Privacy Policy

Effective date: August 19, 2026

The whole policy in one line: the Pinglight app collects nothing and transmits nothing, because it contains no network code at all. This website sets no cookies and runs no analytics, but — like every website — it is served by a host that keeps standard request logs. Section 7 says exactly what those contain.

Publisher and data controller: Delvir Limited Liability Co. ("Delvir," "we," "us")
30 N Gould St, Ste R, Sheridan, WY 82801, United States
Contact: team@delvir.co

This policy covers the Pinglight iOS application (the "App") and the website at pinglight.app (the "Site"). They are different things and are treated separately below.

1. The App collects nothing

Nothing. We operate no server, database, or backend for Pinglight, and the App has no way to send us — or anyone — anything. There is no account, no login, no sync, no cloud, no backup service, no messaging, and no user-generated content that could be transmitted. We use no analytics, advertising, attribution, or crash-reporting tools, and no third-party SDK of any kind. We therefore never receive a device identifier, an advertising ID, an IP address, a usage event, a crash log, a purchase signal, or any other data from your device.

This is not a setting we could quietly flip in an update — it is an architectural fact. The App ships with no networking code: no HTTP client, no sockets, no web view, no third-party library. We do not track, so we do not use Apple's App Tracking Transparency framework; there is nothing to ask permission for.

2. Bluetooth scanning stays on your phone

Pinglight asks for Bluetooth permission so it can listen to the public advertisement broadcasts that nearby devices already transmit. Everything it hears is processed on your phone against registries built into the App. Scan results are shown to you and to no one else. The session log is held in memory only and is erased when you close the App. Pinglight only listens to broadcasts; it never connects to, pairs with, or interrogates any device.

Nothing you scan is ever written to your device's storage. The App keeps no database, no files, no history, and no logs on disk. Every broadcast it hears exists only in memory while the App is open, and is gone the moment you close it — which also means your scan results cannot appear in an iCloud or iTunes device backup, because they never exist anywhere a backup could reach. The one and only thing the App stores is a single flag recording that you have seen the first-launch notice about what it can and cannot tell you, inside the App's own sandboxed container. Deleting the App deletes that too. Nothing was ever copied anywhere else, so there is nothing for us to delete on request — we never had anything.

The broadcasts Pinglight shows you may relate to devices belonging to other people. That information is displayed only to you, on your phone, and it is never transmitted to us. Your responsibilities when using it are set out in our Terms of Use.

3. Purchases are handled by Apple

Pinglight is a one-time paid app sold through the App Store. Your Apple ID, payment method, and purchase record are handled entirely by Apple, which acts as an independent controller of that transaction data under its own privacy policy — not as our processor, and not on our instructions. Apple does not share your name, email, or payment details with us, and we do not receive them. Refunds are handled by Apple. If you use iCloud or iTunes/Finder device backups, any backup of the App's local settings is governed by Apple's backup and iCloud terms, not by us.

4. No selling, no sharing, no tracking (CCPA/CPRA)

We do not track you across apps or websites, and we serve no ads. Because we collect no personal information, we have nothing to share, sell, rent, or disclose to anyone. Stated plainly, as those terms are defined by the California Consumer Privacy Act as amended by the CPRA: we do not sell your personal information, we do not share it for cross-context behavioral advertising, and we have not done either in the preceding twelve months. We have never done so, and structurally cannot, because none reaches us. We do not use or disclose sensitive personal information for any purpose beyond those permitted without a right to limit. There are no "service providers," "contractors," or "third parties" processing user data on our behalf for the App, because no user data ever reaches us. We do not knowingly sell or share the personal information of consumers under 16.

Because we do not track, there is nothing for a Do Not Track or Global Privacy Control browser signal to switch off; we honor them by construction.

