Privacy at Notificator

Your alerts are useful because they are yours.

This policy explains what information Notificator handles, why it is needed, how it is protected, and the choices available to you across the mobile apps, WordPress plugin, API, website, and compatible devices.

Effective21 July 2026
AdvertisingNone
Data salesWe do not sell personal data
Contacthello@notificator-project.com

01

Who this policy covers

This policy applies to Notificator, including the Notificator mobile applications for iOS and Android, the Notificator WordPress plugin, the Notificator API and notification infrastructure, compatible Notificator devices and firmware, and the website at notificator-project.com.

Notificator is an independent open-source project operated by Vagelis Papaioannou (“Notificator”, “we”, “us”, or “our”). Questions about this policy or your data can be sent to hello@notificator-project.com .

02

Information we handle

Account and profile information

When you create an account, we process your email address, authentication information, account identifier, and security settings such as two-factor authentication. You may also choose to provide profile details such as your name, phone number, and notification preferences. Password authentication is handled by our authentication provider; we do not receive your password in readable form.

Notification and integration information

We process the information needed to route an alert, which may include its title, message, category, source, event name, timestamp, website or integration name, and event details supplied by you or your connected service. API-key records, allowed domains, delivery preferences, and related configuration are also stored so integrations can authenticate and deliver alerts.

Keep event payloads focused.

You control the content sent by your WordPress site and other integrations. Avoid including passwords, access tokens, payment details, health information, or other sensitive personal data in notification titles, messages, or event arguments.

App and push-delivery information

To deliver mobile notifications, we process push tokens, device platform, app registration status, notification permission state, and associated account identifiers. The app also stores necessary information locally, including your signed-in session, encryption material, preferences, and cached notifications and device information. Sensitive encryption material is stored using the operating system’s secure-storage facilities when available.

Device information

If you connect a compatible device, we may process its identifier, name, type, active or paused state, firmware version and update status, connection details, command results, and operational telemetry. Location information is processed only when you deliberately provide coordinates, a city, or a time zone for a device feature such as weather display; the mobile app does not request continuous location access.

Website, newsletter, and support information

When you subscribe to project updates or contact us, we process the information you submit, such as your name, email address, company or project, and message. If you report a problem, we also process any diagnostic details you choose to provide. Our hosting providers may process routine network information, such as IP address, browser or device type, request time, and requested page, for delivery, reliability, and security logs.

Information we do not use for advertising

Notificator does not contain third-party advertising SDKs, does not sell personal data, and does not use your information for cross-app or cross-site advertising tracking. The website does not currently use advertising cookies or behavioral analytics tools.

03

How and why we use information

We use information only as reasonably necessary to:

  • Create, authenticate, secure, and support your account.
  • Receive, encrypt, synchronize, display, and deliver the alerts you configure.
  • Connect WordPress sites, API integrations, mobile apps, and compatible devices.
  • Manage API keys, delivery channels, preferences, devices, and firmware operations.
  • Send service messages, password resets, security notices, or opted-in project updates.
  • Respond to support requests, diagnose failures, prevent abuse, and protect the service.
  • Maintain, improve, and comply with legal obligations applicable to the project.

Where privacy law requires a legal basis, we generally rely on performing the service you requested, our legitimate interests in operating and securing it, your consent for optional communications or permissions, and compliance with legal obligations. You may withdraw consent for optional processing at any time, without affecting processing that already occurred lawfully.

04

Service providers and disclosures

We share information only when required to operate a feature, protect the service, comply with law, or follow your direction. Key providers include:

  • Supabase for authentication, account records, and database services.
  • Expo and the Apple or Google push services for mobile notification delivery.
  • Netlify for website, form, and API hosting.
  • Email-delivery providers for password recovery, requested email notifications, support replies, and newsletter messages.
  • MQTT and connected-device infrastructure when you enable those delivery channels.

These providers may process information in countries other than yours under their own terms and privacy commitments. We may also disclose information when legally required, to investigate fraud or security threats, or to protect users and the project. Public GitHub issues and blog discussions are visible to everyone, so do not post personal data or secrets there. Blog comments are provided through Giscus and GitHub Discussions; GitHub processes your account and interaction under its own privacy terms when you load or use that feature.

05

How we protect information

We use encrypted network connections, access controls, scoped authentication, request validation, and other reasonable safeguards. Notification history synchronized through the service is designed to be encrypted using your account’s public key before database storage. Incoming event data must still be processed temporarily to route the notification, and email delivery necessarily exposes the email content to the selected email provider.

No system can guarantee absolute security. Protect your account, enable two-factor authentication where available, keep API keys secret, restrict their allowed domains, and revoke any credential you believe has been exposed. Please report suspected security issues privately through our contact form rather than a public issue.

06

Retention

Account-linked information is generally retained while your account is active or while it is needed to provide the service. You can remove notifications, devices, and API keys using available controls. Support messages and operational or security logs are retained only as long as reasonably needed for the request, reliability, abuse prevention, dispute resolution, or legal obligations.

When an account-deletion request is completed, account-linked records are deleted or anonymized unless limited retention is required for security, fraud prevention, legal compliance, or backup recovery. Data may remain temporarily in protected backups until those backups rotate out of use.

07

Your privacy choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information.

  • Update profile information and notification preferences in the app.
  • Allow or disable push notifications in your operating-system settings.
  • Disable email delivery, API keys, devices, or individual WordPress delivery channels.
  • Delete stored notification history, devices, and API keys using available app controls.
  • Unsubscribe from project newsletters using the link in the message or by contacting us.
  • Request access, correction, export, or deletion by emailing us from the address associated with your account.

We may need to verify your identity before completing a request. You may also have the right to complain to your local data-protection authority.

08

Request account deletion

To request deletion of your Notificator account and associated data, email hello@notificator-project.com from the email address connected to your account with the subject “Delete my Notificator account”, or use the contact form and choose the same wording in your message.

After verifying account ownership, we will delete or anonymize the account profile, registered push tokens, API keys, connected-device records, and stored notification history associated with the account, subject to the limited retention described above. Account deletion is permanent and may prevent connected plugins and devices from delivering future alerts until configured with another account.

Request deletion

09

Children’s privacy

Notificator is not directed to children, and we do not knowingly collect personal information from children who cannot legally consent to its processing. If you believe a child has provided information to Notificator, contact us so we can review and remove it where appropriate.

10

Changes to this policy

We may update this policy when Notificator’s features, providers, or legal obligations change. The effective date at the top of the page will be updated, and material changes may also be announced through the app, website, or project channels.

11

Contact

Notificator Project
Operated by Vagelis Papaioannou
Email: hello@notificator-project.com
Website: notificator-project.com