In short
- We do not store the IP addresses of notification subscribers.
- We use no cookies in the panel. On the marketing site, Google Analytics measurement cookies load only if you give explicit consent; there is no advertising code on any of our pages.
- Notification content is delivered to the browser’s push service encrypted; the service in between cannot read it.
- We do not sell your data, share it for advertising, or use it to train our own products.
- The application database and its backups are kept in Türkiye; sub-processors abroad are used for notification delivery and payments.
What we collect
As an account holder: your email address, your name if given, an irreversible hash of your password, billing details, and the content you create in the panel (projects, campaigns, segments, automations).
For your site’s notification subscribers: the push endpoint address and encryption keys issued by the browser, the tags you define, browser, operating system, language, country, time zone, and subscription/last-seen timestamps. Plus delivery and click events for the notifications you send.
Cookies and local storage
The panel writes no cookies; it uses only four strictly necessary local-storage keys: your session tokens, your theme preference and your interface-language preference. The marketing site does carry Google Analytics measurement cookies, and those load only if you give explicit consent — which is why we show a consent banner on your first visit. The full list and the button to withdraw consent are in the Cookie and Local Storage Policy.
Analytics
We use two measurement tools and they are not the same thing. The first is Umami, cookie-free and hosted on our own server: it writes no cookies, does not track you across sites, stores no raw IP address, and sends no data to any third party — so it needs no consent and runs on every visit. The second is Google Analytics 4: it runs on every visit but stays in cookieless mode unless you give explicit consent — it writes no cookie to your browser and builds no identifier that recognises you. Even in that mode a page-view signal (including a truncated IP address) is sent to Google; we do not store it. If you choose “Accept”, measurement switches to the cookie-based mode. Advertising and personalisation signals are off in every case. No analytics code runs in the panel; the usage data we collect there is limited to operational records needed to run the service.
How click tracking works
When a notification is clicked, the user passes through a signed link before being forwarded to the destination. That link records which campaign was clicked and is cryptographically signed — a third party cannot manufacture fake clicks. Multiple clicks by the same subscriber on the same campaign count as one.
Security measures
- Passwords are hashed with Argon2id; no plaintext password is stored.
- Push signing keys and mobile provider credentials are stored encrypted in the database with AES-256-GCM.
- All traffic is carried over HTTPS.
- Outbound requests are SSRF-guarded: customer-supplied addresses cannot be pointed at the internal network.
- API keys are stored hashed, shown once at creation, and can be revoked.
- Sign-in is rate limited and accounts lock progressively.
Children’s data
The service is aimed at businesses and is not intended for account holders under 18. If we learn that we have inadvertently processed a child’s data, we delete it without delay.
Changes
When we update this policy we change the last-updated date at the top of the page. For a change with significant consequences for you, we notify the email address on your account.