Privacy policy
NoticeTap is published by HTuse. This policy covers noticetap.com and the NoticeTap Android app. Last updated: 17 September 2026. Contact: support@noticetap.com.
Information you provide
An email/password account stores your email address, username, display name, a salted password hash and a hashed recovery code. We cannot read your original password or recover a lost recovery code. An email/password login identifier is not a claim that ownership of the email has been verified.
If you choose Google sign-in when available, Google supplies an account identifier, verified email and profile name. We do not receive your Google password. We use that information to authenticate your NoticeTap account. Google also processes information under its own privacy policy.
Your preferences, bookmarks, alert history, reminder settings and account timestamps are stored so those features can work across signed-in devices. Support emails contain whatever you choose to send. Please do not send passwords, recovery codes, government identity documents or payment information.
Browser storage and notifications
Essential session cookies keep you signed in. Browser storage saves interests, bookmarks, cookie choices and cached public pages for offline use. Browser notification subscriptions contain a delivery endpoint and encryption keys. We associate a subscription with your account when you enable alerts while signed in.
Push services operated by your browser or device provider deliver alerts. Notification titles can be visible on a lock screen. You can disable alerts in NoticeTap or in browser settings. Local saved data can be cleared through your browser.
Android app storage and alerts
The Android app stores your preferences, saved notice identifiers and a cached public feed on your device. Account session tokens are encrypted using Android Keystore. Sign-in opens your browser and returns a short-lived, single-use code to the app; the app exchanges it using a proof tied to that sign-in attempt.
When enabled and configured, Android push alerts use Google Firebase Cloud Messaging (FCM). Google processes an app installation identifier and delivery token to route notifications. We associate that token with your signed-in account to deliver matching notices. Guest or unregistered devices use periodic background checks, which Android may delay.
You can disable alerts in the app or Android settings. Signing out disables app alerts and removes locally stored account preferences and saved identifiers. Clearing app storage or uninstalling removes local app data. The native app does not include advertising or Firebase Analytics.
Your feed and device viewing history
For you balances recent notices, your chosen topics, states, organisations, sectors, ministries and organisation types, and variety across sources. The notice menu explains each suggestion. It does not infer sensitive personal traits or guarantee eligibility.
Recently viewed and Not interested store up to 50 opened notice identifiers and 30 hidden identifiers, with timestamps, locally for up to 30 days. Expired records are removed when you use the website or app. These records are not synced to your account. To retrieve history and personalise recommendations, the website or app sends the relevant notice identifiers to NoticeTap with the feed request; hosting request logs may record those requests. We do not send these lists to Google Analytics.
Use Clear history on Recently viewed or reset hidden notices under Interests & alerts. Signing out clears this device’s history for that signed-in account. Clearing browser/app storage removes locally held records. Cached public notice contents may remain for offline reading until the device cache is cleared.
Optional Google Analytics
With your permission, we use Google Analytics 4 (measurement ID G-XF5DG2PTXW) to understand public page usage and improve the site. Google may receive page paths, device/browser information, approximate location derived from network information and online identifiers. Optional analytics can place cookies in your browser.
We do not intentionally send account credentials, email addresses, usernames or search terms to Analytics. Private account, inbox, saved, viewing history, following, search and administration pages are excluded from our page-view tracking. We disable advertising personalisation and Google signals in our site configuration.
Analytics scripts are loaded only after you choose Allow analytics. You can choose Only necessary without losing core features, and reopen Cookie settings to change your choice. Changing your choice stops future site analytics collection; it does not automatically erase information already processed by Google. See policies.google.com/privacy for Google’s practices.
Security and abuse prevention
Signup uses a self-hosted proof-of-work verification. It does not require a third-party advertising CAPTCHA. We store short-lived challenge and rate-limit records to reject replayed verification and excessive attempts.
Our hosting provider may process request logs and network information for operations, security and abuse prevention. Security measures reduce risk but cannot guarantee that every threat will be prevented.
Why information is used and who receives it
We use account data to provide requested features, authenticate users, protect the service and respond to support requests. Optional analytics depends on your cookie choice. We do not sell account information.
Service providers include Hostinger for hosting and database infrastructure, browser push providers for notifications, Firebase Cloud Messaging for Android push delivery, and Google when you choose its sign-in or website analytics features. Processing may occur outside India. Source websites operate independently and have their own privacy policies when you visit them. Information may also be disclosed where law requires it or to protect legal rights.
Retention and deletion
Account data remains while your account is active. Deleting your account from account settings removes its active account record, saved notices, inbox, reminders, sessions and linked push subscriptions. Browser data and copies already delivered to a device must be removed on that device.
Session cookies expire after up to 14 days unless refreshed by a new sign-in. Google sign-in challenges expire after five minutes. We keep a rotating set of up to 14 automatic encrypted server backups; old copies leave that set as new backups are created. Disaster-recovery copies held separately can outlast that rotation and are retained only for recovery and security purposes. If a backup is restored, deletion requests must be reapplied.
Analytics information is subject to the Google Analytics property’s retention settings. For access, correction, deletion or retention questions, contact support@noticetap.com. We may need to verify that you control the relevant account before acting.
Young users and changes to this policy
Public notices can be browsed without an account. If you are under 18, use account and notification features with a parent or guardian’s permission and supervision. Do not submit sensitive personal information. Contact us if you believe a child’s information needs to be removed.
We will update this page when our practices change. Material new uses of optional data may require a new choice. The date above identifies the current policy.