1. Scope
Pigeon is an invitation-only business phone and call-workflow service. The closed beta is limited to approved United States firms and users age 18 or older. Firms control their workspace and business records; individual users control their personal Pigeon contacts and account choices subject to legitimate firm recordkeeping needs.
2. Information we collect
- Account information such as name, email, user ID, firm, role, and extension.
- Firm information, membership, subscription status, and phone configuration.
- Contacts explicitly entered, selected from a device picker, or imported from Clio.
- Client and matter information imported by an authorized firm.
- Call metadata such as phone numbers, direction, timestamps, duration, status, and provider call identifier.
- User content such as call notes, contact notes, and billing disposition.
- Push registration identifiers needed to deliver incoming calls and notifications.
- Privacy-limited crash and reliability diagnostics, including app, operating-system, and device-version information.
- Encrypted Clio authorization credentials when a firm connects Clio Manage.
3. Calls and audio
Pigeon does not record answered two-party calls. Live call audio is processed in real time to provide VoIP calling and is not stored by Pigeon as a call recording.
When an incoming call is unanswered or rejected, a caller may leave a caller-only voicemail. Twilio stores the voicemail media for playback, while Pigeon stores the related firm-scoped metadata. Voicemail is scheduled for deletion after 90 days.
4. How we use information
- Authenticate users and enforce firm access.
- Place, receive, route, display, and organize business calls.
- Provide contacts, recent calls, missed calls, voicemail, notes, and post-call review.
- Associate eligible calls with matters and sync authorized records with Clio.
- Manage firm subscriptions, seats, invitations, and beta eligibility.
- Protect the service, prevent misuse, diagnose failures, and improve reliability.
- Respond to support, privacy, and account-deletion requests.
5. Device contacts
Pigeon does not request unrestricted access to the entire device address book. The system contact picker lets a user choose specific contacts to share. The user then chooses whether each import is personal or shared with the firm.
6. Service providers
We use service providers to operate Pigeon, including:
- Clerk for authentication, firm organizations, invitations, and subscription processing.
- Twilio for VoIP calling, phone routing, push registration, and voicemail media.
- Firebase and Google for Android push delivery and privacy-limited crash diagnostics.
- Apple for iOS distribution, PushKit, APNs, and CallKit platform services.
- Railway for application, API, and PostgreSQL hosting.
- Clio Manage when an authorized firm enables the optional integration.
These providers process information to deliver services to Pigeon and are expected to protect it consistently with their agreements and applicable law. Pigeon does not sell personal information, use it for targeted advertising, or include advertising SDKs.
7. Data sharing
We share information only with service providers needed to operate Pigeon, with a connected integration authorized by the firm, when required by law, or when necessary to protect users, firms, and the service. Personal contacts are visible only to their owner. Firm contacts and firm records are visible to authorized firm users.
8. Retention
- Account-profile data is kept while the account is active and is removed through the verified deletion process.
- Firm-controlled calls, notes, contacts, clients, matters, and billing records are kept while the firm uses Pigeon or while legitimate contractual, security, business-record, or legal obligations apply.
- Verified firm-closure deletion requests are targeted for completion within 30 days, subject to required retention.
- Voicemail media and metadata are scheduled for deletion after 90 days.
- Clio authorization credentials are removed when the integration is disconnected or the firm is deleted.
- Crash and diagnostic information follows the applicable Firebase retention schedule.
- Residual copies may remain in protected backups until those backups are deleted or overwritten. They are not used for ordinary business processing and are restored only for recovery.
9. Account and data deletion
Users may initiate account deletion at pigeon.bluecipherit.com/delete-account. We verify requests using the account email and aim to complete them within 30 days. Individual deletion removes the Pigeon account profile and personal contacts. Firm-controlled business records may remain under the firm's control when legitimate recordkeeping obligations apply; identity is removed or de-identified where practical.
Firm administrators may request closure and deletion of the firm's Pigeon workspace. Data that must be retained for legal, fraud prevention, security, billing, or contractual reasons will be limited to those purposes and retained only as necessary.
10. Security
Pigeon uses authentication, firm-scoped authorization, encrypted network connections, encrypted Clio credentials, provider access controls, and privacy-limited diagnostics. No security practice can guarantee absolute protection, but we use safeguards appropriate to the service and the information processed.
11. Your choices
Users may decline optional device-contact selection, disconnect optional Clio access through their firm administrator, manage device permissions in system settings, request access or correction through support, and request account deletion. Firm administrators control firm membership and firm-wide business records.
12. Children
Pigeon is a business service for users age 18 or older and is not directed to children. We do not knowingly collect information from children through the closed beta.
13. Changes to this policy
We may update this policy as Pigeon changes. The effective date above will be updated, and material changes will be communicated through the service, by email, or through the firm's administrator when appropriate.
14. Contact us
Questions or privacy requests may be sent to contact@bluecipherit.com. Account deletion may be initiated through the account-deletion page.