Download

Privacy Policy

Last updated August 27, 2026

Data we handle

  • Account identity, email or phone number, username, profile name, settings, public profile photo, and private identity selfie.
  • Your age-range attestation, AI-generation consent record, messages, reactions, replies, blocks, reports, device push token, and delivery or seen status.
  • Photos, videos, GIFs, captions, thumbnails, filtered captures, generated media, game results, and the friends or group chats you choose as recipients.
  • Phone numbers from your contacts when you grant Contacts access. Address-book names and other people's photos stay on your device. If you grant Contacts access, phone numbers are sent to our servers over TLS in E.164 form, keyed-hashed server-side, and only those hashes are stored for friend matching. If a contact card matches your number, you can confirm that photo as your public profile photo.
  • Account-linked product events, device and app context, approximate region derived from your network address, and diagnostics used to operate and improve the service.

Pine does not store address-book names or photos of other people and does not create accounts for unregistered contacts.

Profile photo and visibility

Your Pine profile photo is visible to other users in the app. A separate private identity selfie is used to include you in generated media while your consent is active; it is never displayed to another user.

You can replace either identity photo or revoke generation consent in Settings. Revocation removes both identity photos, disables future likeness use, and removes generated media containing you from the service.

Face data: collection, use, sharing, storage, and retention

What we collect. Pine collects the public profile photo you select, capture, or confirm from your own contact card, the private identity selfie you capture, and the facial likeness visible in generated media you create, receive, or appear in. Camera effects may detect facial or hand landmarks on your device while in use. Pine does not store that live landmark data or create face geometry, depth data, faceprints, biometric templates, or face-recognition identifiers.

How we collect and use it. After you tap “Allow Face Data Use,” Pine displays the profile photo publicly and stores the identity selfie privately as the sole identity reference for fictional generated media. Pine operators may start curated generations, and an eligible mutual friend may choose you for a Pine-authored group-generation experience while your consent remains active. Operator-curated generation output is safety-screened before it can be sent. Mini-app generations, user-sent media, avatars, and identity photos are not sent to a moderation provider. Face data is never used for authentication, advertising, marketing, analytics, user profiling, or identifying anonymous people.

Where it is stored and shared. Convex stores identity photos and generated media, enforces mutual-friend and consent checks, and runs product workflows. Vercel AI Gateway and the configured OpenAI or Google Gemini model receive the prompt, request metadata, composition image, and private identity selfies needed for an operator-, self-, or mutual-initiated generation. OpenAI’s moderation endpoint receives operator-curated generation output for safety screening. A mutual friend can select your public profile but never receives your private selfie. No face data is shared with PostHog, advertisers, data brokers, or information resellers.

How long it is retained. In Convex, a current profile photo and identity selfie remain until you replace them, revoke consent, or delete your account; replaced files are deleted once unreferenced. Generated media remains until consent revocation, account deletion, sender removal, or service removal. OpenAI’s moderation endpoint retains no customer content. OpenAI may retain generation customer content in abuse-monitoring logs for up to 30 days, and Google may retain generation prompts, images, and output for abuse monitoring for up to 55 days; either may retain data longer when legally required or necessary to prevent harm.

How data is used

We use this data to authenticate you, find mutual friends, provide group chats and first-party camera experiences, create requested AI media, deliver photos, videos, messages, games, and notifications, power the widget and profile archive, and operate safety controls.

Before either identity photo leaves the device for AI use, Pine obtains explicit, versioned permission. While permission is active, Pine operators may include you in curated media, and mutual friends may select you in Pine-authored experiences that generate group photos or other media. Pine verifies the mutual relationship, active consent, and block status before resolving a private identity selfie on the server; the friend never receives the selfie. Generation sends only the references needed for that request through Vercel AI Gateway to the configured OpenAI or Google Gemini model. You can withdraw permission in Settings; withdrawal stops future use and removes both identity photos and generated media that includes you from the service.

