Privacy Policy

Last updated: September 19, 2026

PingKit ("we", "our", or "the app") is committed to protecting your privacy. This Privacy Policy explains how we handle information when you use PingKit for iOS and PingKit Agent for macOS.

Summary: PingKit does not collect personal data. All 19 diagnostic tools run entirely on your device. There are no accounts and no tracking. We do count, anonymously and in aggregate, which features people reach, so we know what to improve; those counts carry no identifier and cannot be linked to you or your device. AI answers are produced on your own device or by Apple Private Cloud Compute wherever they can be; when neither can answer, and only after you have given permission, PingKit sends a summary of your network to its own AI service at ai.pingkit.app. Never browsing history or account details. Most Guardian monitoring data (your device inventory, scans, and diagnostics) syncs between your devices via your personal iCloud account, which we never see. Cert Monitor and Uptime Watch additionally store the domains you choose to monitor and their check results on PingKit's own backend (a Cloudflare Worker at monitor.pingkit.app) so alerts and push notifications reach you reliably.

Information We Do Not Collect

PingKit does not collect:

We do not operate any third-party analytics or tracking. There is no account system, no sign-up, and no login. PingKit-operated services that do receive data are the anonymous feature counts described immediately below, the AI service at ai.pingkit.app when you have allowed it, and Cert Monitor and Uptime Watch monitoring (monitor.pingkit.app). Some AI answers are produced by Apple Private Cloud Compute instead, which is Apple's infrastructure rather than ours; that flow is described under AI Features below.

Anonymous Feature Counts

To understand which parts of the app people actually reach, PingKit sends aggregate counts of in-app events (for example, that a subscription screen was shown, or that a free trial was started) to our own server at monitor.pingkit.app. This is the only usage measurement we perform, and it is deliberately built so that it cannot describe an individual.

Each report contains only:

Each report deliberately excludes:

Your IP address is used only to rate-limit abuse at the network edge and is never stored alongside these counts. Because there is no identifier, we cannot single you out, build a profile, or link these counts to anything else, and we could not delete "your" data on request because we have no way to tell which rows are yours. These counts are never sold or shared, and are not used for advertising or for tracking you across apps or websites. Reports older than roughly 13 months are deleted.

Local Data Storage

Both the iOS app and macOS Agent store data locally on your device using Apple's SwiftData framework:

You can delete all local data at any time by uninstalling the app.

iCloud Sync (PingKit Guardian)

If you subscribe to PingKit Guardian, PingKit Agent for macOS syncs monitoring data to PingKit on your iPhone via Apple's CloudKit framework. This data is stored in your private iCloud database - only devices signed into your Apple Account can access it.

Data synced via iCloud includes:

This data is encrypted in transit and at rest by Apple. It never passes through any server we operate. We cannot see, access, or retrieve your iCloud data. For details on how Apple handles CloudKit data, see Apple's Privacy Policy.

Monitoring (Cert Monitor and Uptime Watch)

Uptime Watch is available to everyone (one URL for a week at no cost, then with Guardian) and Cert Monitor is a Guardian Plus feature. Both are optional and neither sends anything until you add a target yourself. To deliver reliable alerts and push notifications even while your devices are asleep, they use a PingKit-operated backend (a Cloudflare Worker at monitor.pingkit.app). When you add a domain or endpoint, that target and its check results are uploaded to and stored on this backend.

The backend holds only:

This data is limited to what is needed to run the monitor and notify you. It is never sold or shared, and it is not used for advertising or tracking. Your device inventory, scans, and general diagnostics are not sent to this backend: they stay on-device and sync only through your private iCloud as described above.

Push Notifications

PingKit Guardian uses Apple Push Notification service (APNs) to deliver alerts to your iPhone when the macOS Agent detects network events. These notifications are triggered by CloudKit subscriptions - when the Agent writes an alert to your private iCloud database, Apple's infrastructure delivers the notification. No notification data passes through our servers.

External Services Used by Diagnostic Tools

When you use certain diagnostic tools, the app connects directly to third-party services to perform the requested operation. These connections are made from your device, not through our servers:

Speed Test

Speed tests use Cloudflare's public speed test infrastructure (speed.cloudflare.com). Only bandwidth measurement data is exchanged - no personal information is sent.

IP Geolocation

When you use the IP Geolocation or "Locate My IP" feature, the app queries ipapi.co or ipwho.is to retrieve geographic and ISP information for the specified IP address. These services receive the IP address you are looking up.

