Ir al contenido
Notify
Todos los documentos

Este documento aún no está disponible en tu idioma.

Privacy statement

Actualizado: 2026-07-30Versión 1.0

Notify was built to give attention back, not to collect data. This statement describes exactly which data we process and why.

The controller is Weergeven, Burgstraat 2E, 4201 AC Gorinchem, Nederland (Dutch Chamber of Commerce no. 11063849). Questions or requests: privacy@notify.rocks.

The Dutch version of this statement is the binding one; this translation is provided for convenience.

What we process

Your account

  • Your email address (needed to sign in — we use no passwords, but a sign-in link sent by email).
  • Your language and time zone, so moments arrive at the right time in the right language.
  • Your preferences: theme, quiet hours, daily notification cap, digest time, and whether email may be used as a fallback.

What you follow

  • The reminders and topics you create yourself, including their schedule.
  • The moments that result from them: title, summary, time, whether you read them, and the recorded reason why you received the moment.

Your devices

  • An encrypted push subscription for every device on which you enable notifications. We store the subscription address encrypted only (AES-256-GCM), alongside an unreadable fingerprint used to recognise the same device.
  • The platform (for example iOS or Android) and when the device was last active.

Support and waiting list

  • If you contact the help desk, we keep your email address, your question and our answer.
  • If you join the waiting list for the mobile apps, we keep only your email address and your language.

Technical logs

  • Server logs with a request ID, timestamp and error codes, used to resolve faults and limit abuse. They contain no content of your moments.

Purposes and legal bases

PurposeLegal basis
Providing the service: signing in, watching reminders, delivering momentsPerformance of the contract (Art. 6(1)(b) GDPR)
Showing push notifications on your deviceYour consent — you enable this per device and can withdraw it in your browser or phone settings
Answering your help desk questionPerformance of the contract, or legitimate interest in good support
Security, abuse prevention and troubleshootingLegitimate interest in a working, secure service (Art. 6(1)(f) GDPR)
Waiting list for the mobile appsYour consent — you sign up yourself and can unsubscribe
Legal obligations, such as record keepingLegal obligation (Art. 6(1)(c) GDPR)

What we do not do

  • No advertising, and no selling or renting of data.
  • No profiling for advertising and no automated decisions with legal effects.
  • No tracking cookies and no third-party analytics.
  • No engagement tricks: no red badges, no streaks, no endless feed.
  • We do not read the content of your moments for any purpose other than delivering them.

Every moment you receive carries a recorded reason and provenance that you can inspect in the app. That is a deliberate design choice: you should be able to see why something asked for your attention.

Where your data is stored

All data is stored on servers in the European Union. We use a small number of processors, listed on the subprocessors page: Supabase (database and sign-in, Frankfurt), Vercel (hosting) and Resend (email delivery, EU). A data processing agreement is in place with each of them. Where a processor could process data outside the EU, this happens under the European Commission's standard contractual clauses.

How long we keep it

  • Account and preferences: as long as your account exists.
  • Reminders and moments: as long as your account exists. Delete your account and they go with it. A shorter retention period for moments may apply per plan; it is stated with the plan if so.
  • Devices: until you turn notifications off, the device stops reporting for a long time, or you delete your account.
  • Help desk messages: at most 24 months after the request is closed.
  • Waiting list: until the app is released or you unsubscribe.
  • Server logs: at most 30 days.
  • Audit log of administrative actions: 7 years, without any content of your moments. This log is immutable and exists to demonstrate who changed what and when.

Your rights

You have the right of access, rectification, erasure, restriction, objection and data portability. Two of these you can exercise yourself, immediately:

  • Download: on the You screen in the app, one button gives you all your data as a JSON file.
  • Delete: on that same screen you can delete your account. This immediately erases your profile, preferences, reminders, moments and devices. It cannot be undone.

For the other rights, email privacy@notify.rocks. We respond within 30 days. If you are not satisfied, you can lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl) or with the supervisory authority in your own country.

Security

Push addresses are stored encrypted. Database access runs through strict row-level security, with every query carrying the boundary of your account. Administrative access requires two-factor authentication and every administrative action is recorded immutably. All traffic runs over TLS.

Children

Notify is not directed at children under 16. By creating an account you confirm that you are 16 or older, or that you have permission from your parent or guardian.

Changes

We update this statement when the service changes. The version and date are shown at the top of this page and every change is traceable in our source history. We will tell you through the app or by email about significant changes.

La versión en neerlandés es vinculante; las traducciones son meramente informativas.