Privacy Policy — Privis Alerts App
Zumitomi Oy — Privis Alerts (Android)
Last updated: 12 June 2026
This policy covers the Privis Alerts mobile app. The privis.app messaging service itself is covered by our main Privacy Policy.
1. What the App Does
Privis Alerts is a companion app for the privis.app messenger. Its only job is to notify you that new messages are waiting for you on privis.app. It is designed so that your message content never reaches the alerts side of the app — not in notifications, and not in the notification history it stores. (The app also includes an embedded browser tab for privis.app itself; see section 6 for how that behaves.)
2. Data the App Sends to Our Servers
When you link the app to your privis.app account with a pairing code, the app registers with our servers:
- A push token (an identifier issued by your device for delivering notifications)
- Your device platform (Android or iOS)
- The single-use pairing code you typed
Our server links these to your privis.app account and issues the app a device secret that it uses to authenticate later requests. To show sender names, the app periodically asks our server for a list of recent message arrivals — receiving only sender nicknames and timestamps, never message content.
3. Data Stored on Your Device
- Pairing information (account link, push token, device secret) — stored in your device’s protected keystore
- Notification history (sender nicknames and arrival times, at most the latest 200 entries) — stored in the app’s private storage
Unlinking the device in the app’s Settings deletes this data. Android’s cloud backup is disabled for this app, so this data is never copied to Google’s backup servers.
4. What the App Never Collects
- No message content in the alerts data — the notifications and the stored history never contain it by design
- No contacts, location, camera, microphone, or files
- No analytics, no advertising identifiers, no trackers of any kind
- No phone number, email, or real name (privis.app accounts don’t have them)
5. Third Parties: How Notifications Reach You
Push notifications are delivered through Expo and Google (Firebase Cloud Messaging) — this is the only technically possible delivery route on Android. We deliberately keep these notifications generic (“You have a new message”) so that these third parties never see who messaged you. They see only your push token and the fact that a notification was sent. Sender names are fetched separately by the app directly from our own servers.
6. The Embedded Browser
The app includes a tab that opens privis.app in an embedded browser view. That browser stores the same kind of local data any browser would (your login session, cookies, cached files) on your device, and everything you do there is governed by the main Privacy Policy. Links leading outside privis.app open in your regular browser, not inside the app.
7. Data Location and Retention
Server-side pairing data is stored on our database servers in Frankfurt, Germany (EU, GDPR). It is kept while your device is linked. It is removed when you unlink the device (from the app or from privis.app Settings → Linked devices), and automatically deleted if you delete your privis.app account.
8. Your Rights (GDPR)
The same rights described in the main Privacy Policy apply: access, correction, deletion, and objection. The fastest way to delete the app’s data is to unlink the device and uninstall the app.
9. Changes to This Policy
We may update this policy occasionally. Significant changes will be communicated through the service. The ethos of this policy will never change.
Questions?
Contact our helpdesk:
https://privis.app/?nick=helpdesk