Privacy Policy
Last updated: October 5, 2026
This policy explains which personal data is processed when you use the website pushmyinfo.site, the dashboard app.pushmyinfo.site and the AlmightyPush browser push notification service (together, the “Service”), why, for how long, and what rights you have. It is written in line with the EU General Data Protection Regulation (GDPR) and the Law of Ukraine “On Personal Data Protection”.
1. Who processes the data
The data controller is a private individual developing the AlmightyPush Service, based in Ukraine (“we”, “us”). For any question about personal data, contact support@pushmyinfo.site.
For the data of visitors and subscribers of our customers’ websites, we act as a processor on behalf of the customer (section 4 and the Data Processing Agreement).
2. What data we process and why
2.1. Visiting the website
The server logs technical request data: IP address, time, requested URL and browser details. We need it to run the website, protect it from attacks and investigate errors. Legal basis: our legitimate interest in operating the website securely (Art. 6(1)(f) GDPR). Logs are kept for 14 days. The website uses no analytics or advertising trackers; fonts are served from our own server.
2.2. Demo notification
If you run the demo on the home page and allow notifications, the permission is stored in your browser, and the website registers a Service Worker and shows a single notification directly on your device. No subscription is created and no subscription data is sent to our server. You can revoke the permission in your browser’s site settings.
2.3. Closed beta application
From the application form we receive your name, email, website or project name and a description of how you plan to use the Service. We derive your country from your IP address; the IP address itself is not stored with the application.
- Purpose: to review the application and reply to you, including sending an invitation code.
- Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR).
- Retention: applications are deleted automatically 12 months after submission.
- We receive a notification of a new application with its number and country only — no name, address or text.
2.4. Dashboard account
| Data | Purpose | Retention |
|---|---|---|
| Email, name, password as an irreversible hash, two-factor secret if enabled | Sign-in, account operation and service emails | As long as the account exists |
| Sign-in sessions: IP address, browser, time | Account security | 30 days after the session ends |
| Project activity log: who did what and when, IP address, browser | Security and resolving disputed actions within a team | As long as the project exists |
| API tokens | Integration access you choose to grant | Until the token is revoked |
Legal basis for the project owner: performance of the contract for using the Service (Art. 6(1)(b) GDPR). For team members invited by a customer: the legitimate interest of the customer and of us in enabling the customer’s team to work in the Service (Art. 6(1)(f) GDPR). For logs and sessions, also our legitimate interest in security. Service emails (address confirmation, team invitations, password reset, notices of changes to our terms) are sent via Resend.
2.5. Sign in with Google
If you sign in with a Google account, we receive your name, email, Google account ID and, if available, your profile picture URL from Google. We use this data to sign you in and operate your account, including using your email for the service emails described in section 2.4. We do not sell it or use it for advertising or to train models. Infrastructure providers (section 5) access it only to the extent necessary to operate the Service.
AlmightyPush’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. Cookies and browser storage
The Service uses no advertising or analytics cookies. Everything stored on your device is needed for a feature you use:
| Where | What is stored | Why |
|---|---|---|
| Website pushmyinfo.site | Selected theme; a flag that you are signed in to the dashboard; the demo notification Service Worker | Show the website in your theme and the “Go to dashboard” button; run the demo |
| Dashboard app.pushmyinfo.site | Session cookie; selected theme and animation setting | Signing in and interface settings |
| Our customers’ websites | Service Worker and push subscription; markers that the subscription banner was shown or closed, which banner variant was assigned, and that a notification click reached the site | Delivering notifications, pausing before the banner is shown again, keeping one banner variant per visitor, counting visits from notifications |
Cloudflare, which delivers the website and dashboard, may set technical cookies required to protect against attacks. On customers’ websites, the customer determines and obtains any consent required for these mechanisms.
4. Visitors and subscribers of our customers’ websites
Customers connect the Service to their websites to send notifications to visitors who have subscribed. The customer is the controller of this data, and we process it on the customer’s behalf solely to provide the Service, under the Data Processing Agreement. The customer determines the purposes and legal bases of processing, including selecting recipients of notifications by criteria the customer sets, and informs visitors of its website.
