1. Scope and current status
This notice covers the pipipong.com website, free beta downloads, and voice, text, and computer-task processing that may occur in the beta product. Website visits, installer delivery, and the desktop client may use different technology and services; the final policy should describe each real data flow separately.
Pipipong is still in free beta. Some data flows have not been finalised, so this page marks open questions instead of making unverified promises such as "everything is local" or "fully offline".
2. Website access data
Hosting and security infrastructure may generate necessary technical logs, such as access time, requested pages, IP address, device and browser details, referrer, errors, and security-event information. This information may be used to serve the site, diagnose faults, prevent abuse, and protect the service.
The current configuration does not enable additional audience analytics. If analytics, cookies, or third-party measurement are added later, this notice should be updated before activation and any notice or choice required by applicable law should be provided.
3. Free beta download data
The current macOS technical preview can be downloaded without an application, name, email address, or invitation. Downloading it does not by itself create a Pipipong account or place the user in an application queue.
The website, hosting provider, or file-delivery service may still generate the necessary technical logs described above when a download is requested. If Pipipong later adds an optional feedback or contact form, this notice should identify the information collected, provider, purpose, and retention rules before that form is enabled.
4. Voice, text, and computer-task data
Depending on the build and user choices, Pipipong may process voice input or transcripts, task descriptions, edited instructions, file names or contents, application context, execution plans, permission choices, confirmation records, action logs, results, and error information.
The product should process only what is needed to carry out the user's request and show scope and confirmation steps before critical actions. Exact features, permission boundaries, and recorded information still need to be verified against the working build and must not be inferred from this draft alone.
5. Local and cloud processing
Some tasks may be completed on the device, while others may require a cloud model, API, or remote service. Whether information leaves the device depends on the feature, selected AI, user configuration, and task content.
The released client should explain the main processing route before a task or in settings. Unless a specific build says otherwise, users should not assume that all voice, text, files, or task context remain local.
6. Third-party AI and service providers
When a user downloads the installer or chooses Codex, another AI, hosting, file-delivery, or related services, information necessary to provide that function may be processed by the relevant provider under its own terms and privacy rules. Pipipong should not send unnecessary content to services that are not involved in the task.
The provider list, processing locations, controller or processor roles, and international-transfer arrangements are awaiting confirmation from the actual integrations and must be added before a final policy is published.
7. PPAS package preview and creator uploads
Selecting a .pppet file in PPAS Studio reads, hashes, validates, and previews it locally in the browser. Before the creator explicitly selects “Confirm & upload”, the package bytes, Manifest, action names, trigger definitions, images, and audio are not sent to Pipipong. The browser does not persist the selected package in local storage, IndexedDB, or a service-worker cache.
After explicit confirmation, the exact original file and its content hash may be sent to private quarantine storage for server-side validation. A successful upload creates an owner-scoped private draft; it does not automatically publish the package to the Pet Library. Rejected, aborted, or incomplete temporary uploads become eligible for deletion after no more than 24 hours. Cleanup is scheduled daily, so deletion normally occurs within the following 24 hours; scheduler or storage failures are retried and can extend that time. Private drafts expire after 90 days by default, and the signed-in creator can delete a draft earlier from Studio.
Creators should upload only material they are entitled to use and avoid unnecessary sensitive information, another person's private information, or unauthorised content. The package may describe host permissions and simulated system triggers, but browser preview never starts real computer watchers.
8. Retention and deletion
PPAS Studio currently limits the active lifetime of incomplete uploads to 24 hours and private drafts to 90 days by default. The hourly cleanup normally removes an eligible temporary upload within one further hour, while transient failures are retried. Creator deletion and draft expiry remove the private package object and draft record; a minimal tombstone containing the draft ID, package hash, reason, and deletion time may remain for integrity and replay protection.
Separately, an owner-linked package-version ledger remains after draft deletion or expiry so a package ID cannot be reassigned and the same or an older version cannot be accepted later. It contains the derived owner identifier, package ID, accepted version, package hash, and acceptance time, but not package bytes, storage paths, or package summaries. Its final retention period has not yet been set.
Retention periods for other product data, backups, security logs, and legal records have not been confirmed. The final rules should set periods by data type and purpose, and the official contact process for other deletion requests still needs to be established.
9. User choices and rights
Depending on applicable law and the processing context, users may have rights to access, correct, delete, or export personal information; withdraw consent; restrict or object to certain processing; and complain to a regulator. The final applicable law must determine the exact rights, exceptions, and response periods.
Users may decline optional information, edit a voice transcript before submitting it, refuse unnecessary permissions, stop a task where the product supports it, or choose a different AI service.
10. Security measures and practical limits
Product design priorities include least privilege, execution previews, confirmation for sensitive actions, difference review, snapshots, undo, and action records. These measures are intended to reduce risk but cannot guarantee that errors, data loss, or security incidents will never occur.
Beta testers should still review execution plans, keep backups of important files, and avoid submitting highly sensitive data to a build whose processing has not been verified.
11. Changes to this notice
This notice will change as the client, download delivery, optional feedback channels, and third-party services are confirmed. Material changes should be communicated in a reasonable way, with a new effective or updated date shown on this page. The process for providing historical versions is still to be confirmed.
12. Contact us
Contact channel for privacy questions, rights requests, or security reports: official privacy contact email to be confirmed and published by the product owner.
No application form is required for the current download. Until an official contact channel is published, do not send identity documents, health information, financial details, or other sensitive material through unverified channels.