type: doc
NotiAlarm Privacy Policy
Last updated: 2026-10-10
This policy describes what data NotiAlarm collects, how we use it, who it's shared with, and how to delete it. It applies to the NotiAlarm iOS app and our backend at *.supabase.co.
If you have questions, contact privacy@notialarm.com.
1. Who we are
NotiAlarm is operated by AYYEEHHM DESIGNS LLC, a New York limited liability company ("we", "us"). AYYEEHHM DESIGNS LLC is the only "data controller" for the data described below. We do not sell user data, do not run advertising, and do not share data with analytics or marketing providers.
2. What we collect
We collect only what we need to deliver alarm-grade notifications. Everything is tied to your NotiAlarm account.
Account data
- Email address. Required to sign up and recover your account. If you use Sign in with Apple and choose "Hide My Email," we receive Apple's private-relay address (e.g.
random@privaterelay.appleid.com) instead of your real email. - Password hash. If you sign up with email + password. We never see your plaintext password — only the salted hash stored by our authentication provider.
- Optional display name and timezone. Editable in Settings.
Notification delivery data
- Push notification token. Issued by Apple Push Notification service (APNs). Stored against your account so the backend knows where to deliver your alarms. Refreshed automatically by iOS.
- Per-device "Critical Alerts enabled" flag. True/false, set by you when you grant the Critical Alerts permission (only available if Apple has granted us the entitlement; pending as of this writing).
Webhook event metadata
When a third-party service (e.g., TradingView) posts a webhook to your unique NotiAlarm ingest URL, we record:
- The source name (e.g.,
tradingview) - The alert tag the source sent (e.g.,
NQ1! Crossing 29,102.25) - A SHA-256 hash of the raw request body (for de-duplication only)
- For incoming email, a SHA-256 hash of the normalized sender address, used to match Sender filters (retained with event metadata for 30 days)
- The timestamp the request landed
- The result of any signature verification
- The remote IP address that posted the webhook
- The name of the software that sent it (the HTTP "User-Agent", e.g.
TradingVieworpython-requests)
We do not retain the raw webhook body past the lifetime of the HTTP request that delivered it. The body is parsed for the alert tag and discarded.
Alarm configuration and fire history
- Alarms you create: name, source, match pattern or sender email address you choose to filter, sound choice, vibration choice, dismissal-challenge settings, presentation mode, quiet hours.
- Alarm fires: when each alarm fired, which devices received the push, delivery success per device, when (and how) you dismissed it.
User-uploaded audio
- Custom sound files (m4a, mp3, wav) you upload, up to 5 MB each. If you upload a video file (mp4, mov, m4v), only the audio track is extracted and stored — the video frames are discarded before upload.
- Stored under a path tied to your account ID. Only you (and our backend, when sending you an alarm push that uses the sound) can access them.
Logs
Our backend writes operational logs to detect abuse, debug delivery failures, and meet platform reliability requirements. Logs may include request IDs, timestamps, error messages, and IP addresses. They do not include webhook bodies or alarm contents.
In-app browser for source setup (TradingView)
To help you connect TradingView, the app can open TradingView's own website inside an in-app browser and show setup steps next to it. About that browser:
- You sign in on TradingView's page, including any 2-factor code. NotiAlarm never sees, stores, or transmits your TradingView password, codes, or cookies.
- Your TradingView sign-in is kept on your device only, in storage dedicated to this browser, so you don't have to repeat 2-factor verification every time. NotiAlarm never reads it and it never leaves your device. It is wiped when you sign out of NotiAlarm or delete your account. We do not read the pages you visit or record your activity there.
- Guided setup highlights, on the TradingView page, the button or field to tap next. It is visual only: it finds those elements by their labels and position, never clicks or types anything, does not read other page content, and sends nothing to us.
