This Privacy Policy explains how Pink Door Multimedia LLC ("Pink Door," "we," "us") handles information in connection with the Preen Display apps for iOS/iPadOS and macOS (the "Apps"), the website at preendisplay.com (the "Site"), and any optional online services we operate for the Apps (together, the "Services").
The short version. Preen is built to keep your data on your own devices. Local use needs no account. Purchasing or using Preen Plus requires a platform account connected to your Mac, iPhone, or iPad. There are no analytics or crash-reporting SDKs, no advertising, and no tracking. Your widgets, the data shown on them, and your device pairing all live on your Mac and your iPhone or iPad and travel directly between them over your local network. We do not sell personal information. Native device connections keep widget content on your devices. Optional browser devices process widget content through our platform, as described in section 3.4; explicitly saved private backups store template source on the platform, as described in section 3.7.
1. Information we do not collect
The Apps contain no analytics, telemetry, advertising, or crash-reporting frameworks. We do not collect:
- usage analytics, behavioral data, or advertising identifiers;
- your location, contacts, calendars, photos, or health data;
- widget content from native display connections; optional browser devices and explicit private backup saves process content as described below.
We do not sell personal information, and we do not share personal information with third parties for advertising or cross-context behavioral advertising.
2. Information that stays on your devices
To work, the Apps store information locally on your Mac and iOS device, including: your widgets and their data, pairing records (device names, a per-device identifier, and your Mac's local network address, including its hardware MAC address, used for features like Wake-on-LAN), security keys and session tokens (kept in the system Keychain), and, if you enable related widgets, system statistics your Mac reads locally (such as CPU, memory, and thermal readings, or usage data from developer tools you connect). This information is exchanged directly between your own devices over your local network using encrypted connections. For native device connections, widget content and pairing secrets are not transmitted to us. If you enable Mac Text Select, Preen reads the text you select in other apps through the macOS Accessibility access you grant; that text is shown only to the widget you open from the selection menu on your Mac and is not stored, added to the shared widget feed, forwarded to your iPhone or iPad, or sent to us. Optional browser devices, account and subscription records are described below.
Camera. The iOS app uses your device's camera for exactly one thing: reading the pairing QR code that Preen shows on your Mac. The camera opens only when you start pairing and closes as soon as a code is read or you leave that screen. Frames are decoded on your device to recover the pairing details and are not recorded, saved, or transmitted anywhere — not to us, not to your Mac, and not to anyone else. Nothing the camera sees is used for any other purpose, and no image or video is retained after the scan. iOS asks for camera permission the first time you pair; because scanning that code is the only way to pair, the Apps cannot be paired without it. The Apps do not access your photo library.
3. Information we receive
The small amount of information that can reach infrastructure we operate:
3.1 Software update checks (macOS app)
The macOS app periodically checks preendisplay.com for updates (via the Sparkle updater). Like any web request, this exposes your IP address, the app version requested, and a browser-style user agent to our web server logs. The update check sends no system profile or other telemetry. Server logs are used only to operate and secure the Service and are retained for a limited period.
3.2 The website
The Site is a static website. It uses no analytics scripts, no advertising, and sets no tracking cookies. Our hosting infrastructure keeps standard web server access logs (IP address, requested page, user agent, timestamp) for security and operations.
3.3 Preen Plus subscriptions (optional, where available)
Before purchasing Preen Plus through the App Store, you create or sign in to a Preen account. The purchase is processed by Apple through the App Store under Apple's own terms and privacy policy. Apple does not send us your name, email, billing address, or payment details with its transaction records. To honor your subscription and link it to your account, our server receives and stores from Apple: transaction identifiers, the product purchased, subscription status and expiry, and a random per-install identifier (a UUID generated on your device). The account lets the same subscription authorize Private Relay on your connected Mac and iPhone or iPad.
For website subscriptions, you create or sign in to an account at platform.preendisplay.com. We store your email address and a salted password hash. We share your email with Stripe to create a billing customer; Stripe collects payment and billing details through its hosted checkout and customer portal under its Privacy Policy. Our application database stores Stripe customer, checkout, subscription and event identifiers, the plan, subscription status and expiry, cancellation state, and the version and time of your terms acceptance. We do not store full card numbers or security codes. Billing information may be available to us through Stripe when handling support requests.
