📜 服务条款 (Terms of Service) 📜 Terms of Service 🛡️ 隐私政策 (Privacy Policy) 🛡️ Privacy Policy
隐私与数据保护 最后生效修订: 2026年9月14日

PushNova 隐私政策 (Privacy Policy)

PushNova 恪守最小化数据收集原则,通过端到端加密与边缘计算架构全面捍卫您的数据隐私与信息安全。

🛡️ 数据透明度承诺与 Creem 支付安全说明:
PushNova 严格保护您的账户、设备与推送数据。我们支持基于 P-256 ECIES 的客户端端到端加密 (E2EE),离线消息在边缘暂存后即刻物理销毁。此外,所有付费交易均由 Creem (Creem.io) 作为记录商家托管,本平台绝不收集、处理或存储您的信用卡卡号与敏感金融凭据。

1. 适用范围与隐私承诺

本《隐私政策》详细阐明 PushNova("我们"、"本平台")在您访问 Web 控制台、调用 API 接口或在移动终端运行 PushNova Android 客户端时,如何收集、使用、存储、保护及共享您的个人信息与数据。我们严格遵循全球通用隐私准则(包括 GDPR、CCPA 原则),尊重用户的知情权与控制权。

2. 我们收集的信息类型及处理规范

为向您提供安全、高可用的推送中继服务,我们根据业务场景收集以下四类数据:

(a) 账户信息 (Account Information)

  • 注册凭证:您的工作电子邮箱地址(Email)、用户唯一编号(UID)。
  • 认证安全数据:您的账户密码经过强哈希算法加密散列后安全存储,服务端绝不保存任何明文密码。
  • 第三方登录授权:若您选择 Google 账号一键登录,我们仅接收 Google OAuth 提供的基础验证令牌、已验证邮箱与头像,不获取您的 Google 账号密码。

(b) 终端设备信息 (Device Information)

  • 设备硬件与系统标识:设备品牌与型号(如 Pixel、Xiaomi、Samsung 等)、Android 系统版本号、客户端版本号。
  • 网络推送通道凭证:Google Firebase Cloud Messaging (FCM) 注册 Token、厂商推送 Token(若开启),用于由边缘网关准确定位终端下发通知。
  • 活跃状态与加密公钥:终端在线心跳时间、已绑定的分组 ID 与客户端生成的 P-256 ECIES 端到端加密公钥(Public Key)。私钥始终驻留在您手机的硬件安全环境(Android Keystore)中,绝不上传至服务器。

(c) 消息内容与端到端加密 (Message Data & E2EE Relay)

  • 消息元数据:消息 ID、标题、类型(如默认通知、HITL 人机审批、富文本等)、通道 Topic 及发送时间戳。
  • 端到端加密保障 (E2EE):PushNova 全面支持基于客户端椭圆曲线的 E2EE。在此模式下,发送端在进入网关前已完成密文加密,服务端仅作为不透明的密文管道进行路由转发,无法查看解密后的任何文本内容。
  • 离线暂存与物理销毁机制:若目标设备处于离线状态,加密消息将在边缘数据中心暂存最长不超过 72 小时。一旦设备联网拉取成功或超过有效时限,该记录将即刻从数据库中执行物理擦除,我们不保留明文历史。

(d) 账单计费与支付数据 (Billing & Payment Data - Creem 记录商家)

  • 支付由 Creem 独立托管:PushNova 选用 Creem (Creem.io) 作为记录商家(Merchant of Record)承接全球在线支付。
  • 零金融敏感信息驻留:所有信用卡卡号、银行卡信息、CVC/CVV 验证码及账单地址均由 Creem 遵照 PCI-DSS Level 1 国际金融安全标准进行加密处理。PushNova 服务器完全不接触、不存储、不窥探您的任何支付卡敏感数据。
  • 订单记账信息:我们仅接收 Creem Webhook 异步回调提供的订单 ID、交易时间、套餐名称(PRO 或 Booster)及购买额度,用于在系统内部记录记账流水并为您开通对应推送配额。

3. 数据使用目的

我们收集和处理上述必要数据的目的仅限于:

  • 维护核心推送功能、执行多对多广播路由与群组设备治理;
  • 执行 API Key 鉴权校验、HMAC-SHA256 双向验签及配额计量;
  • 防范自动化黑客探测、DDoS 攻击与垃圾邮件滥用;
  • 向您发送与账户安全相关的关键通知(如新设备登录提醒、验证邮件);
  • 我们郑重承诺:绝不出售、出租或向任何广告网络及数据代理商提供您的个人信息与推送数据。

4. 第三方服务集成与跨境数据传输

为保障全球分布式架构的低延迟响应,我们与以下高合规标准的第三方技术服务商协同工作:

  • 边缘计算与网络安全服务商:提供全球边缘计算、分布式数据存储及网络 DDoS 防护;
  • Google LLC:提供 Firebase Cloud Messaging (FCM) 系统级移动通知下发通道及 Google OAuth 身份认证;
  • Creem.io:提供法定记录商家(MoR)计费、在线收银台与合规税务结算;
  • Resend:提供系统验证邮件发送服务。

5. 数据安全保障

我们实施严苛的多层安全防御体系:全站强制使用 TLS 1.3 高强度传输加密协议;数据库实施细粒度的行级租户隔离;敏感令牌与 Webhook Secret 进行密钥哈希存储;客户端支持硬件级 Keystore 隔离保护。

6. 您的权利与数据控制

根据适用的数据保护法律(包括 GDPR 和 CCPA),您享有以下法定权利:

  • 查阅与导出:您可在 Web 控制台随时查看名下所有设备、分组、API Key 与订单记录;
  • 解除绑定与注销:您可自主在控制台解除手机设备绑定,或随时申请注销 PushNova 账户。账户一旦注销,所有设备凭证、配置规则及配额数据将执行不可逆的全面销毁;
  • 异议与联系:若您对个人数据处理有任何疑虑或需要行使权利,请直接联系我们的隐私保护专员。

7. 政策更新与联系方式

随着业务演进或法律要求,我们可能会适时更新本隐私政策。重大变更将在控制台显著位置展示或通过邮件通知。修改后的政策自公布之日起生效。

如对本隐私政策有任何问题、意见或投诉,欢迎通过以下官方渠道联络:
隐私合规邮箱:support@ezcloud.ltd

Privacy & Data Protection Effective Date: September 14, 2026

PushNova Privacy Policy

PushNova follows a strict data-minimization philosophy, defending your digital privacy through client-side end-to-end encryption and edge computing.

