// Privacy
Effective date: August 12, 2026
This document is provided for transparency about how Pushbrain operates. It is not legal advice. If you need jurisdiction-specific counsel, consult a qualified attorney.
Pushbrain (“Pushbrain”, “we”, “us”, or “our”) provides a Firebase-first push notification management service at https://pushbrain.dev (the “Service”).
This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices available to you. It applies to account holders and visitors of our websites and dashboards.
If you use Pushbrain to send notifications to end users of your apps, you are typically the controller of that end-user data; Pushbrain processes it on your instructions as a service provider / processor, except where we act as a controller for our own account and billing data.
We collect information in three categories: account data, customer content you upload or generate in the Service, and limited technical / usage data.
We use information only as needed to provide and improve the Service, including to:
Where the GDPR or UK GDPR applies, we process personal data on these bases: performance of a contract (providing the Service you request); legitimate interests (securing and improving the Service, preventing abuse — balanced against your rights); consent (where we ask for it, including optional marketing); and legal obligation where required.
Service-account JSON and similar secrets are encrypted at rest (AES-256) and decrypted in memory only as needed to call Firebase Admin APIs. We do not sell these credentials or use them for unrelated products.
Device tokens and notification content you store in Pushbrain remain associated with your account and apps. You are responsible for providing any notices and obtaining any consents required from your end users under applicable law (including push-permission prompts and privacy disclosures in your apps).
If you instruct us to delete an app or account, we delete or irreversibly anonymize associated customer content within a reasonable period, subject to backups and legal retention needs.
When you use AI Studio or Autopilot, we send the prompt context you provide (such as app description, goal, and constraints) to our AI model provider to generate notification copy. Do not include sensitive personal data in prompts unless necessary.
We use AI outputs to display suggestions and, when you enable Autopilot, to populate scheduled sends. We do not use your prompts to train public foundation models except as permitted by our provider agreements and our own product improvement in aggregate/de-identified form where applicable. Provider terms may also apply.
We use the following categories of service providers. We may update this list as our stack changes; material additions will be reflected in this Policy.
We may process and store information in India, the United States, and other countries where we or our subprocessors operate. Where required, we use appropriate safeguards for cross-border transfers (such as standard contractual clauses or equivalent mechanisms).
We retain account and billing records for as long as your account is active and as needed for contracts, tax, and dispute resolution. Customer content is retained while your account/apps remain active. Logs and backups are retained for a limited period for security and reliability, then deleted or overwritten according to our operational schedules.
We use industry-standard measures including encryption in transit (TLS), encryption at rest for service-account credentials, access controls, and least-privilege practices. No method of transmission or storage is 100% secure; you are responsible for protecting your account credentials and for rotating Firebase keys if you believe they are compromised.
Depending on your location (including GDPR, UK GDPR, and CCPA/CPRA), you may have rights to access, correct, delete, export, or restrict certain personal data, and to object to certain processing. California residents may have rights to know, delete, and opt out of “sale” or “sharing” of personal information — we do not sell personal information as that term is commonly understood, and we do not use it for cross-context behavioral advertising.
To exercise rights, email us at the address below. We may verify your identity before fulfilling a request. You may also delete your account via the Service where available, which removes associated customer content subject to Section 10.
The Service is directed to businesses and developers and is not intended for children under 16 (or under 18 where required by local law). We do not knowingly collect personal information from children. Contact us if you believe we have done so.
We may update this Privacy Policy from time to time. We will post the revised version with an updated effective date and, for material changes, provide additional notice (such as email or an in-product banner) where appropriate. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
Questions or privacy requests: contact@pushbrain.dev.
Pushbrain — https://pushbrain.dev
Contact: contact@pushbrain.dev