Past
Privacy Policy
Last updated: 6 September 2026
Past ("Past", "we", "us", or "our") is an independently developed app for recording a
short video, sealing it, and receiving it back on a future date. This policy explains
what we collect, how we use it, and the choices you have. It applies to the Past iOS
app, this website, and the services behind them.
Past is operated by an individual developer. If you have questions about this policy or
your data, contact us at support@pingoal.app.
Who can use Past
Past is intended for users aged 13 and older. It is a general-audience app and is not
directed to children under 13. We do not knowingly collect personal information from
children under 13. If you believe a child under 13 has provided us with personal
information, email support@pingoal.app and we
will delete it. If you are under 18, you should use Past only with the involvement of a
parent or guardian.
Where your recordings live
Your recordings are stored on our servers, not only on your phone.
That is what lets a capsule survive a lost phone and arrive years later. The copy on
your device is a cache. Recordings are held in private storage that only the people
entitled to a capsule can read, and access is enforced by the server, not by the app.
Information we collect
-
Account information. When you sign in with Apple or Google, we
receive a user identifier and an email address from the provider. With Sign in with
Apple you may choose Apple's private email relay, in which case we receive a relay
address rather than your personal email.
-
Your recordings. The video you record is stored so we can deliver it
to you, and to anyone you sent it to, on its unlock date.
-
Information about each recording. Its length, when it was recorded,
when it was sealed, the earliest date you allowed, the date that was drawn, your time
zone at that moment, and the name of the device you recorded on
(for example "Billy's iPhone", the name you gave the device in iOS). The device name
is shown back to you when the capsule opens, so you know where it came from.
-
Your name, when you send to someone. If you send a capsule to another
person, the display name from your sign-in provider is frozen onto that capsule at the
moment you seal it, and shown to the recipients when — and only when — it unlocks.
-
Who a capsule is for. If you share an invite link, we store which
accounts claimed it, the invite code, and when each person claimed and opened it.
-
Notification token. If you allow notifications, we store a push token
for that installation so we can tell you when a capsule unlocks, and we record whether
each notification was delivered.
-
Reports and blocks. If you report a capsule, we store the capsule, the
account that sent it, your account, your reason, and the time. If you block a sender,
we store that the block exists.
-
Support communications. If you email us, we receive what you choose
to include.
Past contains no advertising and no analytics. We do not track you
across apps or websites, we do not sell your personal information, and we do not use
your recordings to train models.
How we use information
- To store your capsules and deliver them, and any you were sent, on their unlock date.
- To send the notification that a capsule has unlocked.
- To let people claim an invite you shared, and to show the sender's name after unlock.
- To act on reports and enforce our Terms of Service.
- To respond to your support requests, and to keep the service secure and working.
Who else touches your data
We use these third-party services to operate Past. Each processes data only as needed to
provide its function:
- Supabase — authentication, database, and storage of your account, your capsules, and your recordings. Our database and storage are hosted in Seoul, South Korea.
- Apple and Google — sign-in.
- Expo — delivery of push notifications. Expo receives the push token and a capsule identifier so the notification can open the right capsule. It never receives the contents of a capsule; the notification itself carries no capsule content.
- Cloudflare — hosting for this website and the invite links it serves.
We do not use an analytics provider, an advertising network, or an email provider. If
that changes, this list changes with it.
International data transfers
Our providers store and process information in South Korea, the United States, and other
countries. By using Past, you understand that your information may be transferred to and
processed in countries other than your own.
What we can and cannot see
Your recordings are not end-to-end encrypted. They are stored privately, and the server
refuses to hand a recording to anyone who is not entitled to it — but as the operator of
the service, we are technically able to access stored content. We do not do so as a
matter of course, and there is no automated scanning of recordings. We access a specific
recording when we have a specific reason: a report, a legal obligation, or a fault we
cannot diagnose any other way.
Data retention
A sealed capsule is kept until its unlock date, which may be years away, and then for as
long as your account is active. You can delete a capsule you created at any time.
When you delete your account, from the App's Settings:
- Your account and sign-in identity are deleted.
- Capsules you made for yourself are deleted, and their recordings are deleted with them.
- Capsules you sent that nobody has claimed are deleted, and their recordings with them.
-
A capsule someone has already claimed is not deleted. It belongs to
them now, and deleting your account would take away something that was given to them.
It is unlinked from you — the account behind it is erased — but the recording and the
sender name frozen on it at seal time remain, so it still arrives on its date.
-
Reports are kept. A report is a safety record, and it survives the
deletion of the capsule and of the accounts involved. It is not linked back to a live
account once that account is gone.
If you would rather not leave a claimed capsule behind, delete it before you delete your
account.
Your choices
- Notifications — turn them off in your device settings at any time. Capsules still unlock.
- Camera and microphone — Past asks only when you first record, and iOS lets you revoke it in Settings. Without them the app cannot record, and that is the only thing it uses them for.
- Deletion — delete individual capsules, or your whole account, from the App. Or email us.
- Access — email support@pingoal.app for a copy of what we hold about you.
Security
Access to capsules and recordings is enforced on the server by row-level security
policies, so a capsule can be read only by the people on its roster, and a recording only
after its capsule has unlocked. Data is encrypted in transit. No system is perfectly
secure, and we cannot guarantee absolute security.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will
update the "Last updated" date above and, where the change is significant, tell you in
the App.
Contact
support@pingoal.app. We answer within 24 hours.