Skip to content
Smoke Signal

Legal

Privacy Policy

Effective: 30 July 2026

Smoke Signal (smokesignal.sh) is operated by Assembly Not Included, a sole trader based in the United Kingdom. This policy explains what personal data we collect, why, and what you can do about it. We have tried to keep it short and honest: the service was designed to collect as little as possible, so there is not much to disclose.

TL;DR

  • We collect one email address, a display name you choose, and the browser push subscriptions needed to deliver notifications. Nothing more.
  • No ads, no analytics, no tracking cookies, no marketing email. We never sell or rent data.
  • Notification content exists on our servers only while it is being delivered, encrypted, and is scrubbed within minutes. What we keep long-term is delivery records (counts, timestamps, outcomes), never the message text.
  • Deleting your account erases everything after a 30-day safety window (sign back in to cancel). The only things that outlive it are purchase records tax law makes us keep (stripped of your identity) and an anonymous marker that the deletion happened.
  • Your data lives in the UK (London). Notifications are delivered through Apple, Google, or Mozilla's push services in a form they cannot read.

Who we are

The data controller is:

Assembly Not Included (sole trader)
16 Beaumont Road
Plymouth, PL4 9BN
United Kingdom
Email: hello@smokesignal.sh

What we collect

We only collect information we have a concrete reason to collect. By activity:

When you create a publisher account

  • Your email address. Used to sign in, recover your account, and send you service notices (for example, "a new device was added to your account"). It is stored encrypted; lookups use a one-way hash. We will only ever email you about your own account. There is no mailing list.
  • A publisher name. Chosen by you, shown to your subscribers on notifications. It can be anything; we don't verify it. If you put personal information in it, that's your choice.

We never ask for a password (the service is passwordless: you sign in with a code we email you), a phone number, or your real name. If you enable optional two-factor authentication, we also store the keys needed to verify it.

When you receive notifications

  • A push subscription for each browser or device you enable: a delivery URL and encryption keys issued by your browser. The URL identifies your device to the push service (Apple, Google, or Mozilla) so notifications can reach it.
  • Device labels you choose (like "work laptop"), to tell your devices apart.
  • You can follow a publisher without an account at all. Anonymous subscribers are pseudonymous: we hold only the push subscription and a random credential, nothing that identifies you.

When you send notifications

  • The notification content (title, body, and link) and the delivery addresses queued with it are held encrypted while delivery is in progress, and scrubbed as soon as hand-off to the push networks completes, within 15 minutes of acceptance at the outside. It is also encrypted end-to-end to each device, so the push networks that carry it cannot read it.
  • You choose each notification's lifetime (up to 24 hours). That lifetime governs how long a push network may hold the still-encrypted message for an offline device, not how long we hold it. An expired notification is dropped and never delivered late. Once a notification is displayed, it lives on that device, outside our systems.
  • Delivery records: message ID, how many subscribers were charged, timestamps, and the outcome, possibly with an irreversible fingerprint (hash) of the content but never the content itself. Kept with your account for billing accuracy.
  • An audit trail of account activity (what action, when, and its outcome, never message content), kept for security until your account is deleted.

When you buy credits

  • Payment is handled entirely by Stripe. Your card details go directly to Stripe and never touch our servers.
  • We keep a transaction record (what was bought, when, and the credit movements on your balance). Stripe holds the payment details and issues your receipt.

Automatically

  • Server logs. Like nearly every web service, our servers record request metadata (method, route, status, timing) including your IP address. Logs are held by our hosting platform and kept only briefly. Our application never stores IP addresses in its database; IPs are also used in short-lived, in-memory rate limiting to prevent abuse.
  • Nothing else. No analytics scripts, no fingerprinting, no ad pixels, no third-party trackers of any kind.

On your device (not sent to us)

The app keeps your credentials, webhook secrets, and settings in your browser's local storage. That data stays on your device. Server-side, your sign-in and device credentials exist only as one-way hashes we cannot reverse; webhook and invite secrets are stored encrypted so the app can show them to you again when you ask.

What we don't collect

No passwords. No phone numbers. No card details (payments go directly to Stripe). No contact lists. No location data. No behavioural analytics. No data purchased or obtained from anyone else.

Cookies

We don't set any cookies. Our service is designed so no response ever sets one, and no cookie is ever accepted as a credential.

One exception outside our control: our infrastructure provider's edge network (Cloudflare) may set a bot-protection cookie (__cf_bm) when your browser talks to our API. It is strictly a security cookie, not tracking, and we receive nothing from it.

