Privacy Policy
Last updated: September 11, 2026
This Privacy Policy describes how CakePing ("we", "us", or "our") collects, uses, and protects information when you use the CakePing mobile application (the "App") and related services. By using the App, you agree to the practices described in this Privacy Policy.
1. Overview
CakePing is a cake card sharing app that lets you browse cake designs, personalise them with names and messages, and share them via rich link previews. We are committed to protecting your privacy and being transparent about what data we collect and why.
The short version: We collect minimal data needed to operate the app. We do not require you to create an account. We do not sell your data. We use third-party attribution services to understand which ad campaigns bring users to CakePing and to measure campaign performance.
2. Information We Collect
2.1 Anonymous Install ID
When you install CakePing, the app generates a random, unique identifier called an Install ID (a UUID v4 string). This ID:
- Is generated locally on your device using a cryptographically secure random number generator
- Is stored securely in your device's secure storage (Keychain on iOS, EncryptedSharedPreferences on Android)
- Is used to identify your installation anonymously — not tied to your name, email, phone number, or any personally identifiable information
- Persists across app launches but can be cleared by uninstalling the app
Purpose: Used to associate your app activity (such as shared CakePings and subscription status) with your device without requiring an account.
2.2 Device and App Information
When the app communicates with our servers, it automatically sends the following non-identifying metadata:
- Platform (iOS or Android)
- App version and build number
Purpose: Used for compatibility, debugging, and providing appropriate content. This data is stored as part of your anonymous user profile and is updated each time the app contacts our servers.
2.3 CakePing Sharing Data
When you create and share a CakePing, the following information is processed and stored:
- Recipient name ("To" field) — the name you enter for the recipient
- Sender name ("From" field) — the name you enter for yourself
- Custom message — the optional message you write
- Image URL — the URL of the cake image you selected
- Template key — the identifier of the template design you chose
- Sender's Install ID — your anonymous Install ID (to associate the share with your device)
- Sender's platform and app version — iOS/Android and version info
Purpose: This data is used to generate a personalised, shareable HTML page with rich link previews (Open Graph meta tags) that displays correctly when shared via WhatsApp, iMessage, SMS, or social media. The generated page is stored on our CDN (Cloudflare R2) and is accessible via a unique, unguessable short URL.
Note: The names and message you enter are provided by you for the purpose of sharing. They are embedded in the shared link's HTML and Open Graph tags. Anyone with the share link can view this content.
2.4 Subscription Information
If you purchase a CakePing Gold subscription:
- Purchase and entitlement data is processed by RevenueCat (our subscription management provider) and the respective app store (Apple App Store or Google Play Store)
- We receive webhook notifications from RevenueCat containing: your anonymous Install ID (used as the app user ID), entitlement ID, product ID, subscription status (active/inactive), and expiration date
- We store this subscription status in our database linked to your anonymous Install ID
Purpose: To manage your subscription access and verify your entitlement to premium features.
We do NOT receive or store: your full name, email address, billing address, or payment card details. All payment processing is handled by Apple/Google through their respective billing systems.
2.5 Attribution Data
We use AppsFlyer, a mobile attribution and marketing analytics platform, to understand which ad campaigns drive app installs and in-app subscriptions. AppsFlyer collects and processes the following data:
- AppsFlyer Device ID — a unique identifier assigned by AppsFlyer to your device
- Device model, operating system version, and screen dimensions
- IP address (used for coarse attribution, not stored long-term)
- Install referrer data (Android only) — information about where the install originated
- SKAdNetwork data (iOS only) — Apple's privacy-preserving ad attribution framework
- App launch events and session data
- In-app purchase and subscription events (forwarded by RevenueCat, including event type, product ID, and revenue amount)
Purpose: To measure the effectiveness of our advertising campaigns, attribute installs to the correct ad source, and share conversion data with our advertising partners (Meta/Facebook and ChatGPT/OpenAI Ads) for campaign optimization.
