通知君隐私政策

更新日期及生效日期:2026 年 9 月 8 日

通知君(NotifyMe,以下简称“本应用”)由通知君开发者提供。本政策适用于本应用、配套通知服务和本网站,说明我们如何处理你的信息,以及你可以作出的选择。如有隐私问题,请通过 mail@yeyeye.vip 联系我们。

本应用通过当前安装的设备身份提供通知服务,无需以姓名、手机号或电子邮箱注册账号。我们不出售个人信息,不投放广告,也不跨应用或网站跟踪你。

一、我们处理的信息

我们不主动读取通讯录、照片、麦克风录音、精确位置、健康信息或剪贴板内容用于分析。你主动复制消息或链接时,所选内容会写入系统剪贴板。请勿在通知自由文本中提交无权处理的个人信息。

二、我们如何使用信息

我们仅为提供通知投递、恢复联网后的消息补拉、消息管理、设备管理、必要的安全防滥用和你主动请求的客户支持而处理上述信息。我们不出售或出租个人信息,不将通知内容用于广告、营销画像或人工智能模型训练。

本网站的产品、隐私政策和支持页面不加载广告、第三方统计脚本或分析 Cookie。我们不使用 IDFA,不将本应用的数据与其它公司的应用或网站数据结合进行定向广告或广告效果衡量。

三、第三方服务与信息共享

Apple 推送服务(APNs):向已绑定系统提醒的设备投递通知时,我们向 Apple 提交 APNs Token、通知标题、正文摘要及必要的通知配置;通知还可能包含消息标识、角标或声音设置。接收消息时没有 Token 绑定的消息仅供 App 内读取,不安排 APNs 投递。Apple 对相关信息的处理适用其隐私政策。已经提交给 Apple 的在途通知可能仍会到达,关闭通知、删除消息、重置链接或删除设备无法保证撤回。

基础设施与邮件服务:我们使用云服务器运行通知服务,并使用阿里云邮件推送(Direct Mail)发送你通过 mail 参数明确指定的通知邮件副本;该服务会处理收件邮箱、通知标题、完整正文及必要的投递元数据。我们也使用邮件服务接收你主动发送的支持请求。服务提供方仅为基础设施、邮件传输及安全维护处理必要信息。我们要求接触用户信息的受托服务提供方按照本政策及适用法律提供同等保护,限制处理目的和访问范围,不得将信息用于独立营销。

除提供上述服务、获得你的单独授权或履行适用法律义务外,我们不向第三方披露你的个人信息。依法必须披露时,仅提供必要范围内的信息。

Apple、你自行选择的自动化平台或邮箱服务可能在你所在国家或地区之外处理信息。请同时阅读相应服务的隐私说明;涉及依法需要单独同意或其它保护措施的处理时,我们将履行相应义务。

四、信息保存与删除

五、你的选择与隐私权利

提出请求时不要发送密码、完整管理凭证或 APNs Token。若本地凭证丢失,新设备身份不能证明旧数据归属,也不能保证撤销旧 Code;你仍可联系支持进行可行范围内的核验。我们不会要求你提供与核验无关的信息。

六、信息安全与敏感内容

我们通过 HTTPS 传输、访问控制和凭证哈希等措施保护信息。通知不是端到端加密通信,本服务和 APNs 需要处理通知内容;任何网络服务都无法保证绝对安全。

专属链接代表向设备发送通知的权限,持有链接的人可能向你发送通知,请勿公开分享;泄露后请及时重置。通知可能显示在锁屏或通知中心,请勿发送密码、验证码、密钥、健康或其它敏感、机密信息。

七、未成年人保护

本应用面向个人开发者及自动化工具使用者,不专门面向儿童,也不主动收集儿童个人信息。监护人发现儿童向我们提供个人信息时,可通过隐私邮箱联系,我们会在核验后采取适当删除或保护措施。

八、政策更新与联系方式

我们会在信息处理方式发生变化时更新本页及生效日期。重大变化通过 App 或本页显著提示,需要时另行征得同意;不会仅以政策更新将既有信息用于新的无关目的。

隐私与支持邮箱:mail@yeyeye.vip。本政策和支持页面无需登录、通知授权或提供 Push Code 即可访问。

Privacy Policy — English

Updated and effective September 8, 2026.

This policy covers NotifyMe (通知君), its notification service and this website, provided by the NotifyMe developer. Contact mail@yeyeye.vip for privacy questions. The service uses an installation identity and does not require registration with a name, phone number or email account.

1. Information and purposes

We process an app-generated installation ID, a service-generated Push Code, a management credential hash and registration/update/sync state. After you enable system alerts and the app obtains an APNs token from Apple, the app also binds that token to the current installation for system notification delivery. Device registration and fetching messages in the app do not require a token. These data support identification, authorization, message sync and delivery, are linked to the installation and are not used for advertising identification.

You or scripts, CI/CD and automation tools holding your link submit notification titles, bodies, tags and reminder settings. An optional mail parameter may provide one recipient address for a copy of the same notification. We process message identifiers, timestamps and delivery/read/deletion state for sending, sync, display and management. Sender-provided request identifiers may be used for deduplication. Content and the optional address are linked to the receiving device identity.

If you contact support, we receive your email address, message and chosen attachments solely to respond, troubleshoot and handle privacy requests. The app does not automatically attach full codes, tokens, credentials or notification bodies; please do not send them. Local copies, preferences and credentials stay in app storage or Keychain. Credentials are sent over HTTPS for registration and authentication; the server persists only a hash, not the plaintext credential.

We do not actively read contacts, photos, microphone recordings, precise location, health information or clipboard content for analytics. Copy actions you initiate write selected content to the clipboard. Do not submit personal information you have no authority to process.

