The short version

  • No account or login is required to use the website or the app.
  • The app does not request your location and does not include any advertising, analytics, or crash-reporting SDKs.
  • We do not sell personal data, and neither the website nor the app engages in behavioral advertising.
  • The app does not track you across other apps or websites.
  • Push notification data exists only to deliver and manage the alerts you asked for.

iOS app: what we collect for push notifications

If you turn on notifications in the app, we register a device record so we know where to deliver alerts. That record contains:

  • An Apple Push Notification service (APNs) token — the address Apple assigns your device for receiving notifications.
  • A random installation ID — generated on your device to identify that installation; it is not tied to your name, email, or any account.
  • A token fingerprint — a one-way hash of your APNs token, used internally so we can recognize the same registration without storing the raw token in more places than necessary.
  • Your app version and APNs environment (production or sandbox) — used to send notifications correctly and to diagnose delivery problems.
  • The alert topics you selected — federal alerts, plus any specific states you chose. Nothing more granular than that is recorded.

This data is used only to:

  • register your device to receive the alerts you selected;
  • route each notification to the right devices for the right topics;
  • avoid sending you duplicate notifications for the same event;
  • determine whether a registration is still likely to be valid; and
  • diagnose delivery problems and investigate abuse or security issues.

We never use this data for advertising, to build a profile of you, or to track your activity across other apps or websites. Nothing about push registration is sold or shared with data brokers.

Registration freshness and retention

A push registration that hasn’t confirmed itself in the last 30 days (through a fresh app launch or registration check) is treated as stale and becomes ineligible to receive new alerts, even if the underlying record is still stored. This protects against sending notifications to devices that may no longer have the app installed or where the token is no longer valid.

Inactive or historical registration records may remain stored after that point rather than being deleted immediately — for example, to preserve delivery history for diagnosing a problem. We do not use stale records to send notifications.

Notification controls

Notification permission is never requested automatically — it’s only requested when you choose to turn on alerts in the app. You can:

  • choose which alert topics (federal, specific states) you receive, from within the app;
  • turn notifications off at any time in iOS Settings → Notifications → Half-Mast; and
  • revoke the app’s notification permission entirely from iOS Settings, which stops delivery immediately.

Location, accounts, and tracking — app

The Half-Mast iOS app does not request your location, does not require or offer an account or login, and does not include any advertising, analytics, or crash-reporting SDK. There is nothing in the app that identifies you personally beyond the randomly generated installation ID described above.

Website: email alerts

Email alerts are a separate, website-only feature, handled through half-mast.com rather than the app. If you subscribe to email alerts, we store the email address you provide and the topics you selected (federal and/or specific states), along with a confirmation status. We use Resend, a third-party email delivery service, to send these emails on our behalf; Resend processes your email address only to deliver the messages we send.

Every alert email includes an unsubscribe link. You can also cancel a pending signup or unsubscribe at any time using the link in any email you’ve received; submitting the signup form does not by itself activate alerts until you confirm your email address.

Website: analytics

The half-mast.com website (not the app) uses Google Analytics to understand aggregate site usage, such as which pages are visited. This does not run on admin pages. Google’s own privacy policy governs how it processes that data. We do not use Google Analytics, or any other analytics service, inside the iOS app.

What we don’t do

  • We do not sell personal data to anyone.
  • We do not use push registration data, or email alert data, for behavioral advertising.
  • The app does not track you across other companies’ apps or websites.
  • We do not collect your location in the app.

Security

We use reasonable technical and organizational measures to protect the data described above, including hashing APNs tokens before storing a fingerprint and hashing unsubscribe tokens. No online service can guarantee perfect security, and we cannot promise that data will never be disclosed due to circumstances outside our control.

Changes to this policy

We may update this policy as the website or app changes. The “last updated” date at the top of this page reflects the most recent revision. Material changes affecting how push or email data is used will be reflected here before they take effect.

Contact

Questions about this policy or your data can be emailed to half.mast.patriot@gmail.com, or sent through our Support page.