Signing in on a Mac, iPhone, or iPad stores its device type and name, account association, a hash of a random sign-in credential, and creation, approval, expiry and revocation times. We also store relay identifiers for Macs authorized to use the account’s Plus access. The credential and cached account status are stored in the device’s Keychain. Signing in on iOS to sync a subscription sends a signed App Store transaction to our server for verification and links the purchase to your account, including its email address. A linked subscription can provide Plus to your other connected devices. Signing in alone does not send widget content; an explicit private backup save uploads template source as described in section 3.7. You can disconnect devices or unlink an App Store purchase at your Preen Plus account. Signing out or disconnecting a device does not cancel a subscription or automatically unlink the purchase.
To administer the Plus allowance, we assign an opaque allowance identifier to an account or to an App Store transaction record awaiting account linkage, and retain registered hub identifiers and names until they are removed or the relevant records are deleted. An unlinked transaction record does not authorize Private Relay. After removal, we retain the opaque hub and allowance identifiers to prevent automatic re-registration, and clear the hub name. Remote display slots are provisioned rather than counted by connection. When you switch on Private Relay on a signed-in iPhone or iPad, we store that installation’s pairing identifier on its sign-in record; that entry is what holds its slot; we clear it when you switch Private Relay off or sign out, and a revoked or disconnected sign-in holds no slot. A browser device holds a slot under its own identifier for as long as it exists. When a display connects through the relay, and about every 45 seconds while it stays connected, the relay sends our platform the hub’s relay pass and a keyed cryptographic hash of the display’s identifier scoped to your allowance. We compare it against the slots provisioned on the account and keep nothing from the check: no lease, reservation, or connection record, and no device activity history. These messages contain no widget content, pairing tokens, or encryption keys. Local-network use never involves the platform.
3.4 Cloud relay (optional, where available)
If you enable the optional cloud relay (which lets your devices connect when they are not on the same network), traffic between your Mac and your iOS device passes through a relay server we operate. Native app traffic is end-to-end encrypted between your own devices: the relay cannot read your widgets or their data and stores no message content. To operate and protect the relay, it processes connection metadata — a one-way cryptographic hash identifying your Mac hub, connection IP addresses, and per-hub transfer volume counters used to enforce fair-use limits.
Browser devices. If you create a browser device at platform.preendisplay.com/v/<uuid>, the platform acts as the Mac’s paired relay client and serves the widget to your browser over HTTPS. This mode is not end-to-end encrypted between your Mac and browser: the platform decrypts widget HTML, live data, and widget interactions in memory to deliver them. We do not persist this widget content. We store the device’s identifier, name, owning account, linked Mac hub, creation time, encrypted pairing credential and relay session keys, and a hashed active-client claim with a 45-second expiry. The device’s identifier is also what holds its remote display slot, from creation until deletion. Deleting the device or account removes these stored records. The Mac retains its pairing record until you remove it there.
A browser device can be opened only by its owner, signed in to the Preen account; there is no unauthenticated or shared-link mode. Anyone using your signed-in browser session could view and interact with the current widget, so sign out on computers you share.
3.5 The widget registry (platform.preendisplay.com)
Preen can install widgets published by other people from our widget registry. Browsing the registry or installing a widget needs no account: your Mac requests the widget by its share id, which — like any web request — exposes your IP address and user agent to our server logs. Once a widget is installed, your Mac periodically asks the registry whether that widget has a newer version; the request carries the widget's id and nothing about you beyond what any web request carries — the same IP address and user agent, into the same logs. We do not build a profile of what you install.
Publishing a widget is different: it requires a publisher account, and it is governed by the registry's own Publisher Terms of Service and Privacy Policy. A published widget — its code included — is public. The same platform account may also hold your website subscription. Connecting a Mac for Plus does not by itself publish or upload its widgets. Private saves and public registry submissions are separate, explicit actions.
Widgets from the registry are written by their authors, not by us. Review is a filter, not a guarantee — read a widget's code before you install it. Registry widgets do run sandboxed: the registry's submission format has no way to request the Mac capabilities described in Section 4, so an installed registry widget cannot launch applications, run scripts, or make requests with your own privileges, and there is nothing for you to approve.
3.6 Support
If you email us, we receive your email address and whatever you choose to include. We use it only to respond and to improve the product.
3.7 Private widget backups
Saving a template to your account sends its name, HTML with embedded CSS and JavaScript, supported text icon, refresh setting and source attribution to Preen over HTTPS. We store that source, its content hash, revision number, byte count, account owner and update times. This happens only on an explicit save after you accept the private storage notice. Signing in or subscribing does not upload your library. Only the owning account and its authorized clients can retrieve it; backups have no public listing or public share link.
