Notify

Privacy Policy

Last updated August 9, 2026

Overview

Notify is operated by belweave. This policy explains the information Notify processes to deliver webhook notifications through the website and iOS app. Notify does not sell personal information or use it for targeted advertising.

Information we process

  • Your Google or Apple account identifier, name, email address, and profile image when provided by the sign-in service. Apple may provide a private relay email address.
  • Encrypted Apple refresh tokens used only to revoke Sign in with Apple authorization when you delete your account.
  • Service settings you create, including titles, image URLs, destination URLs, secret webhook-token hashes, and encrypted webhook tokens.
  • Webhook and agent notification content such as titles, bodies, summaries, project names, images, destinations, idempotency keys, timestamps, read state, and delivery results.
  • Device information needed for delivery, including Expo and APNs push tokens, device name, platform, and last registration time.
  • Agent access-token names, scopes, identifying prefixes, hashes, expiry and usage times. Plaintext agent tokens are shown once and are not stored by Notify.
  • Approval and reply prompts, choices, expiry, response text or decision, requesting token identity, responding device, and response timestamps.
  • Live Activity task titles, status text, optional detail and progress, expiry and update history, requesting token identity, and encrypted ActivityKit delivery tokens. Private mode replaces task content with generic text on the Lock Screen but does not remove the task content from Notify's encrypted network and account-scoped processing.
  • Subscription status and billing identifiers when you choose a paid plan. Payment-card details are collected and handled by Stripe, not stored by Notify.
  • Limited technical logs used to secure, operate, and troubleshoot the service.
  • Product analytics such as page and app-screen visits, feature lifecycle events, first-touch campaign labels, referring and outbound hostnames, app version, coarse outcomes, and related account, service, device, anonymous-install, or session identifiers. Notify never puts notification content, summaries, project names, prompts, replies, tokens, full URLs, IP addresses, email addresses, or user-agent strings in analytics.

How we use information

We use this information to authenticate your account, create and secure webhook endpoints, deliver notifications, show delivery activity, prevent duplicate or abusive requests, deliver requested interactions and return your response to the authorized agent, start and update Live Activities you authorize, provide support, and maintain the reliability and security of Notify.

Service providers

Notify relies on Google and Apple for authentication, Expo and Apple for push delivery and app distribution, Autumn and Stripe for optional web billing, and hosting infrastructure for the website, API, and database. These providers process information only as needed to provide their services and under their own privacy terms.

Retention and deletion

We retain account and service data while your account is active. Webhook and agent notification content — including titles, bodies, summaries, projects, and read state — persists in your inbox and is not expired on a schedule; it is removed when your account is deleted. You can permanently delete your account inside the Notify app. Deletion removes your services, devices, projects, notifications, and activity from the active database. For accounts using Apple, Notify first asks Apple to revoke stored authorization grants; deletion stops and reports an error if that revocation cannot be confirmed. Limited backup copies may remain temporarily until rotated.

Security and your choices

Webhook URLs contain secret tokens and should be treated like passwords. You can rotate a webhook token or revoke a scoped agent token from the dashboard if it is exposed. Device responses require the signed-in account and a registered device identity. Notify uses access controls and encrypted network connections, but no online service can guarantee absolute security.

Children

Notify is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

Contact

Questions or privacy requests can be sent to notify@belweave.ai.