pistachio pistachio

privacy

pistachio measures things about you. so this page is specific about where those measurements go, rather than reserving the right to do anything with them later.

last updated 16 august 2026.

the short version

your scores live on the device you played on — your phone, or your browser if you played on the website. a copy goes to our server so they survive a new phone, tied to an anonymous account rather than to your name or your email. we measure crashes and how the app gets used, and never the results themselves. nothing is sold, nothing is shared with advertisers, there is no advertising software, and nothing here follows you into other apps. one feature — the leaderboard — publishes a name you choose, and a town if you add one. it's switched on when you finish your first test, on a screen that says so and lets you decline, and you can leave it at any time.

what's on your phone

every run you record, in full: which test, when, and the individual attempts that make it up. also the profile you set — a display name, an emblem and a color, and optionally a date of birth and sex.

the two optional ones are asked for exactly once and used for exactly one thing: published reaction-time norms differ by age, so telling us makes that one comparison honest rather than generic. you can leave them blank, clear them later, and everything else works identically. we don't ask guests playing on your phone for either.

what goes to our server

on first launch the app creates an anonymous account — no email, no password, nothing you type. it exists so your history can come back if you get a new phone. against it we store the runs you record, your display name, and your date of birth and sex if you gave them.

signing in with apple is offered for one reason: getting your history back on a new phone. that same anonymous account is upgraded in place, so nothing is lost. we ask apple for nothing at all — not your name, not your email. the credential is what recovers the account, and that is all we need.

runs recorded by a guest on your phone are never uploaded to your account. they stay on the device until that person claims them onto their own.

our server is google firebase — authentication and firestore for your account and your scores, and crashlytics and analytics for the diagnostics described below. google processes all of it on our behalf. we don't use their advertising products.

playing on the website

three of the tests run in a browser, with no app and nothing to install. if you play one, the same thing happens as on the phone: your browser gets an anonymous account — no email, no password, nothing you type — and the run is stored against it so you can carry it into the app later if you want to.

what gets stored is the run itself: which test, when, the individual attempts, and the conditions it was recorded under — that your browser was a browser, whether you used a finger or a mouse, the frame rate it managed and whether your screen reports wide color. those last ones are there because a measurement is only re-readable later if you know what it was taken with. no name, no email, nothing typed.

the score is worked out in your browser, not on our server. nothing has to be sent anywhere for you to see how you did, and if you close the tab without sharing or claiming it, the run is one anonymous record with nothing attached to it.

if you never install the app, that anonymous browser account is all there ever is: it is not linked to a person, and it is not joined up with anything else you do.

the leaderboard, which you can decline or leave

when you finish your first test we ask you to pick a display name, and joining is the default — the screen says exactly what gets published and has a decline button next to it. nothing of yours is published before you have seen that screen and answered it. if you had already installed the app when this changed, you get asked rather than added.

once you're on, one entry per test becomes readable by anyone: the display name you chose, your emblem and color, and one measurement. no history, no other tests, no date of birth. you can take a single score off a board from the board itself, and leaving takes every entry down — the switch sits in edit profile. guests are never added, because a guest has no account to publish under.

you can also add a place — a town, shown under your name. it is blank unless you type it, it is never read from your phone's location (we don't ask for that permission at all), and clearing it stops it being sent. worth a moment's thought: a name and a town together identify somebody rather more than a name on its own.

choose a display name you're happy for strangers to read. it doesn't have to be your real one.

hiding and reporting a name

names on a board are typed by people, so there are two ways to deal with one you'd rather not see. hiding is yours alone: the name stops appearing for you, on every board in the app, and nothing about it is sent anywhere — it is a note your phone keeps to itself. because it is only on that phone, reinstalling the app forgets it.

reporting does send something. we store the name as it stood, the account it belongs to, your account, which board it was on, and which of three reasons you picked — and we email it to ourselves so somebody actually reads it. there is no free-text box anywhere in that, deliberately: a report can't carry a message. reports can't be read back by the app, by you, or by anybody else. reporting also hides the name for you, straight away, without waiting for us.

crashes, and how the app is used

the app reports crashes through firebase crashlytics: a stack trace, your device model and its ios version, plus the anonymous account id so that one person crashing four times can be told apart from four people crashing once. this is how a bug gets found without waiting for someone to write a review about it.

it also measures how the app is used, through google analytics for firebase. that means app opens and how long a session lasts, collected automatically, plus a short list of named events: a test was started, a test was finished, a result was shared, a challenge was started, a challenge was sent, a challenge was accepted, the phone was passed to somebody else, scores were handed over, the first-run reading was completed, the leaderboard was joined or left. where it makes sense the event says which test it was.

no scores, no measurements, no names, no dates of birth and no free text are sent with any of it. what we're trying to answer is which tests people choose, where they stop, and whether they come back — not how anybody performed.

we use the build of analytics that cannot read the advertising identifier. so nothing here is used to track you across other apps or websites, there is no advertising software in the app, and no data is sold or shared with advertisers. google processes this on our behalf.

what the sensors do

two tests use the camera. the pulse test reads color changes through a fingertip on the lens; the distance test uses the camera and lidar to measure how far away a wall is. no image, video or depth map is stored or transmitted — frames are read, turned into a number, and dropped. the app has no microphone permission and never records audio.

the balance and steadiness tests read the accelerometer and gyroscope while you're playing. those readings become the measurements you see and are stored as part of the run.

the app does not use location. it has no access to your contacts, photos, calendar, health data or advertising identifier, and contains no advertising software.

links and files you send

this changed on 12 august 2026, and not in our favour, so here it is plainly. handing somebody their scores used to carry the whole run inside the link, after the # — a part browsers never send to any server. that was better for privacy and we gave it up for two reasons. it had a size limit, so a longer history silently turned into a file attachment; and it was one-way, so your phone could never learn that the "marie" on it is a real account, which is what makes a rematch possible.

now: the runs are stored on our server under a six-character code, readable only by a signed-in app holding that code, and they stop being readable after thirty days — enforced on the server, not just in the app. the web page for one shows no scores at all, because it has no way to read them. when somebody picks their scores up, we record which account did, and tell the phone that sent them. that is the whole point of the change, and it is the one thing worth knowing before you send one.

a challenge link works the same way and always has. a .pistachio file still opens if you have one, but nothing sends them any more.

children

pistachio isn't directed at children, and we don't knowingly collect personal information from anyone under 13. the app is built to be handed round, so a child may well play on an adult's phone — those runs are guest runs, they stay on that device, and no birthday is asked for. if you believe a child has created an account, contact us and we'll delete it.

deleting things

you can delete a single run, a test's whole history, or every score, from edit profile in the app. deleting removes the copy on our server too. leaving the leaderboard removes your entries from it. if you want the account itself and everything attached to it gone, ask and we'll do it.

changes, and how to reach us

if this page changes in a way that affects what's collected, the date at the top changes with it. questions, corrections, or a deletion request: weirdlittleideas@gmail.com.

pistachio is not a medical device. nothing it measures diagnoses anything, and a low score is not a symptom. if something here worries you, talk to a doctor rather than to a phone.