push.tt / Legal

Privacy

A plain description of what push.tt stores, what it is technically unable to read, and who else is involved. Where a limitation exists it is on this page rather than left for you to discover.

What we cannot read

Voice, video and messages on organisation and private channels are end-to-end encrypted. They are sealed on the sending device to each recipient device's public key, and the server relays bytes it has no key for. This is a property of the design, not a policy we promise to keep: there is nothing for us to hand over, because we never hold it.

Public channels are the exception, and the app labels them. Anyone may join one, so an end-to-end guarantee would be theatre. They get TLS in transit and encryption at rest instead.

There is no forward secrecy yet. A stolen device key could expose that device's past messages. A ratchet is planned; until it ships, we would rather write this down than let a padlock icon imply more than it delivers.

What we do store

  • Your account: username, display name, the organisation you belong to, and your devices' public keys.
  • Message and recording metadata — who spoke on which channel and when — because delivery, history and billing need it.
  • Recordings and attachments, as ciphertext. The storage provider holds bytes it cannot open; the key that opens them lives in our database, not with the files.
  • An append-only audit trail of administrative actions, including every time a staff member opens an organisation's message archive.

Things that are off unless your organisation turns them on

Each of these is refused by the server until an administrator acknowledges, in writing, what it changes. That refusal is enforced server-side, not by the app being polite.

  • Retention — keeping organisation-channel history where administrators can read it.
  • Keeping deleted messages.
  • AI transcription. Speech-to-text runs on the phone that recorded it; the transcript is encrypted before it leaves.
  • Device management — kiosk mode and location reporting on company-owned handsets.
  • Navigation — the handset tells a routing provider where it is and where it is going.
  • Bridging a channel to a radio — after which anyone with a scanner in range can hear it. No amount of encryption changes that, which is why the warning is worded the way it is.

When someone joins an organisation, they are shown which of these are actually switched on for it — not a list of what could be.

Where your data physically is

push.tt runs cells in Dallas, Mexico City, Toronto and Nuremberg, all served by one primary database in Dallas, United States. Your handset connects to the nearest cell; the data lives in the US. If your organisation needs data resident in a specific jurisdiction, ask us — that is a deployment question with a real answer, not a checkbox.

Third parties

  • Object storage holds recordings and attachments as ciphertext it cannot decrypt.
  • Map tiles and terrain come from OpenFreeMap and OpenStreetMap data. Loading a map tells that provider roughly where you are looking.
  • Routing, when navigation is enabled, sends the handset's position and destination to a Valhalla endpoint.
  • Telephony, for World Phone numbers and SMS, goes through Twilio and is subject to their terms and to lawful interception on the public telephone network.
  • Payments go through Stripe. We never see a card number.
  • Push wake-ups may use Firebase where it is available. The payload is deliberately content-free — it says "something happened", never what.

Crash reports

Crashes are recorded with a fingerprint, capped per organisation, and visible only to that organisation and to push.tt staff. They carry no message content.

Reporting a problem from the app

The in-app report attaches your account, organisation, app version and handset model, and says so on the screen before you send it. It carries no message content, location or recordings.

Deleting your account

You can delete your account yourself, from Settings → Your account → Delete account in the app, or ask us to do it if you cannot reach the app. That removes your profile, devices, keys, sessions, sent messages and direct conversations.

Two things deliberately survive, and both are on the delete your account page in full: a channel you own that other people are still in is handed to another member rather than destroyed, and if you ever bought anything the purchase record is kept — required of us, and our own rule is that nothing deletes a record of money moving. In that case your account row remains as a tombstone with no name, no address, no password and no key.

Asking us about your data

Write to us through the contact page. Note that for anything end-to-end encrypted the honest answer is that we cannot produce it — your organisation's administrators can, from their own key, if retention is on.

This page describes how the product actually behaves today. It is written to be checkable against the software rather than to be broad enough to cover anything. If you are relying on it for a procurement or compliance review, talk to us so we can answer your specific question directly.