Privacy Policy

Last updated: August 20, 2026

This policy explains what Notibase ("we", "us") collects, why, and the choices you have. It covers our websites, dashboard, APIs and SDKs (the "Service"). Two roles matter: for customer account data we are the controller; for the end-user data our customers send us we act as a processor on the customer's instructions.

1. Data we collect from customers

When you sign in with GitHub or Google we receive your name, email address and avatar — we never see your password. We store your organization, apps, team membership, plan and audit history. Payments are processed by Stripe; we store your Stripe customer reference and plan status, never card numbers. Operational logs (API request metadata, delivery outcomes) are kept to run and secure the Service.

2. End-user data processed for customers

Customers send us the data needed to deliver their messages: push tokens, device platform and locale, the user attributes and events they choose to track, and message content. This data belongs to the customer; we process it only to provide the Service — delivery, segmentation, analytics, the in-app inbox and attribution — and never sell it or use it for our own marketing.

3. Attribution & IP addresses

When someone clicks an attribution link we store the IP address only as a one-way, app-scoped hash, usable for at most 24 hours of install matching within that single app and meaningless anywhere else. Raw IP addresses are not stored with attribution records.

4. Security

Data is encrypted in transit (TLS) and sensitive credentials — push certificates, service accounts, signing secrets, customer API keys for AI providers — are envelope- encrypted at rest with rotatable keys. Access to production systems is restricted and audited; tenant isolation is enforced at the database layer and tested continuously. Report vulnerabilities to [email protected] — we respond quickly and appreciate responsible disclosure.

5. Sub-processors

We use a small set of infrastructure providers to run the Service: hosting (Contabo, EU data centres), payments (Stripe), and the platform delivery services you configure (Apple, Google, browser push services). If you enable AI features with the built-in pool, prompts are processed by our AI provider; with your own key, content goes only to your provider.

6. Retention & deletion

Account data is kept while your account is active. Delivery logs and events are retained for operational and analytics purposes and pruned over time. When you delete your account (or ask us to), customer and end-user data is deleted from live systems within 30 days and expires from encrypted backups on their rotation schedule.

7. Your rights

You can access, correct, export or delete your account data at any time — in the dashboard or by emailing us. If you are an end user of one of our customers' apps, please contact that customer (the controller of your data); we will assist them in honouring your request. Depending on your jurisdiction you may also have rights to restriction, objection and complaint to a supervisory authority.

8. Cookies

The dashboard uses a single strictly-necessary session cookie to keep you signed in. Our websites use no advertising trackers and no third-party analytics cookies.

9. Changes & contact

Material changes to this policy will be announced by email or in the dashboard before they take effect. Questions or requests: [email protected].