Privacy policy
How PushKit handles your data.
Last updated: August 4, 2026
Who we are
PushKit (operated by Holley Design Co) helps you take a Lovable web app to the Apple App Store and Google Play: native wrapping, store assets, a hosted privacy policy for your app, pre-submission audits, store submission, and push notifications. This policy covers the PushKit service itself. Privacy policies that PushKit generates and hosts for your app (at
/privacy/<bundle-id>) describe your app’s practices and are your responsibility as its publisher.What we collect
Account data — your name, email address, and password-authentication data, managed by our auth provider (Supabase).
Billing data— plan, subscription status, and payment records, processed by Stripe. Your card number never touches PushKit’s servers.
App and project data — repository URLs, app names, bundle IDs, descriptions, listing copy, icons, screenshots, reviewer notes, and the privacy-policy text you generate for your apps.
Store and push credentials you provide — App Store Connect API keys, Google Play service-account keys, and APNs/FCM credentials. We store these to act on your instructions (submitting your app, sending your pushes) and for no other purpose.
Push and analytics data— device tokens registered by your app’s end users, and delivery/open events for the campaigns you send. For this data we act as a processor on your behalf; you are the controller for your app’s end users.
Billing data— plan, subscription status, and payment records, processed by Stripe. Your card number never touches PushKit’s servers.
App and project data — repository URLs, app names, bundle IDs, descriptions, listing copy, icons, screenshots, reviewer notes, and the privacy-policy text you generate for your apps.
Store and push credentials you provide — App Store Connect API keys, Google Play service-account keys, and APNs/FCM credentials. We store these to act on your instructions (submitting your app, sending your pushes) and for no other purpose.
Push and analytics data— device tokens registered by your app’s end users, and delivery/open events for the campaigns you send. For this data we act as a processor on your behalf; you are the controller for your app’s end users.
How we use it
To provide the service you signed up for: authenticate you, bill your plan, generate and host your assets and policies, run audits, submit to the stores with your credentials, deliver your push campaigns, and show you your own analytics. We do not sell your data, and we do not use your data to advertise to anyone.
Service providers
We share data only with the processors needed to run PushKit: Supabase (authentication and database), Stripe (payments), our hosting provider, Apple and Google (when you submit your app or send APNs/FCM pushes, using your credentials), and Anthropic (listing text you choose to translate is sent to the Claude API to produce the translation). Each receives only what its function requires.
Cookies
PushKit uses cookies for one thing: keeping you signed in (authentication session cookies). No advertising or cross-site tracking cookies.
Retention and deletion
We keep your data while your account is active. Delete your account and we delete your account data, app data, and stored credentials within 30 days, except records we must keep for legal or accounting reasons (e.g. invoices). You can request deletion, a copy of your data, or a correction at any time using the contact below.
Security
Data is encrypted in transit (TLS) and at rest by our infrastructure providers. Store and push credentials are accessible only to the server-side code that acts on your instructions. No method of storage is perfectly secure; if a breach affects your data, we will notify you without undue delay.
Changes and contact
If this policy changes materially, we’ll note it here and update the date above. Questions or requests: kenya@holleydesignco.com. See also our Terms of Service.