2.6 Locally Stored Data
The following data is stored locally on your device using secure storage:
- Install ID — your anonymous identifier
- Message preferences — the "To", "From", and "Message" text you've entered (so you don't have to re-enter them each time)
- Theme preference — whether you've selected light or dark mode
- Saved cakes — IDs of cakes you've bookmarked (stored in memory only, not persisted to server)
Purpose: To provide a better user experience by remembering your preferences between app sessions.
3. How We Use Your Information
We use the collected information solely for:
- Operating the app — displaying cake designs, categories, and templates
- Generating and hosting shared CakePings — creating personalised shareable links
- Managing subscriptions — verifying and maintaining your Gold subscription access
- Attribution and campaign measurement — understanding which ad campaigns drive installs and subscriptions, and measuring return on ad spend
- App improvement — understanding aggregate usage patterns (e.g., total shares, popular templates) to improve our content
- Technical support — diagnosing and fixing technical issues
We do not use your information for:
- Selling or renting to third parties
- Creating user profiles for marketing
- Tracking your location or behaviour across other apps
4. Third-Party Services
CakePing uses the following third-party services. Each has its own privacy policy:
4.1 AppsFlyer
- Purpose: Mobile attribution and marketing analytics — tracking which ad campaigns drive app installs and in-app events
- Data shared: AppsFlyer Device ID, device model, OS version, IP address (coarse), install referrer (Android), SKAdNetwork data (iOS), app launch events, and subscription/purchase events forwarded by RevenueCat (event type, product ID, revenue)
- Data forwarded to ad partners: AppsFlyer may forward install and in-app event data to our advertising partners (Meta/Facebook and ChatGPT/OpenAI Ads) for campaign measurement and optimization
- Privacy policy: https://www.appsflyer.com/privacy-policy/
4.2 RevenueCat
- Purpose: Subscription management and paywall presentation
- Data shared: Anonymous Install ID (as app user ID), AppsFlyer Device ID, platform, app version
- Privacy policy: https://www.revenuecat.com/privacy
4.3 Meta (Facebook) Ads
- Purpose: Ad campaign delivery and optimization
- Data received: Install events, subscription events (StartTrial, Subscribe), and purchase events — forwarded via AppsFlyer postback
- Privacy policy: https://www.facebook.com/privacy/policy/
4.4 ChatGPT Ads (OpenAI)
- Purpose: Ad campaign delivery and optimization
- Data received: Install events, subscription events, and purchase events — forwarded via AppsFlyer postback
- Privacy policy: https://openai.com/policies/privacy-policy/
4.5 Cloudflare R2 (Object Storage & CDN)
- Purpose: Storing and serving cake images, HTML templates, and rendered CakePing pages
- Data stored: Template HTML files, cake images, and generated shareable CakePing pages (containing the names and message you entered)
- Privacy policy: https://www.cloudflare.com/privacypolicy/
4.6 PostgreSQL Database (Supabase or Render)
- Purpose: Storing anonymous user records, subscription state, cake image metadata, categories, and CakePing share metadata
- Data stored: Anonymous Install ID, platform, app version, subscription status, share metadata (names, message, image URL, template key)
- Privacy policy (Supabase): https://supabase.com/privacy
- Privacy policy (Render): https://render.com/privacy-policy
4.7 Apple App Store / Google Play Store
- Purpose: App distribution, in-app purchases, and subscription billing
- Data shared: Handled entirely by Apple/Google per their own policies
- Apple privacy: https://www.apple.com/legal/privacy/en-ww/
- Google privacy: https://policies.google.com/privacy
4.8 In-App Review (Apple/Google)
- Purpose: Prompting users to rate the app on the App Store or Play Store
- Data shared: No personal data is sent by our app; the review prompt is handled entirely by the OS
5. Data Storage and Security
5.1 Data Storage Location
- Database: Hosted on Supabase (PostgreSQL) or Render, depending on configuration
- File storage: Cloudflare R2 with global CDN distribution
- Backend API: Hosted on Render or via ngrok for development
5.2 Security Measures
- Your Install ID is stored in secure device storage (iOS Keychain / Android EncryptedSharedPreferences)
- All API communication uses HTTPS (TLS encryption)
- RevenueCat webhook signatures are cryptographically verified using HMAC-SHA256
- Database connections use SSL/TLS where configured
- The backend API uses CORS restrictions to limit cross-origin access
- No passwords are stored — we do not use password-based authentication
5.3 Data Retention
- Anonymous user records: Retained for as long as the app is in operation
- CakePing share pages (R2): Retained indefinitely unless manually deleted by an admin
- Subscription state: Retained for as long as needed to manage your subscription
- Attribution data: Retained by AppsFlyer according to their data retention policy
- Local device data: Cleared automatically when you uninstall the app
6. What We Do NOT Collect
To be explicit, CakePing does not collect or process:
- Your email address or phone number
- Your real name (unless you enter it as the "From" name when sharing a CakePing)
- Your precise physical location or GPS data
- Your contacts list or address book
- Photos from your camera roll or gallery (we do not request camera or photo permissions)
- Microphone audio
- Bluetooth or NFC data
- Your browsing history
- Data from other apps on your device
7. Sharing of Your Data
We do not sell, rent, or trade your data with any third party.