4.1. Subscriber data
- subscriber ID, the subscription address at the browser’s push service and notification encryption keys;
- dates of subscription, last visit, last notification and last click; notification and click counters;
- subscription source: domain, landing page and page path, labels passed by the customer’s code, subscription banner variant and language; through the landing page — audience and tags;
- country, region, city and internet provider derived from the IP address, the last IP address, and the country declared by the customer’s page;
- time zone, language, browser, operating system and device type;
- notification events: sent, shown, clicked, closed, visited the website.
4.2. Visitors who did not subscribe
Subscription banner impressions and responses are recorded only in daily totals — per landing page, country, browser, language and banner variant — without visitor identifiers. Technical data of these requests, including IP addresses, remains only in server logs (14 days).
4.3. Retention
- An active subscription — while it is valid and the customer uses the Service.
- A subscription that is no longer valid (the subscriber unsubscribed or the browser removed it) — 180 days from that moment, then it is deleted.
- Notification events — 90 days.
- When a customer deletes a project, subscription collection and sending stop immediately. For 30 days the project owner may ask us to restore it; after that the data is deleted.
- Database backups are kept for up to 14 days, so deleted data disappears from them within that period.
You can unsubscribe at any time by disabling notifications for the website in your browser settings. Unsubscribing stops notifications but does not immediately delete all data — it is deleted within the periods above. For questions about your data, contact the owner of the website where you subscribed: they are the controller and may ask us to delete it earlier.
5. Who receives the data
We do not sell personal data. It is received by providers of infrastructure and additional features of the Service:
| Recipient | What data and why | Where processed | Transfer basis |
|---|---|---|---|
| Webdock (Denmark) | All Service data — server and database hosting | Denmark, EU | No transfer outside the EEA |
| Cloudflare, Inc. | IP addresses and request content for the website, dashboard and API — delivery and attack protection; on the application form, checking that a human is submitting it (Turnstile) | Global network, including the USA | EU-U.S. Data Privacy Framework; EU Standard Contractual Clauses in Cloudflare’s DPA |
| Resend | Email, name and content of service emails — sending them | USA | EU Standard Contractual Clauses in Resend’s DPA; EU-U.S. Data Privacy Framework |
| DeepL SE | Subscription banner texts, no personal data — translation, if the customer connected its own DeepL key | Germany, EU | No transfer outside the EEA |
| Browser push services (Google, Mozilla, Apple, Microsoft) | Subscription address and encrypted notification content — delivering the notification | Generally the USA | The push service is chosen by the subscriber’s browser; the content is not readable to it |
| The controller | Service data — administration and support | Access from Ukraine | Section 6 |
Sign-in data from Google is received from Google (section 2.5), not sent to it. Country and region are derived from a local MaxMind GeoLite2 database; IP addresses are not sent to MaxMind. We may disclose data where required by law.
6. Transfers outside the EEA
We are based in Ukraine, for which there is no European Commission adequacy decision. We collect the data of dashboard users and applicants directly from them. For data we process on behalf of customers in the EEA, transfers rely on the EU Standard Contractual Clauses incorporated into the Data Processing Agreement. Transfer mechanisms for our providers are listed in the table in section 5.
7. Your rights
Where and under the conditions provided by applicable law, you can:
- obtain information about your data and a copy of it;
- have inaccurate data corrected;
- request erasure, including deletion of your account;
- restrict or object to processing;
- receive your data in a machine-readable format (portability);
- withdraw consent where processing is based on it.
Write to support@pushmyinfo.site — we will respond within one month. If you are a subscriber of a customer’s website, the website owner handles the request and we assist them. You also have the right to lodge a complaint with the data protection authority of the EU country where you live or work, and in Ukraine with the Ukrainian Parliament Commissioner for Human Rights.
8. Security
We apply technical and organizational measures to protect personal data, including encryption in transit, secure storage of passwords and secrets, access control and activity logging. Two-factor authentication is available to dashboard users.
9. Age
The dashboard is intended for persons aged 18 or over, for professional use. The website is not directed at children, and we do not knowingly collect their data. Customers are responsible for the audience of their own websites.
10. Automated decisions
We do not make decisions based solely on automated processing that produce legal or similarly significant effects for dashboard users. For customers’ notifications, the Service selects subscribers by criteria the customer sets; the customer determines the purposes and legal bases of that processing.
11. Changes to this policy
The current version is always published on this page, with the date shown at the top. We notify dashboard users of material changes by email at least 30 days in advance. See also our Terms of Use.