- An optional "Automated" setup (off by default, enabled only after you accept an in-app disclaimer) runs a small script on the TradingView page inside that browser. It opens TradingView's alert dialog, sets the alert's value to 0 (so it can never trigger), fills its *Webhook URL* field with your NotiAlarm URL and taps *Apply*. You tap *Create* yourself — creating an alert is what makes TradingView remember the webhook. In both Guided and Automated setup, after you tap Create the script then deletes that one temporary alert (the one set to 0) and returns you to the app. It never creates, edits or deletes any other alert, does not read other fields, and sends nothing to us. You choose between Guided and Automated each time; your acceptance of the disclaimer is remembered on your device (reset it in Settings → Setup, and it resets when you sign out). Stop it any time from the browser.
Phone notifications (iOS 27 Shortcuts)
If you set up the Phone notifications source, you create an automation in Apple's Shortcuts app ("When I receive a notification from …") and choose which apps it covers. That automation hands each matching notification's text and app name to NotiAlarm's "Send to NotiAlarm" action:
- It is processed on your device to decide whether to ring an alarm. NotiAlarm does not read your notifications any other way, and only sees the apps you picked in your automation.
- We store the app name as the name of that app's source in your account (e.g. "Messages"), so it appears in Sources with its own alarms.
- The notification text is not sent to us, unless you share that app's source with other people: then the text is sent as the alert so their phones ring too, and it is handled like any other alert (see *Webhook event metadata* — kept for 30 days).
- Delete the source in NotiAlarm and the automation in Shortcuts to stop it.
In-app usage events
To see where setup gets hard and improve the app, the app records a small number of usage events in our own database (no third-party analytics): for example that you opened the app that day, opened or closed the subscription screen and where from, tapped a plan and whether the purchase completed, cancelled or failed (as reported by Apple — we never see payment details), reached the free-plan limit, and how far you got in a source's setup (source type, step number, Guided or Automated). Each event is a short name plus a few such labels, linked to your account. Events never contain webhook URLs, email addresses, alert contents, passwords, or anything you type.
Setup reminders
If you add a source that hasn't received an alert yet, or create an account without adding a source, we may send you a small number of reminder notifications (never alarms). They use only data already described above (account creation time, your sources, and whether an alert has arrived) and stop after a few days. Turn them off in Settings → Setup → *Setup reminders*.
3. What we do NOT collect
NotiAlarm does not access:
- Your location
- Your contacts
- Your photo library contents beyond a single video you explicitly choose to upload for audio extraction (and that file is processed on-device using Apple's out-of-process picker — we don't receive your photo library catalog)
- Your microphone
- Your camera
- Health data
- Your browsing or app-usage history outside of NotiAlarm (the optional in-app TradingView setup browser is not recorded either — see above)
- Any data from other apps on your device — except notifications you choose to hand NotiAlarm through your own Shortcuts automation (see *Phone notifications* above)
We do not include analytics SDKs, advertising SDKs, or any third-party tracking code in the iOS app.
4. How we use your data
We use the data above only to:
- Authenticate you and let you sign in across devices.
- Deliver alarm notifications to devices you've registered.
- Match inbound webhooks to the alarms you've configured.
- Show you your alarm history and let you debug missed matches.
- Operate, secure, and improve the service (e.g., detecting abuse, fixing bugs, planning capacity).
- Send you setup reminders about your own account (off switch in Settings → Setup).
We do not use your data for marketing, profiling, or sale to third parties.
5. Who we share data with
Your data is stored on infrastructure provided by these third parties, each of which acts as a processor under our direction:
- Supabase (
supabase.com). Hosts our database, authentication, file storage, and serverless functions. All NotiAlarm data lives here. - Apple Push Notification service (
push.apple.com). Delivers iOS notifications. We send your APNs token + a short payload; Apple does the rest. - Apple Sign in with Apple (if you use it). Apple issues us an identity token containing your Apple user ID and email. We verify the token, then store your account in Supabase as above.
- Firebase Cloud Messaging (
firebase.google.com). Reserved for the future Android version; not used by the current iOS app.
