Skip to content

Privacy Policy

Effective date: July 1, 2026 Current version: 2.0

1.1. This Privacy Policy (the “Policy”) explains how the operator of the Notifly service (the “Operator”, “we”) processes personal data of users of the service available at https://ainotifly.com and its subdomains, including the control panel, the Notifly Android application and our programming interfaces (APIs) (together, the “Service”).

1.2. This Policy is drafted with regard to the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and other applicable data protection laws. Where you use the Service from a jurisdiction with its own data protection law, additional local rights may apply to you.

1.3. By using the Service you acknowledge this Policy. Where processing is based on your consent, you may withdraw it at any time (see section 9).

2.1. For personal data relating to your account and your use of the Service, the Operator acts as the data controller.

2.2. For personal data that you upload or route through the Service about other people (recipients of your notifications, senders of inbound email, end users of your monitored websites — see section 3.2), you are the controller and the Operator acts as a processor acting on your instructions (see section 6).

2.3. Controller identity and full legal details are provided on request to support@ainotifly.com.

3.1. Account data (you as the data subject)

Section titled “3.1. Account data (you as the data subject)”
  • email address (used as your login), email-verification status and service tokens for verification / password reset;
  • account password stored only as an irreversible hash (bcrypt); we never store your plaintext password;
  • selected plan, account balance and usage counters (number of messages, monitor checks, AI requests, etc.);
  • IP address of the last connection, User-Agent string, platform type (web, android, cli, mcp, integration), last-activity time and interface language;
  • identifiers and access tokens: client and application (channel) identifiers, device tokens, MCP tokens, webhook / heartbeat / metric / web-script tokens, channel-share tokens;
  • a device identifier used to deliver push notifications (in the Android app, push is delivered over a persistent WebSocket connection; third-party push gateways are not used — see section 7);
  • API request metadata: time, method, status, size.

3.2. Third-party data you provide (processed on your behalf)

Section titled “3.2. Third-party data you provide (processed on your behalf)”

The Service lets you submit personal data about other people. We process such data only as your processor (section 6). It may include:

  • contact details of notification recipients: email addresses, phone numbers (for SMS and voice delivery), Telegram chat identifiers and bot tokens, Slack and custom webhook URLs;
  • the content of notifications and messages you send and receive (title, body, priority, sender name, custom fields) and read receipts;
  • inbound email captured by the “Email Inbox” feature (sender, recipient, subject, body, headers);
  • webhook-router events (source IP address, request headers and payload);
  • web-script / error-tracking data (error texts and stack traces, page URLs, User-Agent strings of your website’s end users, source maps);
  • monitor configurations (target addresses, hosts, headers, filters) and check history;
  • metric values you submit.

When you pay for a paid plan we process payment data to the extent needed to process the payment. We do not store full payment-card numbers; where card payment is used, card data is handled by the payment provider. Payment amounts and details may be retained for accounting and tax purposes.

The Service is not intended for special categories of personal data (Art. 9 GDPR) or biometric data. You agree not to submit such data unless you have ensured a valid legal basis yourself.

We process personal data for the following purposes and on the following lawful bases:

  • providing the Service — performance of a contract with you (Art. 6(1)(b) GDPR);
  • registration, authentication and identification — performance of a contract (Art. 6(1)(b));
  • payments, invoicing, accounting and tax — legal obligation and contract (Art. 6(1)(c), (b));
  • support and correspondence — performance of a contract and our legitimate interests (Art. 6(1)(b), (f));
  • security, prevention and investigation of abuse and incidents — our legitimate interests (Art. 6(1)(f));
  • service communications — performance of a contract and legitimate interests; marketing communications, if any, are sent only with your consent (Art. 6(1)(a)) and you may opt out at any time.

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing (Art. 22 GDPR).

We share personal data only as necessary to provide the Service:

  • cloud infrastructure provider — Amazon Web Services (AWS): hosting, storage and email delivery;
  • payment provider (where connected): to process payments;
  • competent authorities: where required by law.

We do not sell personal data and do not share it for third-party marketing.

When you enable optional integrations, data is transmitted to the corresponding services on your initiative and instruction (see sections 6 and 8): Telegram, Slack, your custom webhooks, and the large language model (LLM) provider used by the AI features.

6. Processing on your behalf (you as controller)

Section titled “6. Processing on your behalf (you as controller)”

6.1. When you submit third-party personal data (section 3.2) and configure delivery, you act as the controller and we act as your processor, processing such data only on your documented instructions and solely to provide the Service.

6.2. You are responsible for having a valid legal basis for submitting that data and for contacting recipients (including any required consents under applicable data-protection and anti-spam / marketing law), and you indemnify us against related third-party claims.

6.3. We make available the information necessary to demonstrate compliance and, on request, will enter into a data processing agreement where required by applicable law.

Push notifications in the Notifly Android app are delivered over a persistent, encrypted WebSocket connection between the app and the Service; third-party push gateways (Apple Push Notification Service, Firebase Cloud Messaging) are not used in the current version. If such gateways or Web Push are added in future, this Policy will be updated and only a technical device token needed for delivery will be shared with the relevant service.

8.1. Our infrastructure for ainotifly.com is provided by AWS and may process data in AWS regions that can be located outside your country.

8.2. When you enable optional integrations, data is transmitted to services (Telegram, Slack, your custom webhooks, the LLM provider — for example OpenAI in the United States) whose servers may be located outside your country. For AI features, only the text of your query is sent to the LLM provider; message content, credentials and access tokens are not.

8.3. Where personal data is transferred to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses. Transfers you initiate through integrations are carried out on your instruction, and you are responsible for their lawfulness.

Subject to applicable law, you have the right to: access your personal data; rectify inaccurate data; erase data (“right to be forgotten”); restrict or object to processing; data portability; and to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with your local data protection supervisory authority.

To exercise your rights, contact support@ainotifly.com from your account email. We respond within the timeframe required by applicable law (and within one month under the GDPR, extendable where permitted). You can also delete your account yourself in the control panel.

We keep personal data no longer than necessary for the purposes above. Indicative periods:

Data categoryRetention
Account, profile, settingsfor the life of the account; unused accounts may be deleted after 12 months
Messages and notificationsuntil you delete them (channel, message) or delete your account
Inbound email (Email Inbox)7 days
Webhook-router events7 days
Web-script errors90 days; source maps — until the related script is deleted
Metricsaggregates up to 365 days; per-minute data 1 day
Monitor check historyper your settings and plan
Device activity log30 days

After account deletion or withdrawal of consent, personal data is deleted without undue delay, except data we must keep by law (e.g. accounting and tax records) for the applicable statutory periods.

We implement appropriate technical and organisational measures to protect personal data, including: TLS/HTTPS encryption in transit; storage of passwords as irreversible hashes (bcrypt); least-privilege access controls; regular backups; logging and monitoring of suspicious activity.

The Service is not directed to children under 16 (or the age of digital consent in your country), and we do not knowingly collect their personal data.

The use of cookies and similar technologies is described in a separate Cookie Policy.

We may update this Policy. The current version is always available at https://ainotifly.com/legal/privacy/. We will notify you of material changes through the Service or by email.

Privacy questions and requests: support@ainotifly.com.