Privacy policy

Effective 1 October 2026.

NotifyBell is operated by Altix Code Ltd, a company registered in the Republic of Cyprus (“Altix”, “we”, “us”). This policy explains what personal data we collect when you use our website and dashboard (the “Service”), what we collect and process on your behalf when your own backend publishes notifications and your users receive them through the NotifyBell embed, why, how long we keep it, who we share it with, and the rights you have over it. It applies to the marketing site, the dashboard, the API, and the embeddable widget.

Two different roles are in play throughout this policy, and they matter: for data about you and your NotifyBell account, Altix is the data controller. For data about the people who receive notifications through your app (your “Subscribers” — your own end-users, identified by an identifier your backend assigns), you are the data controller and Altix is a data processor acting only on your instructions — see “When we process data on your behalf” below.

1. Data we collect about you

When you sign up and use the Service, we collect:

2. When we process data on your behalf

NotifyBell exists to store and deliver notifications your own backend publishes, to your own users, through an API key and an embeddable widget you add to your product. When your backend publishes a notification or registers a Subscriber, and when a Subscriber reads or interacts with it through the embed, we process the following on your behalf, as your processor, under your instructions (which are to operate the Service as described in our documentation):

This data can include personal data about your users, depending entirely on what your backend sends us and what notification content you choose to publish — a notification title you write yourself may itself contain personal data about the recipient or a third party, and that is your choice and your responsibility as controller, not ours. We do not read, moderate, or make any product decision based on the content of a notification; it passes through unchanged other than being stored and delivered.

The connection between the embed and your backend is authenticated with a short-lived, signed subscriber token, minted by your backend using a per-app signing key that we seal at rest (AES-256-GCM) and never expose to a browser. A compromised token grants access to exactly one Subscriber’s own inbox, nothing else.

3. Why we process it

4. Who we share it with

We do not sell personal data. We share it only with the processors needed to run the Service, each bound by contract to use it solely to provide their service to us:

Issued invoices are recorded in Altix Code Ltd’s own internal invoicing system, used across our products, so we can meet our accounting and tax obligations as a single company. This is an internal system we operate ourselves, not a third party.

Some of these processors are located outside the European Economic Area. Where that is the case, we rely on the European Commission’s Standard Contractual Clauses, or an equivalent recognised safeguard, to cover the transfer.

We may also disclose data where required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Altix, our customers, or others.

5. How long we keep it

6. Deleting your account

Account owners can permanently delete their account from Settings at any time. Doing so:

This action cannot be undone. The dashboard asks you to type your account’s name to confirm before it proceeds. Because Subscriber data is yours to control, you may also stop sending us new Subscriber data at any time simply by stopping your own integration — you do not need to delete the whole account to do that.

7. Cookies

Our own website and dashboard use a single strictly necessary cookie to keep you signed in. We do not use advertising or cross-site tracking cookies on our site. The embeddable widget does not set cookies on your users’ browsers; it authenticates with the short-lived subscriber token your backend issues, held in memory by the embed for the life of the page.

8. Your rights

If you are in the European Economic Area, the UK, or another jurisdiction with similar protections, you have the right to:

To exercise any of these rights, email privacy@altixcode.com. If your request concerns data about a Subscriber rather than your own NotifyBell account — for example, a request from one of your users to see or delete the data we hold about them on your behalf — we will direct it to you, the Customer, who is the controller for that data and the right party to handle it, unless you have instructed us otherwise. We will of course assist you in fulfilling that request, including by deleting a named Subscriber’s records on your instruction.

9. Security

Passwords are hashed with bcrypt and never stored in plain text. Invite, password-reset, email-verification and API-key credentials use single-use or revocable, cryptographically random tokens that are hashed (SHA-256) at rest — we hold no value that lets us, or anyone who reads our database, reconstruct your API key or a live reset link. Each app’s signing key is sealed at rest with AES-256-GCM and never reaches a browser. Traffic to the Service, the API, and the embed is encrypted in transit with TLS. Access to production infrastructure is restricted to the people who need it to operate the Service.

10. Children

The Service is intended for businesses and developers integrating it into their own products, and account registration is not directed at, or knowingly used to collect account data from, children under 16. Where your own application serves Subscribers who are children, you remain the controller responsible for the lawfulness of that processing, including any parental-consent obligations that apply to you.

11. Changes to this policy

If we make a material change to this policy, we will notify account owners by email and update the effective date above before the change takes effect.

12. Contact

Altix Code Ltd (Cyprus). For any question about this policy or your data, email privacy@altixcode.com.