We do not share data with TradingView or other webhook sources. Those services post to us; we don't send anything back. When you use the in-app setup browser, you interact with TradingView's website directly under TradingView's own privacy policy — TradingView is not a processor for us and receives nothing from us except the webhook URL you paste (or let the optional script paste) into your own alert.
Between users: if you subscribe to another user's shared webhook URL, that URL's owner can see that you're subscribed — shown as a masked version of your email (e.g. s•••t@gmail.com, never the full address) plus the date you subscribed — and can remove your subscription. You can unsubscribe yourself at any time.
We will disclose data only when legally required (e.g., a valid subpoena) and only the specific data requested.
5a. Purchases & subscriptions
- Payments are processed entirely by Apple. If you subscribe to NotiAlarm
Pro, the transaction happens through your Apple ID and the App Store. We
never see or store your card number, billing address, or Apple ID
credentials. Subscription entitlement is checked on your device against
Apple's StoreKit records.
- Manage or cancel subscriptions any time in your Apple ID settings. Apple's
standard [Licensed Application End User License Agreement](https://www.apple.com/legal/internet-services/itunes/dev/stdeula/)
applies to the app.
6. How long we keep data
| Data | Retention |
|---|---|
| Account, alarms, devices, custom sounds | Until you delete your account |
| Alarm fire history | Until you delete your account |
| Webhook event log (metadata only) | 30 days, then automatically purged |
| Operational logs | Up to 30 days |
| Raw webhook bodies | Not retained beyond the request itself |
| In-app usage events | Until you delete your account |
When you delete your account (Settings → Delete Account inside the app), everything tied to your account is purged immediately, including your custom sound uploads. The cascade is enforced at the database level via auth.users on delete cascade.
7. Your rights
You can:
- Access your data: everything we hold is visible inside the app.
- Correct your data: edit account fields, alarms, and sounds in the app at any time.
- Delete your account: Settings → Delete Account inside the app. The deletion is immediate and irreversible. If you also want our operational logs purged on a faster timeline than the 30-day default, email us.
- Export your data: not yet available in v1. Email us if you need a copy of what we hold.
If you are in the EU/EEA, UK, or California, you have additional statutory rights (data portability, restriction of processing, etc.). Email us and we will honor them.
8. Security
- All traffic between the app and our backend uses HTTPS / TLS 1.2+.
- Passwords are stored as salted hashes by our authentication provider (never plaintext).
- Webhook ingest URLs contain 128 bits of randomness, are unique per user, and can be rotated from the app at any time (old URL returns
410 Gone). - Database access is governed by row-level security: every query is scoped to the authenticated user. The service role key never ships in the iOS app.
No system is perfectly secure. If you believe your account has been compromised, rotate your webhook URLs from the Sources screen and email us so we can investigate.
9. iOS permissions we request
| Permission | Why |
|---|---|
| Notifications | Required to deliver alarms. Without this you receive nothing. |
| Time Sensitive notifications | Lets alarms break through Focus / Do Not Disturb when you've added NotiAlarm to a Focus's allowed apps. |
| Critical Alerts (when granted by Apple) | Lets alarms bypass hard silent mode and sleep silence. Disabled by default; you opt in per device. |
| Background audio mode | Required so the alarm sound can start playing from a background push, before you tap the notification. |
We never request location, contacts, camera, microphone, or health permissions.
10. Children
NotiAlarm is intended for users 13 and older (or the equivalent age of digital consent in your jurisdiction). We do not knowingly collect data from children under 13. If you believe a child has signed up, email us and we'll delete the account.
11. Changes to this policy
We may update this policy from time to time as the app evolves. When we do, we'll revise the "Last updated" date at the top of this page, and any material changes will be reflected here before they take effect. Please review this page periodically for the latest version.
12. Contact
Privacy questions, deletion requests, or anything else: privacy@notialarm.com.
By mail: AYYEEHHM DESIGNS LLC, 350 Northern Blvd STE 324-1737, Albany, NY 12204, USA.