Home

Privacy Policy

Last updated: July 8, 2026

This Privacy Policy explains how palmpush processes information when you use the palmpush website, iOS app, API, JavaScript SDK, PWA SDK, support channels, and related services.

palmpush is a small notification delivery service. It lets you create private notification listeners and send short push notifications to devices or browsers that subscribe to those listeners.

1. Controller

palmpush is operated by:

palmstudio GmbH Pfalzgrafenstraße 38 67434 Neustadt Germany

Privacy contact: Enable JavaScript to view the support email.

2. Important service facts

palmpush does not currently provide user accounts, paid subscriptions, in-app purchases, advertising, analytics advertising, or user profiling.

palmpush uses listener tokens as the main access mechanism. A listener token is a secret capability token. Anyone who has a listener token may be able to send notifications to that listener, subscribe another device, rename the listener, or change listener-related settings. You should treat listener tokens like passwords.

palmpush does not intentionally collect precise location data, contacts, photos, microphone recordings, health data, or payment information.

3. Information we process

Depending on how you use palmpush, we process the following categories of information.

Device and browser registration data

When a device or browser registers for notifications, palmpush may process:

  • A random local device ID generated by the app or browser.
  • The platform, such as iOS or web.
  • Firebase Cloud Messaging registration tokens for iOS devices.
  • Web Push subscription data for browsers, including the push endpoint, keys, and related subscription metadata.
  • Creation, update, last-seen, and stale-token timestamps.
  • Error or stale-token reason fields when a push token or Web Push subscription no longer works.

The random local device ID is not an Apple device identifier. It is generated by palmpush and stored locally. On iOS it is stored in app storage. In the PWA it is stored in browser local storage. If the app or browser storage is deleted, a new local device ID may be created.

Listener and subscription data

When you create or use a listener, palmpush may process:

  • The listener token.
  • The listener name.
  • The local device ID that created the listener.
  • Whether delivery is enabled for the listener.
  • The listener subscriber count.
  • Subscription records linking a listener token to a local device ID.
  • Whether notifications are enabled for a specific subscription.
  • Creation and update timestamps.

Notification content and delivery history

When a notification is sent, palmpush may process:

  • The notification title and body.
  • The listener token the notification was sent to.
  • The local device ID of subscribed devices.
  • A generated send or event ID.
  • The delivery provider used for a delivery attempt.
  • Delivery status, attempts, success state, provider message IDs, error codes, error messages, and timestamps.

palmpush stores notification title and body data so subscribed devices can show listener history and so the service can diagnose delivery issues.

Website, API, and security data

When you use the website, API, SDKs, or app, normal technical data may be created by hosting, cloud, logging, and security systems. This can include IP addresses, request metadata, timestamps, user agent information, HTTP headers, error logs, diagnostic logs, abuse-prevention records, and similar operational data.

Support data

If you contact support, we process the contact details you provide, the content of your message, and any follow-up information needed to respond.

4. Purposes of processing

We process information to:

  • Register devices and browsers for push notification delivery.
  • Create, rename, list, mute, enable, disable, and delete listener subscriptions.
  • Deliver push notifications through Apple, Firebase, browser, and Web Push infrastructure.
  • Show notification history to subscribed devices.
  • Detect stale push tokens and remove or update broken delivery targets.
  • Monitor reliability, debug errors, prevent abuse, and protect the service.
  • Respond to support requests.
  • Comply with legal obligations and enforce the Terms of Use.

5. Legal bases

Where the GDPR or similar European data protection law applies, we rely on the following legal bases:

  • Article 6(1)(b), performance of a contract, when processing is necessary to provide palmpush features you use.
  • Article 6(1)(a), consent, where you allow push notifications or make another consent-based choice. You can withdraw notification permission in your device or browser settings.
  • Article 6(1)(f), legitimate interests, for operating, securing, debugging, maintaining, and protecting palmpush.
  • Article 6(1)(c), legal obligations, where we must process or retain information to comply with applicable law.

6. Push notification infrastructure

palmpush relies on third-party infrastructure to deliver notifications and run the service. This may include:

  • Google Firebase and Google Cloud services, including Firebase Cloud Messaging, Firestore, hosting, cloud functions, and logs.
  • Apple Push Notification service and Apple platform services for iOS notification delivery.
  • Browser and Web Push services operated by browser vendors or platform providers.
  • Hosting, domain, email, and support infrastructure providers.

These providers process information as needed to provide infrastructure, deliver notifications, secure systems, and maintain logs. A push notification may include the title and body supplied by the sender.

7. Sharing

We do not sell personal information. We share information only when needed to:

  • Operate, host, secure, and maintain palmpush.
  • Deliver push notifications.
  • Use service providers acting on our behalf.
  • Respond to lawful requests or comply with legal obligations.
  • Protect palmpush, users, third parties, or the public.
  • Investigate abuse, security incidents, or violations of the Terms of Use.

8. International transfers

Service providers may process information in countries other than your country of residence, including countries outside the European Economic Area. Where required, we rely on appropriate safeguards such as adequacy decisions, standard contractual clauses, provider data processing terms, or other transfer mechanisms allowed by applicable law.

9. Retention

We keep information only for as long as needed for the purposes described in this Privacy Policy, unless a longer retention period is required or allowed by law.

Device and browser registration records may remain while the device or browser is registered with palmpush and while they are needed to detect stale or broken push delivery targets.

Listener and subscription records may remain until the subscription or listener is deleted. If the current device is the last subscribed device for a listener and that subscription is deleted, palmpush deletes the listener.

Notification history may remain while it is needed to show listener history to subscribed devices, diagnose delivery, and operate the service. palmpush does not currently provide a fixed automatic deletion period for notification history.

Operational logs may be retained according to provider settings and operational needs for security, debugging, reliability, and abuse prevention.

Support messages may be retained for as long as needed to handle the request, maintain records, and protect legal rights.

10. Your choices and controls

You can:

  • Disable push notifications in iOS, browser, or operating system settings.
  • Disable delivery for a listener or for the current device where the app provides that control.
  • Delete a listener subscription in the app.
  • Stop using an exposed listener token and create a new listener.
  • Delete app or browser storage, which may remove the local device ID from that device or browser.

Because palmpush currently has no user accounts, we may need enough information to identify the relevant listener, device, browser, or support request before we can respond to access, deletion, or correction requests. For security, we may limit a request if we cannot verify that the requester controls the relevant listener token, device, browser, or communication channel.

11. Your privacy rights

Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, data portability, and withdrawal of consent. You may also have the right to lodge a complaint with a data protection supervisory authority.

To exercise privacy rights, contact: Enable JavaScript to view the support email.

12. Security

We use technical and organizational measures designed to protect palmpush. However, no service can guarantee absolute security.

Listener tokens are especially important. If a listener token is exposed, other people may be able to send notifications to that listener or interact with it. If you believe a token was exposed, create a new listener and stop using the old token.

13. Children

palmpush is not directed to children. Do not use palmpush if you are not old enough to use it under the laws that apply to you.

14. Automated decision-making

palmpush does not currently use personal information for automated decision-making that produces legal or similarly significant effects, and it does not create advertising profiles.

15. Changes

We may update this Privacy Policy when the service, legal requirements, or operational practices change. The updated version will be posted on this page with a new "Last updated" date.

16. Contact

For privacy questions, support requests, or rights requests, contact Enable JavaScript to view the support email. or use the palmpush support page.