Privacy Policy
NotifyMe | Penso Technology S.r.l.
Effective Date: Jan 1, 2026 — Last Updated: Jul 28, 2026
1. Scope
This Privacy Policy explains how we process information when you use our iOS App to send notifications to your own device. The App uses Firebase Cloud Messaging (FCM) and Firebase Analytics. We do not use other Firebase SDKs.
2. Data Controller & Contacts
- Data Controller: Penso Technology S.r.l., Piazzale delle Provincie 8, 00162 Rome, Italy
- Contact: via our Support website
3. What We Collect
- Device identifiers & tokens: APNs/FCM device tokens necessary to deliver notifications to your device. (Generated by Apple/FCM SDKs.)
- Notification metadata: timestamps, delivery outcomes, basic diagnostics to operate, troubleshoot, enforce Fair Use, and prevent abuse.
- Analytics events (privacy-friendly): app opens, subscription status events, crashes, and usage telemetry without advertising identifiers (IDFA). You can disable/enable analytics collection per Section 8.
We do not intentionally collect names, emails, addresses, or message content beyond what is necessary to deliver and operate the Service.
4. Purposes & Legal Bases (GDPR)
- Service delivery (Contract Art. 6(1)(b)): Generate/display device token, deliver notifications, provide subscription features.
- Security & Fair Use (Legitimate Interests Art. 6(1)(f)): Detect misuse, prevent spam/abuse, maintain integrity/availability.
- Analytics (Consent Art. 6(1)(a), where required): Measure basic app usage to improve the Service, using privacy-friendly settings; in the EEA you may need consent depending on configuration. Controls provided (Section 8).
5. Processors & Transfers
We use third-party service providers to operate the Service, including push delivery and analytics (currently Google Firebase). These providers act as processors under our instructions and may process data in the EU and/or the United States subject to Standard Contractual Clauses (SCCs) and appropriate safeguards. For details, see Firebase’s Data Processing and Security Terms.
Where data is transferred from other jurisdictions with transfer requirements (for example, Brazil under the LGPD), we rely on the transfer mechanisms provided in our processors’ data processing terms as required by applicable law.
6. APNs/FCM Delivery
Push delivery is a best-effort service influenced by device state, OS, and networks; APNs/FCM may throttle, store, or drop messages.
7. Retention
- Tokens & telemetry: retained only as long as needed for operation, troubleshooting, and Fair Use enforcement, then deleted or anonymized.
- Legal requirements: retained as required by law (e.g., billing records via Apple).
We respect Firebase deletion mechanisms and processor obligations.
8. Your Choices & Controls
- Analytics: You can disable analytics collection at any time via in-app settings; we implement Firebase controls (FIREBASE_ANALYTICS_COLLECTION_ENABLED, setAnalyticsCollectionEnabled).
- Notifications: You can disable push permissions at OS level and in-app.
- Token hygiene: Rotate token if exposed; contact us for help.
9. Your Rights
If you are in the EEA or UK, you have the rights to access, rectify, erase, restrict, object to processing, and data portability, and — where processing is based on consent — to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with a supervisory authority; in Italy, this is the Garante per la Protezione dei Dati Personali (www.garanteprivacy.it).
If you are in another jurisdiction whose law grants you similar rights (for example, Brazil under the LGPD or a US state privacy law that applies to you), we will honor requests as required by that law. As a matter of practice, we extend access and deletion requests to all users regardless of location.
To exercise any of these rights, contact us via our Support website. We will cooperate with our processors to fulfill requests.
10. Children
The Service is not directed to children. Purchasing a Subscription requires you to be at least 18 years of age or the age of majority in your jurisdiction (see our Terms and Conditions, Section 3). We do not knowingly collect personal data from children below the age of digital consent applicable in their country (between 13 and 16 in the EEA; 14 in Italy). If we learn that we have collected personal data from a child below that age without valid parental consent, we will delete it. Parents or guardians may contact us via our Support website.
11. Changes
We may update this Privacy Policy; material changes will be signposted in-app. Continued use after changes indicates acceptance.