Pip Privacy Policy
Last updated: 6 August 2026
Pip is a calm day-planning app operated by NXeraTech, a sole trader based in Dublin, Ireland. This policy explains what information Pip handles, why it is used, where it goes, and the choices available to you.
Information kept on your device
Pip stores the following information locally on your device:
- your brain dumps and the plans and tasks created from them;
- task state, timers, parked tasks, completed and past days;
- the struggles and planning window selected during onboarding;
- app preferences, including reminder, guidance, and analytics settings; and
- a random installation identifier used to authenticate requests and apply usage limits.
Pip does not currently provide an account, cloud sync, or device-to-device backup. The local information is removed when the app is uninstalled, subject to how your Android device manages app storage.
Brain dumps and AI processing
When you ask Pip to make or reshape a plan, the text you typed or dictated is sent off your device over HTTPS to Pip's Cloudflare Worker at api.nxeratech.ie. The Worker sends the brain dump and relevant context to the configured model provider, currently OpenAI, so the requested plan, first step, or repair can be generated.
Relevant context can include your selected struggles, planning window, local date, day and time of day, how many tasks were completed yesterday, and the tasks involved in a repair. The Worker does not store raw brain dump text or generated plan text in its usage logs. The model provider processes the content under its own data-processing terms.
Voice input
If you use voice input, Android's speech-recognition service processes the microphone audio. NXeraTech does not directly receive or store the audio. The resulting transcript is treated like typed brain-dump text when you submit it to Pip.
Worker usage, quota, and diagnostic information
Pip's Worker stores limited operational information in Cloudflare KV so it can authenticate requests, enforce daily allowances, understand feature use, and diagnose model behaviour. This can include request identifiers, model and token-usage metadata, allowance counters, dates, and non-text analytics such as event name, task position, a duration bucket, typed or voice input mode, and prior-plan count. Task titles and brain-dump text are not included in analytics events.
Short-lived authentication and allowance records are normally retained for about two to three days. Model-usage and related operational records are normally retained for about 35 days. Analytics events are retained for 90 days.
Anonymous product analytics
Pip can send a small set of anonymous product-usage events to PostHog EU Cloud so NXeraTech can understand where people leave the core planning loop. These events cover opening the app or composer, creating a plan, opening, submitting, or accepting a repair, closing the day, and showing or dismissing the paywall. They also cover enabling or disabling the morning reminder, changing its hour, and tapping the reminder.
A plan-created event includes only the number of tasks and whether the input method was typed or voice. A reminder-time event includes the hour only, not the minute. Events may also include a random analytics identifier and basic app, device, and operating-system details added by the analytics service. Pip never sends brain-dump text, task or plan content, repair descriptions, or other user input to PostHog. Session replay and automatic event capture are disabled.
Anonymous usage analytics are on by default. You can stop future events at any time in Settings, under Privacy, by turning off “Share anonymous usage analytics”. The setting is stored on your device and does not affect Pip's planning features.
Reports you send
Settings includes an in-app form for reporting a generated plan or task. When you send a report, Pip sends the selected plan or task text, your comment, the plan or task identifier, the app build identifier, the time submitted, and a one-way SHA-256 hash of your installation identifier to NXeraTech's Cloudflare Worker. Pip does not add the original brain dump to the report.
Reports are stored in a dedicated Cloudflare KV namespace for up to 180 days so NXeraTech can review and act on them. Worker logs contain report metadata such as the report identifier, target type, and submission time, but not the selected response text or your comment.
Notifications and permissions
Pip may ask for microphone permission for voice input and notification permission if you choose to turn on the morning reminder. When enabled, Pip schedules one local notification each morning at the time you choose. It cancels that morning's notification after a plan is created. You can change the time or turn the reminder off in Pip's Settings, and can also turn notifications off in Android's app notification settings. Pip does not request exact-alarm, location, camera, or contacts access.
Why this information is used
NXeraTech processes the content you submit because it is necessary to provide the planning features you request. Limited usage, security, and diagnostic and anonymous product-usage information is processed for NXeraTech's legitimate interests in operating, protecting, and improving Pip. Content reports are processed to review safety and quality concerns. Information may also be processed where needed to comply with a legal obligation.
Service providers and international transfers
Pip relies on the following service providers:
- Cloudflare, for the Worker, request handling, and KV storage;
- OpenAI, for model processing used to generate and reshape plans;
- PostHog EU Cloud, for anonymous product analytics;
- GitHub Pages, to host this privacy policy; and
- Google Play and Android, for app distribution, permissions, and device services.
These providers may process information outside Ireland or the European Economic Area. Where required, NXeraTech relies on appropriate contractual and legal safeguards used by those providers for international transfers.
Payments, advertising, and sharing
Purchases and subscriptions are processed by Google Play. Pip sends the purchase token and product details to its Worker so entitlement can be verified, but NXeraTech does not receive your payment-card details. Pip does not show advertising or sell your personal information. Information is shared only with the service providers needed to operate the features described above, or where required by law.
Your choices and rights
You can edit or delete tasks and past days in Pip and can remove local app data by uninstalling the app. You can stop future anonymous usage events from Settings, under Privacy. You can control microphone and notification permissions in Android settings. Depending on applicable law, you may also have rights to request access, correction, deletion, restriction, or a copy of personal information held by NXeraTech, and to object or complain to a data-protection authority.
Because Pip has no user account and uses a random installation identifier, please include enough detail for NXeraTech to locate a report if you contact us about it. Some requests may require verification.
Children
Pip is not directed to children under 13.
Changes to this policy
This policy may change as Pip develops. The current version and its update date will remain available at this page.
Contact
Questions or privacy requests can be sent to nxeratech@gmail.com.