Pika
РусскийEnglishTerms of Service

Reference translation. The legally binding version is the Russian text: privacy.html.

Privacy Policy

Pika service (zhedor.com/app/pika/) · Last updated: 11 August 2026 · version PP-2026-08-11

This is an English translation provided for convenience. The Russian text above is the binding version, published under Article 18.1 of Russian Federal Law 152-FZ.

1. Operator

The service Pika — an app for specialists (coaches, tutors, beauty masters, instructors, studios) and their clients — is operated by Evgeny A. Dorokhov, a self-employed individual registered in the Russian Federation (professional income tax regime), TIN 272511721775, postal address available on request. Contact for any privacy request, including consent withdrawal: [email protected].

2. What we process

2.1. Booking a court: what the club receives

Booking a court inherently means the club learns who is coming. We therefore pass to the club you book with: your name, phone number and your booking records at that club, including the club's ability to export them to a file for its own records. You give a separate, unticked consent to this before your first booking; without it a booking cannot be made.

The club is an independent controller of what it receives: it decides how to use those records (attendance, contacting you, settlements) and is responsible for that processing itself, including retention and answering your requests. We do not control what the club does with the exported file.

The club never receives your e-mail address, your social account identifier, your IP address, or any information about your bookings at other clubs.

A club may be located outside the Russian Federation (Thailand, for example); in that case the transfer is a cross-border transfer performed under Article 12 of 152-FZ. Withdrawing your consent with us stops our processing and further bookings, but records already passed to a club must be withdrawn from that club — it is an independent controller of them.

We do not process special categories of personal data or biometric data. The profile photo is an interface element and is not used to identify a person biometrically.

3. Why, and on what legal basis

To register and authenticate you; to provide the features you use (schedule, client cabinet, messaging, balance and payments, progress); to sync your data across your devices and let you recover access; to send the service notifications you enabled; to answer your requests; to keep the service secure; and to comply with the law. Legal bases: your consent, performance of the user agreement, a controller's instruction (for clients' data), our legitimate interest in security, and legal obligations.

We do not sell personal data, do not share it with advertisers, run no analytics or advertising trackers on the service, and never use your data to train generalized AI/ML models. Data given for registration is never used for marketing e-mail.

3.1. Readers of a public blog

If you sign in with a social network on a specialist's public blog page to leave a comment or a reaction, we process: your social account identifier, the name and profile picture the network provides, the public @handle you choose, your comments and reactions, and request metadata (IP address, browser details) used solely to protect the service from spam and abuse. The legal basis is your consent, given via a separate unticked checkbox at sign-in.

Your name, @handle, profile picture and comment text are public and may be indexed by search engines. Your e-mail, social identifier and IP address are never published. A copy of the profile picture is stored on our servers in Russia — public pages do not link to the social network's servers, so the network learns nothing about your visits here.

In your profile you can remove the picture, change the @handle, or delete the profile — with all your comments, or leaving them anonymised. Withdrawing consent equals deleting the profile.

4. Storage, location and retention

Primary recording and storage of Russian citizens' personal data takes place in a PostgreSQL database hosted on a server located in the Russian Federation, as required by Article 18(5) of 152-FZ. No foreign cloud database is used as the primary store.

Active account data is kept for the life of the account. After deletion, data is erased within 30 days, except records the law requires us to keep. Accounts inactive for 180 days may be purged after notice. Web-server logs are kept for up to 12 months.

5. Transfers outside Russia

A sports club you book with receives your name, phone number and bookings at that club (section 2.1); where the club is located abroad, this is a cross-border transfer.

Some operations involve services located outside the Russian Federation: login providers (Google — USA, Yandex — Russia, LINE — Japan, Meta/Facebook — USA); Google Calendar (USA, only if you connect it); browser and OS push-delivery services (Google, Mozilla, Microsoft, Apple); Telegram Bot API (UAE, only if you link Telegram); and the mail server serving the operator's domain. Transfers are performed under Article 12 of 152-FZ, and the operator notifies Roskomnadzor of its intent to carry out cross-border transfers.

6. Google API data (Limited Use)

The App accesses Google data only if you explicitly connect your Google Account from the in-app Calendar screen. With your consent we request:

We do not access Gmail, Drive, Contacts, or any other Google data.

We do not copy your calendar events into our database — they are fetched live from Google each time you open the Calendar screen. The only sensitive item we retain is the Google OAuth refresh token, stored outside the public web root, in a file with restricted operating-system permissions, keyed by a one-way SHA-256 hash of your app token. Disconnecting Google in the App immediately and permanently deletes that token; you may also revoke access at myaccount.google.com/permissions.

Pika's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google API data is never used for advertising or profiling, and is never used to develop, improve, or train generalized AI/ML models.

7. Security

All traffic travels over TLS/HTTPS. Access tokens are never placed in a URL, query string or log file. Third-party secrets and tokens are stored outside the public web root with restricted operating-system permissions. Only the operator can reach the server and the database, solely to run the service. Rate limiting and abuse protection are in place. In case of a data breach we notify Roskomnadzor within the statutory deadlines.

8. Your rights

You may request confirmation of processing and information about it; require that inaccurate, outdated or unnecessary data be corrected, blocked or erased; withdraw your consent at any time; and complain to Roskomnadzor or a court. Write to [email protected] — we answer within 30 days. You can delete your account and all associated data from within the App. If a specialist entered your data, contact them first as the controller of that data.

9. Cookies

We use cookies and browser local storage strictly to run the service: session and access token, chosen language and theme, quick-start draft, application cache (service worker) and CSRF protection during social login. No advertising or analytics cookies are set. Disabling cookies makes signing in impossible.

10. Minors

The service is intended for users aged 18 and over. A specialist may run sessions with minor clients; in that case consent for processing the minor's data must be given by their legal guardian, and obtaining it is the specialist's obligation.

11. Changes

We may update this policy; the “Last updated” date above reflects the current version.