隐私政策
PushWard is run by MAWIK Maciej Kędziora, a sole proprietorship registered in Poland ("we", "us"), the controller of the personal data described here. This policy explains what we collect, what we don't, and what you can do about it.
What we collect
When you sign in with Apple, we receive only an opaque identifier -- no email, no name. The iOS app sends us your device push tokens (so we can deliver Live Activities and notifications), basic device info (OS version, app version, model, locale, permission state) for diagnostics, and the activities and notifications you create through the API.
If you use the optional email channel, we also store the recipient email addresses you register (each confirmed by the recipient through a double opt-in link), the subject lines and delivery status of the emails you send through us, and -- transiently, only while we hand it to our email provider for delivery -- the message body. That confirmation email tells each recipient who added them, and every message lets them unsubscribe at any time.
Organizations (PushWard Team)
If you join an organization, it can see your name in the app, your role, and for each of your devices: its name and model, the OS and PushWard app version, when it was last active and whether notifications are allowed. It cannot see your location, your Apple ID email address, or the Live Activities, notifications, widgets and keys of your personal account. You are shown this before you join, you choose which of your devices receive the organization's sends, and you can leave at any time. Each organization decides what it sends to its members and is responsible for having a reason to do so. Contact [email protected] for a data processing agreement.
Changes to an organization, such as members joining or leaving and settings changed in the console, are written to its audit log with who made them, when, and the IP address and user agent of the request. The organization's owners, admins and viewers can read the log, including those details.
Billing. PushWard Team subscriptions are sold by Paddle.com, our reseller and merchant of record. Paddle collects the payment and the billing details (the billing contact's name and email, the company name, VAT ID, address and country) and handles them as the seller, under its own privacy notice. Card and bank details go to Paddle and never reach us. Paddle tells us the billing contact, company, VAT ID and country, and the subscription's state (seats, renewal date, payment status), so we can run the organization's seats and answer billing questions.
What we don't collect
We never ask for your email, name, phone, address, or location to create or use your
account -- Sign in with Apple gives us only an opaque identifier. There are two
exceptions: the optional email channel above, where the recipient addresses you choose
to send to are stored so we can deliver and verify them, and the billing contact of a
PushWard Team subscription (name, email, company, VAT ID), which Paddle reports to us.
No advertising identifiers, IDFA, or cross-app tracking. No tracking or advertising
cookies. The iOS and Mac apps and this website use no third-party analytics, crash reporters, or
SDKs of any kind. The iOS app talks only to Apple (including iCloud) and to api.pushward.app.
Cookies
The website and the iOS app set no cookies. The web console at console.pushward.app uses two cookies on api.pushward.app, both
strictly necessary to sign in, so they need no consent: __Host-pw_login protects the Sign in with Apple step and expires after 10 minutes, and __Host-pw_session keeps you signed in for up to 7 days, ending sooner after a
day without use or when you sign out. Both are HttpOnly, Secure and SameSite=Strict, so
page scripts and other websites cannot read or send them. We store each console session
with your browser's user agent and delete the record 7 days after you sign out or it
expires. The console's checkout and billing pages load Paddle's checkout (Paddle.js),
which may set Paddle's own cookies under Paddle's privacy notice.
How your data is handled
We process this data to operate the service (contractual basis) and to protect it from abuse (legitimate interest). API tokens and integration keys are stored as SHA-256 hashes -- we never see your plaintext tokens. Push delivery telemetry hashes destination tokens too, and payload contents are never logged. IP addresses are used transiently for rate limiting and discarded, except in an organization's audit log (above).
Emails you send are delivered through a third-party email delivery provider; bounce and spam-complaint feedback is used to suppress addresses that should not be contacted again. If you turn on iCloud settings sync, your app preferences (notification settings, language, sort order) are mirrored through your own private Apple iCloud account -- secrets such as tokens and keys are never included.
Where your data lives
Application data is hosted in the EU (Frankfurt). Push tokens transit Apple's APNs
infrastructure (US-based), covered by the EU-US Data Privacy Framework and Standard
Contractual Clauses. The third parties that touch your data are Apple (Sign in with
Apple, push delivery, and -- if you enable it -- iCloud settings sync), Cloudflare (DNS
and TLS for pushward.app), and -- only if you use the email channel -- a
third-party email delivery provider, which sends your emails from the EU (Frankfurt)
region. For PushWard Team subscriptions, Paddle handles payments and billing details as
described above. We do not sell, rent, or share your data for advertising.
How long we keep it
Activities you create through the API are automatically deleted once their TTL expires. Records of emails you've sent are kept for 90 days; the recipient addresses you register stay until you remove them or delete your account. Addresses that hard-bounce or report your mail as spam are added to a suppression list we keep indefinitely so we don't email them again. Everything else exists for as long as your account does -- delete your account from inside the iOS app and everything tied to you (devices, activities, tokens, integration keys) is removed by database cascade. Backups roll over within 30 days.
An organization's audit log entries are deleted after 12 months. An organization whose trial ended without a subscription is deleted 30 days later, and one whose subscription ended is deleted 60 days later; owners can also delete it at any time. When you leave an organization or delete your account, your membership ends and the organization no longer sees your devices. Paddle keeps the invoices and billing records of PushWard Team as the seller, under its privacy notice. We keep our own records of Paddle's payouts to us for as long as Polish tax law requires (five years from the end of the year in which the tax on them is due). The copy of the billing contact that Paddle reports to us is deleted with the organization.
Your rights
Under the GDPR you can access, correct, export, or delete your data, restrict or object to processing, and lodge a complaint with the Polish data protection authority (UODO, uodo.gov.pl). Email [email protected] to exercise any of these rights -- or start a data request straight from the iOS app's Backup & Sync settings -- we respond within 30 days. You can also delete your account directly from the iOS app at any time.
Changes & contact
If we change this policy, the updated version will be posted here. Controller: MAWIK Maciej Kędziora, NIP 8943263728, Wrocław, Poland. Questions: [email protected] · GitHub.