Handler
Reliable Push NotificationsEmergencyGlobal Mute & Alert SnoozeInboxAlert details with historyQuiet HoursLive updatesConfigurable sounds
MissionSelf-hostedSoonOpen BetaContactDocs
LoginCreate free account

Legal

Privacy Policy

Document version: 2026-07-31.

Last updated: 31 July 2026
Document version: 2026-07-31

This Privacy Policy explains how "WeAstronauts Software" Konrad Broda ("Handler", "we", "us", "our") collects, uses, stores, and shares personal data when you use the Handler notification service, including our websites (such as gethandler.app), APIs, web panel, and mobile applications for iOS and Android (collectively, the "Service" or the "App").

This is a single combined policy for the App, API, and websites. It is intended to satisfy disclosure expectations of the Apple App Store and Google Play as well as GDPR.

Controller / developer identity

Controller / developer"WeAstronauts Software" Konrad Broda
Addressul. Tadeusza Pawlikowskiego 7/8, 31-127 Kraków, Poland
NIP/VATPL5772001628
Product nameHandler
Contact (privacy & support)[email protected]

For GDPR purposes, we are the controller of personal data processed to operate your Handler account and deliver the Service. The same legal entity is the developer named on App Store / Google Play listings.

Payments: paid plans are sold through Paddle as Merchant of Record. For payment transactions, Paddle acts as an independent controller of buyer payment data under its own Privacy Policy. We receive from Paddle the fulfilment data needed to activate and support your subscription (for example email, country, subscription status), not your full card details.


Personal data we process

Account and registration

  • Email address (login identifier)
  • Password (stored only as a secure hash; we never store plaintext passwords)
  • Account identifiers / tokens we issue
  • Profile or settings you choose (for example notification preferences, quiet-hours schedules, critical-alert / time-sensitive delivery preferences)

Devices and clients

  • Device registration data needed for push delivery (platform, app version, push token / provider device id)
  • Approximate device metadata useful for support and abuse prevention (for example OS family, device model class)

We do not require advertising identifiers (IDFA / GAID) for core Service operation. We do not link persistent hardware identifiers (such as IMEI) to your account for advertising or tracking.

Messages and notifications

  • Message / alert content, titles, priorities, timestamps, acknowledgement state, and related metadata submitted via the API or integrations
  • Application / channel / source identifiers associated with messages

Message content is created by you or by third-party systems you connect (for example monitoring tools). We process it as needed to store, deliver, display, and delete messages according to the Service. We do not control or endorse third-party message content.

Technical and security logs

  • IP addresses, request timestamps, user-agent / client metadata, and similar connection logs
  • Error and operational logs for debugging, security, and abuse prevention

Billing (paid plans)

  • Subscription plan, status, renewal period
  • Paddle customer / subscription identifiers
  • Limited billing contact details Paddle shares for fulfilment and support

We do not store full payment card numbers. Card and tax invoicing data for purchases are handled by Paddle.

Communications

  • Content of emails or other messages you send to us (for example support requests)

Mobile applications (iOS and Android)

This section is written for App Store and Google Play reviewers and users.

What the App does with data

The Handler mobile App is a client for the Service. It:

  • signs you in to your Handler account;
  • registers the device for push notifications;
  • receives and displays alerts;
  • syncs inbox / active-alert state and acknowledgement state with our servers;
  • stores limited data locally so the App works offline / between sessions.

Data stored on the device

Depending on platform and settings, the App may store locally:

  • session / auth tokens;
  • cached messages and related UI state;
  • notification, sound, and quiet-hours preferences;
  • push registration state.

Local data remains on your device until you clear app data, uninstall the App, or we delete associated server-side records after account deletion.

Permissions

We request only permissions needed for core functionality:

Permission / capabilityWhy
Network accessTalk to Handler API; sync messages
Push notifications (APNs / FCM)Deliver alerts when the App is backgrounded or closed
Critical / time-sensitive alerts (where you enable them)Deliver high-priority operational alerts according to your settings

We do not require access to contacts, photos, microphone, camera, precise location, SMS, call logs, or your inventory of other installed apps for core Handler functionality.

Push permission is requested in context of enabling alerts. You can revoke notification permission in system settings; the App will then be unable to show pushes until you re-enable it.

