Privacy policy

Your data, explained.

Bellwire connects project signals to your iPhone. New projects are Private by default, so notification, Inbox, and card content can travel directly from your service to your device.

Effective July 25, 2026

Scope

This policy applies to the Bellwire iOS app, bellwire.app, and Bellwire APIs. Services you connect to Bellwire may have their own privacy policies.

Data we collect

We collect the information needed to authenticate you, connect your projects, deliver notifications, and keep the service reliable.

  • Account data: the email address, name, and account identifier provided through Sign in with Apple. We do not receive your Apple password.
  • Device data: a stable installation identifier, APNs token, device name and platform, app version, notification state, recent activity time, and public device keys. Private device keys remain in the iOS Keychain.
  • Bellwire Cloud project data: when you choose hosted features, project names, logos, endpoints, schemas, Surface configuration, event payloads, sensitive-field markers, live state, and delivery history.
  • Bellwire Private control data: account, project, and device-key identifiers; encrypted Direct v2 envelopes; hashed credentials and idempotency keys; opaque short-lived wake references; priority, timestamps, and content-free delivery status. The service endpoint stays inside the encrypted envelope, while notification, Inbox, and Surface content travels directly between your service and device.
  • Subscription data: verified App Store product, transaction and original-transaction identifiers, App Store environment, subscription status, purchase, expiry, and revocation times, and the Bellwire account UUID supplied to StoreKit. Bellwire does not receive payment-card details or your Apple ID password.
  • Website data: we collect anonymous page, referrer, campaign, language, and interaction events through PostHog. PostHog stores a random browser identifier in a cookie and local storage so we can distinguish returning visitors and measure unique visits. We do not use session replay. If you joined the pre-release waitlist, we may still retain the email address, language, and website source you provided until you ask us to remove it.
  • Operational and product analytics: request timing, payload size, error class, rate-limit and delivery records, plan, product ID, Private/Hosted mode, usage percentage, project/device counts, storefront, and app version. Analytics never includes notification title, body, Event data, Private reference, or token.

How we use data

We use this data to provide and improve Bellwire, authenticate accounts and Agents, establish Direct connections, synchronize hosted project state, deliver notifications, understand anonymous website usage, respond to support, prevent abuse, and meet legal obligations.

We no longer collect waitlist signups. Any email retained from the pre-release waitlist is used only for Bellwire access and product updates, and you can ask us to remove it at any time.

Agents and project content

Every new project starts Private. Your Agent may create Direct endpoints and wake credentials, but cannot enable Hosted mode by itself. A signed-in user must approve each change to Hosted. Avoid putting passwords, private keys, payment card data, health data, or other unnecessary information in cards, events, manifests, or notifications.

In Bellwire Cloud, hosted event content is stored so Bellwire can provide history and the views you configured. Fields marked sensitive are excluded from hosted notification titles and bodies.

Bellwire Direct

For a Direct connection, the iPhone creates separate P-256 agreement and signing keys. Private keys stay in the device-only iOS Keychain. Bellwire receives the public keys and relays a connection manifest encrypted for that device. Bellwire cannot decrypt the service endpoint or connection manifest.

After decrypting the manifest, the app stores it locally, deletes the short-lived relay envelope, and requests card data directly from your HTTPS service. Requests are signed with a timestamp and one-time nonce so your service can authenticate the device and reject replay attempts.

Your connected service receives the direct request and may process the device-key identifier, connection identifier, IP address, request time, and response under its own privacy policy. Bellwire does not control that service. Private refresh depends on its availability, and cached content may remain visible on your device if a refresh fails.

For a Private notification, your service sends Bellwire only a random opaque reference and priority. Bellwire and APNs receive a content-free wake with the project ID and reference, but no project name, title, body, Event data, Logo URL, or service hostname. The iPhone signs a request to your service and rewrites the notification locally. If that request fails or times out, iOS displays the generic Bellwire alert.

Hosted mode sends configured Event, Inbox, Surface, and detailed notification content through Bellwire Cloud and Apple Push Notification service. Enabling Hosted revokes Private wake tokens; switching back to Private revokes Hosted ingest tokens and requires a ready Direct v2 device.

When data is shared

We use service providers to operate Bellwire, including Apple for sign-in, subscriptions, and push delivery; Cloudflare for the public website, authentication, D1 data storage, API, queue, generic Private wake, and encrypted Direct-envelope relay; and PostHog for limited website and product analytics. During the verified migration period, Supabase may retain historical authentication and Bellwire Cloud records until their approved deletion.

Providers receive only the data needed for their role. We may also disclose information when legally required, to protect users and the service, or as part of a business transfer with appropriate safeguards.

Retention and deletion

A Direct connection envelope is deleted immediately after the app accepts it or expires within 24 hours. A Private wake reference is cleared after terminal delivery attempts or within 24 hours; content-free Private wake and delivery metadata is retained for 7 days. Private Event and Inbox content is cached only on the iPhone for up to 30 days or 500 items per project and can be cleared manually.

Hosted Event, Inbox, and delivery history is retained for 7 days on Free and 90 days on Pro. Subscription and transaction records may remain as needed for entitlement, accounting, fraud prevention, dispute resolution, and legal compliance. Your connected service controls deletion of the Private content it holds.

Deleting a project permanently removes its Bellwire control-plane or Hosted data, tokens, and configuration from active systems. Deleting your account under Settings → Account → Delete account also clears that account's Private cache, manifests, and device private keys from the app. Canceling a subscription does not itself delete your account or content.

You can also request access, correction, export, deletion help, or waitlist removal at feedback@bellwire.app. Limited records may remain where required for security, fraud prevention, legal compliance, or backup recovery.

Security

Bellwire uses encrypted network connections, account-specific device keys, signed Direct requests, encrypted connection envelopes, scoped and revocable project credentials, account access controls, and sensitive-field filtering for hosted notification text. No online service can guarantee absolute security.

If you believe a Bellwire token or account is compromised, revoke the affected credential and contact us promptly.

International use and children

Our providers may process data outside your country. We use contractual and technical safeguards where applicable.

Bellwire is not directed to children under 13 or below the minimum digital-consent age in their location. Contact us if you believe a child provided personal data.

Changes and contact

We may update this policy as Bellwire changes. We will revise the effective date and provide additional notice when a material change requires it.

Questions or privacy requests can be sent to feedback@bellwire.app.

Email privacy supportfeedback@bellwire.app