pinekey.io

pinekey.io / Privacy / gabble

gabble — Privacy Policy

Last updated: September 11, 2026 · Operated by Pinekey

gabble (listed on Google Play as "gabble – Find & Chat", package io.pinekey.justchat; formerly "just chat") is a chat app for adults. Tap Match and you are paired with a stranger in an anonymous random chat. You also have a profile that other members can see: they can browse it in Explore, send you likes, open a 1:1 chat with you by sending a paid greeting, and read your posts in a public feed. This policy explains what data gabble collects, why, who else receives it, and how long it is kept.

TL;DR

  • To use gabble you create an account with email and password, Google sign-in, or Sign in with Apple (iOS), and give a nickname, date of birth, gender, and country. Photos, a bio, and hashtags are optional.
  • Your messages, posts, likes, blocks, and activity are stored on our servers in the United States (AWS). Profile photos are hosted on Cloudflare and screened by AWS Rekognition.
  • Random chats are anonymous: the other person never receives your name or photos. Your profile is not anonymous: other members see it in Explore, in their Likes list when you like them, next to your feed posts, and in 1:1 chats opened with a greeting.
  • We show ads (Google AdMob, which uses your advertising ID), process purchases through Google Play or the App Store, and use Firebase for push notifications, analytics, and crash reports. We do not sell your data.
  • gabble is for people 18 and older.
  • Delete your account in the app (Profile → Settings → Delete account) or request it at pinekey.io/gabble/delete-account. Some records are kept after deletion — see section 03.

01 Who we are

gabble is built and operated by Pinekey (listed as "Pine Key" on Google Play), an independent mobile app studio, which is the data controller for the information described here. For any privacy question or request, contact pinekey.dev@gmail.com.

Privacy officer: Byunghun Lee (이병훈) — pinekey.dev@gmail.com

02 Information we collect

Account and profile

  • Sign-in. Your email address and password (stored only as a salted hash), or — with Google sign-in or Sign in with Apple — the email address and account identifier the provider gives us. With Google sign-in, your Google display name is suggested as your nickname.
  • Required profile details. Nickname, date of birth (used to confirm you are 18 or older and to show your age), gender, and country (you choose it from a list; we do not detect your location).
  • Optional profile details. Profile photos, a bio, and up to 10 hashtags.

Content and activity

  • Messages. The chat messages you send in random chats and in 1:1 chats, the opening message of each greeting you send, and which messages you have read.
  • Posts and reactions. Feed posts you write, likes on posts, likes you send to other people's profiles, and people you block.
  • Matching and activity. When you join and leave the matching queue, who you were matched with (so we can avoid re-matching you with the same person), and the time you were last active and the days you were active — the app reports both every 15 minutes in the background while you are signed in, even when you are not using it.
  • Feedback. App feedback you choose to send, and — if you delete your account — the reason you select, any comment you add, and your app platform and version.
  • Purchases. When you buy Gum (in-app currency) or subscribe, we receive the store's purchase token, order ID, product, price, currency, and subscription dates from Google Play or the App Store. We never receive your card or bank details.
  • Emails you send us. Support, deletion, and safety emails, including any attachments, are kept in our email inbox.

Device and technical

  • Push token. Your Firebase Cloud Messaging token and device platform, so we can deliver notifications.
  • Collected by SDKs in the Android app. Your advertising ID and app set ID, your IP address (used to estimate general location), device information, interactions with the app and its ads, app usage events, crash reports, and diagnostic logs — collected by Google AdMob and Firebase (see section 04). Diagnostic logs can include technical identifiers such as your account ID or push token.
  • Server logs. Our servers record request logs — IP address, time, requested address, your account ID when you are signed in, and device headers such as the user agent — for security and troubleshooting.

How we use it

To run the service (accounts, matching, chats, profiles, feed, notifications, purchases); to keep it safe (age requirement, photo screening, blocking, limiting repeated sign-in attempts, and investigating abuse); to show ads to users without a subscription; and to understand usage, measure the service, and fix crashes.