Quiet hours: when enabled for a channel, scheduled quiet windows typically silence notification sounds while alerts continue to be delivered and stored (for example in Inbox). You may configure priority overrides (for example high or emergency) so selected alerts keep sound during quiet windows.

SDKs and third parties in the App

  • Apple Push Notification service (APNs): iOS delivery
  • Firebase Cloud Messaging (FCM): Android delivery (when the Play/build variant uses FCM)
  • Expo Push Service (Expo / 650 Industries): push relay hop used for some Android / React Native delivery paths while that hop remains enabled
  • Apple and Google distribution infrastructure required to build and ship the App
  • Sentry (Functional Software, Inc.): crash / error and performance diagnostics in App and website builds where enabled

Shipped native clients are not described as an Expo-runtime product; Expo appears here only where it participates in push transport.

We do not include third-party advertising SDKs, ad networks, or cross-app tracking SDKs in the Handler App. We do not sell personal data from the App.

Message payloads and device push tokens are transmitted through Apple, Google, and (where the Expo hop is used) Expo push infrastructure as required to deliver notifications. Their handling of that transport is governed by their own policies; we require and expect subprocessors we engage for the Service to protect user data consistent with this Policy and applicable law (see “Third-party protection”).

Analytics and tracking

We do not use the App for third-party advertising measurement. We do not track users across third-party apps or websites for advertising. Our sites/apps are not designed around responding to browser Do Not Track signals for ad tracking because we do not engage in that type of tracking.

We may use error and performance monitoring (currently Sentry) to diagnose crashes, failed requests, and reliability issues. That tooling may process technical data such as IP address, device/browser metadata, URLs, and stack traces. It is not used for advertising measurement.


Legal bases (GDPR)

If you are in the EEA, UK, or Switzerland, we rely on:

BasisExamples
Contract (Art. 6(1)(b))Creating and securing your account; storing and delivering messages; providing paid features you subscribed to
Legitimate interests (Art. 6(1)(f))Security, fraud/abuse prevention, service reliability, product improvement, aggregated operational metrics that do not override your rights
Legal obligation (Art. 6(1)(c))Tax, accounting, or regulatory retention where required
Consent (Art. 6(1)(a))Optional marketing emails, where we ask for consent (including via Paddle checkout marketing consent, if enabled); certain optional OS permissions (for example notification permission)

You may withdraw consent at any time (for example disable notifications in OS settings, unsubscribe from marketing, or delete your account) without affecting processing already performed lawfully.


How we use personal data

We use personal data to:

  • provide, operate, maintain, and secure the Service and App;
  • deliver push notifications and in-app message history;
  • authenticate users and devices; enforce rate and plan limits;
  • process subscriptions in cooperation with Paddle;
  • send transactional emails (account, security, billing-related notices);
  • diagnose outages and improve reliability;
  • comply with law and enforce our Terms of Service.

We do not sell personal data. We do not use personal data for third-party advertising networks.


Data location

Default: Service data is hosted on Amazon Web Services (AWS) in the European Union, region eu-central-1 (Frankfurt).

Enterprise: a written Enterprise agreement may provide for data isolation and/or a different agreed storage location. Unless such an agreement applies, the EU default above governs.

Some subprocessors may process limited data outside the EU when necessary to provide their part of the Service (for example Apple or Google push infrastructure, or Paddle payment processing). Where required, international transfers rely on appropriate safeguards such as Standard Contractual Clauses and/or adequacy decisions.


Subprocessors and recipients

We share personal data only as needed to run the Service, with providers such as:

RecipientRole
Amazon Web Services, Inc. / AWS EMEACloud hosting, database, storage, logs (EU region)
Amazon Simple Email Service (SES)Transactional email (account verification, password reset, and service notices)
Apple Inc.Push notification transport (APNs) for iOS devices
Google LLCPush notification transport (FCM) for Android devices (when enabled)
Expo / 650 Industries, Inc.Expo Push Service (push relay for devices still using Expo push tokens)
Sentry (Functional Software, Inc.)Error and performance monitoring (App, website, and API where enabled)
Paddle (Paddle.com Market Limited / relevant Paddle entities)Merchant of Record (payments, taxes, subscription billing)
Cloudflare, Inc.DNS, CDN, related edge / DDoS protection, and bot challenges (for example Turnstile on login/register) when enabled for our domains

We may also disclose data if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset transfer (with notice where required).

