AlmightyPushРусская версия

Privacy Policy

Last updated: October 5, 2026

This policy explains which personal data is processed when you use the website pushmyinfo.site, the dashboard app.pushmyinfo.site and the AlmightyPush browser push notification service (together, the “Service”), why, for how long, and what rights you have. It is written in line with the EU General Data Protection Regulation (GDPR) and the Law of Ukraine “On Personal Data Protection”.

1. Who processes the data

The data controller is a private individual developing the AlmightyPush Service, based in Ukraine (“we”, “us”). For any question about personal data, contact support@pushmyinfo.site.

For the data of visitors and subscribers of our customers’ websites, we act as a processor on behalf of the customer (section 4 and the Data Processing Agreement).

2. What data we process and why

2.1. Visiting the website

The server logs technical request data: IP address, time, requested URL and browser details. We need it to run the website, protect it from attacks and investigate errors. Legal basis: our legitimate interest in operating the website securely (Art. 6(1)(f) GDPR). Logs are kept for 14 days. The website uses no analytics or advertising trackers; fonts are served from our own server.

2.2. Demo notification

If you run the demo on the home page and allow notifications, the permission is stored in your browser, and the website registers a Service Worker and shows a single notification directly on your device. No subscription is created and no subscription data is sent to our server. You can revoke the permission in your browser’s site settings.

2.3. Closed beta application

From the application form we receive your name, email, website or project name and a description of how you plan to use the Service. We derive your country from your IP address; the IP address itself is not stored with the application.

2.4. Dashboard account

DataPurposeRetention
Email, name, password as an irreversible hash, two-factor secret if enabledSign-in, account operation and service emailsAs long as the account exists
Sign-in sessions: IP address, browser, timeAccount security30 days after the session ends
Project activity log: who did what and when, IP address, browserSecurity and resolving disputed actions within a teamAs long as the project exists
API tokensIntegration access you choose to grantUntil the token is revoked

Legal basis for the project owner: performance of the contract for using the Service (Art. 6(1)(b) GDPR). For team members invited by a customer: the legitimate interest of the customer and of us in enabling the customer’s team to work in the Service (Art. 6(1)(f) GDPR). For logs and sessions, also our legitimate interest in security. Service emails (address confirmation, team invitations, password reset, notices of changes to our terms) are sent via Resend.

2.5. Sign in with Google

If you sign in with a Google account, we receive your name, email, Google account ID and, if available, your profile picture URL from Google. We use this data to sign you in and operate your account, including using your email for the service emails described in section 2.4. We do not sell it or use it for advertising or to train models. Infrastructure providers (section 5) access it only to the extent necessary to operate the Service.

AlmightyPush’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. Cookies and browser storage

The Service uses no advertising or analytics cookies. Everything stored on your device is needed for a feature you use:

WhereWhat is storedWhy
Website pushmyinfo.siteSelected theme; a flag that you are signed in to the dashboard; the demo notification Service WorkerShow the website in your theme and the “Go to dashboard” button; run the demo
Dashboard app.pushmyinfo.siteSession cookie; selected theme and animation settingSigning in and interface settings
Our customers’ websitesService Worker and push subscription; markers that the subscription banner was shown or closed, which banner variant was assigned, and that a notification click reached the siteDelivering notifications, pausing before the banner is shown again, keeping one banner variant per visitor, counting visits from notifications

Cloudflare, which delivers the website and dashboard, may set technical cookies required to protect against attacks. On customers’ websites, the customer determines and obtains any consent required for these mechanisms.

4. Visitors and subscribers of our customers’ websites

Customers connect the Service to their websites to send notifications to visitors who have subscribed. The customer is the controller of this data, and we process it on the customer’s behalf solely to provide the Service, under the Data Processing Agreement. The customer determines the purposes and legal bases of processing, including selecting recipients of notifications by criteria the customer sets, and informs visitors of its website.

4.1. Subscriber data

4.2. Visitors who did not subscribe

Subscription banner impressions and responses are recorded only in daily totals — per landing page, country, browser, language and banner variant — without visitor identifiers. Technical data of these requests, including IP addresses, remains only in server logs (14 days).

4.3. Retention

You can unsubscribe at any time by disabling notifications for the website in your browser settings. Unsubscribing stops notifications but does not immediately delete all data — it is deleted within the periods above. For questions about your data, contact the owner of the website where you subscribed: they are the controller and may ask us to delete it earlier.

5. Who receives the data

We do not sell personal data. It is received by providers of infrastructure and additional features of the Service:

RecipientWhat data and whyWhere processedTransfer basis
Webdock (Denmark)All Service data — server and database hostingDenmark, EUNo transfer outside the EEA
Cloudflare, Inc.IP addresses and request content for the website, dashboard and API — delivery and attack protection; on the application form, checking that a human is submitting it (Turnstile)Global network, including the USAEU-U.S. Data Privacy Framework; EU Standard Contractual Clauses in Cloudflare’s DPA
ResendEmail, name and content of service emails — sending themUSAEU Standard Contractual Clauses in Resend’s DPA; EU-U.S. Data Privacy Framework
DeepL SESubscription banner texts, no personal data — translation, if the customer connected its own DeepL keyGermany, EUNo transfer outside the EEA
Browser push services (Google, Mozilla, Apple, Microsoft)Subscription address and encrypted notification content — delivering the notificationGenerally the USAThe push service is chosen by the subscriber’s browser; the content is not readable to it
The controllerService data — administration and supportAccess from UkraineSection 6

Sign-in data from Google is received from Google (section 2.5), not sent to it. Country and region are derived from a local MaxMind GeoLite2 database; IP addresses are not sent to MaxMind. We may disclose data where required by law.

6. Transfers outside the EEA

We are based in Ukraine, for which there is no European Commission adequacy decision. We collect the data of dashboard users and applicants directly from them. For data we process on behalf of customers in the EEA, transfers rely on the EU Standard Contractual Clauses incorporated into the Data Processing Agreement. Transfer mechanisms for our providers are listed in the table in section 5.

7. Your rights

Where and under the conditions provided by applicable law, you can:

Write to support@pushmyinfo.site — we will respond within one month. If you are a subscriber of a customer’s website, the website owner handles the request and we assist them. You also have the right to lodge a complaint with the data protection authority of the EU country where you live or work, and in Ukraine with the Ukrainian Parliament Commissioner for Human Rights.

8. Security

We apply technical and organizational measures to protect personal data, including encryption in transit, secure storage of passwords and secrets, access control and activity logging. Two-factor authentication is available to dashboard users.

9. Age

The dashboard is intended for persons aged 18 or over, for professional use. The website is not directed at children, and we do not knowingly collect their data. Customers are responsible for the audience of their own websites.

10. Automated decisions

We do not make decisions based solely on automated processing that produce legal or similarly significant effects for dashboard users. For customers’ notifications, the Service selects subscribers by criteria the customer sets; the customer determines the purposes and legal bases of that processing.

11. Changes to this policy

The current version is always published on this page, with the date shown at the top. We notify dashboard users of material changes by email at least 30 days in advance. See also our Terms of Use.