P freeprivacypolicy.app
Service

Privacy policy for OneSignal

Push tokens, segments, and Journeys — the right wording for your policy.

Generate policy with OneSignal Free · no signup · hosted public URL

What OneSignal collects

OneSignal stores a per-device push token (APNs on iOS, FCM on Android), the user's subscription status, the segments they belong to, and any tags you push (setExternalUserId, sendTag). For Journeys, it also stores event timestamps that drive the workflow.

GDPR consent

OneSignal's SDK supports an explicit consent flag: setRequiresUserPrivacyConsent(true). Until you call provideUserConsent(true), no data is sent. Your privacy policy should describe the consent gate when you target EU users.

Ready to publish?

Answer six questions, get a hosted public URL the App Store, Google Play, and ad networks accept. No credit card.

Generate policy with OneSignal

Frequently asked questions

Are push tokens "personal data"?
EU and UK regulators treat persistent device identifiers — including push tokens — as personal data because they can be linked to a person via other signals.

Related reading