1. Scope
This notice covers pipipong.com, direct desktop-app installer delivery, the current macOS technical preview, public Pet Community pages, and the PPAS Studio linked from this site. Pipipong is a technical preview, so users should review the version-specific status and safety information before using it with important files.
2. Website access and downloads
Hosting, security, and file-delivery providers may process necessary technical logs such as request time, page or file requested, IP address, browser and device information, referrer, errors, and security events. These records are used to deliver the site and installer, diagnose faults, and prevent abuse.
The current site does not enable optional audience analytics. The macOS installer can be downloaded without giving Pipipong a name, email address, or application form. A download request may still appear in the necessary delivery logs described above.
Public Pet Community pages and creator profiles can be browsed without an account. Community sign-in, email verification, favourites, reports, pet-package downloads, personal libraries, uploads and publishing are not currently enabled, so this public flow does not collect account-profile or community-action data.
3. Desktop-client task data
Depending on the task and settings, the desktop client may process voice input, local transcripts, task descriptions, edited instructions, selected file names or contents, application context, execution plans, permission choices, confirmations, action logs, results, and errors.
Speech transcription is performed locally in the current build. Computer and fixed-project task execution currently requires a configured Codex executor. Content needed for that execution may be sent to the configured provider under its own terms; users should not assume every task is fully offline.
4. Scope, permissions, and user control
Pipipong is designed to show the task scope and plan before acting, request only the permissions needed for the chosen action, and require confirmation for sensitive changes. Users can edit a transcript, decline a permission, cancel before confirmation, and review the resulting action record where the build supports it.
Users should avoid including unnecessary sensitive information in prompts, files, or pet packs and should keep independent backups of important work.
5. Third-party services
Installer delivery, hosting, and a user-configured executor may be provided by third parties. Information required for a chosen function is processed under the relevant provider's terms and privacy rules. Pipipong does not claim support for an executor that is not listed on the current Status page.
6. PPAS Studio: local-only preview
When a creator selects a .pppet file, the current public PPAS Studio reads, hashes, validates, previews, and prepares reports locally in the browser. The selected package bytes and assets are not sent to Pipipong and are not persisted in LocalStorage, IndexedDB, or a service-worker cache.
Hosted drafts, package uploads, server-side submission, review, and publication are disabled. Before any of those capabilities are enabled, Pipipong must provide verified-email authentication, private quarantine storage, server-side authorisation and validation, current legal notices, moderation operations, deletion and export controls, and an updated privacy disclosure.
7. Retention, access, and deletion
Because the current public community has no account, favourites, personal library, hosted draft, upload, or report flow, it does not offer account-data deletion or export controls. Those controls are a launch requirement, not a currently available service. Necessary infrastructure logs and third-party records are retained under the relevant provider's operational and legal policies.
Depending on applicable law and context, a person may have rights to access, correct, delete, or export personal information, restrict or object to processing, or complain to a regulator. Use the verified privacy contact shown on this page when it is available. Do not send identity documents or other sensitive records through an unverified channel.