Privacy
Last updated 18 September 2026
Who holds your data
Acciti is the controller of the personal data described here. For anything about this policy, or to exercise any of the rights below, write to [email protected].
What is collected, and why
| Data | Why | Lawful basis |
|---|---|---|
| Email address | Signing in, and sending you a code | Contract |
| Display name | Showing who you are in the product | Contract |
| Passkey public keys | Signing you in without a password | Contract |
| Device tokens and names | Delivering notifications to a device | Contract |
| Message contents | Delivering them, and showing your history | Contract |
| Delivery receipts | Telling you what reached which device | Contract |
| Monthly message counts | Enforcing the plan allowance | Contract |
| Stripe customer and subscription ids | Taking payment | Contract |
| Sign-in times and session labels | Showing you the sessions on your account | Legitimate interest in account security |
| Pages opened, and which features were used | Seeing which parts of the product people reach | Legitimate interest in improving the service |
The private half of a passkey never leaves your device and is never sent to us. Sending tokens and session tokens are stored only as hashes.
What is in a message
A message carries whatever the sender put in it: a title, a body, and optionally a link. It is stored so it can be delivered and so you can read your own history, and it is sent to Apple in order to reach your device.
Do not put anything in a notification that you would not want on a lock screen.
Who else processes it
Five, and no more. There is no advertising, and nothing is sold or shared for anybody else's purposes.
Product analytics is one of them. It records the path of each page you open, a short list of things the product was used for, and your account id. Autocapture, session replay and anything carried in a URL are switched off, so the text of an alert, a user key and an invitation token never reach it.
Hetzner · Germany
Hosts the servers and the database. Sees everything stored, at rest.
Apple · United States
Delivers the push notification. Receives the message title and body, and the device token.
Stripe · Ireland and the United States
Takes payment. Receives your email address and payment details, never message contents.
Purelymail · United States
Carries the sign-in code. Receives your email address and the code, never message contents.
PostHog · European Union
Product analytics, on PostHog's EU cloud. Receives the path of each page you open, a short list of product events, and your account id. Never message contents, never your address, never a user key.
Data leaving the EU
Your account and your messages are stored in Germany. Delivering a notification and sending a sign-in code involve processors in the United States, which means those transfers rely on the European Commission's standard contractual clauses.
How long it is kept
Messages and delivery receipts are deleted automatically once they pass your plan's retention window. Receipts go first, because they are the bulk of the data and the half that stops being useful soonest.
| Plan | Messages | Receipts |
|---|---|---|
| Free | 30 days | 7 days |
| Solo | 90 days | 30 days |
| Team | 365 days | 90 days |
- Sign-in codes expire ten minutes after they are issued.
- Sessions expire thirty days after you sign in.
- Your account, devices and passkeys are kept until you delete the account, and go with it when you do.
- Records of payments are kept for as long as accounting law requires, which is five years in Denmark.
Your rights
You can ask for a copy of your data, ask for it to be corrected or deleted, ask for processing to be restricted, object to processing based on legitimate interest, and ask for your data in a portable form. Write to [email protected] and you will have an answer within a month.
Most of this needs no request. Your messages, devices, passkeys and sessions are all on the dashboard, closing your account deletes them, and Download your data gives you the portable copy as JSON without anyone here being involved.
If you think your data is being handled wrongly you can complain to Datatilsynet, the Danish data protection authority.
What is stored in your browser
The site keeps two things in local storage: the token that keeps you signed in, and whether you chose light or dark. Neither leaves your browser except as the sign-in token on requests to the API.
Analytics adds a third, an identifier for this browser, kept in local storage and in a cookie of the same name so the two halves of one visit are not counted as two people. It holds no address, no user key and nothing you have sent or received. Turn on Do Not Track in your browser and analytics does not run at all.
Security
Traffic is encrypted in transit. Passwords do not exist, so there are none to leak; passkeys are stored as public keys only. Session and sending tokens are stored as hashes, so the database does not contain a credential that would work if it were copied.
If a breach affects your data, you will be told, and so will Datatilsynet, within the time the law allows.
Automated decisions
There are none. Nothing here profiles you or makes a decision about you without a person involved.
Children
The service is not intended for anybody under 16, and accounts are not knowingly created for them.
Changes
This policy can change. The date at the top says when it last did, and a change that affects how your data is used is announced by email before it takes effect.