pier
Legal

Privacy Policy

What Pier collects, what it deliberately doesn't, and who processes it. Written from the code.

Effective date: 16 July 2026

This policy explains what Pier ("Pier", "we") collects when you use the Pier desktop app, this website, and our hosted services, and what we deliberately don't. Pier is an independent project operated by an individual. For data protection purposes, that operator is the data controller, and you can reach them at hi@pierapp.co.

Pier is built local-first. We collect as little as possible. If you want the long, code-level version of the same story, read Data & transparency.

What we collect

Waitlist. If you join the waitlist on this site, we store the email address you submit, plus your GitHub username and note if you choose to add them. We use them for exactly one purpose: sending you an invite. There is no mailing list and we don't share it. If you want your entry deleted, email hi@pierapp.co and we'll remove it.

Account information. If you sign in, we receive basic profile data from your chosen provider (GitHub or Google): your email, name, avatar URL, and username. We use it to identify your account, apply your plan, and route reserved subdomains to you. We also store your sign-in sessions, each with the IP address and browser or OS it came from, so the app can show you your devices list and let you revoke any of them.

Usage analytics (anonymous, opt-out). Released builds send anonymous, content-free product analytics via PostHog (US region) so we can understand adoption and feature use. It is on by default. These are counts and booleans only, for example "a dev server was started" or "a tunnel was created", plus your app version, OS, architecture, release channel, and locale. There is no link to your account: the only identifier is an anonymous, randomly generated device id. The first time you open the app, a card tells you analytics is on, and you can turn it fully off in Settings → General at any time, which also drops the anonymous id.

Tunnel metadata. When you create a public tunnel, we store what's needed to route and manage it: the assigned subdomain and hostname, a tunnel or lease record, the Cloudflare resource ids, and its lifecycle status, associated with your account. We do not inspect, log, or store the contents of traffic passing through your tunnel.

Payment information. Paid plans are processed by Polar as merchant of record. We do not receive or store your card details. We receive only the subscription status needed to apply your plan.

Operational logs. Our servers keep short-lived request logs (timestamps, paths, status codes, coarse IP) for security, abuse prevention, and debugging.

What we do not collect

We never collect your source code, file names or paths, environment variables, package names, repository identity, the contents of your tunnels' traffic, or precise location. The analytics layer is explicitly configured with autocapture, session recording, and pageview capture disabled, plus a property filter that drops anything that isn't a short, non-identifying value. There is no crash reporting in the app, and no analytics on this website.

How we use it

To operate and secure the Service, apply your plan, route tunnels, prevent abuse, send you an invite if you asked for one, and improve the product in aggregate. We don't sell your personal information.

Third parties (sub-processors)

We share the minimum necessary with the providers that run parts of the Service:

  • Cloudflare: tunnel routing and DNS for *.onpier.dev, plus the CDN that serves app downloads and updates.
  • Polar: payments and subscriptions.
  • GitHub / Google: sign-in (OAuth), when you choose to use it.
  • Railway: running the backend.
  • Neon: the database.
  • Vercel: hosting this website.
  • Resend: sending invite emails.
  • PostHog (US): anonymous product analytics, unless you have opted out.

Retention

Account, waitlist, and tunnel or lease records are kept while your account or entry is active, and as long as needed for history, billing, and abuse handling. Operational logs are short-lived. Anonymous analytics are retained per PostHog's project settings.

Your choices and rights

  • Opt out of analytics anytime in Settings → General. It takes effect immediately and the anonymous id is dropped.
  • Delete your account, waitlist entry, or data: email hi@pierapp.co and we'll delete account, waitlist, and tunnel records, subject to legal and billing retention.
  • Depending on where you live, you may have rights to access, correct, export, or erase your personal data. Email us to exercise them.

Local storage on your device

Pier stores your projects, settings, notes, and run history locally on your machine, not on our servers. Your sign-in token and any generated service passwords are stored in your OS keychain (macOS Keychain or Windows Credential Manager) rather than in files.

Children

The Service isn't directed to children under 16, and we don't knowingly collect their data.

Changes

We may update this policy. Material changes will be posted with a new effective date.

Contact

Privacy questions or data requests: hi@pierapp.co.

On this page