Pubby

Privacy

Pubby is an alarm, not a service. There is no account, no sign-in, no advertising and no tracking. We neither want nor hold your name or your email address. What leaves the app is a handful of anonymous numbers about what works in it – and those can be switched off – plus the eight characters that make invites countable.

We take your privacy seriously – seriously enough that Pubby is built to hold almost nothing about you in the first place.

What stays on your phone

Your settings – the siren you picked, how long it waits, your webhook address if you set one. They sit in the app's own private storage, are never sent anywhere, identify nobody, and go when you uninstall the app. The one exception is the free week: our relay knows when it began, and why is under invites below.

What Pubby asks permission for

Notifications, so it can show that guarding is on and so you can stop the alarm. Vibration. Permission to keep running while the screen is off, because a guard that sleeps is not a guard. And internet access – used by a shared watch, by a webhook you set up yourself, and by the anonymous statistics below. Guarding and the siren need no network at all.

Pubby never asks for your location, your contacts, the camera, the microphone, your photos or files, your phone number, or any advertising identifier.

Anonymous statistics

So we can tell which parts of Pubby people actually use and which are just extra code, a handful of numbers leaves the app: that something happened – a watch started, the siren sounded, a friend's alarm arrived on this phone, the welcome got to the end, the widget arrived on a home screen or left it, notifications were allowed or refused, someone opened the Plus offer – along with the app version, the Android version, the phone model and the language. A few events carry one more word: whether the app, the widget or the tile started the watch, whether that watch can show a notification at all, what came of the offer of a Quick Settings tile, whether an invite code arrived by link or was typed, how it went, how a webhook call ended, which buy button it was, and how many days a trial has. That is the whole list.

No ID, no cookies, no advertising identifier, nothing that leads back to you. Events are held together by a session that lives in memory alone: an hour of inactivity gives it a new number and closing the app loses it. So not even we can tell that two watches came from the same phone.

Your webhook address never leaves, nor do the four words, nor anything else you typed. How long something lasted goes out rounded – “a few minutes”, “over an hour” – rather than to the second. An exact time would be a record of you; a range answers the question of how long people actually guard for.

We rest this on legitimate interest: knowing whether what we build is being used. If you would rather we did not, one switch in Settings turns it off and nothing else changes.

The shared watch

This is the part that sends the most, and it runs only when you start it.

A shared watch puts the same alarm on a friend's screen. Your phone reports whether guarding is on or the alarm is sounding, when that last changed, and how full the battery is – and it scrambles all of it before sending. The key that unscrambles it travels only in the tail end of the link, the part browsers never send to a server. So our relay passes along something it cannot read. Whether you are being robbed is not our business.

The four words are the key. Anyone who holds the link, photographs the code or overhears the words can watch, so treat them like a spare key rather than something to say across a room you do not know.

Twelve hours after a watch ends or falls silent, everything about it is deleted and the link stops meaning anything. There is no history and no archive.

Notifications for whoever is watching with you

A phone puts a browser tab to sleep within a minute of the screen going off, so your friend can accept a notification instead. Their browser gives us an address to knock on, and we keep it for the length of the watch and no longer.

The notification is empty – a buzz and nothing else, with everything it means fetched only after they tap it. So their browser's notification service, run by Google, Mozilla or Apple, is told that something happened but never what.

Accepting also saves the watch link in their own browser, key and all, so that a tap minutes later opens the right watch. It stays on their device and goes when they clear this site's data.

Invites and the free week

An invited friend is a month for them and a month for you, and for that to be countable our relay has to tell one phone from another. It knows yours by the eight characters the app derives from the number Android hands each install. The derivation is one-way and the server fingerprints the result once more, so the original number never sits with us.

What is kept is your code, when it was made, whose code you came through if you came through anyone's, when your free week began – and, if you earned the lifetime, which Google Play code you were given for it. That is all of it. No name, no email address, no phone number, nothing you typed anywhere.

Unlike a watch, this is not deleted. Those few rows are the only memory that a phone has had its free week already, and that somebody is owed months for the people they brought in – deleting them hands out a second week and takes months off somebody else. Uninstalling does not remove them, and a fresh install on the same phone gets the same code.

What can be read out of it is that two installs are connected, and nothing more: whose phones they are is written down nowhere here. If you want them gone anyway, write to us and include your code.

Who else is involved

  • Cloudflare runs the relay for us and sees what any website sees, including IP addresses. We use them for one thing – stopping anyone from opening watches in a loop – and we do not keep them.
  • Aptabase processes those anonymous numbers for us, on servers in Germany. It is open source and built to have nothing to store: no cookies, no identifiers, and an IP address is turned into a country and then dropped.
  • Diane runs the comments under the articles on this site. It sets no cookies, asks nobody to sign in, and keeps only what a comment is made of: the name you typed, what you wrote, and your IP address as a hash it compares against itself to stop a flood. The hash is never handed back to anyone, us included.
  • Google Play handles anything you buy. We are told only whether this install has been paid for, never your card, your name or your address.
  • Your own webhook, if you set one up, is told which event happened and when. Nothing else, and nothing about you. You chose where it goes; what happens at the far end is between you and whoever runs it.

This website

No cookies. The landing page runs the same anonymous statistics as the app: which page is being read, in which language, and which parts of it people used. None of that leads back to you, and it stores nothing whatsoever in your browser to do it.

The watch page is left out of it entirely. Whoever lands there did not choose Pubby – they came because of a friend and will be gone in a quarter of an hour. And the four words in the link are the key, so none of that address may be sent anywhere at all.

Under each article there is a comment box. You sign into nothing to write in it and it stores nothing in your browser. The name you sign a comment with is published alongside it and does not have to be your own. A comment stays until we delete it; write to us if you want yours taken down.

The only thing any page here stores in your browser is the watch link described above, and only if you asked for notifications.

Your rights

You can ask what we hold about you, have it corrected or deleted, object to how it is used, or ask for a copy of it.

Honestly, there is very little to ask for. We hold no name, no email address and no account. What exists outside your phone is a shared watch you started yourself, which ending it – or waiting twelve hours – erases, and the few rows about invites and the free week, which stay on purpose. The anonymous numbers cannot be handed over, because they are nobody's.

If you think we have handled something badly, write to us.

Who we are

Pubby is made by AquaSoup. For anything on this page, or anything you would rather ask than guess: hello@pubby.vip.

Changes

If this policy changes in a way that matters, the date below changes with it and the app's release notes will say so. Old versions do not quietly start doing something new.

Last updated 7 September 2026.

Back to Pubby