What other users see

  • Random chats: the other person sees your messages, when you have read them, and when you are typing — but not your nickname, photos, or other profile details.
  • Your profile — nickname, approved photos, age, gender, country, bio, and hashtags — is visible to other members: in Explore (which lists recently active members, with the time they were last active), on your profile page, in the Likes list of anyone you like (they also get a notification with your nickname), next to your feed posts, and in 1:1 chats opened with a greeting that you send or receive. In 1:1 chats the other person also sees read and typing status.
  • Feed posts are public to all members.

What we do not collect

gabble does not request location permission and does not collect precise (GPS) location. It does not access your contacts, microphone, camera, SMS, or files; the only photos we receive are the ones you pick with the system photo picker and upload.

03 How your data is stored

  • Your account, profile, messages, posts, activity, and purchase records are stored in databases on Amazon Web Services (AWS) in the United States (N. Virginia region). Profile photos are stored and delivered by Cloudflare Images. If you live outside the United States, your data is transferred there over encrypted connections each time you use the app. Transfers from the EEA, the UK, and Switzerland rely on the safeguards in our providers' data protection terms, such as Standard Contractual Clauses. You can stop the transfer by deleting your account.
  • Passwords are stored only as salted hashes (Argon2id; accounts carried over from just chat keep their earlier bcrypt hash until their next sign-in). Data between the app and our servers travels over HTTPS.
  • Our team can access stored data, including chat messages, when it is needed to run the service, respond to your requests or to reports, investigate abuse, or comply with the law. Passwords and tokens are hidden in our internal tools.
  • The app caches your profile, recent messages, and session tokens on your device.
  • Push notifications for 1:1 chats include the sender's nickname and a preview of up to 200 characters of the message; like notifications include the sender's nickname. Notifications for random chats contain neither.

Retention and deletion

We keep your data while your account exists. You can delete your account at any time in the app — Profile → Settings (gear icon) → Delete account. Deletion in the app takes effect immediately and signs you out on every device. You can also request deletion at pinekey.io/gabble/delete-account; requests by email are handled by our team and completed within 30 days of confirming the request.

Before you delete: deleting your account does not cancel a subscription bought through Google Play or the App Store — cancel it in the store first. Unused Gum, including Gum you paid for, is lost and cannot be restored.

Deleted when your account is deleted: your sign-in identities and password, push tokens, profile photos (we also delete the image files from Cloudflare; if a file deletion fails, the file can remain at its address — email us and we will remove it), your hashtags, your feed posts and the likes on them, likes you gave to posts, likes and greetings you sent or received, your blocks, your place in the matching queue, and your Gum balance.

Chats: you leave every chat. A chat in which you were the last participant is deleted together with its messages. In a chat where the other person remains, the messages you already sent — including the opening message of a greeting — stay visible to them, shown without your name or photo, until that chat is deleted.

Kept after deletion, de-identified: purchase, subscription, and Gum ledger records are kept with the link to your gabble account removed, for refunds, accounting, tax, and fraud prevention; they still contain the store's order ID and purchase token, which Google or Apple can associate with your store account. App feedback is kept the same way, to improve the app. A de-identified account record is also kept — your nickname is replaced and your bio erased — together with your gender, date of birth, country, sign-up date, match history, daily-activity records, and the deletion reason and any comment you gave (with your app platform and version), for aggregate statistics and so matching keeps working for the people you were matched with. It no longer contains your email, sign-in identifiers, nickname, photos, or contact details, but because it keeps an internal account number and your date of birth, we still treat it as personal data. These records have no automatic deletion date; we keep them for as long as they are needed for these purposes.

Backups and logs: automated database backups are kept for one day, server logs are kept for a limited time, crash reports and diagnostic logs are kept by Firebase Crashlytics for 90 days, and database snapshots we take before updating the service are kept until we delete them. Your data can remain in these copies for that time.