The only scenarios in which your data may be shared are:
1. Shared CakePing links: When you share a CakePing, the link you share contains the names and message you entered. Anyone who opens that link can see this content. This is the intended functionality of the app.
2. Attribution partners: We share anonymous install and subscription event data with AppsFlyer, which may forward it to our advertising partners (Meta/Facebook and ChatGPT/OpenAI Ads) for campaign measurement and optimization. This data is not linked to your personal identity.
3. Legal compliance: If required by law, court order, or government request, we may disclose data as legally required.
4. Service providers: Our third-party service providers (AppsFlyer, RevenueCat, Cloudflare, database host) process data on our behalf to operate the service. They are bound by their own privacy policies and data processing agreements.
8. Your Rights
8.1 Access Your Data
You can view your anonymous Install ID in the app's Settings → Device → Install ID. This ID is the key to all data associated with your installation.
8.2 Delete Your Data
- Uninstall the app: This removes your Install ID, message preferences, theme preference, and saved cakes from your device
- Request deletion: You can request deletion of your server-side data (anonymous user record, CakePing shares, subscription state) by contacting us with your Install ID
- Delete shared links: Individual shared CakePing pages can be deleted by an admin upon request
8.3 Opt Out
- Sharing: Simply do not use the share function
- Subscriptions: Cancel your subscription via the App Store or Google Play Store
- Attribution tracking:
- **iOS**: You can limit ad tracking by denying the App Tracking Transparency (ATT) prompt when it appears, or by going to Settings → Privacy & Security → Tracking and disabling tracking for CakePing
- **Android**: You can reset or delete your advertising ID by going to Settings → Privacy → Ads and selecting "Delete advertising ID"
- All data: Uninstall the app and contact us to delete your server-side records
8.4 Disable Data Collection
The app uses AppsFlyer for attribution and campaign measurement. You can limit this tracking by:
- **iOS**: Denying the App Tracking Transparency (ATT) permission. When ATT is denied, AppsFlyer uses Apple's privacy-preserving SKAdNetwork for limited attribution.
- **Android**: Resetting or deleting your Google Advertising ID in device settings.
- **All platforms**: Uninstalling the app stops all data collection.
The only other data sent to our servers is:
- Your anonymous Install ID and device metadata (sent on app launch)
- CakePing share data (sent only when you choose to share)
9. Children's Privacy
CakePing is designed for general audiences and does not specifically target children under 13 (or the equivalent age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
10. International Users
CakePing is available globally. Your data may be processed and stored in servers located in the United States, European Union, or other regions where our service providers operate. By using the app, you consent to the transfer and processing of your data in these jurisdictions.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the "Last updated" date at the top of this page
- Notify you of significant changes through the app or via other reasonable means
We encourage you to review this Privacy Policy periodically.
12. Open Source Transparency
CakePing's backend and admin panel are built with transparency in mind. The data we collect is limited to what is described above, and we have designed the system to minimise data collection while still providing a functional service.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us at:
- Email: milan@appmixo.com
When contacting us about your data, please include your Install ID (found in Settings → Device) so we can locate your records.