The export excludes live feeds, widget databases, local scripts, execution grants, separate images, and credentials stored outside the source. Widgets with actions or PNG icons cannot be saved in this version. Text or secrets embedded in the HTML are included, so review the source before saving. Private backups are not end-to-end encrypted: the platform and infrastructure providers process readable source to store and return it. We do not execute saved templates on the platform, submit them for public review, or use them for Preen or provider training, evaluation, embeddings, or model improvement. A download you request through your own AI client goes to that provider under your separate agreement.
We record the version and time of your storage acceptance and the terms and privacy revisions it identifies, separately from publishing consent. To prevent duplicate saves on retries, we keep a bounded ledger of the latest 1,000 successful saves per account. It contains request identifiers and hashes, timestamps, and result metadata, not source. Deleting a backup removes its name and other result metadata from these receipts; the retry identifier, request hash, owner, timestamp and deletion marker remain until displaced by later receipts or account deletion.
Each account can keep 50 saved widgets, up to 1 MiB per revision, with 10 MiB across all retained revisions. Only the latest 10 revisions per widget are retained; older revisions are removed as new ones are saved. Plus expiry stops new uploads but does not remove existing backups or prevent listing, downloading, restoring or deleting them. Deleting a saved widget removes its source and retained revisions from the live database. Account deletion also removes storage consent and retry records. Local copies remain on your devices.
We currently keep no scheduled infrastructure snapshots or point-in-time recovery archive of private widget source. Deleting a backup removes its source and retained revisions from the live database when the deletion succeeds. We will update this policy before introducing infrastructure backups that retain private source after live deletion.
4. Third parties acting on your instructions
Preen is a tool for building your own widgets, including with AI coding agents you run yourself (such as Claude Code or Codex). When you author widgets that way, your prompts and widget content go to your chosen AI provider under your own agreement with that provider — not through us. Likewise, widgets can be configured (with your explicit consent on the Mac) to run actions such as launching apps, running scripts, or making web requests from your Mac; any data those actions send goes where you direct it. We are not a party to, and do not receive, any of that data.
5. Service providers
Our Site, update feed, relay, registry, private backup storage, and subscription server are hosted on third-party cloud infrastructure (currently Railway) located in the United States. Apple processes App Store purchases; Stripe processes website payments. These providers process data only as needed to host our Services. If you access the Services from outside the United States, the limited data described above is processed in the United States.
6. Legal bases (EEA/UK users)
Where the GDPR or UK GDPR applies, we process the limited data described above: to perform our contract with you (delivering updates, honoring subscriptions, operating the relay, widget registry and private backups); for our legitimate interests in securing and operating the Services (server logs, abuse prevention); and to comply with legal obligations. We do not perform profiling or automated decision-making.
7. Retention
Server access logs are retained for a limited operational period. Account, device-connection, and subscription records are kept for as long as needed to operate account access, honor subscriptions, and meet our legal and accounting obligations. Relay metadata counters are transient, and the platform keeps no record of relay admission checks. Native display content and native pairing secrets stay on your devices. Browser-device records and private backups follow the separate storage and deletion descriptions in sections 3.4 and 3.7.
8. Your rights
Depending on where you live (for example, the EEA, UK, or California), you may have rights to access, correct, delete, or receive a copy of personal information we hold, and to object to or restrict certain processing. Contact us at the address below and, if your request concerns an account or subscription, include your Preen account email or the transaction identifier from your App Store receipt so we can locate the record. We will not discriminate against you for exercising your rights. EEA/UK users may also lodge a complaint with their supervisory authority.
9. Children
The Services are not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
10. Security
Connections between your devices use encrypted channels with certificate pinning established during QR-code pairing; secrets are stored in the operating system Keychain; native-app relay traffic is end-to-end encrypted; browser devices and private backups use the separate platform-mediated flows described above. No method of transmission or storage is perfectly secure, and you should review source before choosing to store it with us.
11. Changes to this policy
We may update this policy as the Services evolve. We will post the updated policy on this page with a new "Last updated" date and version number, and the Apps show the version you accepted in Settings, so you can tell when the two have diverged.
12. Contact
Pink Door Multimedia LLC
Email: josh@pinkdoormultimedia.com