Effective date: 2026-05-17 · Last updated: 2026-05-17
Notificator is a notification client that receives messages from a server you configure. This policy describes what data the mobile app handles and how, on both iOS and Android. The mobile app and the server are operated by separate parties: this policy covers only the mobile app.
Notificator collects only the data needed to deliver notifications from your configured server. We do not run advertising, we do not track user behavior across apps or websites, and we do not sell data to third parties.
The app uses Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM, operated by Google) to deliver notifications. Your push token is exchanged with these services as required for delivery; message content is exchanged only with the server you configure inside the app.
No analytics SDKs, advertising SDKs, or tracking SDKs are integrated.
All network traffic between the mobile app and your configured server runs over TLS (HTTPS). Account credentials are additionally encrypted at the application layer with a per-subscription RSA key before they leave the device, so a network observer with a corporate TLS-intercepting middlebox still cannot read them in plaintext. On-device, your password is stored only in the platform's hardware-backed secure storage — iOS Keychain or Android Keystore — and access can be gated behind biometric authentication when your administrator enables that policy.
Push tokens and the locally cached notification history live on your device. The local history rolls itself off after seven days; individual rows can be deleted manually at any time. The mobile app does not maintain any server-side database under our control; all server-side storage is operated by whoever runs the server you configured.
Notification delivery relies on Apple's APNs (United States) and Google's FCM (United States and other regions) as transit providers. Their handling of the push token is governed by their own privacy policies (see Third Parties above). No data is transferred internationally by Notificator itself; transfers between you and your server depend on where that server runs.
You can stop the app from collecting data at any time by signing out, revoking permissions in your device settings, or uninstalling the app. To request information about data your server holds about you — or to exercise rights granted by GDPR, CCPA, or comparable laws (access, rectification, erasure, portability, restriction, objection) — contact your server's administrator. They are the data controller for everything the server stores.
To remove every piece of data Notificator keeps on the device:
Data held by your configured server is outside our control — contact your server administrator to request deletion there.
Notificator is not directed to children under 13. We do not knowingly collect personal information from children.
We may update this policy from time to time. The latest version will always be available at this URL with a revised "Last updated" date. Material changes will be surfaced inside the app on first launch after the update, asking you to acknowledge them.