AI-generated or AI-edited Pine photos and videos are fictional and must not be presented as real events. AI instructions and templates are fixed and curated by Pine; users choose only an offered experience and eligible mutual friends. Pine does not send identity photos, avatars, user-sent artifacts, or mini-app generations to OpenAI’s moderation endpoint. Operator-curated generation sends the base image, prompt, request metadata, and depicted people’s private selfies through Vercel AI Gateway to OpenAI, with Google Gemini available after a safety refusal, and screens that output with OpenAI’s moderation endpoint before sending. Pine-authored group-generation experiences may send the selected mutuals’ private selfies, a fixed composition template, and a fixed prompt through the Gateway to the configured OpenAI or Google Gemini model. The selecting friend never receives the private selfies and cannot supply the generation instructions. Pine configures no-prompt-training and does not opt in to provider model training. OpenAI’s moderation endpoint has no abuse-monitoring retention. OpenAI may retain generation customer content for up to 30 days, and Google may retain Gemini generation content for up to 55 days, or longer when legally required or necessary to prevent harm.

Camera, microphone, speech-recognition, photo-library, motion, Contacts, and notification access is requested only when a feature needs it and depends on your device permission. Live camera effects may process frames, face or hand landmarks, and motion on the device. Captured media is uploaded only when you choose to send it.

Details: AI & likeness.

Messages, media, sharing, and providers

Inside Pine, messages and media are limited to their intended mutual-friend recipients and shared group chats. Sent media may also appear in a sender’s profile archive to mutual friends who share the underlying chat. A recipient or depicted person may save or share media outside Pine. Blocking either direction removes in-app shared-post access. Copies shared outside the service are controlled by the person who shared them, not by Pine.

Convex provides authentication, product data, realtime chats, file storage, and workflows; Twilio receives the phone number and verification metadata needed to deliver and validate one-time codes; Vercel provides hosting and AI Gateway; OpenAI generates some images and reaction suggestions and screens operator-curated generation output; Google Gemini generates media for configured experiences and may provide operator-generation fallback; Expo provides push delivery; PostHog provides analytics and diagnostics; Superwall is installed for future purchases but no paywall is currently presented. Identity photos, avatars, user-sent media, mini-app generations, and private chat text are not sent to an automated moderation provider.

Pine requires its processors to protect personal data consistently with this policy and applicable law, and does not authorize them to use it for advertising or model training. Review the Twilio privacy notice, Vercel privacy notice, OpenAI privacy policy, Google privacy policy, and PostHog privacy policy.

PostHog receives account-linked, allowlisted product activity and diagnostics, plus person profile fields needed for support (name, username, email, and public profile photo URL). It does not receive private identity selfies, generated or user-captured media, prompts, message text, contacts, address-book names, or private media URLs. Session replay is disabled and PostHog does not record screen, touch, or text capture.

Pine may ask for App Tracking Transparency permission on iOS. With or without that permission, Meta, TikTok, and Google/Firebase receive standard app install and conversion events (for example app open, completed registration, and onboarding completion) so Pine can measure advertising performance. Device advertising identifiers are used only when you allow tracking. Face data is never used for advertising. Review the Meta privacy policy, TikTok privacy policy, and Google privacy policy.

Retention and your choices

Contact hashes remain until your next sync, Contacts permission revocation, or account deletion. Current identity photos remain until replacement, consent revocation, or account deletion. Sent messages, media, results, and delivery metadata remain until sender removal, account deletion, service removal, or the applicable chat is deleted. A reported profile or media copy remains only while its report is open or under review, then is deleted when the report closes. Generated media containing you is removed after consent revocation.

Settings lets you revoke generation consent, change notification choices, block users, and permanently delete your account. Deletion immediately locks the account and begins durable removal of authentication, profile, contacts, relationships, devices, reactions, replies, messages, reports, identity photos, created media, generated media containing you, and linked PostHog people and events. Processor deletion may complete asynchronously. Limited records may remain when required by law, safety, fraud prevention, or backup rotation.

Age and safety

Pine is not intended for children under 13. Users aged 13–17 must attest that a parent or legal guardian permits their use and AI-likeness processing. User-sent images and video thumbnails are screened after delivery and removed if they fail safety checks; AI-generated output is screened before sending. Reports are reviewed by operators. Operators can inspect reported media, remove media or a profile photo, and suspend or restore an account with an audit history. Blocking remains available to every user.

Contact

Pine is a product of Undefined Software, Inc.. Email alon@undefinedinc.io for privacy, deletion, safety, or support questions. Also review our safety policy.