1. Scope
Pigeon is a self-serve business phone app for solo professionals and owner-operators. It is available in the United States to users age 18 or older. The account holder controls the company workspace and its business records, including personal contacts and account choices, subject to legitimate recordkeeping needs.
2. Information we collect
- Account information such as name, email, user ID, company, and role. If a phone extension is stored on the account, we keep that extension.
- Company information, the account holder's membership, subscription status, and phone configuration.
- Subscription records such as the selected plan, billing period, renewal date, transaction status, and cancellation status.
- Contacts explicitly entered or selected from a device picker, and contacts you choose to import from an optional practice-management integration.
- Client and matter information you choose to import through an optional practice-management integration.
- Call metadata such as phone numbers, direction, timestamps, duration, status, and provider call identifier.
- User content such as call notes, contact notes, and billing disposition when you record one.
- Push registration identifiers needed to deliver incoming calls and notifications.
- Privacy-limited crash and reliability diagnostics, including app, operating-system, and device-version information.
- Encrypted authorization credentials when you connect an optional practice-management integration, such as Clio Manage, PracticePanther, or MyCase.
3. Calls and audio
Pigeon does not record answered two-party calls. Live call audio is processed in real time to provide VoIP calling and is not stored by Pigeon as a call recording.
When an incoming call is unanswered or rejected, a caller may leave a caller-only voicemail. The calling service stores the voicemail media for playback, while Pigeon stores the related company-scoped metadata. Voicemail is scheduled for deletion after 90 days.
4. How we use information
- Authenticate the account holder and limit access to that account.
- Place, receive, route, display, and organize business calls.
- Provide contacts, recent calls, missed calls, voicemail, notes, and post-call review.
- When you connect an optional practice-management integration, associate eligible calls with matters and sync the records you authorize.
- Manage the company subscription.
- Process renewals, cancellations, refunds, taxes, payment failures, and billing support.
- Protect the service, prevent misuse, diagnose failures, and improve reliability.
- Respond to support, privacy, and account-deletion requests.
5. Device contacts
Pigeon does not request unrestricted access to the entire device address book. The system contact picker lets a user choose specific contacts to share. You then choose whether each import is personal or available on the company account.
6. Service providers
We use service providers to operate Pigeon, including:
- An account service for authentication, the company account, and subscription management.
- Stripe for payment processing, fraud prevention, disputes, refunds, and related financial compliance.
- A calling provider for VoIP calling, phone routing, push registration, and voicemail media.
- Firebase and Google for Android push delivery and privacy-limited crash diagnostics.
- Apple for iOS distribution, PushKit, APNs, and CallKit platform services.
- Railway for application, API, and PostgreSQL hosting.
- Clio Manage, PracticePanther, or MyCase when you choose to connect that optional integration.
- Microsoft Clarity for usage analytics on Pigeon web pages, including public pages and signed-in admin pages.
Payment details are entered directly into the Stripe payment workflow. Blue Cipher LLC does not receive or store full payment-card numbers. We receive subscription and transaction status needed to provide access, support billing, and maintain business records.
These providers process information to deliver services to Pigeon and are expected to protect it consistently with their agreements and applicable law. Pigeon does not sell personal information, use it for targeted advertising, or include advertising SDKs.
7. Data sharing
We share information only with service providers needed to operate Pigeon, with an optional integration you choose to connect, when required by law, or when necessary to protect the account holder, the company, and the service. Personal contacts are visible only to the account holder who created them. Company contacts and other company records are available on that company account.
8. Retention
- Account-profile data is kept while the account is active and is removed through the verified deletion process.
- Company calls, notes, contacts, and, when present, clients, matters, and billing records are kept while the company uses Pigeon or while legitimate contractual, security, business-record, or legal obligations apply.
- Subscription and transaction records may be retained as needed for accounting, tax, fraud prevention, dispute handling, contractual, and legal obligations.
- Verified company-closure deletion requests are targeted for completion within 30 days, subject to required retention.
- Voicemail media and metadata are scheduled for deletion after 90 days.
- Authorization credentials for an optional practice-management integration are removed when that integration is disconnected or the company is deleted.
- Crash and diagnostic information follows the applicable Firebase retention schedule.
- Residual copies may remain in protected backups until those backups are deleted or overwritten. They are not used for ordinary business processing and are restored only for recovery.
9. Account and data deletion
Users may initiate account deletion at pigeon.bluecipherit.com/delete-account. We verify requests using the account email and aim to complete them within 30 days. Deletion removes the Pigeon account profile and personal contacts. Company business records may remain when legitimate recordkeeping obligations apply; identity is removed or de-identified where practical.
The account holder may request closure and deletion of the company's Pigeon workspace. Data that must be retained for legal, fraud prevention, security, billing, or contractual reasons will be limited to those purposes and retained only as necessary.
10. Security
Pigeon uses authentication, access limited to the company account, encrypted network connections, encrypted credentials for an optional practice-management integration, provider access controls, and privacy-limited diagnostics. No security practice can guarantee absolute protection, but we use safeguards appropriate to the service and the information processed.
11. Your choices
You may decline optional device-contact selection, disconnect an optional practice-management integration, manage device permissions in system settings, request access or correction through support, and request account deletion. The account holder controls company records and may manage or cancel the subscription through Pigeon Admin.
12. Children
Pigeon is a business service for users age 18 or older and is not directed to children. We do not knowingly collect information from children.
13. Changes to this policy
We may update this policy as Pigeon changes. The effective date above will be updated, and material changes will be communicated through the service or by email when appropriate.
14. Contact us
Questions or privacy requests may be sent to contact@bluecipherit.com. Account deletion may be initiated through the account-deletion page.
Start Your Free Trial