PressPilot is a mobile app made by The Tiny Apps Company that puts your Frappe Cloud sites, benches and deploys in your pocket. It is an independent, third-party companion app for Frappe Press — the open-source platform behind Frappe Cloud and self-hosted Press instances. It talks to the same REST API the official web dashboard uses, so it acts as a faithful mobile mirror of that dashboard, whether you point it at frappecloud.com or your own server.
Because PressPilot manages real production infrastructure, we take a deliberately minimal approach to your data. Most of what you see in the app — your sites, benches, deploy logs, backups and billing figures — travels directly between your own server and your device. We never store it. This policy explains, in plain language, exactly what we do and do not collect, why, who we share it with, and the choices you have.
This policy covers the PressPilot app on Android and iOS. It does not cover Frappe Cloud, your self-hosted Press server, or any other service you connect the app to — those are operated by Frappe Technologies or by you, under their own terms and privacy practices.
1 Who we are and how to reach us
PressPilot is built and operated by The Tiny Apps Company ("we", "us", "our"). We are the data controller for the limited personal data described in this policy — principally the contact details you give us in-app and the push token used to notify you.
If you have a question about your privacy, want to exercise a right described below, or simply want to understand what we hold about you, email us. We aim to respond promptly and honestly.
The Tiny Apps Company is based in Surat, Gujarat, India, and this policy — together with our Terms — is governed by the laws of India and the State of Gujarat.
- Company: The Tiny Apps Company
- Registered address: KALP Business Center, City Light Road, City Light Town, Athwa, Surat, Gujarat 395007, India
- Contact for all privacy matters: Apps@thetinyappscompany.com
- Role: Data controller for the contact and notification data described here
2 The short version
We designed PressPilot so that the sensitive parts of your work never pass through us. Here is the whole story in a few lines, before the detail.
Your password is never stored — not on your device, not on our servers, not in logs or crash reports. During sign-in it lives in memory only for the seconds it takes to exchange it for an API token, and then it is gone. The token itself is kept in your phone's hardware-backed secure storage.
Your live infrastructure data — sites, benches, deploys, logs, backups, billing — is fetched on demand straight from your server to your device and is never stored on our servers. The only personal data that reaches our backend is the contact information you choose to give us and a device token so we can send you notifications. We do not sell personal data, and there are no third-party advertising SDKs in the app.
- Password: used transiently in memory during sign-in, never stored anywhere
- API token + server URL + selected team: stored only in your device's secure storage
- Live infrastructure data: streamed server-to-device, never stored by us
- Contact details + push token: synced to our Firebase backend, only to notify and support you
- No data selling, no advertising trackers
3 Your credentials and the on-device token
You can sign in to PressPilot in under a minute with the same email and password you already use on the Frappe dashboard, including two-factor authentication, or you can supply an API key directly. Whichever route you take, we treat your credentials as something to touch as briefly as possible and never to keep.
When you sign in with a password, the app sends it once, over an enforced HTTPS connection, to the Frappe server you named — in exchange for an API token (a key and secret pair). Your password exists only in the app's working memory for that moment and is never written to disk, logs, analytics or crash reports. One-time passcodes used for two-factor authentication are likewise never stored.
The API token, the server URL you connected to, and the team you have selected are the only sign-in details the app retains, and they are kept exclusively in your device's hardware-backed secure storage — the iOS Keychain or Android EncryptedSharedPreferences. They stay on your device. Signing out clears the token from that storage.
- Password: in-memory only during sign-in, then discarded; never persisted
- Two-factor one-time passcodes: never stored
- Stored on device only: API token (key + secret), server URL, selected team
- Storage location: iOS Keychain / Android EncryptedSharedPreferences
- Transport: HTTPS enforced for every request
4 Your live infrastructure data (which we do not store)
The heart of PressPilot is the data it shows you about your own infrastructure: your list of sites and their status, benches and their tracked branch and commit hash, deploy progress, step-level job logs, backups, installed apps, custom domains, server health, and read-only billing figures such as plan usage and unpaid invoice totals.
All of this is fetched on demand, directly from your Frappe server to your device, using your API token. It is not routed through, copied to, or stored on The Tiny Apps Company's servers. When you close a screen, that data is gone from anywhere but your server. We never see it.
