Legal
Privacy Policy
Last updated: September 9, 2026
This Privacy Policy explains how NitroPush ("NitroPush", "we", "us", or "our") handles personal data when you visit nitropush.org, create or use a NitroPush account, interact with our dashboard, APIs, CLI, documentation, or support, or use an application that receives updates through the NitroPush SDK (collectively, the "Service").
This policy applies to information for which NitroPush determines the purposes and means of processing. When a customer uses NitroPush to deliver updates to its own application, that customer generally controls the application and its end-user relationship. NitroPush processes related SDK data to provide the Service to that customer.
1. Information we collect
Account and profile information
- Email address, display name, organisation, and account identifiers.
- Authentication records, one-time-code activity, session information, and OAuth profile details supplied by your chosen identity provider.
- Team membership, roles, permissions, invitations, and account preferences.
Billing and transaction information
- Plan, billing period, subscription status, invoices, transaction references, amounts, currency, and refund status.
- Billing contact details and the phone number supplied during checkout.
- Usage measurements needed to calculate charges, including peak active authenticated developer seats.
Payments are processed by Cashfree Payments. NitroPush does not store your full card, bank-account, or UPI credentials. Cashfree may collect and process those details under its own privacy terms.
Product and customer content
- Apps, projects, environments, releases, JavaScript bundles, source maps, assets, signing-key metadata, and configuration you submit.
- Support requests, feedback, attachments, and other communications you send us.
- Notification integration settings and delivery records for integrations you enable.
SDK and device telemetry
Applications integrating NitroPush may send operational events needed to check, download, install, verify, and measure OTA updates. Depending on the application and SDK version, these events may include:
- Event type and timestamp, such as app start, update check, download, install, rollback, or error.
- Application identifier, deployment environment, binary version, OTA release label, and bundle metadata.
- Platform, operating-system version, device model, locale, network type, and approximate device-memory class.
- A customer-app-scoped, client-generated device identifier used for aggregate active-device measurement.
- Diagnostic information such as status codes, failure category, and update performance.
Network requests necessarily expose an IP address to our infrastructure. We use it for delivery, security, and rate limiting. Where an IP-derived value is retained for product analytics, NitroPush truncates or anonymises it rather than retaining the full address in the device record.
Website, dashboard, and technical data
- Browser and device type, referring page, pages viewed, approximate region, timestamps, and interaction events.
- Request metadata, IP address, user agent, response status, security events, and diagnostic logs.
- Session cookies and similar storage required to keep you signed in and protect the Service.
2. How we obtain information
We receive information:
- Directly from you when you register, pay, configure the Service, contact support, or upload content.
- Automatically from your browser, device, or an application using the NitroPush SDK.
- From your organisation's administrators and teammates.
- From service providers such as identity, payment, email, infrastructure, and security providers.
3. How and why we use information
- Provide the Service: authenticate users, host and deliver releases, process update checks, maintain accounts, and provide support.
- Billing: create subscriptions, calculate seat-based charges, process payments, send receipts, handle cancellations, and administer refunds.
- Security and reliability: prevent abuse, verify requests, investigate incidents, debug failures, protect accounts, and maintain availability.
- Product improvement: understand feature performance and aggregate usage, improve documentation, and develop new capabilities.
- Communications: send login codes, transactional notices, billing messages, security alerts, service updates, and replies to your requests.
- Legal compliance: keep records, enforce our terms, respond to lawful requests, and protect legal rights.
Where applicable law requires a legal basis, we rely on performance of our contract, our legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where consent is required. You may withdraw consent at any time, without affecting earlier processing.
4. How we share information
We may disclose information to:
- Your organisation: administrators and authorised members can access information connected to their organisation, including projects, team activity, usage, and billing.
- Service providers: infrastructure hosting, object storage and CDN, payment processing, authentication, email delivery, analytics, monitoring, and customer-support providers that process data for us.
- Integrations you choose: services such as Slack or Discord when you enable an integration or direct us to send information there.
- Professional advisers: auditors, insurers, accountants, and legal advisers subject to appropriate confidentiality duties.
- Authorities and affected parties: where reasonably necessary to comply with law, legal process, or valid government requests; enforce agreements; or protect rights, safety, and the integrity of the Service.