5. Children's privacy (COPPA)

Pinglight is rated 4+ on the App Store, and we collect no personal information from any user, of any age. It follows that the App does not collect personal information from children under 13, and we do not knowingly collect, use, or disclose children's personal information as defined by the U.S. Children's Online Privacy Protection Act (COPPA), or the personal data of anyone under 16 as contemplated by the GDPR. There are no accounts, no chat, no user-generated content, no advertising, and no way for a child — or anyone — to submit information to us through the App. If you believe a child has somehow provided personal information to us, email team@delvir.co and we will delete it.

6. Your rights (GDPR / UK GDPR / CCPA / CPRA and similar laws)

Data protection laws such as the EU and UK GDPR and the CCPA/CPRA give you rights to access, correct, delete, port, and limit the use of your personal data, to opt out of its sale or sharing, and not to be discriminated against for exercising those rights. In connection with the App, we hold no personal data about you to act on. Nothing about you or your scans ever reaches us, so there is nothing to access, correct, delete, export, or stop selling.

If you send a request to the address below, our accurate and complete response is written confirmation that we hold no personal data about you. You may use an authorized agent to make a request; we will still have nothing to disclose. We do not charge for requests and we do not discriminate against anyone who makes one.

For the App, no personal data is processed, so no lawful basis under Article 6 GDPR is engaged, no cross-border transfer of personal data occurs, no transfer mechanism such as Standard Contractual Clauses is required, no automated decision-making or profiling takes place, no retention schedule is needed, and there is no data on any server of ours to breach. For the limited Site and email data described in Sections 7 and 8, our lawful basis is our legitimate interest (Article 6(1)(f)) in operating and securing our website and in answering messages people choose to send us. You have the right to lodge a complaint with your local supervisory authority.

7. This website

The Site is a handful of static files. It sets no cookies of any kind, first- or third-party. It stores nothing in your browser's local storage. It runs no analytics, no advertising or tracking pixels, no session recording, no A/B testing, no embedded social or video widgets, and no third-party fonts or scripts: the type is whatever your own device already has, every image, style, and script comes from this domain, and a Content-Security-Policy header on every page instructs your browser to refuse anything loaded from anywhere else. There are no forms, no logins, and no way to submit anything to us through the Site.

What we cannot truthfully claim is that no server is involved at all. The Site is hosted by Vercel Inc., and like every web host, Vercel's infrastructure automatically receives and logs the technical details your browser sends with each request in order to deliver the page, keep the Site available, and defend it against abuse. Those records typically include your IP address, the page or file requested, the date and time, the HTTP status and response size, your browser's user-agent string, and any referring page. Vercel processes this on our behalf as our service provider, under its own security and privacy commitments, and retains it for a limited period on a rolling basis. We do not use these records to identify you, we do not build profiles from them, we do not enrich or combine them with anything else, we do not sell or share them, and we do not connect them to the App in any way — the App never contacts this Site or any other server.

8. If you email us

If you write to team@delvir.co, we receive your email address, your message, and whatever else your mail program includes, handled through our business email provider acting as our service provider. We use it only to answer you and to keep a record of the exchange, we keep it no longer than we reasonably need to, and we never add you to a mailing list, sell it, or share it for advertising. Please don't send us sensitive personal information — we have no need for it.

9. Security

The strongest security measure available to a product is not holding the data in the first place, and that is the one Pinglight uses: your scan results exist only in your phone's memory and never leave it. The Site is served over HTTPS with HSTS and a restrictive Content-Security-Policy. Because we operate no database and hold no user data, there is no store of personal information about our users that could be breached.

10. Changes to this policy

We may update this policy — for example, if a future version of Pinglight ever adds a feature that involves data leaving your device. If that happens, we will update this document, change the effective date above, and update the App Store privacy label to match before that version ships. We will not silently expand data collection. Material changes will be reflected here; the version you agreed to is the one in force when you used the App.

11. Contact

Questions, or a data request you would like answered in writing:

Delvir Limited Liability Co.
30 N Gould St, Ste R
Sheridan, WY 82801
United States
team@delvir.co