Privacy Policy
Last updated: June 18, 2026
This Privacy Policy explains how Mindeon ("we", "us") handles information in connection with the NotifyBridge mobile app and the NotifyBridge API (collectively, the "Service"). NotifyBridge is built to deliver push notifications from hardware and IoT devices to end users with minimal personal data collection. By using the Service, you agree to the practices described below.
1Information We Collect
NotifyBridge does not require account registration, email addresses, or sign-in. To operate, the Service collects and stores the following:
| Data | Purpose |
|---|---|
| User Key | A randomly generated identifier created on your device that links your apps, devices, and push notification usage. It is not derived from and does not contain personal information. |
| API Token | A randomly generated credential used to authorize notification requests for an app you create. |
| Device Push Token (Firebase Cloud Messaging token) | Used to deliver push notifications to your phone via Apple Push Notification service (through Firebase Cloud Messaging). Refreshed automatically by the operating system and updated in our records. |
| Device / Relay Labels | Names you choose for apps, hardware devices, and relays (e.g. "Greenhouse Sensor #42"). These are user-supplied labels, not derived from personal data. |
| Device Codes & QR Codes | Randomly generated codes used to link a piece of hardware to a subscriber's phone. |
| Notification Content | The message text and priority sent from your hardware, transmitted to deliver the notification and stored briefly for delivery history within the app. |
| Usage & Credit Counters | Counts of notifications sent per month, used to enforce the free monthly allocation and track any additional push credits purchased. |
| Platform Information | The operating system platform (e.g. iOS) associated with a registered device, used to route notifications correctly. |
We do not collect your name, email address, physical address, contacts, photos, precise location, browsing history, or any advertising identifiers. We do not use the Service to track you across other apps or websites.
2How We Use Information
- Delivering notifications — routing messages from your hardware to the correct subscriber device(s).
- Authentication of requests — verifying that a notification request comes from a valid app and account using the API token and user key.
- Usage enforcement — tracking monthly notification volume against your free allocation or purchased credits.
- Service operation and reliability — diagnosing delivery failures (e.g. disabling a device record if its push token is no longer valid).
We do not sell your information, and we do not use it for advertising or build profiles about you for marketing purposes.
3Legal Basis for Processing (EEA / UK / Switzerland)
If you are located in the European Economic Area, the UK, or Switzerland, we rely on the following legal bases under GDPR/UK GDPR to process your data:
- Contractual necessity — processing the identifiers and push tokens described in Section 1 is necessary to provide the notification delivery service you requested.
- Legitimate interests — securing the Service, preventing abuse of the free allocation, and diagnosing delivery failures.
- Legal obligation — where we must retain or disclose information to comply with applicable law.
4Third-Party Service Providers (Sub-Processors)
NotifyBridge relies on the following sub-processors to operate. We share only the minimum data each provider needs to perform its function:
- Firebase Cloud Messaging (Google LLC) — used to deliver push notifications to devices. Your device's push token and notification content are shared with Firebase solely to deliver notifications. See Google's Privacy Policy.
- Apple App Store / StoreKit (Apple Inc.) — used to process in-app purchases of additional push credits and to deliver notifications to iOS devices via the Apple Push Notification service. Payment details are handled entirely by Apple; we never receive or store your payment information. See Apple's Privacy Policy.
- Cloudflare, Inc. — our API runs on Cloudflare Workers and D1, which process requests and store the data described in Section 1 on our behalf, and may log standard connection metadata (e.g. IP address, timestamp) for security and abuse prevention. See Cloudflare's Privacy Policy.
We do not permit these providers to use your data for their own advertising purposes, and we do not sell or rent your information to anyone.
5International Data Transfers
Our sub-processors (Google, Apple, Cloudflare) operate global infrastructure, so your data may be processed in countries other than your own, including the United States. Where required, these providers maintain appropriate safeguards for cross-border transfers, such as Standard Contractual Clauses.
6Data Retention
- User keys, apps, and devices — retained for as long as they remain active, so notifications continue to be delivered correctly.
- Push tokens — retained until replaced by a newer token or until the associated device is removed; tokens that Apple/Firebase report as invalid are automatically disabled.
- Notification content — retained only as needed to display delivery history within the app; not retained indefinitely.
- Usage and credit counters — retained on a monthly basis for billing and allocation purposes.
- Server connection logs (maintained by Cloudflare on our behalf) — retained for a limited period for security, abuse prevention, and debugging.
You may request deletion of your data at any time as described in Section 9.
7Data Sharing
We do not sell or rent your information. We share data only with the sub-processors listed in Section 4, to the extent necessary to operate the Service, or where required by law (e.g. in response to a valid subpoena or court order).
If a device is claimed by a subscriber (end user) under Subscriber Mode, the developer who created that device can see the device's name and notification activity, but not any personal information about the subscriber, since none is collected.
8Cookies & Do Not Track
The NotifyBridge mobile app and API do not use cookies. This website (mindeon.net) is a static site and does not set cookies or use third-party analytics or advertising trackers. We do not respond to browser "Do Not Track" signals because we have no tracking to disable.
9Your Choices & Rights
- Disable notifications — you can turn off push notifications at any time in your device's system settings.
- Delete a device or app — remove devices, relays, or apps directly within NotifyBridge to stop further data collection for them.
- Request data deletion — contact us (see Section 13) with your user key to request deletion of all associated records.
- Regional rights — depending on where you live (e.g. EEA/UK under GDPR, California under CCPA/CPRA), you may have additional rights to access, correct, or delete your data, or to object to certain processing. We aim to respond to verified requests within 30 days.
10Children's Privacy
NotifyBridge is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided information to us, contact us and we will remove it.
11Data Security
We use industry-standard measures, including encrypted transport (HTTPS/TLS) for all API requests, to protect the data described in this policy. No method of transmission or storage is 100% secure, but we work to protect your information using commercially reasonable safeguards.
12Data Breach Notification
If we become aware of a security incident that compromises your data, we will notify affected users and, where required by law, the relevant supervisory authority, without undue delay.
13Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
14Contact Us
If you have questions about this Privacy Policy or wish to exercise any of the rights described above, contact us at privacy@mindeon.com.