Push notifications, from our own server
Since bWalletX 5.1.70, phones, the web wallet and the extension get push notifications from push.bwalletx.com. What notifies you, what the server knows and doesn’t, and what it costs.
Status: out in bWalletX 5.1.70, on iPhone and Android, in the web wallet and in the Chrome extension.
A wallet with chat needs to tap you on the shoulder
bWalletX has chat built in: token rooms, DMs, calls and b, the assistant. Chat that only works while the app is open isn’t much use. If a friend sends you a message, you should find out without having to check. That needs push notifications.
The usual way to add them is to sign up for a notification company, drop its SDK into the app and send it everything: who your users are, who is messaging whom, and often the text of the messages. It is quick to set up, and it means a third party ends up with a list of your users’ conversations.
We didn’t want that, so we run our own small push server at push.bwalletx.com.
What notifies you
- Direct messages. Always, unless you turn that conversation off.
- Mentions. When someone mentions you in a room, unless you turn that room off.
- Group messages. Only if you ask for them. Each room has a bell with three settings: All, Mentions and Off. Groups start on Mentions, so a busy room doesn’t buzz your phone all day.
- Calls. An incoming call rings through.
- Answers from b. When the assistant replies in a room.
Tapping a notification opens the room or DM it is about.
Two more rules keep it calm. If a room gets busy, you get one notification per room every 30 seconds at most, and the next one says “N new messages in X” instead of one buzz per line. And you can set quiet hours, which hold back everything except calls.
Your preview setting and quiet hours belong to your account, not to one device, so they follow you from your phone to the web wallet to the extension. The settings are in Settings › Notifications › Push notifications.
What the server knows
To send you a notification, the server has to know a few things, and it keeps only those:
- Your handle and your devices. For each device: the platform (iPhone, Android, web or extension) and the push token Apple, Google or your browser gave it. That token is an address for a device, nothing more.
- Your settings. Previews on or off, quiet hours and your time zone, and the bell setting for each room you have changed.
You register by signing in with your wallet, the same signed proof bChat uses. There is no email address and no password. If you turn notifications off, or sign out, the device is removed.
What it doesn’t know
The push server doesn’t read your rooms. When a message is sent, bChat, which already knows who is in each room, tells the server who should be told and passes a short preview. The server decides who gets a notification, sends it and forgets it. No message text is ever stored. Its database has a devices table and a settings table, and that is all. Its log line for each event says the kind of event and how many devices it went to. It doesn’t log who sent what to whom.
Previews are off by default. With previews off, the text of the message never leaves our server. The notification says “$alice sent you a message” or “$alice mentioned you in $ROOM”, and you open the app to read it. Answers from b say “Tap to read the answer”. If you turn previews on, the message text goes into the notification so you can read it on your lock screen.
What we can’t avoid
We want to be exact here, because “our own server” can sound like more than it is.
Phones only accept notifications through their maker’s service. An iPhone notification has to go through Apple’s push service, and an Android one through Google’s Firebase Cloud Messaging. There is no way around that for an app on those phones. So Apple or Google carries the notification to your device, and sees what is in it. That is why previews are off by default: with them off, all Apple or Google can see is that $alice sent you a message, not what she said.
In the web wallet and the extension, notifications use standard Web Push. The browser’s push service carries them, but the content is encrypted for your browser, so the push service can’t read it.
What running our own server changes is the part in the middle. No notification company gets a copy of every user, every device and every conversation. The list of who talks to whom stays with us and bChat, and the stored part is limited to devices and settings.
What it costs
Apple, Google and the browser push services don’t charge to deliver notifications. The cost is our time and a small server. It runs next to our other services on a server we already rent, and we maintain it ourselves. We had to set up our own Apple push key, a Firebase account and a key pair for Web Push, and those keys live on the server only, never in any code repository.
There are real downsides. When something breaks, nobody else fixes it. Amazon Fire tablets have no Google Play services, so Android push doesn’t reach them. And on an iPhone, the web wallet can only get notifications once it has been added to the home screen. We think that is a fair price for not handing out a map of who our users talk to.
Turning it on
In the phone apps the switch starts on. In the web wallet and the extension it starts off until you turn it on in Settings, which is when the browser asks for permission. The full details, including how to turn each room down or off, are on the push notifications page.