Policy
Privacy Policy
Last updated: August 30, 2026
This policy explains how alrim processes information through alrim.app, alrim.me, alrim.io, and the related Android apps. It covers channel
subscriptions, notification publishing and history, push delivery, and the optional Android
Notification Relay feature.
1. Information We Process
- - Notification content and structured JSON that a publisher or Relay user intentionally submits, including titles, text, custom fields, controls, and optional attachments.
- - Channel identifiers, channel titles, publisher-key hashes, delivery status, timestamps, errors, and other records needed to publish, deliver, and maintain notification history.
- - Request metadata such as IP address and user agent for abuse prevention, diagnostics, reliability, and service security.
- - Local app or browser data such as channels, preferences, Relay rules, selected source apps, and other settings stored on your device.
- - Push-delivery identifiers such as Firebase Cloud Messaging tokens or topic-subscription data when push notifications are enabled.
2. Android Notification Relay
- - Relay is optional, starts inactive, and requires notification access that you grant in Android settings.
- - Android notification access allows the app to inspect posted notifications, which may contain personal or sensitive information. Relay evaluates notifications on your device only while you have active rules.
- - You choose the source apps, destination channel, match conditions, and JSON fields for each rule. When a rule matches, only the fields produced by that rule are sent over HTTPS to the selected alrim.io channel.
- - If several active rules match one notification, each matching rule sends its own payload. alrim.io does not use Relay to reply to, dismiss, or modify the source notification.
- - The source-app picker reads the list of launchable apps locally. Merely viewing or searching that list does not transmit your installed-app list to alrim.io.
- - Relay rules and publish keys remain in the app's private storage. One recent notification sample may be kept in process memory for preview and disappears when the app process ends.
3. Notification Publishing, History, and Visibility
- - alrim.io accepts publisher requests, sends notifications, and stores send-history records so subscribed clients and publisher tools can synchronize and review history.
- - Channel history is designed to be available to people or devices that know the channel identifier or channel URL. Do not publish secrets that should not be visible to recipients of that channel.
- - Publisher keys are credentials and are stored locally by publisher clients when you save a channel. Server history stores a one-way publisher-key hash rather than the plain key.
- - Uploaded attachments are stored by our object-storage provider and may be available through their generated URLs to recipients who receive or obtain the notification.
4. Push Notifications and Firebase
- - We use Firebase Cloud Messaging or similar infrastructure to deliver push notifications to subscribed devices.
- - Google Firebase may process push tokens, topic-subscription data, delivery metadata, and notification payloads under its own privacy terms.
- - You can disable notification permission or unsubscribe channels through the app and Android or browser settings.
5. Camera and QR Scanning
- - The alrim.me Android app may request camera access when you choose to scan a channel QR code.
- - Camera preview frames are processed locally for QR recognition and are not intentionally uploaded merely because the scanner is open.
- - You can deny camera access and use a channel link or manual entry instead.
6. How We Use Information
- - To provide publishing, Relay, subscription, delivery, synchronization, and history features that you request.
- - To operate and secure the service, prevent abuse, diagnose failures, and improve reliability.
- - To respond to support, privacy, security, and legal requests.
- - We do not sell personal information and do not use Relay notification content for advertising.
7. Service Providers and Disclosure
- - Hosting, Cloudflare R2 object storage, Firebase push delivery, app distribution, and security providers process information only as needed to operate their parts of the service.
- - We may disclose information when required by law or when reasonably necessary to protect users, the service, or the public from fraud, abuse, or security threats.
8. Retention and Deletion
- - Server-side send-history database records, including notification payloads and related request metadata, are removed by hourly cleanup after they become older than 90 days and are also cleaned when the service starts.
- - Uploaded attachment objects and thumbnails under our channel-storage prefix are automatically deleted by the Cloudflare R2 lifecycle after 90 days.
- - Local channels, preferences, Relay rules, and publish keys remain on your device until you delete them, clear app storage, or uninstall the app.
- - The in-memory Relay sample disappears when the app process ends.
- - To request deletion of server-side information, email [email protected] with the relevant channel identifier and enough information for us to verify and locate the data.
9. Your Controls
- - Relay rules can be stopped or deleted individually. Notification access can be revoked at any time in Android settings.
- - You can control push and camera permissions through Android or browser settings and remove locally stored data through in-app controls or system app-storage settings.
- - Relay does not send notification data when there are no active matching rules.
10. Security
We use HTTPS, app-private storage, bounded inputs, and operational safeguards intended to
protect information. No internet service or device storage system can guarantee absolute
security. Keep publisher keys private and use destination channels appropriate for the
information you choose to relay.
11. Children's Privacy
alrim is not directed to children under the age required by applicable law to use the service
without parental consent. Contact us if you believe a child's information was submitted in
violation of applicable law.
12. Changes and Contact
We may update this policy and will revise the date above when we publish changes. For privacy
questions, access or deletion requests, or policy concerns, email [email protected].