What we share, and why

We share data only where it is necessary to run the service, never for marketing, and we never sell it. Our processors:

WhoWhat they doWhat they see
DigitalOcean (London, UK)Hosts our servers and databaseEverything the service stores, encrypted at rest as described above
CloudflareDNS, TLS, and serving the web appRequest metadata (including IPs) at the network edge
ResendDelivers our account emails (sign-in codes, recovery, security notices)Your email address and the message being sent
StripeProcesses payments when you buy creditsYour payment details (which we never see) and billing information; we receive confirmation of the purchase
Apple / Google / Mozilla push servicesDeliver notifications to your browserYour push subscription URL and an encrypted payload; Web Push encryption means they cannot read notification content

Beyond that, we would disclose data only if legally compelled to (for example, a valid court order), and if the service were ever transferred to a new operator, your data would remain protected by this policy.

Where your data lives

Our servers and database are in London, United Kingdom. Three things involve transfers outside the UK: account emails (delivered via Resend), payments (processed by Stripe), and push delivery (Apple, Google, or Mozilla, depending on your browser, with content they cannot decrypt). These transfers are protected by UK-approved safeguards: standard contractual clauses with the UK Addendum and, for Resend, certification under the UK Extension to the EU-US Data Privacy Framework.

How long we keep things

DataKept for
Email address, publisher name, subscriptions, devices, credit balanceUntil you delete them or your account. Accounts don't expire (see below)
Purchase and transaction recordsAs long as UK tax law requires us to keep business records (up to 6 years), even after account deletion
Notification content and its queued delivery addresses (encrypted)Scrubbed when delivery hand-off completes, at most 15 minutes after acceptance
Delivery records and the account audit trail (never message content)Until your account is deleted
Sign-in codes and two-factor challenges10 minutes, single-use
Email invites48 hours; shareable invite codes last until you revoke them
Dead push subscriptionsRemoved automatically as soon as the push service reports them gone
Server logs (incl. IP addresses)Briefly, per our hosting platform's log rotation

A note on "accounts don't expire": we deliberately never delete an account for inactivity: your webhooks keep working even if you don't log in for years. The flip side is that your email address and publisher name stay stored until you delete the account. Deletion is always available, in the app.

You're in control

  • Delete your account from the app at any time. Deletion is scheduled with a 30-day safety window (sign back in within it to cancel), and then everything is permanently erased: email, name, delivery records, subscriptions, balance. There is no recovery after that. Two narrow exceptions survive: if you bought credits, the minimal transaction records UK tax law obliges us to keep (stripped of your email and name, leaving only payment references and amounts), and an anonymous marker recording that the deletion happened.
  • Unsubscribe from any publisher, or remove any device, at any time. Device installations can exist independently of an account (that's how anonymous subscribing works), so removing the app or its subscriptions from a device is done on the device itself.
  • Anonymous subscribers can remove the subscription from their device.
  • Your UK GDPR rights (access, correction, portability, objection, restriction) are yours; email hello@smokesignal.sh and we'll handle it. There is no charge.
  • If you're unhappy with how we handle your data, you can complain to the UK Information Commissioner's Office (ico.org.uk), though we'd appreciate the chance to fix it first.

Our lawful bases

We process your account data because it is necessary to provide the service you signed up for (UK GDPR Article 6(1)(b), contract). Rate limiting, security logging, and abuse prevention rely on our legitimate interest in keeping the service safe and working (Article 6(1)(f)). Purchase records are kept because tax law obliges us to (Article 6(1)(c)). We don't process anything based on consent, because we don't do anything optional with your data.

Security

How your data is protected: your email address is encrypted at rest; sign-in and device credentials are stored only as one-way hashes (we cannot reproduce them, and neither can anyone who steals the database); webhook and invite secrets are encrypted; optional two-factor authentication is available on every account; notifications are encrypted at rest for the minutes they are queued and end-to-end in transit to each device; everything travels over TLS; and secrets are redacted from logs before they are written. No system is perfectly secure, but if we ever discover a breach affecting your data, we will tell you and the regulator as the law requires.

Children

Smoke Signal is not directed at children and you must be 16 or older to use it. We don't knowingly collect data from anyone younger; if you believe we have, email us and we will delete it.

Changes to this policy

If we change this policy, the current version will always be at smokesignal.sh/privacy with its effective date. For material changes we will notify account holders by email. A changelog lives at the bottom of this document.

Contact

Questions, requests, complaints: hello@smokesignal.sh


Changelog

  • 30 July 2026: first version.