That server — frappecloud.com or your self-hosted Press instance — is operated by Frappe Technologies or by you, not by us. Its own collection, retention and security of your infrastructure data is governed by Frappe's terms or your own configuration, not by this policy.
5 Contact details you give us, and why
Some features involve a small amount of personal data that does reach our backend. When you provide contact information in the app — typically your name, email address and phone number, given during onboarding, as part of lead capture, or when you request support — that information is synced to our developer backend, which runs on Google Firebase (Cloud Firestore).
We use these details for two purposes only: to deliver notifications about your infrastructure (including push and phone notifications about deploys, job failures, available updates and billing events), and to provide you with support and respond to your enquiries.
We do not use your contact details for third-party advertising, and we do not sell them. We ask only for what those two purposes need.
- What: name, email address, phone number (as you provide them)
- Why: to notify you about your infrastructure, and to support you
- Where: Google Firebase (Cloud Firestore), our developer backend
- Not used for: advertising or sale of personal data
6 Device push token
To send push notifications to your phone — the deploy that failed at 9pm, the client site that went down, the 23 updates that piled up over the weekend — the app registers a device push token with Firebase Cloud Messaging and stores that token on our backend.
A push token identifies your device as a delivery destination for notifications; it is not your password and grants no access to your infrastructure. We use it solely to route notifications to your device, and deep-link them to the affected site or bench.
If you disable notification permission on your device, or sign out, the token stops being used for delivery. You can revoke notification permission at any time in your device settings.
7 Technical and diagnostic data
PressPilot requires network access to talk to your server and to Firebase, and notification permission to alert you. In the course of normal operation, standard technical information — such as the network requests the app must make and basic device and app information needed to deliver notifications reliably — is processed.
We keep diagnostic collection deliberately narrow. Crucially, your password and one-time passcodes are excluded from logs and crash reports by design. We do not embed third-party advertising or behavioural-tracking SDKs in the app.
Where the app or its infrastructure providers generate diagnostic data (for example, delivery information from Firebase Cloud Messaging), it is used to keep the service working and secure, not to build a marketing profile of you.
8 Legal bases for processing
Where data protection law such as the GDPR or UK GDPR applies, we rely on the following legal bases for the limited personal data we process.
We rely on the performance of a contract with you to authenticate you and provide the app's core functionality. We rely on your consent for notifications — which you grant through the device's notification permission and can withdraw at any time. We rely on our legitimate interests to provide support you request, to secure the app, and to keep the service running reliably, balanced against your rights and expectations.
Because your password is never stored and your live infrastructure data never reaches us, the personal data we actually hold — your contact details and push token — is small and purpose-limited, which keeps this processing proportionate.
- Contract: authenticating you and delivering core app functionality
- Consent: sending push and phone notifications (withdrawable anytime)
- Legitimate interests: support, security, and reliable operation
9 Third parties and sub-processors
We keep our list of third parties short and name them plainly. The main one is Google Firebase, which we use for Cloud Firestore (storing the contact details you provide) and Firebase Cloud Messaging (delivering push notifications with your device token). Firebase is a Google service and processes this data on our behalf as a sub-processor, under Google's own privacy terms.
The other significant party is your Frappe server itself — frappecloud.com or your self-hosted Press instance. Your credentials and infrastructure requests go directly to it. It is operated by Frappe Technologies or by you, and its handling of your data is governed by Frappe's terms or your own configuration, not by us.
We do not share your personal data with advertisers or data brokers, and we do not sell it. We may disclose data if legally required to do so, or to protect the rights, safety and security of our users and our service.
- Google Firebase — Cloud Firestore (contact details) and Firebase Cloud Messaging (push token), as our sub-processor under Google's privacy terms
- Your Frappe server — receives your credentials and infrastructure requests directly; operated by Frappe or by you
- No advertising networks, no data brokers, no sale of data
10 International data transfers
Google Firebase operates a global infrastructure, so the contact details and push token we sync to it may be processed on servers located in countries other than your own, including outside your region.
Where such transfers involve personal data protected by laws like the GDPR or UK GDPR, they are covered by the safeguards Google provides for its Firebase services, such as standard contractual clauses and equivalent transfer mechanisms.
