Legal

Privacy Policy

Last updated: 27 July 2026

Overview

There are two separate places your data can live, and the difference matters:

  • On our servers we hold your email address, a licence token, and a billing record. That is all.
  • On your own device only we hold everything else: the searches you monitor, your login sessions, and the personal details Auto-Reply uses to complete contact forms. This data is never sent to us.

We do not sell your data, we do not run advertising or marketing analytics, and we do not build profiles of you. We do use error monitoring on our website, which is described in section 5.

1. Data We Hold On Our Servers

When you purchase Notifio, we store the following in our database:

  • Email address — provided by you at checkout. Used to send your activation token and the alert and reply report emails the desktop app requests.
  • Licence token — a randomly generated code tied to your email. Used to verify your copy of the app is activated.
  • Stripe identifiers — a reference to your payment, and, if you buy the Auto-Reply upgrade, a reference to that payment and the date you bought it. We do not store card numbers, bank details, or any other payment data.

We do not store your name, postal address, phone number, date of birth, income, or any of the other details Auto-Reply uses. Those never reach our servers.

2. Data Stored Only On Your Device

The Notifio desktop app runs on your machine. The following is stored in your local application data directory and is never transmitted to us:

  • The search URLs you add to monitor
  • Browser session cookies for sites you log into, and the browser profile those sessions belong to
  • Snapshots of listing results, used to detect new listings
  • Activity log lines
  • Your reply profile — the details you enter for Auto-Reply to submit, which may include your name, email, phone number, date of birth, nationality, occupation, employer, income, household size, and any custom fields you add yourself
  • The message you send to landlords
  • The reply flows you record for each website, including the form fields involved. Recorded values are masked, so these files do not contain your personal details
  • A short record of each reply attempt — which listing, which site and the outcome. This is kept only so Auto-Reply never messages the same listing twice and stays within its sending limits. No screenshots are taken and no message text is stored

Your reply profile is encrypted at rest using your operating system's own credential store (Keychain on macOS, DPAPI on Windows), so it is not readable as plain text on disk.

The only data the desktop app sends to our server is your email address and licence token, to validate your licence and to request alert and report emails.

3. Data Sent To Rental Websites By Auto-Reply

This is the point of the Auto-Reply feature, so it is worth stating plainly. When Auto-Reply submits a contact form, the details from your profile and your message text are sent directly from your computer to the rental website you chose to monitor. Depending on what that website asks for, this can include your name, email address, phone number, age, occupation, income, and household details.

We do not receive, see, or store any of that. Once the data reaches the website, that website is responsible for it and its own privacy policy applies. You decide which websites Auto-Reply is enabled for, and it is off by default.

4. Cookies

Our website does not set advertising or analytics cookies. We do not use tracking pixels, and we do not use Google Analytics, Meta Pixel, or any similar advertising or audience-measurement tool.

When you click through to Stripe's hosted checkout page (stripe.com), Stripe may set their own cookies on that domain. This is outside our control and governed by Stripe's Privacy Policy. We do not have access to those cookies.

5. Third-Party Services

We use the following services to operate Notifio:

  • Stripe(stripe.com) — processes payments for the licence and the Auto-Reply upgrade. Your card details are entered on Stripe's servers and never pass through ours. Stripe is PCI-DSS compliant. See Stripe's Privacy Policy.
  • Resend (resend.com) — delivers transactional email: your activation token, listing alerts, and Auto-Reply reports. Your email address is passed to Resend solely for this purpose. See Resend's Privacy Policy.
  • Vercel (vercel.com) — hosts our website and API. Vercel processes request metadata, including IP addresses, in order to serve requests.
  • Sentry (sentry.io) — error and performance monitoring for our website. When a page you visit throws an error, or is included in a small sample of traced page loads, Sentry receives technical diagnostic data which can include your IP address, browser, and the page URL. It is used only to find and fix faults, never for marketing or profiling.
  • Upstash (upstash.com) — Redis-backed rate limiting on our API endpoints. Your IP address is used as a short-lived counter key and expires automatically within seconds to minutes. No request history is retained.
  • Amazon Web Services — stores and serves the application download files.

Some of these providers operate outside the United Kingdom. Where personal data is transferred internationally, we rely on the transfer safeguards each provider has in place, such as standard contractual clauses and the UK international data transfer addendum.

6. Data Retention

We retain your email address, licence token, and billing record for as long as your licence is active, and afterwards only as long as needed for tax and accounting obligations. If you ask us to delete your data, we will remove your record from our database. Note that this deactivates your licence.

Rate-limiting counters expire automatically within seconds to minutes. Error monitoring data is retained according to Sentry's retention settings for our project and is deleted automatically after that period.

Data held on your own device stays there until you delete it. You can remove all of it by deleting the Notifio application data folder:

  • Windows: %APPDATA%\Notifio
  • macOS: ~/Library/Application Support/Notifio

Uninstalling the app does not by itself remove this folder.

7. Your Rights

Under UK GDPR and the Data Protection Act 2018, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Request a copy of your data in a portable format
  • Object to processing of your data
  • Complain to the Information Commissioner's Office

To exercise any of these rights, email us at support@notifio.app. We will respond within 30 days.

For data stored only on your device, we have no access to it and cannot retrieve or delete it for you. See section 6 for how to remove it yourself.

8. Security

Our website and API are served over HTTPS. We apply rate limiting to all sensitive API endpoints to prevent abuse.

Your licence token is randomly generated and stored in our database in a readable form, so that we can resend it to you if you lose it. Treat it like a password: anyone who has both your email address and your token could activate a copy of the app in your name. It grants no access to your device, your profile, or your reply history.

Your reply profile on your own device is encrypted using your operating system's credential store, as described in section 2.

No system is perfectly secure. We recommend keeping your activation token confidential and not sharing it with others.

9. Changes to This Policy

We may update this policy if our practices change. We will update the "Last updated" date at the top. Continued use of Notifio after changes are posted constitutes acceptance.

10. Who We Are and How to Contact Us

The data controller for this website and service is Notifio.

Questions about this policy? Email us at support@notifio.app.