Privacy Policy

Effective date: 2026-09-18

Last updated: 2026-09-20

Pip is a food companion app. It suggests dishes you might want to eat. This policy explains what we hold about you, why, and how to get rid of it. If you live in Washington or Nevada, please also read our Consumer Health Data Privacy Policy, which covers the food-restriction information you give us and gives you additional rights.

Pip is operated by Craft Fidelity Studios, LLC, a Delaware limited liability company. You can reach us at support@pipfind.com.

Pip is available in the United States only

Pip is offered only to people in the United States. We do not offer Pip in the European Union, the United Kingdom, or anywhere else, and we are not asking for or knowingly accepting information from people outside the United States.

What we hold

We have built Pip to hold as little about you as we can while still being useful. Here is the entire list.

A pseudonymous account ID. You sign in through Google. We receive confirmation from Google that the sign-in succeeded. Google's sign-in service assigns your account an ID: a random string that does not contain your name or email address. We do not create it. That ID is what our systems use to recognize you.

We do not store your name. We do not store your password, and we never see it.

Your email address, and the one place it lingers. We do not keep your email address in your account. There is no field for it. When we need it, we read it from Google at that moment and discard it.

We want to be more careful than that sentence alone allows. When our staff act on an account, Google's own administrative logs record what happened, and those entries can contain the email address of the account involved. Those logs are deleted after 30 days. Google also keeps its own platform audit records of administrative and system events for 400 days, which we cannot shorten. Those records describe what our staff and systems did rather than what you did, but we would rather tell you that not everything clears at 30 days than let you assume it does.

If you join our waitlist, that is different, and it is described further down.

Foods you tell us you cannot or will not eat. You tell Pip which foods to keep away from you, whether that is an allergy, a medical restriction, a religious or ethical rule, or simple dislike. We store what you told us against your pseudonymous ID so that Pip's suggestions respect it. This is the information that Washington and Nevada law treat as health information, and our Consumer Health Data Privacy Policy describes it in more detail. We also learn from it in one specific way, and we would rather name it than fold it into a general phrase about improving our services: when diners tell us a restriction and then tell us whether a suggestion worked, we use that to learn which dishes genuinely suit that restriction. What we learn is a fact about the dish, not a picture of you. We do not use it to decide anything about you beyond which dishes to suggest.

What you tell us about our suggestions, and the meals you log. When Pip suggests a dish, you can tell us whether it was a good suggestion. When you say you are getting a dish, Pip opens a log entry for that meal; you can rate it, tell us the day you ate it, and write a note in your own words. We keep each of these against your pseudonymous ID alongside which dish it was, which restaurant, and which of your restrictions were active at the time. We also keep which visit it belonged to. A visit means you, one restaurant, within a few hours; we group your reactions and log entries under it so that changing your mind is not counted twice, and so that you can find that visit again. A log entry is private. There is no way to share one today, and if that changes we will say so here first. If you write a note, please know it is your own words and we do not control what goes in it, so it may contain health information; we hold it to the same bar as everything else here. We keep what you write for 180 days and then remove it; the rating and the reaction stay.

Whether you were at the restaurant. If you let Pip use your location, we compare your position once, in memory, with the restaurant you are rating, and keep one word: at the restaurant, not at the restaurant, or unknown. We do not keep your coordinates, we do not write them to any log, and we do not keep the comparison. We ask for your location only when it helps you, never at sign-up, and if you say no, or your phone cannot tell, the word is "unknown" and nothing else changes. We use it for one thing: to tell apart what you told us at the table from what you told us later, which helps us learn which suggestions work. We never do this for a place that is not a restaurant. If a listing is a pharmacy, a grocer, or anything else, the word stays "unknown" by rule.

A record of ingredient searches, kept apart from your account. Separately from your account, we keep a record of the ingredient searches people run in Pip. Each entry holds the word that was typed, whether Pip found matching dishes, a rough indication of how much of the menu got filtered out, and the day it happened. Nothing else.

