Privacy

Last updated 18 September 2026

Who holds your data

Acciti is the controller of the personal data described here. For anything about this policy, or to exercise any of the rights below, write to [email protected].

What is collected, and why

DataWhyLawful basis
Email addressSigning in, and sending you a codeContract
Display nameShowing who you are in the productContract
Passkey public keysSigning you in without a passwordContract
Device tokens and namesDelivering notifications to a deviceContract
Message contentsDelivering them, and showing your historyContract
Delivery receiptsTelling you what reached which deviceContract
Monthly message countsEnforcing the plan allowanceContract
Stripe customer and subscription idsTaking paymentContract
Sign-in times and session labelsShowing you the sessions on your accountLegitimate interest in account security
Pages opened, and which features were usedSeeing which parts of the product people reachLegitimate interest in improving the service

The private half of a passkey never leaves your device and is never sent to us. Sending tokens and session tokens are stored only as hashes.

What is in a message

A message carries whatever the sender put in it: a title, a body, and optionally a link. It is stored so it can be delivered and so you can read your own history, and it is sent to Apple in order to reach your device.

Do not put anything in a notification that you would not want on a lock screen.

Who else processes it

Five, and no more. There is no advertising, and nothing is sold or shared for anybody else's purposes.

Product analytics is one of them. It records the path of each page you open, a short list of things the product was used for, and your account id. Autocapture, session replay and anything carried in a URL are switched off, so the text of an alert, a user key and an invitation token never reach it.

  • Hetzner · Germany

    Hosts the servers and the database. Sees everything stored, at rest.

  • Apple · United States

    Delivers the push notification. Receives the message title and body, and the device token.

  • Stripe · Ireland and the United States

    Takes payment. Receives your email address and payment details, never message contents.

  • Purelymail · United States

    Carries the sign-in code. Receives your email address and the code, never message contents.

  • PostHog · European Union

    Product analytics, on PostHog's EU cloud. Receives the path of each page you open, a short list of product events, and your account id. Never message contents, never your address, never a user key.

Data leaving the EU

Your account and your messages are stored in Germany. Delivering a notification and sending a sign-in code involve processors in the United States, which means those transfers rely on the European Commission's standard contractual clauses.

How long it is kept

Messages and delivery receipts are deleted automatically once they pass your plan's retention window. Receipts go first, because they are the bulk of the data and the half that stops being useful soonest.

PlanMessagesReceipts
Free30 days7 days
Solo90 days30 days
Team365 days90 days
  • Sign-in codes expire ten minutes after they are issued.
  • Sessions expire thirty days after you sign in.
  • Your account, devices and passkeys are kept until you delete the account, and go with it when you do.
  • Records of payments are kept for as long as accounting law requires, which is five years in Denmark.

Your rights

You can ask for a copy of your data, ask for it to be corrected or deleted, ask for processing to be restricted, object to processing based on legitimate interest, and ask for your data in a portable form. Write to [email protected] and you will have an answer within a month.

Most of this needs no request. Your messages, devices, passkeys and sessions are all on the dashboard, closing your account deletes them, and Download your data gives you the portable copy as JSON without anyone here being involved.

If you think your data is being handled wrongly you can complain to Datatilsynet, the Danish data protection authority.

What is stored in your browser

The site keeps two things in local storage: the token that keeps you signed in, and whether you chose light or dark. Neither leaves your browser except as the sign-in token on requests to the API.

Analytics adds a third, an identifier for this browser, kept in local storage and in a cookie of the same name so the two halves of one visit are not counted as two people. It holds no address, no user key and nothing you have sent or received. Turn on Do Not Track in your browser and analytics does not run at all.

Security

Traffic is encrypted in transit. Passwords do not exist, so there are none to leak; passkeys are stored as public keys only. Session and sending tokens are stored as hashes, so the database does not contain a credential that would work if it were copied.

If a breach affects your data, you will be told, and so will Datatilsynet, within the time the law allows.

Automated decisions

There are none. Nothing here profiles you or makes a decision about you without a person involved.

Children

The service is not intended for anybody under 16, and accounts are not knowingly created for them.

Changes

This policy can change. The date at the top says when it last did, and a change that affects how your data is used is announced by email before it takes effect.

A sound when it matters.

Not when it does not. One request in, one notification on your phone, your watch and your Mac.

© 2026 Acciti

iPhone, Apple Watch and Mac

Built on Swift, Postgres and APNs.