DATA
Information needed to run Pushify.
Pushify handles account and device identifiers, display names, channel memberships and roles, scoped credential metadata, delivery status, notification content, phone responses, support cases, abuse reports, blocks, and security audit records. Bearer and session secrets are stored only as one-way hashes by the server. Password authentication uses Argon2id, and Android protects its current session with Android Keystore.
DELIVERY
Cloudflare and Firebase participate.
Public HTTPS traffic passes through Cloudflare. Ordinary Android notifications can expose their content to Pushify and Firebase Cloud Messaging. End-to-end encrypted channels use a generic Firebase wake-up and store per-device libsignal ciphertext on Pushify. The providers still receive connection, timing, size, and routing metadata.
RETENTION
History is bounded, but copies differ.
Server event, response, delivery, and deduplication history is retained for 90 days. Operational backups follow the documented backup schedule. Android keeps an app-private inbox until the user deletes it or an enforceable expiry or purge removes it. Another recipient's phone, screenshots, exports, and backup copies cannot be recalled with certainty.
CONTROL
Export and closure are available to invited users.
The Android Account screen can request a metadata export that excludes credentials, FCM tokens, and message bodies. It can also request account closure. Active channel ownership must be transferred or resolved first. Closure revokes access and disables the account, while shared history and immutable security audit records continue under their existing retention rules.
LIMITS
No advertising analytics or public identity vendor.
The beta has no advertising analytics, public signup, email/SMS identity verification, or payment provider. If that changes, this notice and the product gate must change before collection begins.