There is no ID of any kind in these entries. Not your account ID, not a session ID, not a device ID, not your network address. We record the day, not the time of day. We have an internal engineering rule against ever adding an identifying column to this record, and we do not have a way to work backward from an entry to a person.

We keep this record for one reason, and we want to state it plainly rather than hide it inside a general phrase about improving our services: knowing which ingredients people actually look for, and where Pip came up empty, tells us which foods to cover better, and it is how we decide what to build next.

We publicly commit that we will process this record only in this unidentified form, that we will not attempt to re-identify it or link it to any person or device, that we will not combine it with any other record that could identify a person, and that we will impose the same obligations by contract on anyone who ever receives it. We do not share it outside our company today.

A record of actions our staff take on accounts. When our staff create, disable, re-enable, send a sign-in link for, or delete an account, we record what was done, when, which staff member did it, and which account it was. We keep this so we can show who did what to an account, including after the account has been deleted. Once an account is deleted, this record still identifies it by your account ID. We are building a coded reference to replace it, and until that exists we would rather tell you what the record actually holds.

What our Consumer Health Data Privacy Policy does not cover. If you joined our waitlist, the email address you gave us is not consumer health data and is not covered by that policy. It is an address and a date. Waitlist entries are stored apart from accounts, carry no information about food, allergies, diet, or health, and are not connected to any restriction you may later enter as a Pip user. They are described below.

Our record of ingredient searches contains the word typed, whether Pip found matches, a rough indication of how much of the menu got filtered out, and the day. We do not claim this record is exempt under Nevada's health-data law: that exemption requires stripping the date down to the year, and we keep the day. We would rather tell you that than claim an exemption we have not earned. It carries no account ID, session ID, device ID, or network address, we record the day rather than the time of day, and we cannot work backward from an entry to any person. It is described above.

What we do not do

We do not sell your information. Not for money, and not in trade for anything else of value.

We do not share your food restrictions with advertisers, data brokers, or anyone buying audiences.

We do not use your food restrictions to target advertising to you.

We do not build a profile of your health beyond the restrictions you typed in yourself.

We do not track your precise location to figure out where you seek health care, and we do not set up digital perimeters around clinics, hospitals, pharmacies, or any other place that provides health care.

We do not keep your location. The only thing we keep from it is the one word described above.

Who else touches your information

Google. Google Identity Platform handles your sign-in. Your relationship with Google is governed by Google's own privacy policy. We receive only the sign-in result and, when we need it in the moment, your email address.

Google Cloud. Pip runs on Google Cloud Platform, using Cloud Run for the application and Cloud SQL for the database. Google holds our data on our instructions under data processing terms and is contractually barred from using it for its own purposes.

That is the complete list. We are not sharing your information with anyone else, and if that changes we will tell you what changed and get your permission before it applies to your food restrictions.

If we are ever acquired. If our business is sold or merged, information may transfer to the buyer as part of that transaction. The buyer would take on the same obligations described in these policies.

How long we keep things

We do not run a fixed calendar for deletion. We keep things according to the rules below, and we would rather state rules we actually follow than a number we do not yet enforce automatically.

What you tell us about our suggestions, and the meals you log. The note you write is kept for 180 days and then removed, along with the record of which restrictions were active at that visit. The rest of a log entry — the dish, the restaurant, your rating, the day you gave us — stays for as long as your account exists, or until you delete that entry yourself in the app. The record of a visit — which restaurant, when, and whether you were there — stays for as long as your account exists. We are saying plainly that your account therefore holds a list of the restaurants you told Pip about and when. We run that removal by hand today rather than on a schedule, we keep a record of each run, and we would rather say so than imply it is automatic.

Your pseudonymous ID and your food restrictions. Kept for as long as your account exists. When you delete your account, they are deleted. See the next section for exactly what that means.

Your email address. Not kept in your account at all. Read from Google when needed, discarded immediately after. Administrative log entries that can contain it are deleted after 30 days, with the 400-day platform records described above as the exception we cannot shorten.