Accounts created before September 10, 2026: on that date gabble (formerly "just chat") moved to a new system. We kept an archive of the data the previous system held at that time — including your email address, password hash, nickname and other profile details, photo links, push token, posts, purchase and subscription records, and chat history — together with backups made before the switch. The archive is kept apart from the service, in our database on AWS in the United States and in a MongoDB Atlas database, and is not used to run gabble. Deleting your gabble account does not remove your data from this archive; email pinekey.dev@gmail.com and we will delete your data from the archive. Copies inside database snapshots and backups remain until those snapshots and backups are deleted.

Your choices and rights

You can edit your profile in the app, turn notification categories on or off in Profile → Notification, and reset or delete your advertising ID in your Android settings. You can also ask us to access, correct, export, or delete your data, or exercise other rights you have under the law where you live (for example in the EEA, the UK, or Korea), by emailing pinekey.dev@gmail.com. Where the law requires a legal basis, we rely on our contract with you (running your account and the service), our legitimate interests (keeping gabble safe, preventing fraud, and fixing crashes), and legal obligations. You can also complain to your local data protection authority.

04 Third parties

gabble relies on the following services. We do not sell your personal data.

ServicePurposeData involved
Amazon Web ServicesHosting and databases (United States)All account, profile, message, activity, and purchase data
AWS RekognitionAutomatic screening of profile photos for explicit contentThe photos you upload. We have opted out of AWS using this content to improve its own services.
Cloudflare ImagesPhoto storage and deliveryYour profile photos, stored with your account ID
Google Sign-In · Sign in with Apple (iOS)Optional sign-inEmail address, account identifier, display name
Google Play Billing · App Store (iOS)Purchases and subscriptionsPurchase token, order ID, product, price, and your account ID or a hash of it, attached to the purchase to match it to your account
Firebase Cloud Messaging · Apple Push Notification servicePush notificationsPush token and the notification content described in section 03
Google AdMob (Android)In-app adsAdvertising ID, app set ID, IP address, device information, and interactions with the app and its ads — collected and shared with Google for advertising, analytics, and fraud prevention. The SDK runs for all users, including subscribers who are not shown ads.
Google Analytics for Firebase (Android)Usage analyticsApp usage events, including in-app purchase events; app instance ID; advertising ID; device information; approximate location derived from IP address
Firebase Crashlytics (Android)Crash and error diagnosticsCrash reports, error logs (which can include technical identifiers), device model and OS version, installation ID
MongoDB AtlasPart of the archive of data from before September 10, 2026 (see section 03); not used to run gabbleData held by the previous system, such as matching and group-chat data
Google (Gmail)Sending password-reset emails and receiving your emailsYour email address, a one-time reset link, and the emails you send us

AWS, Cloudflare, MongoDB Atlas, Firebase, and Gmail process this data on our behalf as service providers. Google AdMob also uses the data it collects for its own advertising, analytics, and fraud-prevention purposes under Google's policies. Apple and Google handle sign-in and store purchases under their own terms. Photos that AWS Rekognition cannot clear stay hidden from other users unless they pass manual review.

05 Children's privacy

gabble is for adults. You must be 18 or older to use it, and we check your date of birth at sign-up and whenever you change it. This check started on September 11, 2026; accounts created earlier, including those carried over from just chat, were not held to it. gabble is not directed to anyone under 18. On Google Play it is restricted to users aged 18 and older, so users identified as minors cannot find or download it; in the Republic of Korea it carries the 청소년이용불가 rating. If we find that an account belongs to someone under 18, we delete it. To report a suspected minor, email pinekey.dev@gmail.com. Our child safety standards are at pinekey.io/gabble/child-safety.

06 Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected on this page with a new "Last updated" date.

07 Contact

Questions or requests, including access, correction, and deletion: pinekey.dev@gmail.com. Account deletion without the app: pinekey.io/gabble/delete-account.

© 2026 Pinekey

Privacy · pinekey.io