Privacy

Privacy policy

Effective and last updated: August 30, 2026

TL;DR

The short version

This website

No ads, analytics, cookies, accounts, or third-party embeds. The web host receives ordinary request logs.

Your server

A self-hosted KyPost installation is controlled by its operator. Busnes.app does not receive its mail or account data merely because it uses KyPost.

Push relays

If enabled, maintainer-operated relays process device tokens and limited notification data to deliver Apple or Google push notifications.

Your choices

You can use generic notifications, choose UnifiedPush or polling, and contact the relevant server operator about data on a self-hosted installation.

This summary helps you understand the policy, but the full policy below controls.

1. Who we are

Busnes.app is a d/b/a operated by Matthew Beacher. In this policy, “Busnes.app,” “we,” and “us” refer to Matthew Beacher doing business as Busnes.app. Contact us at [email protected].

2. Scope and responsibilities

This policy covers the kypost.org website, official KyPost client applications, and any push-relay or support service operated by Busnes.app. It does not make Busnes.app responsible for independently operated KyPost servers.

For the website and maintainer-operated services, Busnes.app determines why and how personal information is processed. For a self-hosted installation, the person or organization running that server normally makes those decisions and should provide its own privacy notice.

3. The website

The KyPost marketing and documentation site does not use advertising, analytics, cookies, account forms, or third-party embedded content.

InformationPurposeLegal basisRetention
IP address, requested URL, referrer, browser/device information, and timestampDeliver the site, maintain security, and diagnose failuresLegitimate interests in operating and protecting the site180 days

The site is hosted by GitHub Pages. GitHub may process request information under its own privacy statement. Because the site does not track visitors across websites, it does not alter its behavior in response to Do Not Track or Global Privacy Control signals.

4. Maintainer-operated services

If an operator enables Apple Push Notification service or Firebase Cloud Messaging, a Busnes.app-operated Cloudflare Worker may process a server identifier, device token, delivery provider, notification payload, timestamp, and limited security or failure-log information. Generic notifications do not contain sender names, subjects, or message bodies. Preview content is included only when the user enables previews.

We use this information to deliver notifications, diagnose failed delivery, secure the relay, and prevent spam or abuse. The legal basis is performance of the requested service and our legitimate interests in keeping it reliable and secure. Relay request content is held only in memory for delivery; security and failure logs are retained for 180 days.

If you contact us through GitHub or email, we process your account details, correspondence, and attachments to answer you, maintain KyPost, or investigate a security report. GitHub and your email provider process that information under their own terms.

5. Self-hosted KyPost

A KyPost Server may process account information, password verifiers, sessions, mailbox credentials, messages, headers, attachments, contacts, public keys, encrypted or wrapped private-key material, device registrations, push tokens, preferences, filter rules, classification results, diagnostics, and logs.

The server operator chooses its infrastructure, users, integrations, backups, logging, retention, and deletion practices. Official clients may keep local copies of mail, contacts, attachments, keys, pairing information, and notification registrations. Busnes.app does not receive this information merely because someone installs or uses the software.

KyPost’s built-in classifier runs using the model configured on the operator’s server. The default design does not send inbox contents to a cloud AI provider. An operator can change the software or connect other services, so users should ask their operator about its actual configuration.

6. Where information may go

  • Website infrastructure: GitHub Pages and its infrastructure providers.
  • Push delivery: Cloudflare, Apple, Google, or a UnifiedPush provider when the corresponding option is enabled.
  • Mail delivery: the chosen IMAP/SMTP provider, recipients, and their mail providers.
  • Key discovery: WKD hosts or public keyservers when lookup or publication is enabled.
  • Support: GitHub and relevant email providers when someone contacts us.
  • Legal and safety: authorities or other parties when required by law or reasonably necessary to protect rights, safety, and service security.

Some recipients may process information outside your country. Applicable transfer protections depend on the server operator’s location, configuration, and chosen providers.

7. Retention and security

We keep maintainer-controlled personal information only for the periods described above, then delete or anonymize it unless a longer period is required for legal, security, or dispute-resolution purposes. Self-hosted server operators determine their own retention and backup schedules.

We use access controls, encryption in transit, restricted service credentials, and limited logging appropriate to the information we control. No system is completely secure. Protect your server, devices, passwords, recovery material, and backups.

8. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal information; object to certain processing; withdraw consent; and complain to a privacy regulator. We do not sell personal information or use it for cross-context behavioral advertising.

Send requests concerning the website or maintainer-operated services to [email protected]. For information held by a self-hosted KyPost Server, contact that server’s operator. We may need to verify your identity before completing a request.

9. Children

KyPost is not directed to children under 13, and we do not knowingly collect personal information from children through the website. If you believe a child has provided information to a maintainer-operated service, contact us so we can review and delete it where appropriate.

10. Changes to this policy

We will post revisions here and update the date at the top. If a change materially affects a maintainer-operated service, we will also provide notice through an appropriate project or service channel before the change takes effect when reasonably possible.

11. Contact

Privacy questions and requests: [email protected]