Third-party protection

Any third party with whom we share user data to operate the Service (including subprocessors, parent/related entities if any, and required platform partners such as Apple/Google for push) is expected to provide the same or equal protection of user data as described in this Policy and required by applicable App Store / Play policies and data-protection law, limited to the purposes disclosed here.


Retention

DataTypical retention
Account profileFor the life of the account
Messages (visibility / archive entitlement)See table below. Older history may be hidden, clamped, or unavailable in the product
Messages (storage)Message records may remain on our servers beyond the archive entitlement (hard retention) until account deletion, a future pruning job, or another deletion path we document; storage duration is not identical to the archive window
Device / push tokensWhile the device remains registered, or until the account is deleted
Security / access logsTypically up to about 90 days, depending on log type and infrastructure settings, unless needed longer for an active security investigation
Billing fulfilment recordsAs needed for the subscription lifecycle and applicable legal retention
After account deletionActive personal data removed within 30 days; backups expire on the normal backup cycle

Message archive by plan

Plan entitlements include a message archive window: how long message history is kept available to you in the product under your plan (visibility entitlement). That window is not a promise that underlying storage is erased the day the window ends. Windows may change; the live pricing page and product billing docs are authoritative. In the product UI, history may be pruned, limited, clamped, or not yet fully aligned with the entitlement window. Older items can become unavailable when they fall outside the applicable limit even if storage has not yet been purged.

PlanMessage archive entitlement
Individual Free7 days
Individual Plus1 year
Individual Pro2 years
Team Business3 years
Team EnterpriseAs specified in the contract (often 3 years or longer)

We may update plan windows; material changes will appear on the pricing page and in this Policy. Downgrade may shorten the applicable archive as described in the Terms of Service.


Account deletion and data deletion

To delete your Handler account and associated personal data, email [email protected] from the address on your account with subject Delete my Handler account.

Upon a verified deletion request we will delete your account and associated personal data from active systems within thirty (30) days. Freezing an account is not a substitute for deletion. Limited records may be retained where legally required (for example tax/billing artefacts held by or via Paddle, or security logs for an ongoing investigation).

You may also revoke optional consents without deleting the account (for example OS notification permission, marketing unsubscribe). We may add in-product account deletion later; until then, email is the supported path.


Cookies and similar technologies

Our marketing or documentation sites may use strictly necessary cookies (for example session or security). We do not use third-party advertising trackers as part of the core Service.

Logged-in product sessions may use cookies or local storage to keep you signed in. You can clear them via your browser or by signing out.


Your rights

Depending on your location, you may have the right to:

  • access your personal data;
  • rectify inaccurate data;
  • erase data (“right to be forgotten”);
  • restrict or object to certain processing;
  • data portability;
  • withdraw consent where processing is consent-based;
  • lodge a complaint with a supervisory authority.

In Poland, the supervisory authority is the President of the Personal Data Protection Office (UODO) (uodo.gov.pl).

How to exercise rights: email [email protected]. We will respond within 30 days, or sooner if required by law.


Children

The Service is not directed to children under 16. We do not knowingly collect personal data from children under 16. If we learn that such an account exists, we will delete it.


Security

We apply technical and organisational measures appropriate to the risk, including TLS/HTTPS in transit, access controls, hashed passwords, and infrastructure isolation on AWS. No method of transmission or storage is 100% secure; you are responsible for protecting your credentials and API tokens.


Breach notification

If a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify affected users and/or the competent authority as required by GDPR and applicable law.


Changes

We may update this Privacy Policy by posting a new version on this page and changing the “Last updated” / document version date. Where a change materially affects how we process personal data for existing users, we will provide additional notice (for example email or in-product) where appropriate. Updates that primarily document the Service for new users or clarify existing practices may be published on this page without a separate notice.


Contact

Privacy questions: [email protected]

"WeAstronauts Software" Konrad Broda
ul. Tadeusza Pawlikowskiego 7/8
31-127 Kraków, Poland
NIP/VAT: PL5772001628
Product: Handler

HandlerJoin Discord

Email

[email protected]

Apps

Product

  • Features
  • Open Beta
  • Mission
  • Contact

Resources

  • Documentation
  • Create free account

Legal

  • Privacy Policy
  • Terms of Service

© 2026 Handler. From DevOps for DevOps.