Your live infrastructure data does not factor into international transfers on our side, because it travels only between your device and your own server and never reaches us.
11 Data retention
We hold personal data only as long as it serves the purpose we collected it for. Contact details you provide are retained while you use the app and for as long as needed to support you, after which they are deleted or anonymised. If you ask us to delete your contact details, we will do so, subject to any obligation we have to retain limited records by law.
Your device push token is retained while it remains valid for delivering notifications; it is discarded when it expires, when you disable notifications, or when you sign out.
The API token, server URL and selected team stored on your device persist only until you sign out or remove the app, at which point they are cleared from secure storage. Because we never store your password or your live infrastructure data, there is nothing of that kind on our side to retain.
12 Security measures
Security is the reason PressPilot exists as an ops console rather than a toy, and it shapes how we handle data. All communication with your server and with our backend is over enforced HTTPS. Your password is never persisted, and your API token lives only in your device's hardware-backed secure storage — the iOS Keychain or Android EncryptedSharedPreferences.
Billing in the app is strictly read-only, so you can check plan usage and unpaid invoice totals without any risk of accidentally changing something. The app also lets you see and revoke the support-access grants that Frappe engineers request against your sites — a straightforward way to keep your own security tidy, wherever you are.
No method of transmission or storage is perfectly secure, and the app performs powerful, sometimes destructive operations against production systems, so we encourage you to protect your device with a passcode or biometrics, keep the app updated, and sign out on devices you no longer control.
13 Your privacy rights
Depending on where you live, you may have rights over the personal data we hold — principally your contact details and push token. These commonly include the right to access a copy of your data, to correct inaccurate data, to delete it, to restrict or object to certain processing, and to data portability. You also have the right to withdraw consent for notifications at any time, without affecting processing that already took place.
Because much of what PressPilot handles never reaches us, some rights are satisfied on your device directly: you control your credentials, you can sign out to clear the on-device token, and you can revoke notification permission in your device settings at any time.
To exercise any right over the data we do hold, email us at Apps@thetinyappscompany.com. We will verify your request and respond within the timeframe required by applicable law. If you are in the EEA or UK and are unhappy with our response, you may also lodge a complaint with your local data protection authority.
- Access, correct, delete, restrict, object, and port your data
- Withdraw notification consent anytime via device settings
- Contact us at Apps@thetinyappscompany.com to make a request
14 Children
PressPilot is a professional tool for people who run production infrastructure. It is not designed for or directed at children.
You must be at least 16 years old to use the app — or 18 where a higher minimum age is required by local law. We do not knowingly collect personal data from anyone below the applicable minimum age.
If you believe a child has provided us with personal data, please contact us and we will delete it.
15 Not affiliated with Frappe
PressPilot is an independent, third-party client. The Tiny Apps Company is not affiliated with, endorsed by, or sponsored by Frappe Technologies Pvt. Ltd.
The names "Frappe", "Frappe Cloud" and "Frappe Press" are used only descriptively, to identify the platform PressPilot works with. All trademarks belong to their respective owners.
When you use PressPilot, you connect to a Frappe Cloud or self-hosted Press server that Frappe or you operate. Your relationship with that platform, and its own privacy practices, are separate from this policy.
16 Changes to this policy
We may update this policy from time to time — for example, if we add a feature, change a sub-processor, or need to reflect a change in the law. When we do, we will revise the effective date at the top and, where changes are significant, make a reasonable effort to let you know within the app.
The version in force is always the one published with the current effective date. Continuing to use PressPilot after an update means you accept the revised policy.
We encourage you to review this page periodically so you stay informed about how we protect your data.
17 How to contact us
If anything here is unclear, or you want to raise a concern, ask a question, or exercise a right, we would rather hear from you than have you guess.
Email us at Apps@thetinyappscompany.com and we will help.
For matters involving your Frappe Cloud or self-hosted Press server itself — as opposed to the PressPilot app — please contact Frappe or your own server administrator, since that infrastructure is outside our control.
- Privacy and general contact: Apps@thetinyappscompany.com
- Company: The Tiny Apps Company
- Effective date: 20 July 2026