DNS Lookup and Security Scan

DNS lookups may query Google Public DNS (dns.google) or Cloudflare DNS (cloudflare-dns.com) to resolve domain names and check DNS security. The domain name being queried is sent to these services.

Whois Lookup

Domain and IP ownership lookups query public RDAP servers operated by domain registries (such as Verisign, Public Interest Registry, and others). The domain or IP being queried is sent to these services.

Security Scan

The external exposure check queries Shodan's InternetDB (internetdb.shodan.io), a public and free API that returns the open ports and published CVE records already known for a given IP address. Your public IP address is sent to this service during this check. In PingKit Agent for macOS this check is off unless you turn it on; on iPhone and iPad it runs as part of a security scan. The security scan also connects to captive.apple.com (Apple's captive portal detection endpoint) and may inspect TLS certificates on google.com to detect MITM interception.

AI Features

PingKit's AI features include the assistant, security explanations, remediation guides, scan summaries and device identification. An answer can be produced in three different places, and which one produces it decides what leaves your device. PingKit tries them in order and stops at the first that succeeds.

  1. On your own device. Apple Intelligence's on-device model writes the answer on your iPhone, iPad or Mac. Nothing leaves your device, and neither PingKit nor Apple receives anything. This is free and needs no subscription. It requires hardware that supports Apple Intelligence (iPhone 15 Pro or later) and one of the languages Apple's on-device model covers, so it is not available on every device or in every language.
  2. Apple Private Cloud Compute. When a question is more than the on-device model can handle, PingKit can send it to Apple Private Cloud Compute. This is Apple's infrastructure, not ours: the data goes to Apple, PingKit never sees it, and Apple's own privacy terms govern it rather than this policy. Apple states that data sent to Private Cloud Compute is used only to fulfil the request, is not retained, and is not accessible to Apple. This step requires a PingKit Guardian subscription.
  3. PingKit's own AI service. If neither of the above can answer, PingKit can send a summary of your network to its own service at ai.pingkit.app, running on Cloudflare Workers AI. PingKit asks your permission before its own service ever receives anything, and it does not ask once and remember forever: you can withdraw that permission at any time in the app, under Settings, and the next request will ask again.

What is sent to PingKit's own service, when you have allowed it: your connection type and speed, how many devices are on your network and what kind each one is, what a security scan found, the hostname a device announces for itself, and, when you use the assistant, your question and the last few turns of that conversation. Your preferred language is sent so the answer comes back in it.

What is not sent: the names you have given your devices in PingKit, hardware (MAC) addresses, your Wi-Fi network name, your public IP address, your browsing history, the contents of your traffic, or any name, email or account detail.

Device identification works slightly differently, and it is worth stating plainly. When PingKit's on-device classifier cannot confidently identify a device on your network, it can ask the AI service at ai.pingkit.app to help. That request carries the signals the device broadcasts about itself, which includes the hostname it announces, its reverse DNS name and its NetBIOS name. This uses the same permission as everything above and is refused outright if you have not given it, but unlike the assistant it does not require a subscription.

What is stored:

What is not stored: your questions, your conversations, your scan results, your device names, your network configuration, or anything else that could identify you. Answers produced on your device or by Apple Private Cloud Compute are not recorded by PingKit at all, because they never reach us.

A change made on 19 September 2026, stated here because the previous version of this policy described something different. Until that date, device identification requests were written to a retained corpus intended for future model training, and that corpus included the hostnames devices announce. Hostnames frequently contain people's names. That collection has been stopped, the stored data has been deleted, and the code that wrote it has been removed from the service. No device identification data is retained today.

All Other Tools

Ping, traceroute, MTR, port scanning, LAN discovery, Bonjour browsing, SSL inspection, HTTP analysis, and Wake-on-LAN operate entirely on your local network or connect directly to hosts you specify. No third-party services are involved.

Location Permission

PingKit does not request location permission and cannot access your location. Reading Wi-Fi details such as your network name would require it, so PingKit does without those details rather than ask.

Third-Party Services

In-App Purchases

Subscriptions are processed entirely by Apple through StoreKit. We do not have access to your payment information. See Apple's Privacy Policy for details.

Crash Reporting

PingKit uses only Apple's built-in crash reporting (available through Xcode). Crash reports contain technical diagnostic data (stack traces, device model, OS version) and are collected by Apple for App Store builds. No personal information or network diagnostic results are included. We do not use any third-party crash reporting services.

Children's Privacy

PingKit is not directed at children under 13. We do not knowingly collect information from children.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

Contact Us

If you have any questions about this Privacy Policy, please contact us at:

support@pingkit.app