Last updated: 10 September 2026

Summary

webhook-notify receives HTTP requests at a URL you control and shows them as macOS notifications. To do that we store each received request for up to 14 days, then delete it.

  • We do not use any analytics, tracking, or advertising SDK. The app contains none.
  • We do not sell or share personal information, and never have.
  • We do not use your data to train machine learning models.
  • The only time your webhook content leaves our systems is if you press “Suggest with AI”.

The rest of this policy is the detail.

Who we are

The Trustee for the Aly Boo Family Trust (ABN 70 204 274 606), Queensland, Australia, operates webhook-notify and the hosted service at hooks.flitsy.app. Contact us at j@jaym.cc.

The two kinds of data, and who controls them

This distinction matters, so it is up front.

Account data. Information about you as a customer: your email address, name, and subscription status. For this data we are the controller (in GDPR terms) and this policy describes what we do with it.

Webhook content. The requests that arrive at your endpoints. You decide what is sent to your endpoints, and that content may contain personal information about other people who are not our customers. For this content you are the controller and we act as your processor: we hold it on your instructions, only to deliver it to your devices. You are responsible for having a lawful basis to send it to us. If you need a data processing agreement in order to use the service lawfully, contact us at j@jaym.cc and we will put one in place.

Be aware: webhook content is stored in our database in a form our operators can read. It is not end-to-end encrypted, and we can technically access it (for example, while diagnosing a fault you report). We access it only where necessary to operate the service or to respond to a support request from you, and we never disclose it except as described under Who we share data with below.

What we collect

Account data

DataWhySource
Email address, nameIdentify your account, contact you about the serviceYou, via sign-in or Setapp
Sign-in identifier (WorkOS user ID or Setapp user ID)Link your sign-in to your accountWorkOS or Setapp
Subscription tier, trial end date, billing period end, cancellation statusDecide whether you have accessPolar or Setapp
Polar customer and subscription identifiersReconcile payments and let you manage your subscriptionPolar
A Setapp refresh token (Setapp customers only)Re-check hourly that your Setapp subscription is still activeSetapp
API key hashes (SHA-256), a label, and last-used timeAuthenticate the app to the serviceGenerated by us

We store only a hash of each API key. We cannot recover the key itself.

Webhook content

For every request received at one of your endpoints, we store:

  • the HTTP method;
  • an allowlist of headers only: content-type, user-agent, x-github-event, x-github-delivery, x-gitlab-event, x-slack-signature, x-request-id, x-webhook-id. All other headers, including any Authorization or Cookie header, are discarded and never written to our database;
  • the query string;
  • the request body, parsed as JSON where possible, otherwise the raw body text;
  • the IP address the request came from;
  • timestamps for when it was received and when it was delivered to your app.

We also store the listener’s name, description, and notification template configuration, which you provide.

Data held on your Mac

The app stores your API key in the macOS Keychain, and your service URL, poll interval, cached account email, plan, and entitlement in standard macOS preferences. This stays on your Mac. We do not collect device identifiers, hardware information, crash reports, or usage statistics.

PurposeBasis
Providing the service, managing your account and subscriptionPerformance of a contract (Art 6(1)(b))
Receiving and storing webhook contentPerformance of a contract with you; for the content itself we act on your instructions as processor (Art 28)
Storing source IP addresses, rate limiting, quota enforcementLegitimate interests (Art 6(1)(f)): protecting the service from abuse
Sending an AI template suggestion to AnthropicYour consent, given by pressing the button (Art 6(1)(a))
Keeping records for tax and accountingLegal obligation (Art 6(1)(c))

Who we share data with

We use the following service providers. We do not sell personal information to anyone, and we do not disclose it for advertising.

ProviderWhat they receiveWhyWhere
Amazon Web ServicesAll hosted dataHosting and databaseSydney, Australia
WorkOS (direct customers)Your email and nameSign-inUnited States
Polar (direct customers)Your email, your account ID, payment details you enterPayment processing; Polar is merchant of recordUnited States
MacPaw Way Ltd. / Setapp (Setapp customers)Confirmation of your subscription statusVerifying entitlementCyprus / EU
Anthropic (only if you press “Suggest with AI”)The sample webhook payload you selected, truncated to 6,000 charactersGenerating a suggested notification templateUnited States

Anthropic does not use data submitted through its API to train its models. We do not send your account data to Anthropic, and we do not send webhook content to Anthropic at any other time.

We may also disclose information where required by law, or to establish or defend a legal claim. If we are ever compelled to disclose your data, we will tell you unless we are legally prohibited from doing so.

International transfers

Our servers are in Australia. If you are in the European Economic Area or the United Kingdom, using the service means your data is transferred out of the EEA/UK.

Australia is not the subject of a European Commission adequacy decision. We rely on the Standard Contractual Clauses, or where applicable Article 49(1)(b) (transfer necessary for performance of a contract with you), for these transfers. Some of the providers listed above are in the United States, and those transfers are covered by the Standard Contractual Clauses or by the providers' own certifications.

How long we keep things

DataRetention
Webhook content (bodies, headers, query strings, source IPs)14 days, then permanently deleted by an automatic daily sweep
Listeners and notification templatesUntil you delete them, or until your account is deleted
Account dataFor as long as your account exists
Account data after deletionDeleted within 30 days, except records we must keep for tax and accounting (typically 5 years under Australian law)
API key hashesUntil revoked, or until the account is deleted

Deleting a listener deletes all of its stored payloads immediately.

Your rights

Wherever you live, you may ask us to give you a copy of your data, correct it, delete it, or export it in a machine-readable format. Email j@jaym.cc and we will respond within 30 days.

If you are in the EEA or UK, you have rights of access, rectification, erasure, restriction, portability, and objection under the GDPR, and the right to withdraw consent for the AI feature at any time (simply stop using the button). You may lodge a complaint with your national supervisory authority.

If you are in California, you have the right to know what personal information we collect, to delete it, to correct it, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined in the CCPA, so there is nothing to opt out of. We will not discriminate against you for exercising any right.

If you are in Australia, you may complain to us and, if you are unsatisfied with our response, to the Office of the Australian Information Commissioner (oaic.gov.au).

Deleting your account deletes your listeners and all stored webhook content with them.

Security

Traffic to and from the service is encrypted with TLS, and the database connection uses TLS. API keys are stored only as SHA-256 hashes on our side, and in the macOS Keychain on yours. Access to production systems is restricted and protected by key-based authentication.

No system is perfectly secure. If we become aware of a data breach that is likely to result in serious harm, we will notify affected users and the relevant regulators as required by the Privacy Act 1988 (Cth), the GDPR, and any other applicable law.

Children

The service is not directed at children and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.

Changes

We will post any change here and update the date at the top. If a change materially affects how we handle your data, we will notify you in the app or by email before it takes effect.

Contact

j@jaym.cc The Trustee for the Aly Boo Family Trust (ABN 70 204 274 606), Queensland, Australia