Your privacy.
Your calendar lives on your instance. This explains the information the shared Pipmo service handles around it.
Last updated: 6 September 2026
Who runs Pipmo
Pipmo is operated by Bobby Holmes, through embers.cafe. Bobby Holmes is the controller of personal information processed to operate the shared website, installation service and support desk. Contact hey@pipmo.app for support or privacy enquiries.
Your instance, your data
Your plans, routines, calendar connections, account and preferences are stored in the Cloudflare account that hosts your Pipmo instance. We do not maintain a central copy of your calendar or a register of active instances. There is no routine instance heartbeat or background location tracking.
The instance owner controls that instance’s data and integrations. If someone else provides your instance, contact them about information they hold. Saved places and journey estimates are used by your instance; opening directions sends the selected destination to your maps provider.
The website, demo and cookies
Cloudflare serves and protects this website and processes connection information such as IP addresses and request metadata. The site does not currently use advertising pixels or third-party audience analytics. Fonts and companion artwork are served with the site.
Your theme choice is saved in browser storage. Open your Pipmo remembers an instance address locally in your browser. The interactive demo holds sample entries in the page; it does not send those entries to the installation service or an AI provider. Clearing browser storage removes saved website preferences.
The installer uses a secure, HTTP-only session cookie. Release administration uses a separate authenticated session cookie. These support the functions you request and are not advertising cookies. The support page loads our Embers Hub form and may use Cloudflare Turnstile for abuse prevention.
Installing and updating
You sign into Cloudflare for each installation or update. During that operation we temporarily handle the access token, selected account and instance identifiers, deployment progress and owner claim code. Session contents are encrypted at rest and expire within 30 minutes. Deployment credentials are removed when the operation completes or fails; expired sessions are deleted. No ongoing refresh access is requested.
The owner claim code protects the first account on your instance. Only its hash is stored in the instance database. It is single-use and valid for 24 hours. Keep it private; the installation service’s copy is available only during the short-lived setup session.
Release checks and deployment records
Checking for updates requests the public release catalog and exposes ordinary connection metadata, such as an IP address, to the hosting infrastructure. It does not upload your calendar.
Deployment outcome records contain an operation identifier, action, release version, status, an error code when relevant and timestamps. They do not contain your Cloudflare account ID, instance address, calendar contents or credentials. They help us understand release reliability, not which instances are still active.
Notifications and optional AI
If enabled, iPhone notifications pass through the shared Apple push relay. It handles a device push token and encrypted notification content and forwards them to Apple. The relay does not have the key to read that content. IP addresses and device tokens are used for rate limiting; the relay application does not keep a database of notification payloads.
Your instance communicates with the calendar and AI providers you configure. AI is optional. When used, the planning request and relevant context are sent to your selected provider, whose terms and retention settings apply. Basic entry and scheduling work without an AI provider. The public demo does not call one.
When you contact us
The support form sends your name, email address, optional subject and message to our Embers Hub support desk at hub.embers.cafe. Email enquiries use hey@pipmo.app. We use the information you provide to investigate and answer your enquiry. Please do not include passwords, access tokens, claim codes or unnecessary calendar information.
Why we use this information
We process information to provide the installation, update and support functions you request, protect the service against abuse and investigate failures. Where UK or EU data protection law applies, we rely on legitimate interests in operating a reliable service, securing it and responding to enquiries. We may also retain or disclose information where necessary to meet a legal obligation. We do not sell personal information or use it for advertising.
How long information is kept
- Installation sessions
- Up to 30 minutes, with access credentials removed earlier when an operation completes or fails.
- Release admin sessions
- Up to one hour, limited by the identity provider’s token expiry. Release and admin audit history is retained to maintain a record of release changes.
- Deployment outcomes
- Technical outcome records currently have no automatic deletion schedule. They are retained to investigate release reliability and contain no instance addresses or account IDs.
- Browser preferences
- Until you change or clear them, or your browser removes them.
- Support correspondence
- For as long as needed to resolve the enquiry and handle related follow-up, security issues or legal requirements. You can request deletion using the contact below.
- Your instance
- Controlled by the instance owner. Removing the app from a phone does not delete information on the instance.
Infrastructure providers process connection and security records under their applicable service and privacy terms. We do not promise that those records disappear when a Pipmo session expires.
Service providers and international processing
Cloudflare provides hosting and security infrastructure. Apple delivers enabled push notifications. Our support desk and email infrastructure process correspondence you send. Providers may process information outside your country. Cloudflare’s data processing terms describe its international transfer safeguards, including applicable standard contractual clauses and the UK addendum. Its privacy policy also covers its own processing and Turnstile. Contact us for information about safeguards relevant to your enquiry.
Integrations you choose for your own instance operate under your arrangements with those providers. Enabling one does not make its data part of a central Pipmo calendar.
Your choices and rights
You can disable optional integrations or notifications, clear browser storage and manage information on your instance. Depending on applicable law, you may request access, correction, deletion, restriction or portability of personal information held by the shared service. Some rights are subject to legal exceptions.
You may object to processing based on legitimate interests. Email hey@pipmo.app to exercise your rights or ask a privacy question. We may need enough information to verify your identity without collecting unnecessary documents.
You can complain to the UK Information Commissioner’s Office or the relevant regulator where you live.
Changes to this policy
We will update the date on this page when this policy changes. Any future paid feature or license check will be explained before it is enabled. Current free instances are not enrolled in a central license service.