HomeIntegrationsPricingDocsBlogCompareGet Started

// Privacy

Privacy Policy

Effective date: August 12, 2026

This document is provided for transparency about how Pushbrain operates. It is not legal advice. If you need jurisdiction-specific counsel, consult a qualified attorney.

1. Who we are

Pushbrain (“Pushbrain”, “we”, “us”, or “our”) provides a Firebase-first push notification management service at https://pushbrain.dev (the “Service”).

This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices available to you. It applies to account holders and visitors of our websites and dashboards.

If you use Pushbrain to send notifications to end users of your apps, you are typically the controller of that end-user data; Pushbrain processes it on your instructions as a service provider / processor, except where we act as a controller for our own account and billing data.

2. Information we collect

We collect information in three categories: account data, customer content you upload or generate in the Service, and limited technical / usage data.

  • Account data: email address, Firebase Authentication user ID, display name (if provided by Google sign-in), password hashes managed by Firebase Auth (we do not store plaintext passwords), and billing-related identifiers (plan, customer/subscription IDs from our payment processor).
  • Customer content: Firebase service-account credentials you upload (encrypted at rest), app configuration, FCM device registration tokens and related device metadata (platform, environment, permission status, activity timestamps, install identifiers), notification titles/bodies, campaign and scheduled-job settings, send history and delivery aggregates, AI prompt context and generated copy when you use AI features, API keys you create in Pushbrain, and webhook configuration.
  • Technical / usage data: IP address, browser/user-agent, request logs, approximate timestamps, and basic product analytics events needed to operate and secure the Service. If we enable privacy-focused web analytics (for example Plausible), it is configured to minimize personal data and avoid advertising cookies where possible.
  • Payment data: card numbers and payment credentials are collected and processed by our payment processor (currently Dodo Payments). We do not store full card numbers on Pushbrain servers.

3. How we use information

We use information only as needed to provide and improve the Service, including to:

  • Create and authenticate accounts, and provide the dashboard, APIs, and SDKs.
  • Send push notifications through your Firebase project using credentials you supply.
  • Store and prune device tokens, run scheduled jobs, drips, A/B tests, and audience-health features you enable.
  • Generate AI-assisted notification copy when you request it, using the prompts and app context you provide.
  • Process subscriptions, invoices, and plan limits.
  • Detect abuse, debug failures, secure the Service, and comply with law.
  • Communicate about the Service (transactional email, security notices, and — where permitted — product updates). You can opt out of non-essential marketing emails.

4. Legal bases (EEA/UK users)

Where the GDPR or UK GDPR applies, we process personal data on these bases: performance of a contract (providing the Service you request); legitimate interests (securing and improving the Service, preventing abuse — balanced against your rights); consent (where we ask for it, including optional marketing); and legal obligation where required.

5. Customer content, Firebase credentials, and end users

Service-account JSON and similar secrets are encrypted at rest (AES-256) and decrypted in memory only as needed to call Firebase Admin APIs. We do not sell these credentials or use them for unrelated products.

Device tokens and notification content you store in Pushbrain remain associated with your account and apps. You are responsible for providing any notices and obtaining any consents required from your end users under applicable law (including push-permission prompts and privacy disclosures in your apps).

If you instruct us to delete an app or account, we delete or irreversibly anonymize associated customer content within a reasonable period, subject to backups and legal retention needs.

6. AI features

When you use AI Studio or Autopilot, we send the prompt context you provide (such as app description, goal, and constraints) to our AI model provider to generate notification copy. Do not include sensitive personal data in prompts unless necessary.

We use AI outputs to display suggestions and, when you enable Autopilot, to populate scheduled sends. We do not use your prompts to train public foundation models except as permitted by our provider agreements and our own product improvement in aggregate/de-identified form where applicable. Provider terms may also apply.

7. How we share information

We do not sell your personal information. We share information only with:

  • Infrastructure and subprocessors listed in Section 8, solely to operate the Service.
  • Professional advisors or authorities when required by law, valid legal process, or to protect rights, safety, and security.
  • A successor entity in a merger, acquisition, or asset sale, subject to this Policy or equivalent protections.

8. Subprocessors

We use the following categories of service providers. We may update this list as our stack changes; material additions will be reflected in this Policy.

  • Google Firebase Authentication — account sign-in (email/password and Google).
  • Google Firebase Cloud Messaging — push delivery through your own Firebase project when you connect credentials.
  • Cloud hosting providers — website (e.g. Vercel) and API/backend hosting.
  • Dodo Payments — subscription checkout and billing; card data is handled by Dodo, not stored as full card numbers on Pushbrain servers.
  • AI model provider(s) — generate notification copy when you use AI Studio or Autopilot.
  • Privacy-focused web analytics (e.g. Plausible), if enabled — aggregate traffic measurement without advertising cookies where possible.

9. International transfers

We may process and store information in India, the United States, and other countries where we or our subprocessors operate. Where required, we use appropriate safeguards for cross-border transfers (such as standard contractual clauses or equivalent mechanisms).

10. Retention

We retain account and billing records for as long as your account is active and as needed for contracts, tax, and dispute resolution. Customer content is retained while your account/apps remain active. Logs and backups are retained for a limited period for security and reliability, then deleted or overwritten according to our operational schedules.

11. Security

We use industry-standard measures including encryption in transit (TLS), encryption at rest for service-account credentials, access controls, and least-privilege practices. No method of transmission or storage is 100% secure; you are responsible for protecting your account credentials and for rotating Firebase keys if you believe they are compromised.

12. Your rights

Depending on your location (including GDPR, UK GDPR, and CCPA/CPRA), you may have rights to access, correct, delete, export, or restrict certain personal data, and to object to certain processing. California residents may have rights to know, delete, and opt out of “sale” or “sharing” of personal information — we do not sell personal information as that term is commonly understood, and we do not use it for cross-context behavioral advertising.

To exercise rights, email us at the address below. We may verify your identity before fulfilling a request. You may also delete your account via the Service where available, which removes associated customer content subject to Section 10.

13. Children

The Service is directed to businesses and developers and is not intended for children under 16 (or under 18 where required by local law). We do not knowingly collect personal information from children. Contact us if you believe we have done so.

14. Cookies and similar technologies

We use essential cookies or local storage required for authentication and security. We may use limited analytics that do not rely on advertising cookies. You can control cookies through your browser settings; disabling essential storage may prevent sign-in.

15. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version with an updated effective date and, for material changes, provide additional notice (such as email or an in-product banner) where appropriate. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.

16. Contact

Questions or privacy requests: contact@pushbrain.dev.

Pushbrain — https://pushbrain.dev

Contact: contact@pushbrain.dev

Create an account → · Privacy · Terms

Pushbrain
Built for developers who ship. Not for enterprises who plan.
DocsFirebaseFeaturesPricingFAQBlogCompareAlternativesUse casesGitHubAboutContactPrivacyTermsSign in