Privacy Policy.
What we collect, why we collect it, who else sees it, and how to make us delete it. Written to be read, not to be survived.
Effective 10 October 2026. These terms take effect when OpenPush opens to the public. They are published now so you can read them before deciding whether to sign up, and so any change between now and then is visible rather than sprung on you. If you need contractual certainty sooner, email legal@openpush.ai and we will deal with you directly.
The short version
Right now openpush.ai is a marketing site with one form on it. If you join the early-access waitlist we keep what you typed, plus enough context to know where you came from and to stop the form being abused. We do not set cookies, we do not run analytics or advertising trackers, and we do not sell anything to anyone. You can be removed at any time by clicking unsubscribe in any email we send you, or by emailing us.
The OpenPush product is a separate matter, and it does collect more — including, where a developer switches them on for their own app, an advertising identifier, precise location and an email address. Those switches are off by default. There is a section on this below, before you get to the boring parts.
When the OpenPush platform itself launches, it will process data on behalf of the developers who use it. That relationship is a different one, and it is governed by the Data Processing Addendum rather than by this policy. The distinction matters and we come back to it below.
Who we are
OpenPush is operated by SuperTuned Inc, 1 Sansome Street, San Francisco, CA 94104, USA. For anything in this policy you can reach us at privacy@openpush.ai. We do not currently have an appointed representative in the EU or the UK; where one is required, that appointment is still outstanding and we would rather say so than imply otherwise.
What we collect when you join the waitlist
This is the complete list — it is generated from the same schema the form writes to, so it cannot quietly drift out of date.
- What you type into the form. Email address, and optionally your name, your studio or company, and your app or store URL. Optionally which push provider you use today, roughly how many monthly active users you have, and which platforms you need.
- How you got here. UTM campaign parameters if the link you followed carried them, the referring site, and the page you were on when you submitted the form.
- Technical context of the request. Your browser's user-agent string, the country our edge network reports, and a one-way salted SHA-256 hash of your IP address. We do not store raw IP addresses at any point.
- Our own record-keeping. When you signed up, how many times you have submitted the form, whether we have sent you the confirmation email, and an opaque token that powers your unsubscribe link.
Every field except your email address is optional. The qualification questions exist so that when we get in touch we already know whether you need a OneSignal migration and which platforms matter to you — not so that we can build a profile of you.
Why we hash your IP address
The signup endpoint is public, so it needs some way to recognise a flood of automated submissions. Storing raw IP addresses would do that job and would also create a record of where you were sitting when you filled in a form. Instead we store a one-way SHA-256 hash of the address combined with a secret salt. It is enough to spot abuse, and it cannot be reversed back into an address.
Why we are allowed to hold it
You gave it to us: you filled in a form asking to be told when early access opens, so we are processing your details to do exactly the thing you asked for. Under the GDPR that is consent for the marketing email and legitimate interests for the abuse-prevention data. Withdrawing consent is a single click and does not cost you anything.
If we ever contact developers who did not fill in the form — for example from publicly listed contact addresses — that is a different lawful basis with different obligations, including telling you where we got your address. Any such outreach will say so plainly in the message itself.
What we do with it
- Email you when your onboarding slot opens, and about the launch. That is the point of the list.
- Prioritise you for hands-on migration help if you told us you are on OneSignal.
- Understand, in aggregate, which pages and campaigns bring developers in — so we know what to write more of.
We do not sell your data, rent it, or hand it to advertisers. We do not use it to build behavioural profiles or to target you elsewhere on the internet.
Use across our other products
SuperTuned Inc builds more than OpenPush. Where account and usage data from OpenPush is used to build or improve features across those products, we will say so here specifically — which data, for what purpose, and on what lawful basis — before it happens, and we will minimise and aggregate it wherever the purpose allows. This section is deliberately not a blanket permission slip, and it will never be read as covering our customers' own subscribers' personal data: that data belongs to the customer, and moving it between products would need their instruction, not ours.
What the OpenPush product collects about your users
The section above is about you, the person filling in the waitlist form. This section is about the product, because you should know before you sign up rather than after.
OpenPush can process mobile device and account identifiers on behalf of the developers who use it. Three categories are sensitive enough to name individually: an advertising identifier, precise location, and an email address. Each is a per-app switch, each is off by default, and each stays off until a developer deliberately turns it on for their own app. Turning one off again erases what was collected under it — it is a switch, not a pause.
IP addresses are different: we store them by default as part of ordinary request handling, abuse prevention and debugging. Whether they are kept in full, truncated, or not at all is controlled by a single service setting (OP_IP_STORAGE), and we will say here which mode is in force before we ever change it.
Where OpenPush processes any of this on behalf of a developer, they are the controller and we are their processor under the DPA.
Cookies and tracking
This site sets no cookies. There is no analytics script, no advertising pixel, no session storage, and no third-party embed on any page. Fonts are served from our own origin rather than a font CDN, so loading a page here does not tell anyone else that you visited. If that ever changes, this page changes first and a consent banner appears where the law requires one. See the cookie notice for the current state.
Who else touches your data
A small number of vendors process waitlist data on our behalf and only on our instructions. They are named individually, with what each one gets, on the subprocessors page. Beyond that, we disclose data only where we are legally compelled to, and we will tell you if that happens unless we are prohibited from doing so.
Those vendors are based in the United States. If you are in the EU or the UK, that is an international transfer, and the safeguards for it — standard contractual clauses and the UK addendum — are being finalised before the effective date above.
How long we keep it
Waitlist records stay until you unsubscribe or ask for deletion, or until the early-access programme has clearly ended and the list has served its purpose. Unsubscribing marks your record so that no campaign can reach you again; if you want the record gone entirely rather than suppressed, ask and we will delete it.
Your rights
Depending on where you live you can ask us for a copy of what we hold, correct it, delete it, restrict what we do with it, object to it, or take it elsewhere in a portable format. You can also complain to your local data protection authority. We do not charge for any of this and we do not require you to explain yourself.
Email privacy@openpush.ai and we will come back to you within 30 days. For the fastest route off the list, use the unsubscribe link at the bottom of any email we have sent you — it works in one click and does not ask you to log in.
Children
OpenPush is a tool for developers and is not directed at children. We do not knowingly collect data from anyone under 16 through this site. Games and apps built on OpenPush may well reach children, and the obligations that creates fall on the developer as the controller of their own users' data — the DPA is where that is dealt with.
Changes
When this policy changes materially we will update the date at the top and, if you are on the waitlist, tell you by email rather than hoping you re-read the page.
SuperTuned Inc
1 Sansome Street, San Francisco, CA 94104, USA
Privacy: privacy@openpush.ai · Legal: legal@openpush.ai · Security: security@openpush.ai