Last updated: March 28, 2026 • Effective: March 28, 2026
OpenPushAPI ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our push notification API platform at openpushapi.com and related services (collectively, "the Service"). Please read this policy carefully. If you do not agree with its terms, please discontinue use of the Service.
Controller: OpenPushAPI is operated by the legal entity identified in customer invoices and agreements. For privacy questions before signup, contact privacy@openpushapi.com.
Account data: When you register, we collect your name, email address, and password (hashed). If you upgrade to a paid plan, payment information is processed by Stripe — we store only a customer token reference, not your card details.
Usage data: We collect information about how you use the Service, including API requests, notification campaigns created, features used, and log data (IP address, browser, timestamps).
Subscriber data (your end-users): When your website or app integrates our SDK, we collect push subscription tokens and associated device information (browser, OS, device type, language, timezone) on your behalf. This data belongs to you and is processed by us solely to deliver notifications for your account. We also collect anonymous geo-location data (country/city) derived from IP addresses.
Communications: If you contact us by email, we retain those communications to respond to inquiries and improve our support.
We use the information we collect to:
We do not sell your personal data or use it for advertising purposes.
We retain your data for as long as your account is active. Notification delivery logs and analytics are retained based on your plan:
| Plan | Retention |
|---|---|
| Free | 30 days |
| Starter | 90 days |
| Pro | 180 days |
| Business | 1 year |
| Enterprise | Custom (unlimited available) |
Upon account deletion, all personal data is removed within 30 days.
We implement industry-standard security measures including:
No method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it to security@openpushapi.com.
If you are located in the European Union or European Economic Area, you have the following rights under GDPR:
To exercise these rights — including requesting a data export or account deletion — email privacy@openpushapi.com from the address associated with your account. We will respond within 30 days. Data export is provided in JSON format.
California residents have the right to:
To submit a CCPA request, contact privacy@openpushapi.com.
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected such information, we will delete it immediately. If you believe a minor has submitted information to us, please contact privacy@openpushapi.com.
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for cross-border transfers, including Standard Contractual Clauses where applicable for EU data. Our delivery infrastructure spans multiple regions to ensure performance and compliance.
For privacy-related requests or questions about this policy, contact our privacy team: