Privacy policy

Privacy

What the Mac app reads, what it sends through ntfy, what remains local, and how commerce, support, and website providers process data.

1. Who is responsible

ANGELTECH is responsible for the NotiFerry website, product, and direct support data it controls. Contact privacy@agentkey.dev. Independent providers control their own services and processing.

ANGELTECH controls the product-support information it receives. Lemon Squeezy, ntfy, Apple, Google, and the site infrastructure process data for their own services under their published terms.

Operator
ANGELTECH · 9 Route de la Conche, 19320 Saint-Martin-la-Méanne, France
Payment and receipt
Link, LLC f/k/a Lemon Squeezy LLC
Website host
OpenAI Ireland Ltd · 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland
Provider roles
ANGELTECH supplies and supports NotiFerry; Lemon Squeezy handles checkout, payment, receipts, and license records; ntfy relays notifications; OpenAI Sites hosts this website.

2. Notification data and your controls

Notification content stays on your Mac until forwarding is enabled and a new eligible record is read after the current baseline. With the read-only folder permission you select, the app can read the source app, source identifier, title, subtitle, body, and record timing. These fields can contain messages, one-time codes, health, financial, employment, or other sensitive information.

Before enqueueing, NotiFerry applies your app exclusions and privacy mode: full preview, app and title only, or a generic alert. Pausing forwarding discards notifications received while paused; resuming does not backfill them. You can clear queued content, rotate the topic, revoke folder access, or reset setup.

Avoid regulated or high-risk content.

The default relay is not end-to-end encrypted. Do not forward medical, financial, legal, authentication, employment-regulated, or safety- critical alerts unless you have assessed the third-party transport and have authority to do so.

3. Local storage and exact queue behavior

After privacy filtering, an owner-only SQLite outbox stores at most the newest 1,000 pending rows. A row is eligible for retry for 24 hours from enqueueing. Expired rows are deleted on the next enqueue or delivery- claim activity, so an inactive database may retain an expired row longer than 24 hours until that activity, manual clearing, reset, or app-data deletion. Successful delivery, permanent failure, capacity trimming, clearing, and reset remove rows earlier.

Source is capped at 256 UTF-8 bytes, source identifier and title at 512 bytes each, subtitle at 1,024, and body at 3,800. The database uses owner-only permissions, rollback journaling, and SQLite secure deletion, but it is not separately encrypted and storage systems can retain copies. NotiFerry keeps no separate history of successfully delivered content; macOS maintains its own Notification Center database independently.

4. ntfy and mobile push

The app sends the filtered fields and topic over HTTPS to your configured ntfy server. The random public topic is a bearer secret: anyone who learns it can subscribe and publish until it is rotated. The app stores the topic and any optional ntfy credential in macOS Keychain. A copied subscription link is placed on the system clipboard and is automatically cleared after two minutes only if the clipboard has not changed.

Public ntfy.sh may cache messages for approximately 12 hours under its current configuration. ntfy states that iOS instant delivery uses Firebase Cloud Messaging through Apple Push Notification service, so ntfy, Google, and Apple may process content or metadata. A custom ntfy server has the operator’s own retention and logging settings.

5. Diagnostics, analytics, crashes, and cookies

The app does not automatically upload a support report. When you choose “Copy privacy-safe diagnostics,” it puts a bounded report on the macOS clipboard containing version/build, macOS version, CPU architecture, engine/permission/onboarding/license categories, counts, and operational timestamps. It excludes notification content, app identifiers, paths, server/topic details, credentials, purchase data, free-form errors, and URLs. Unlike the copied topic link, this diagnostic text is not timed for automatic clipboard clearing; review it and overwrite the clipboard when finished.

Analytics
No product or website analytics service is enabled in this release.
Crash reporting
No automatic crash-reporting service is enabled in this release.
Cookies and browser storage
The website sets no NotiFerry analytics or advertising cookies and uses no browser local storage.

6. Trial, licensing, purchase, and support

macOS Keychain stores the random installation identifier, trial start, license key, activation instance, and validation timestamps. Trial history is intentionally retained across the in-app reset. The trial start and history remain in macOS Keychain after in-app reset and reinstall; they end only when the relevant Keychain item or device data is removed.

Activation and validation send the license key and an installation-derived instance name to Lemon Squeezy’s license API. The app receives license status and associated store, product, variant, activation, and validation metadata; Lemon Squeezy can associate the license with order and customer records. NotiFerry caches a successful validation for 24 hours and permits at most seven days offline after that validation.

Purchase/accounting records
Purchase, receipt, tax, and refund records are retained only as needed to operate the purchase and meet applicable legal obligations.
Support records
Support correspondence is retained while needed to answer and resolve the request, or longer when an applicable legal obligation or dispute requires it.
Website security logs
NotiFerry does not enable application observability. Infrastructure providers may process security logs under their own published policies.

7. Purposes, legal bases, and transfers

ANGELTECH processes information to provide support and perform the license contract, meet legal obligations, and protect the product and users from abuse.

Some independent providers operate outside the EEA. Their published privacy terms describe where they process data and the safeguards they apply.

ANGELTECH does not sell notification content or use it for targeted advertising or model training. Information may be disclosed when lawfully required or necessary to protect users, the service, or legal rights.

8. Retention, choices, and rights

Unsubscribing does not erase a message already cached by ntfy. Rotation prevents future use of the old topic but cannot guarantee deletion from independent infrastructure. Reset clears setup, ntfy secrets, preferences, and the queue, and attempts to release a paid activation; it intentionally retains trial history. Removing the app does not remove macOS Notification Center history or necessarily remove Keychain items.

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection for personal information ANGELTECH controls, and complain to a competent authority. Contact privacy@agentkey.dev. For data controlled by ntfy, Apple, Google, Lemon Squeezy, or the host, contact that provider. Checkout availability depends on Lemon Squeezy, applicable law, and payment restrictions.

9. Changes

Policy version 2026-08-06 is effective 2026-08-06. A material change to notification handling will be disclosed before the changed behavior is enabled where required by law.