2. Use and tracking

We use information only for notification delivery, sync after reconnecting, message/device management, necessary security and support you request. We do not sell or rent personal information, advertise, create marketing profiles, or train AI models with notification content. These public pages use no advertising, third-party analytics scripts or analytics cookies. We do not use IDFA or combine app data with other companies' app or website data for targeted advertising or ad measurement.

3. Service providers and sharing

When sending system notifications to a device with an APNs binding, Apple APNs receives the token, title, body preview and necessary notification settings; payloads may also include message identifiers, badge or sound settings. Messages received without a token binding are available in the app without scheduling APNs delivery. See Apple's Privacy Policy. In-flight notifications may still arrive after permission is disabled, messages or the device are deleted, or the link is revoked, and cannot be guaranteed to be recalled.

Cloud hosting and email providers process necessary information for infrastructure, mail delivery and security. We use Alibaba Cloud Direct Mail to send a notification copy only when a mail parameter is supplied; it processes the recipient address, title, full body and necessary delivery metadata. We require entrusted providers with access to user information to offer equivalent protection under this policy and applicable law, limit purposes and access, and refrain from independent marketing. Apart from these services, your separate authorization or legal obligations, we do not disclose your personal information to third parties. Legally required disclosure is limited to necessity.

Apple, your chosen automation platforms or email providers may process information outside your country or region; also review their privacy notices. We will meet applicable requirements for separate consent or other safeguards where required.

4. Retention and deletion

Device identity remains for continued service until its deletion is completed. Updating or invalidating an APNs token does not delete the entire identity. Normal server message reading and delivery are available for 3 days from creation. An optional recipient address and its mail claim/completion/result state are stored with the message and removed in the same cleanup window. Mail is attempted once; an ambiguous SMTP result is not retried automatically, and a copy already submitted to the provider cannot be recalled. Deleted message content and sync state may remain briefly to prevent deleted messages from reappearing and to support undo. Expired messages and deletion records are removed by a task running every 10 minutes; failures or downtime may delay physical removal until recovery. This is not a promise that every physical copy is deleted at exactly 72 hours.

Local copies remain until you delete them, clear them or remove app data. Uninstalling normally removes app storage, but Keychain or system backups may retain information according to system behavior and device settings. Uninstalling does not delete server data.

Message-associated caller IP addresses and request headers use the same 3-day business-access window as the message and are deleted by the same scheduled cleanup; failures, downtime and backups have the same limitations described above for server messages. Separate rate-limit counters expire after a 60-second window. Redacted diagnostic logs are grouped by date and deleted by scheduled retention controls within a maximum of 30 days; they may be removed sooner when no longer needed. Diagnostics are not used for unrelated purposes.

Support correspondence is retained while needed to respond, verify and execute requests and resolve necessary disputes. You may request email deletion; we explain any legally required retention. Necessary recovery backups are access-restricted, not used for routine queries, marketing or notification replay, and cleaned up when no longer required. Deletion requests also examine relevant copies; deletion in the business database does not mean simultaneous removal of all backup or third-party copies.

5. Choices and privacy rights

Use iPhone Settings → Notifications → NotifyMe to disable notifications or adjust previews, sound and Lock Screen display. Successful device registration provides your private link without notification permission or an APNs token. With system alerts off, open the app, return to the foreground, enter Messages or refresh manually to retrieve messages from the last three days; automatic background retrieval and real-time alerts are not promised. If you later enable notifications and bind a token successfully, newly received messages can also trigger APNs alerts. Messages received without a binding are not pushed later. Permission changes do not replace your installation identity or private link. Disabling permission does not stop external scripts or delete cloud data.

You can delete or clear messages in the app. Deleted message content and sync records may remain for sync or undo until cleanup; undo does not restart stopped reminders. Clearing messages does not delete device identity or disable the link. Resetting the Push Code prevents new pushes to the old link but keeps existing messages; update your scripts.

For complete deletion, open Settings → Reconfigure Push in the app and confirm. This deletes the current device identity and associated cloud messages and reminders, and clears the local identity and messages. Once the operation succeeds, the previous push link stops working immediately. Notifications already submitted to Apple may still arrive. Rely on the app's success result; uninstalling, reinstalling or a failed network request is not confirmation of deletion.

For access, correction, a copy, or help with a lost credential or failed deletion, use Contact Support in the app or email mail@yeyeye.vip. We verify ownership only as necessary and explain the outcome or inability to fulfill a request. Normal complete deletion in the app does not require contacting support first.

You may withdraw notification permission, stop scripts, request deletion, or exercise applicable rights to restriction or complaint. Withdrawal does not undo completed processing; in-flight notifications, information needed for privacy requests and legally required retention remain subject to this policy. Never send passwords, full credentials or APNs tokens. After credential loss, a new identity cannot establish ownership of old data or guarantee old-code revocation; contact us for feasible verification. We will not request unrelated information.

6. Security, children and updates

We use HTTPS, access controls and credential hashes. Notifications are not end-to-end encrypted: the service and APNs process their content, and no network service can guarantee absolute security. Anyone holding your private link may send notifications. Keep it private and reset it if exposed. Notifications may appear on the Lock Screen or in Notification Center; do not send passwords, verification codes, keys, health information or other sensitive or confidential content.

The app is for developers and automation users, is not directed at children and does not knowingly seek children's personal information. Guardians may contact us for appropriate deletion or protection after verification.

We update this policy and its effective date when practices change, prominently notify material changes in the app or on this page and obtain separate consent when required. A policy update alone does not authorize unrelated new uses of existing information. Contact mail@yeyeye.vip. This policy and the support page are public without login, notification permission or a Push Code.