A waitlist entry. Deleted when you get an account, when you ask us to remove it, or 24 months after you joined if none of those has happened.

Your address on our provider's do-not-mail list. When you unsubscribe, your email address stays on our email provider's do-not-mail list for as long as we use that provider. We keep it for one reason: so that we cannot email you again by mistake. Removing it is what would put you back on the list.

The record that we deleted your account. When your account is deleted we keep a record that the deletion happened and the date it happened. That record does not contain your food restrictions, your email address, or anything else you typed. It does identify the account by its ID, and it holds a count of how many items were removed — for example, how many restrictions you had stored. We are telling you about that count rather than describing the record as holding nothing about you. We keep this record so that we can show a deletion happened. We are building a coded reference to replace the account ID here, and a way to re-apply deletions if an old copy of your data ever reappears; neither exists yet, and when they do we will say so here.

The ingredient search record. The entries are not connected to you or your account and cannot be traced back to you, so deleting your account does not affect them. We keep them in that unidentified form for as long as they are useful for improving Pip. We do not yet operate an automatic deletion schedule for them. When we build one, we will publish the schedule here.

Our server's operating logs. Like any service, our servers keep technical logs of the requests they handle in order to run and secure Pip. These are deleted after 30 days. We set that period ourselves and enforce it, rather than inheriting a default that could change underneath us.

Deleting everything

You can delete your account from inside Pip, and you can also ask us to delete it by writing to support@pipfind.com. You do not need to create an account, or keep one, in order to ask us for anything described in these policies.

Deletion is permanent, with one narrow exception we describe honestly rather than bury: if you have unsubscribed from our newsletter, your address stays on our provider's do-not-mail list so that the unsubscribe cannot be undone. That is covered above, and it is the only thing that survives. There is no recycling bin and no recovery window for anything else. When you ask:

We delete your account at the identity provider first, so the sign-in path is closed before anything else happens.

We then delete your pseudonymous ID and everything stored against it: your food restrictions, your reactions, your log entries, and the visits they belonged to.

We notify the identity provider that holds your account and require them to delete it as well.

We write a record that the deletion happened: the date, and a coded reference to your account, used only to re-apply the deletion if an old copy of your data reappears.

Copies inside our backup systems are removed as those systems cycle, which for our production database is about seven days. We are telling you the real number rather than the outer limit the law allows. If we ever restored a backup taken from before your deletion, your data would come back in that copy and we would have to find and delete it again by hand. We do not yet have an automatic way to do that, and when we build one we will say so here.

We will act on a deletion request within 45 days of receiving it. If a request is unusually complex we may take one additional 45 days, and we will tell you before we do.

Your other rights

You can ask us to:

Write to support@pipfind.com. We will not charge you, we will not make you sign up for anything, and we will not treat you worse for asking. We answer these free of charge up to twice a year.

If we say no. If we refuse a request, we will tell you why and how to appeal, and we will decide the appeal within 45 days. If we deny the appeal, we will give you a way to complain to your state attorney general. Washington residents can contact the Washington Attorney General's office; Nevada residents can contact the Nevada Attorney General's office.

Security

Access to your food restrictions inside our company is restricted to the people and systems that need it to make Pip work. We use commercially standard technical and organizational safeguards to protect it, appropriate to how little we hold and how sensitive it is.

Children

Pip is not for people under 13, and we do not knowingly collect anything from them. If you believe a child has created an account, write to us and we will delete it.

Changes

If we change these policies, we will update the date at the top and, where the change is significant, tell you in the app. Change of 2026-09-20, taking effect 2026-09-30: we added what we keep about the meals you log, which visit they belonged to, and the one word about whether you were at the restaurant; nothing is collected under those additions before that date. If we ever want to collect a new category of health information, or use what we already hold for a new purpose, we will disclose that first and ask your permission before doing it. We will not apply a new purpose to information we already hold without asking.

Contact

Craft Fidelity Studios, LLC
8 The Green STE B, Dover, DE 19901
support@pipfind.com