Private alert channel
Everything below rests on one rule: a channel asks, and the phone decides. What arrives is guaranteed; how loudly it arrives is not, and any page that told you otherwise was selling.
Private means sealed, not merely unlisted
A private channel is not one that is simply missing from a directory. It requires an invite code both to subscribe AND to read anything about it, and a request without one gets exactly the same “not found” as a handle that never existed — because a different answer would let anybody confirm that a school’s or an ops team’s channel exists by guessing its name. Invite codes can carry a use limit and can be revoked; revoking is a timestamp and by default removes nobody who already joined.
More than one person, without sharing a password
A workspace holds the channels; people are invited into it with a role — owner, admin, editor, analyst or billing. An editor can compose and send; an analyst can read the numbers and nothing else; billing sees invoices and not subscribers. A member can also be restricted to a single channel, which is what a large organisation needs when the communications team and the facilities team should not be able to speak as each other.
Nothing that could identify anybody
Subscribing needs no account, no email address and no phone number. What a subscription actually holds is a random identifier the app generated, a platform, an app version, a language and a time zone — coarse enough that hundreds of millions of people share one. There is no name, no contact detail, no advertising identifier and no location, and there is no export that would let an operator build one. You cannot leak a list you never collected.
Questions, answered plainly
Can somebody find my private channel by guessing the name?
No. A sealed channel answers a request without an invite code with exactly the same “not found” that a nonexistent handle gets. There is no response that distinguishes “this exists but you may not see it” from “this does not exist”, because that difference is itself a leak.
Can I let somebody send without giving them everything?
Yes. Roles separate composing, sending, reading the numbers and seeing invoices, and a member can be restricted to a single channel. The same split exists for API keys, so a script can be allowed to send and forbidden from deleting.
What do you collect about somebody who subscribes?
A random identifier the app generated, a push token, the platform, the app version, the language and the time zone. No name, no email address, no phone number, no location, and no advertising identifier. Subscribing needs no account at all.
Do subscribers need an account?
No. They install the app, subscribe to a handle, and that is the whole of it. Only the person running the channel signs up for anything.
Say it once. Every subscribed phone gets it.
Free up to 100 subscribers, no card to start, and the handle is yours permanently.
Start a channel