Privacy Policy
Privacy Policy for Notibase — what we collect, why, and the choices you have.
This policy explains what Notibase ("we", "us") collects, why, and the choices you have. It covers our websites, dashboard, APIs and SDKs (the "Service"). Two roles matter: for customer account data we are the controller; for the end-user data our customers send us we act as a processor on the customer's instructions.
1. Data we collect from customers
When you sign in with GitHub or Google we receive your name, email address and avatar — we never see your password. We store your organization, apps, team membership, plan and audit history. Payments are processed by Stripe; we store your Stripe customer reference and plan status, never card numbers. Operational logs (API request metadata, delivery outcomes) are kept to run and secure the Service.
2. End-user data processed for customers
Customers send us the data needed to deliver their messages: push tokens, device platform and locale, the user attributes and events they choose to track, and message content. This data belongs to the customer; we process it only to provide the Service — delivery, segmentation, analytics, the in-app inbox and attribution — and never sell it or use it for our own marketing.
3. Attribution & IP addresses
When someone clicks an attribution link we store the IP address only as a one-way, app-scoped hash, usable for at most 24 hours of install matching within that single app and meaningless anywhere else. Raw IP addresses are not stored with attribution records.
4. Security
Data is encrypted in transit (TLS) and sensitive credentials — push certificates, service accounts, signing secrets, customer API keys for AI providers — are envelope- encrypted at rest with rotatable keys. Access to production systems is restricted and audited; tenant isolation is enforced at the database layer and tested continuously. Report vulnerabilities to [email protected] — we respond quickly and appreciate responsible disclosure.
5. Sub-processors
We use a small set of infrastructure providers to run the Service: hosting (Contabo, EU data centres), payments (Stripe), and the platform delivery services you configure (Apple, Google, browser push services). If you enable AI features with the built-in pool, prompts are processed by our AI provider; with your own key, content goes only to your provider.
6. Retention & deletion
Account data is kept while your account is active. Delivery logs and events are retained for operational and analytics purposes and pruned over time. When you delete your account (or ask us to), customer and end-user data is deleted from live systems within 30 days and expires from encrypted backups on their rotation schedule.
7. Your rights
You can access, correct, export or delete your account data at any time — in the dashboard or by emailing us. If you are an end user of one of our customers' apps, please contact that customer (the controller of your data); we will assist them in honouring your request. Depending on your jurisdiction you may also have rights to restriction, objection and complaint to a supervisory authority.
8. Cookies
The dashboard uses a single strictly-necessary session cookie to keep you signed in. Our websites use no advertising trackers and no third-party analytics cookies.
9. Changes & contact
Material changes to this policy will be announced by email or in the dashboard before they take effect. Questions or requests: [email protected].