此文档暂无你的语言版本。
Privacy statement
更新日期:2026-07-30版本 1.0
Notify was built to give attention back, not to collect data. This statement describes exactly which data we process and why.
The controller is Weergeven, Burgstraat 2E, 4201 AC Gorinchem, Nederland (Dutch Chamber of Commerce no. 11063849). Questions or requests: privacy@notify.rocks.
The Dutch version of this statement is the binding one; this translation is provided for convenience.
What we process
Your account
- Your email address (needed to sign in — we use no passwords, but a sign-in link sent by email).
- Your language and time zone, so moments arrive at the right time in the right language.
- Your preferences: theme, quiet hours, daily notification cap, digest time, and whether email may be used as a fallback.
What you follow
- The reminders and topics you create yourself, including their schedule.
- The moments that result from them: title, summary, time, whether you read them, and the recorded reason why you received the moment.
Your devices
- An encrypted push subscription for every device on which you enable notifications. We store the subscription address encrypted only (AES-256-GCM), alongside an unreadable fingerprint used to recognise the same device.
- The platform (for example iOS or Android) and when the device was last active.
Support and waiting list
- If you contact the help desk, we keep your email address, your question and our answer.
- If you join the waiting list for the mobile apps, we keep only your email address and your language.
Technical logs
- Server logs with a request ID, timestamp and error codes, used to resolve faults and limit abuse. They contain no content of your moments.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service: signing in, watching reminders, delivering moments | Performance of the contract (Art. 6(1)(b) GDPR) |
| Showing push notifications on your device | Your consent — you enable this per device and can withdraw it in your browser or phone settings |
| Answering your help desk question | Performance of the contract, or legitimate interest in good support |
| Security, abuse prevention and troubleshooting | Legitimate interest in a working, secure service (Art. 6(1)(f) GDPR) |
| Waiting list for the mobile apps | Your consent — you sign up yourself and can unsubscribe |
| Legal obligations, such as record keeping | Legal obligation (Art. 6(1)(c) GDPR) |
What we do not do
- No advertising, and no selling or renting of data.
- No profiling for advertising and no automated decisions with legal effects.
- No tracking cookies and no third-party analytics.
- No engagement tricks: no red badges, no streaks, no endless feed.
- We do not read the content of your moments for any purpose other than delivering them.
Every moment you receive carries a recorded reason and provenance that you can inspect in the app. That is a deliberate design choice: you should be able to see why something asked for your attention.
Where your data is stored
All data is stored on servers in the European Union. We use a small number of processors, listed on the subprocessors page: Supabase (database and sign-in, Frankfurt), Vercel (hosting) and Resend (email delivery, EU). A data processing agreement is in place with each of them. Where a processor could process data outside the EU, this happens under the European Commission's standard contractual clauses.
How long we keep it
- Account and preferences: as long as your account exists.
- Reminders and moments: as long as your account exists. Delete your account and they go with it. A shorter retention period for moments may apply per plan; it is stated with the plan if so.
- Devices: until you turn notifications off, the device stops reporting for a long time, or you delete your account.
- Help desk messages: at most 24 months after the request is closed.
- Waiting list: until the app is released or you unsubscribe.
- Server logs: at most 30 days.
- Audit log of administrative actions: 7 years, without any content of your moments. This log is immutable and exists to demonstrate who changed what and when.
Your rights
You have the right of access, rectification, erasure, restriction, objection and data portability. Two of these you can exercise yourself, immediately:
- Download: on the You screen in the app, one button gives you all your data as a JSON file.
- Delete: on that same screen you can delete your account. This immediately erases your profile, preferences, reminders, moments and devices. It cannot be undone.
For the other rights, email privacy@notify.rocks. We respond within 30 days. If you are not satisfied, you can lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl) or with the supervisory authority in your own country.
Security
Push addresses are stored encrypted. Database access runs through strict row-level security, with every query carrying the boundary of your account. Administrative access requires two-factor authentication and every administrative action is recorded immutably. All traffic runs over TLS.
Children
Notify is not directed at children under 16. By creating an account you confirm that you are 16 or older, or that you have permission from your parent or guardian.
Changes
We update this statement when the service changes. The version and date are shown at the top of this page and every change is traceable in our source history. We will tell you through the app or by email about significant changes.
荷兰语版本具有法律约束力;翻译仅供参考。