rather state them than let
the word "hashed" imply more than it delivers:
We therefore treat these hashes as personal data, protect them like personal data, and delete them on the schedule in section 7. We do not describe them as anonymous data, because they are not.
The hash is also part of the ping history the owner of a link can retrieve from their dashboard (the dashboard does not currently display it on screen). At most it lets a link owner tell whether two pings came from the same network — it does not reveal the visitor's IP address, name or location to them.
If you are in the EEA or the UK, we rely on the following bases under the GDPR / UK GDPR. Brazilian law gives the same processing the equivalent bases under the LGPD — performance of a contract (Art. 7(V)), consent (Art. 7(I)) and legitimate interests (Art. 7(IX)) — row for row with the table below.
| Data | Purpose | Basis |
|---|---|---|
| Push subscription, links, ping records | Delivering the service you asked for — a link that notifies you | Art. 6(1)(b), performance of a contract |
| Notification permission in your browser | Sending push notifications to your device | Your explicit browser-level consent, revocable at any time |
| Google account id, email, name, picture | Signing you in and showing your dashboard | Art. 6(1)(b), performance of a contract |
| Hashed IP addresses, rate-limit counters, server logs | Preventing abuse, spam and denial of service; keeping the service secure | Art. 6(1)(f), legitimate interests |
| Analytics | Understanding how the site is used | Art. 6(1)(f), legitimate interests — the analytics is cookieless and stores nothing on your device (section 2.5) |
We keep the list short, but it is not empty. The following third parties process data on our behalf or as an unavoidable part of the service:
Web Push does not work without them. Your browser — not us — chooses the push service, and the endpoint it hands us belongs to one of:
When you get pinged, we send the notification to that service and it delivers it to your device. The notification body is encrypted with the keys your browser gave us, so the push service cannot read the message text. It does see the endpoint (which identifies your browser installation), and the time and frequency of your notifications, and it may hold an undelivered notification for up to 24 hours before discarding it. These companies are US-based and operate under their own privacy policies.
Only if you choose to sign in. Google handles the sign-in itself and tells us your account id, email, name and picture URL. Google's own privacy policy applies to what happens on their side.
The application, its database and its logs run on a server we operate ourselves, located in Brazil. There is no hosting company holding your data on our behalf.
The site is served through Cloudflare, which provides our CDN and the tunnel that connects our server to the internet. All traffic to PingMe! passes through Cloudflare, and Cloudflare therefore sees the IP address of every visitor. It acts as our processor and operates under its own privacy terms.
Our analytics (section 2.5) runs on the same server and is not a third party. We use no external backup service and no error-tracking service.
We may disclose data where we are legally required to do so, or where it is necessary to establish, exercise or defend legal claims — for example a report of harassment carried out through a ping link.
| What | Kept for |
|---|---|
| Ping records (time, message, hashed IP) | 90 days, then deleted automatically |
| Links created without an account that have never been pinged | 90 days from creation, then deleted automatically |
| Links that have been pinged at least once, and all links belonging to a signed-in account | Until you delete or archive them, or delete your account |
| Push subscription (device registration) | Until it is deleted — from the dashboard, or with your account. Revoking notification permission stops it working and we mark it inactive after the next failed delivery, but the record itself stays until deleted. Subscriptions created without an account are not on any automatic deletion schedule today; ask us and we will remove one |
| Google account details (id, email, name, picture URL) | Until you delete your account |
| Session cookie | 30 days, or until you sign out |
| Server access and application logs | At most 30 days, and usually less — the log is rotated by size as well as by age |
The deletion job runs once a day, in the early hours. It is a scheduled sweep, not an instant expiry, so a record may survive up to about a day past its window before the next run removes it. Deletion is permanent — there is no archive it moves to.
Depending on where you live you have rights of access, correction, deletion, restriction, objection and portability. Here is how each one works in practice here.
To exercise any right by email, write to [email protected]. We answer within 15 days. That is the deadline set by Art. 19 of the LGPD, and it is shorter than the one month the GDPR allows, so we apply it to everyone.
If you think we have handled your data badly, you can complain to us first and, if that does not resolve it, to a supervisory authority. In Brazil that is the ANPD (Autoridade Nacional de Proteção de Dados). If you are in the EU or the EEA you may instead complain to the supervisory authority of the country you live or work in; in the UK, to the Information Commissioner's Office (ICO).
HttpOnly, Secure and SameSite=Lax, and state-changing requests are origin-checked.No service can promise perfect security, and we do not. If you find a vulnerability, please tell us at [email protected], the same address as everything else in this policy.
Our servers are in Brazil. If you are in the EU or the UK, your browser sends your data straight to us here. Under the EDPB's Guidelines 05/2021 that is not a restricted transfer at all: you are the data subject sending your own data, so there is no exporter and no transfer mechanism is required. We do not need standard contractual clauses for you simply using the site.
Transfers do arise through the processors in section 6 — Cloudflare, the browser push services and, if you use it, Google Sign-In. Those companies are largely US-based and each operates under its own transfer framework and privacy terms. We use no other processor outside Brazil.
PingMe! is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has used the service and you want their data removed, contact us and we will remove it.
If we change what we collect or how long we keep it, we will update this page and change the "last updated" date at the top. The retention periods in section 7 in particular are configuration values and must be re-checked here whenever they are changed.
Dataflair Ltda, Pelotas, RS, Brazil — [email protected]. That one address reaches us for privacy questions, data requests, abuse reports and security reports alike — there is no separate department for each.
No Data Protection Officer. We have not appointed one, and we are not required to: none of the triggers in Art. 37 GDPR applies to us. We are not a public authority, our core activity is not large-scale systematic monitoring of individuals, and we do not process special categories of data on any scale.
No EU representative. We rely on the exemption in Art. 27(2)(a) GDPR: our processing of EU data is occasional, small in scale, unlikely to result in a risk to people's rights and freedoms, and involves no special categories of data and no criminal-conviction data. On that basis no representative in the Union is appointed.