- Business transferees: in connection with a merger, financing, acquisition, reorganisation, bankruptcy, or sale of all or part of our business, subject to appropriate protections.
We do not sell personal data or share it for cross-context behavioural advertising.
5. Cookies and similar technologies
The dashboard uses an essential, HTTP-only session cookie to authenticate you and protect your session. We may also use essential browser storage for security and interface preferences. Our public website uses privacy-focused analytics to understand aggregate traffic and page performance. We do not use third-party advertising cookies.
Browser privacy signals, including Do Not Track, are not governed by one consistent industry standard. Because we do not sell personal data or use cross-site advertising, there is no advertising sale or sharing to opt out of through such a signal.
6. Data retention
We keep personal data only for as long as reasonably necessary for the purposes described above, including to provide the Service, meet contractual and legal obligations, resolve disputes, and enforce agreements. Retention depends on the nature of the data:
- Account and organisation data is generally retained while the account is active and for a limited period after closure.
- Uploaded releases and customer content are retained according to the customer's actions, plan, and applicable deletion or backup cycles.
- Detailed SDK telemetry is generally retained for up to 12 months, after which it may be deleted or aggregated.
- Operational and security logs are generally retained for up to 90 days, but may be kept longer when needed to investigate an incident.
- Billing, tax, audit, fraud-prevention, and transaction records may be retained for up to seven years or longer where law requires.
- Backups may retain deleted information for a limited rolling period before secure expiry.
We may retain de-identified or aggregated information that can no longer reasonably identify an individual.
7. Security
We use administrative, technical, and organisational safeguards designed to protect information, including encrypted transport, access controls, environment separation, security logging, secret management, and protected infrastructure and backups. NitroPush also supports signed OTA bundles so customers can verify release authenticity on device.
No system is completely secure. You are responsible for protecting your account credentials, deployment keys, signing keys, and devices, and for promptly notifying us if you suspect unauthorised access.
8. International data transfers
NitroPush and its providers may process information in countries other than the country where you live. Where required, we use legally recognised safeguards for international transfers, such as contractual protections, and assess provider security and confidentiality commitments.
9. Your privacy rights
Depending on where you live, you may have rights to request access, correction, completion, deletion, restriction, objection, portability, or information about how personal data is processed. You may also have the right to withdraw consent, nominate another person to exercise certain rights, appeal a decision, or complain to a data-protection authority.
To make a request, email contact@nitropush.org with the subject "Privacy request". Describe your request and the account or organisation involved. We may ask for information needed to verify your identity and authority. We will respond within the period required by applicable law and will explain if an exception applies.
If NitroPush processes your information solely on behalf of one of our customers, please contact that customer first. We will assist the customer as required by our agreement and applicable law.
10. Account and content deletion
Organisation owners may request account closure or deletion by contacting us. Before deleting an organisation, export anything you need and remove active payment obligations. Deletion may be delayed where data must be retained for security, fraud prevention, billing, tax, dispute resolution, or other legal requirements.
11. Children's privacy
NitroPush is a business and developer service and is not directed to children. You must be at least 16 years old, or the minimum age required in your jurisdiction to consent to online services, to create an account. We do not knowingly collect personal data directly from children. Contact us if you believe a child has provided personal data to NitroPush improperly.
12. Customer responsibilities
Customers decide which applications use NitroPush and are responsible for providing their own end-users with legally sufficient privacy information, obtaining required permissions, configuring appropriate data collection, responding to end-user requests, and ensuring they have a lawful basis to send data to NitroPush.
13. Third-party services and links
The Service may link to or integrate with third-party services. Their privacy practices are governed by their own terms and policies, not this policy. We encourage you to review them before enabling an integration or providing information.
14. Changes to this policy
We may update this policy as the Service, our practices, or legal requirements change. We will post the updated policy here and change the "Last updated" date. If a change materially affects your rights, we will provide additional notice where required, such as through the dashboard or by email.
15. Contact and grievances
For privacy questions, requests, or grievances, contact NitroPush at contact@nitropush.org. Include enough detail for us to identify the relevant account and understand your concern. Please do not send passwords, private signing keys, payment credentials, or other sensitive secrets by email.