Privacy Policy
NotiStudio ("NotiStudio", "we", "us") is operated by CodeFactory. This policy explains what information NotiStudio collects, how we use it, and the choices you have. NotiStudio connects your developer and business tools (such as GitHub, Stripe, and Vercel) and routes the events they emit into your chat channels (such as Discord and Slack) according to rules you define.
Information we collect
Account information
Authentication is handled by our identity provider, Clerk. When you sign up we store your email address, name, profile image URL, and a Clerk user identifier so we can recognize your account.
Connected source data
When you connect a source — a GitHub App installation, a Stripe Connect account, or a Vercel integration — we store the connection's identifiers and labels (for example a GitHub installation id and account login, a Stripe account id, or a Vercel team or user id) and the repositories or accounts you bind to your projects. We do not store your source providers' OAuth access or refresh tokens; where a token is briefly needed (for example to read an account name once on connect), it is used and then discarded, not persisted.
Event data
Sources deliver events to NotiStudio via signed webhooks. We turn each routable event into a record containing its source, category and severity, environment, a short human-readable title and detail, an optional amount, and timestamps. We also store a redacted copy of the provider's payload — stripped of personal and sensitive fields — keyed by the provider's delivery id so a re-delivered event is not duplicated.
Destination secrets
For each chat channel you connect, we store the channel's incoming-webhook URL so we can deliver messages to it. These URLs are encrypted at rest (AES-256-GCM) and decrypted only on our servers at the moment of delivery; they never appear in any data we return to your browser.
Delivery logs
We record the outcome of each outbound delivery (sent or failed, attempt count, and the last error message) so deliveries can be retried and so you can see what happened.
How we use your information
We use your information solely to provide the service: to receive events from your connected sources, evaluate your routing rules, deliver notifications to your chosen destinations, and to operate, secure, debug, and support NotiStudio. We do not sell your data, and we do not use it for advertising.
How information is shared
We share data only as needed to run the service:
- Service providers (sub-processors) that operate our infrastructure — Clerk (authentication) and Neon (database hosting).
- Services you connect — by design, data flows to and from the third parties you choose: your sources (such as GitHub, Stripe, and Vercel) and your destinations (such as Discord and Slack). What we send to a destination is the notification content you routed there.
- Legal — where required by law, or to protect the rights, safety, or security of NotiStudio, our users, or the public.
Third-party services you connect are governed by their own privacy policies; we encourage you to review them.
Security
We verify the cryptographic signature of every inbound webhook before processing it, encrypt destination secrets at rest, and scope every database query to your account. No method of transmission or storage is perfectly secure, but we protect your data using industry-standard practices.
Data retention and deletion
We retain your data while your account is active. You can disconnect any source or destination at any time, and deleting your account removes your associated data from our systems — cascading deletes remove your sources, projects, routes, events, and delivery records.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data. You can exercise these rights — or ask any privacy question — by emailing jc@codefactory.ai.
Children
NotiStudio is not directed to children and is not intended for anyone under 16.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, take reasonable steps to notify you.
Contact
Questions about this policy or your data? Email jc@codefactory.ai.