Data deletion
How to request deletion of your data in Pingente
Last updated: September 28, 2026 · Applies to the Pingente app (Android, package app.pingente), published by Camilo Carromeu. Complements the privacy policy.
1. What there is to delete
Pingente does not require a user account (the recovery account is optional). Everything you create (faces, notes, photos, events) stays on your phone. What may exist on our server, indirectly tied to you, is small:
- Installation identifier of the app, sent with every server call.
- Purchase record for in-app purchases: Google Play receipt, order number and the tag activated with it.
- Tag ownership: a hash of the key generated by your phone, which prevents another device from adopting your tag, along with the tag model and the name you gave it.
- Pending gift, if you gifted a tag: its ID, model and name and, if you kept the current face, the finished image of that face.
- Crash reports (Sentry), only when the app crashes: device, versions, error trace, tag model and face name, with no name, e-mail or account identifier.
- Recovery account (optional), only if you created one under "Recover my tags": your e-mail address, its creation date, the sessions (token hash, last use and device name) and the links to your tag IDs, with the permission to receive postcards by e-mail, if you switched it on.
2. How to request
Recovery account: you delete it yourself, immediately, in the app — "Recover my tags" → "Delete recovery account" (the app asks for a two-step confirmation). E-mail, sessions and links are deleted right away; your tags' ownership and activation stay on the phone and the tag. If you no longer have the phone with the active session, request it by e-mail as below, stating the account's e-mail address.
Other data:
- In the app, open the tag → ⋯ menu → Details and note the ID of each tag (8 characters).
- E-mail [email protected] with the subject "Data deletion — Pingente", the tag IDs and, if you bought an activation in the app, the Google Play order number (starts with
GPA., found in Google's receipt e-mail). - We reply within 15 days and complete the deletion within 30 days, with confirmation by e-mail.
- To erase what is on the phone (faces, notes, photos, ownership key), simply uninstall the app.
3. What is deleted and what is kept
| Data | What happens |
|---|---|
| Installation identifier and request-replay records | Deleted. |
| Google Play order number and receipt | Order number deleted. We keep only an opaque receipt identifier, with no personal data, so the same receipt cannot activate another tag. |
| Tag ownership (key hash, model and name) | Deleted. Note: the tag becomes free to be adopted by any phone. |
| Tag activation (permanent license) | Kept. It is the product you bought, tied only to the tag ID, with no personal data — deleting it would void the purchase. |
| Gift (finished image and tag name) | Deleted. Without a request, it is deleted automatically 7 days after it is accepted, or after 180 days if nobody accepts it. |
| Crash reports | Anonymized at the source and automatically deleted after 90 days. |
| Code purchases on the website (resellers) | Invoice and payment data stay with Paddle (Merchant of Record) for tax obligations, up to 5 years; we keep the transaction id and the codes for the same period. |
| Recovery account (e-mail, sessions and tag links) | Deleted immediately, from the app or on request. Tag ownership and activation are not affected. |
4. Your rights
Besides deletion, you may request access, correction or portability at the same e-mail (LGPD, art. 18; GDPR, arts. 15–20). Controller: Camilo Carromeu, Campo Grande/MS, Brazil.