Your data
Everything you write in ThatPigeon is yours. It sits on servers in the European Union, you can pull it out into a CSV file whenever you like — free, with a subscription or without one — and when you delete your account the live database empties at once, with the photos destroyed on the spot and no copy anywhere. This page tells you exactly what we collect, who touches your data, and how to check every claim on it yourself, in five minutes, without taking our word for anything.
What we collect, and why
What you type in. Your birds with their rings and names, the lofts, the pairings and the youngsters, the races and the results, the health events, the journal. That is your working data — we hold it to show it back to you and to calculate from it. None of it goes anywhere.
Your account email, so we can sign you in. Photos of your birds, if you upload any.
Six anonymous usage events, so we know whether the app is being used. The
full list is a single const in the code, and both the app's event type and the
list on the privacy policy are generated from it —
packages/core/src/analytics-events.ts. Not two lists that can drift into
disagreeing; one list, read by both sides.
What each event says: that the app was opened · that a bird was added · that a result was saved · that you exported something, and what kind · that you opened Statistics · that you opened Trends. The last two carry a single number with them — how many seasons the loft has, and how many cards had something to say. A number, never which.
A ring number never leaves the phone as analytics data. Nor does a bird's name, a race, a season, or any user or device identifier. The rule is written in the same file as the list: an event carries a name and at most one property that is a size. If a future event cannot be described there in one honest sentence that a fancier would accept, the event is wrong, not the sentence.
Separately, crash reports: when the app crashes we receive the error log, with the phone model and the system version. No personal data.
Where the data lives
In the European Union — the database, the photos and the authentication, at the same infrastructure provider, in a European region. The anonymous events go to an analytics provider with servers in the EU.
That is a published promise, not one made only here: it is in the privacy policy on this site, which is what binds us.
For how long
As long as your account exists. We delete nothing on our own initiative and archive nothing "for later". When you want it to end, see below — and read the part about backups, because it is the only place where "deleted" has a tail.
Export
Export is free, with a subscription or without one, and you are never asked to
pay for it. Settings
gives you one button per file — Export birds, Export race results, Export
journal, Export health events, Export pairings and clutches, Export your
listings for sale — with the
labels exactly as they appear in the app, from apps/mobile/src/i18n/en.ts.
Photos are not included: a CSV holds records, and a photograph is not a
record.
The files are plain CSV: they open in any spreadsheet, ours or anyone's. The
columns are fixed and the same every time — not a format that shifts under you.
The headers are not hand-written anywhere: they are constants in
packages/core/src/csv.ts, checked by tests that write the file and read it
back (packages/core/src/csv-roundtrip.test.ts,
packages/core/src/csv-health-breeding.test.ts). Column by column, what each
one means: Import and export formats.
You can check this yourself — steps 5 and 6 below.
Your data stays yours whatever happens to ThatPigeon. If the app is sold, transferred to somebody else or shut down, the export stays yours: you can take out everything you have entered, at any time, and if an end date ever arrives the export stays available for at least 60 days after it. That is not an intention written on this page — it is in the Terms, under Your data is portable, which is what binds us.
Deletion
You delete the account from Settings → Delete account. The app asks you to
type DELETE to confirm, then Delete my account.
What happens then is two different things, and we tell you both.
The live database empties immediately. The birds, the races, the results, the journal, the lofts — gone the moment you confirm. You can check this yourself: steps 7 and 8.
The photos are destroyed on the spot and exist in no backup. Our infrastructure provider states explicitly that uploaded files are not part of the database backups, and that restoring an old backup does not bring back files deleted since. For photos, "deleted" means deleted, with no tail.
Copies of the rows remain for at most 8 days in routine backups. The provider takes a daily copy of the database and keeps the current day plus seven previous ones. A row deleted just after a copy survives in that copy until it expires — at most eight days — and after that it does not exist. Nobody reads those copies in the ordinary course of things; they are there in case the server fails.
We told you the second half because the first alone would have been true and misleading at the same time. The same sentence is now in the privacy policy too.
Who touches the data
Three providers, each with a strict role:
- Infrastructure — the database, the photos and the authentication. This is where your data lives.
- Usage analytics — the six events above, and nothing more. Servers in the EU.
- Error reporting — the crash logs.
Nobody else. We do not sell data, we do not share it with third parties and we do not show ads — all three are written in the published privacy policy.
Check it yourself
Five minutes, your own phone, no account of ours. Every "you can check this" claim on these pages points at a numbered step here.
- Install the app from the public testing link on the front page.
- Sign in with your email address. You get a code; you are not asked to invent a password.
- Add a bird — ring and name. Then add two more. You are not asked to move to a paid plan and nothing stops you.
- Add a race result to one of them, so the file in step 5 has something in it.
- Export, from Settings. You are not asked to pay, now or after a subscription ends.
- Open the file, on your phone or on a computer. Your birds are there, in plain text, in the documented columns — readable in any program, not only in ours.
- Delete the account from Settings, and confirm.
- Sign in again. The loft is empty. The rest of the answer is the backups section above, on this same page.
Further reading
- Import and export formats — the columns of each file, as a specification, and what we read on import.
- How we calculate — the formula behind every number we show you, with the function from the code beside it.
- Security — the security model, the tests that check it on every commit, and why they are written the way they are.