Data and privacy
2026-09-14
Accounts and contact
Google sign-in shares your verified email, identifier and name. Email registration stores a password hash and a temporary confirmation challenge. The contact form and support mailbox store your reply email and correspondence. Sessions use an HttpOnly cookie; your chosen interface language is stored locally. The site has no advertising trackers.
Applications and notifications
PushPort stores application settings and encrypted Firebase sender credentials. The Android SDK sends an installation ID, Android ID when available, FCM token, app version and package, language and locales, timezone, device model, OS/SDK versions and notification subscription state. The backend records synchronization, send outcomes and notification taps. Country is approximate and comes from Cloudflare IP geolocation; it may reflect a VPN. The SDK does not request GPS coordinates, contacts or an advertising identifier.
Apple and Web subscriptions
Apple SDK sends a random installation ID, APNs token and environment, Bundle ID, locale, timezone, app/OS versions and notification state. Web SDK sends a random installation ID, website origin, browser push endpoint and subscription encryption keys, locale, timezone and permission state; local state is kept in IndexedDB. Neither SDK collects Android ID or IDFA. APNs and VAPID private keys remain encrypted on the server. Apple and browser push providers handle delivery; Firebase is used for Android. KMP reuses the native installation and adds no separate identity.
Infrastructure and external content
Hetzner hosts the service in Germany. Cloudflare provides website HTTPS and proxying; Google provides optional sign-in and FCM delivery. Domain email runs on our mail server. Technical logs may include IP, request path, time and response code. A notification image is downloaded from the sender’s chosen host, which sees the device request and IP. Following a notification link opens the destination under its own data practices.
Access, storage and questions
Account and application data remain until removal by the operator. Correspondence remains in the support system and mailbox; no automatic correspondence deletion policy is configured. Verification codes expire after 10 minutes, are stored as HMACs, and finished outbox bodies are cleared. Database/configuration backups are retained for 14 days and mail backups for 7 days. Application owners and authorized PushPort administrators can access relevant data. Contact [email protected] for access, deletion or other data questions. Owners of integrated applications must describe their use of PushPort and configure any required user choices.
Android activity and optional profiles
Automatically: installation UUID, separate PushPort user ID, Android ID where available, FCM token, notification permission and opt-in, language and locales, timezone, package/app/OS/SDK versions, manufacturer/model, carrier, foreground sessions and usage time. The backend records last IP and approximate country from trusted ingress. Background synchronization is not an app visit. Tags, email, E.164 phone, coordinates and custom events are supplied explicitly by your app. PushPort never reads contacts, IMEI, advertising ID or GPS automatically. Email/phone metadata does not enable email/SMS delivery. Each new installation receives a new PushPort userId. Restarts and updates preserve it. Android ID links history only; users are not merged and tags are not copied after reinstall. Existing user IDs remain unchanged. Explicit verified login can still link an account. When required, setConsentRequired must run before initialization. Consent and Android notification permission are separate. Revocation stops future PushPort collection/sync and presentation; it cannot recall in-flight requests or delete server history.
Website analytics (optional)
Only with your consent, we use Google Analytics 4 on pushport.dev to understand visits, pages used, approximate location, browser/device characteristics and successful actions such as registration, application/campaign creation and contact form submission. Google processes connection data including your IP address. We exclude email addresses, names, message content, app/campaign identifiers and URL query parameters from events. Referrers are reduced to the referring website; advertising features and Google Signals are disabled. Analytics cookies (_ga and the stream cookie) last up to 180 days without automatic renewal; your accept/refuse choice is saved locally for 180 days. Event-level retention in Analytics is 2 months. Use “Cookie settings” on any page to refuse or withdraw consent; withdrawal stops tracking and removes these cookies on this browser. Google is the analytics provider and may process data outside the EEA. More information: https://policies.google.com/privacy. The operator dashboard and SDK test website do not include this tracking.