🛡️ Data Transparency & Payment Security with Creem:
PushNova is committed to safeguarding your account, device, and message data. We provide P-256 ECIES client-side End-to-End Encryption (E2EE), with offline messages securely purged immediately upon delivery. Furthermore, all paid transactions are handled exclusively by Creem (Creem.io) as our Merchant of Record. PushNova never collects, processes, or stores your credit card numbers or sensitive financial data.

1. Scope & Privacy Commitment

This Privacy Policy outlines how PushNova ("we", "us", or "our") collects, processes, retains, protects, and discloses personal data and operational information when you access our Web Console, utilize our REST/WebSocket APIs, or run the PushNova Android application. We align our data governance with international data protection frameworks, including GDPR and CCPA principles.

2. Information We Collect & How It Is Handled

To provide high-availability message dispatch and fleet governance, we collect four categories of information:

(a) Account Information

  • Registration Details: Your business email address and unique user identifier (UID).
  • Authentication Credentials: Passwords are salted and cryptographically hashed before being written to storage; plaintext passwords are never stored.
  • Third-Party Sign-In: If you sign in via Google OAuth 2.0, we receive only basic profile claims (verified email address, profile avatar, OpenID token). We do not obtain access to your Google account password.

(b) Device & Terminal Information

  • Hardware & OS Identifiers: Device manufacturer and model (e.g., Pixel, Xiaomi, Samsung), Android OS version, and PushNova app build number.
  • Push Gateway Tokens: Google Firebase Cloud Messaging (FCM) registration tokens and vendor device push tokens necessary for targeted notification delivery.
  • Activity State & Public Keys: Terminal heartbeat timestamps, group affiliations, and client-generated P-256 ECIES public keys used for E2EE. Your private key stays securely locked within your device's Android Keystore and is never transmitted to our servers.

(c) Message Payloads & End-to-End Encryption

  • Notification Metadata: Message identifier, title, dispatch mode (standard, HITL human-in-the-loop, rich markdown), channel topic, and timestamp.
  • End-to-End Encryption (E2EE): PushNova features native client-side E2EE. In this mode, messages are encrypted before transmission; our servers act solely as a blind transport pipeline and have no technical capability to decrypt or inspect the message body.
  • Temporary Queue & Purge Policy: If an intended recipient device is offline, encrypted messages are held temporarily in edge storage for up to 72 hours. Once retrieved or upon expiry, the message payload is permanently and irrevocably deleted. We do not maintain historical message archives.

(d) Billing & Payment Data (Creem as Merchant of Record)

  • Creem as Merchant of Record: PushNova partners with Creem (Creem.io) to handle international payment processing, checkout hosting, and tax compliance as our official Merchant of Record.
  • Zero Sensitive Card Storage: All credit card transactions are handled directly within Creem's PCI-DSS Level 1 certified payment infrastructure. PushNova does not collect, process, or hold your credit card numbers, CVV codes, or bank account credentials.
  • Order Ledgers: PushNova stores only transaction verification records: Creem checkout IDs, order status, purchase tier (PRO or Booster), timestamp, and assigned quota allotment for accounting and license provisioning purposes.

3. Purpose of Processing

We process collected data strictly for the following operational needs:

  • Facilitating core notification routing, channel broadcasts, and fleet device management;
  • Authenticating API keys, validating HMAC-SHA256 webhook signatures, and measuring quota usage;
  • Preventing malicious bot attacks, DDoS incidents, and abusive spam relays;
  • Delivering critical account security notifications (e.g., login alerts, verification emails);
  • We do not sell, rent, or monetize your personal information with data brokers or advertising third parties.

4. Third-Party Infrastructure & Cross-Border Transfers

To ensure resilient global delivery, we partner with industry-leading infrastructure providers:

  • Edge compute & network security provider: global edge computing, distributed data storage, and DDoS protection;
  • Google LLC: Firebase Cloud Messaging (FCM) push delivery and Google OAuth authentication;
  • Creem.io: Merchant of Record payment processing and checkout services;
  • Resend: Transactional email verification delivery.

5. Data Security Measures

We implement industry-standard defenses: mandatory TLS 1.3 encryption in transit; multi-tenant database isolation; API key hashing; and client-side cryptographic key storage isolated in hardware security modules.

6. Your Privacy Rights

Subject to applicable regulations (such as GDPR and CCPA), you possess the right to:

  • Access & Export: Review all devices, groups, API keys, and order ledgers linked to your account via the console;
  • Device Unbinding & Deletion: Unbind terminals at any time or submit an account deletion request. Deletion triggers the permanent erasure of all associated tokens and configuration files;
  • Inquiries & Objections: Contact our compliance team regarding any privacy concerns.

7. Policy Updates & Contact Information

We may update this Privacy Policy from time to time. Material modifications will be posted to the console or communicated via email. Continued use following changes represents acceptance.

For questions or privacy inquiries, please contact:
Compliance Officer: support@ezcloud.ltd