Legal
Privacy
How NewsletterIdea handles browser-only readiness answers, legacy scans, account, payment, email, API, support, and operational data.
Last updated September 8, 2026
Scope
This policy covers NewsletterIdea.com, the browser-only readiness check, completed legacy scans, customer account pages, the public API, paid research, support, transactional email, marketing email, and operational logs.
Cookies and optional processing
Essential storage supports account security, checkout, fraud prevention, and remembering your privacy choices. It is active without optional consent. Analytics, marketing, personalization, and advertising are off by default and are enabled only for the purposes you select.
A protected consent cookie stores an opaque browser token, your selected categories, the policy version, and expiry. It does not contain your email address, account id, IP address, or the pages you visit. Optional visitor and session identifiers are not created until analytics is allowed.
Use Privacy choices to grant, change, withdraw, or delete your saved browser choice at any time. Withdrawal takes effect immediately for new processing and queues required removals from connected marketing or advertising destinations.
Global Privacy Control
When your browser sends the Global Privacy Control signal, NewsletterIdea treats it as a request to disable advertising, sale or sharing, marketing identifiers, and cross-context audience use. The signal overrides an older browser choice for those purposes. Analytics, first-party personalization, and requested marketing remain separate choices that you can turn off on the privacy choices page.
Data we collect
- Account data: email address, normalized email, role, plan, session metadata, support contact details, and account security events.
- Readiness-check answers: the current draft is stored only in your browser's local storage so you can resume. The diagnostic does not send answers, scores, or results to NewsletterIdea, an analytics provider, a search provider, or an AI model.
- Validation Sprint signup data: when you deliberately request the 7-Day Newsletter Validation Sprint, we collect your normalized email, explicit marketing consent, consent-policy version, form and placement keys, and available server-derived attribution. We do not collect or attach your readiness answers, score, stage, or generated brief.
- Legacy scan and purchase data: ideas submitted before the free audit was retired, consent status, completed report access, research references, selected products, checkout status, and delivery state.
- API data: API key metadata, scopes, hashed key material, idempotency fingerprints, usage records, rate-limit events, webhook configuration, and request audit data.
- Logs: error details, request ids, trace ids, LLM call traces, task audit trails, webhook events, and delivery diagnostics needed to operate and debug the service.
- Email data: transactional delivery events for sign-in links, confirmations, support, invoices, and product delivery; marketing email consent and unsubscribe state when marketing is enabled.
Validation Sprint email consent
The Validation Sprint uses double opt-in. We send one transactional confirmation message containing an opaque, single-use link and store only its confirmation-token digest. Marketing starts only after you submit the confirmation form. Re-enabling marketing after an unsubscribe requires fresh consent and a new confirmation.
Unsubscribe and preference changes take effect immediately for pending marketing work. We may retain the consent history and a non-reversible email hash in an active suppression record so an address that opted out, bounced, complained, or was deleted is not contacted again. A safety or legal suppression is not removed through the ordinary preference flow.
AI/LLM processing
NewsletterIdea uses AI/LLM processing for opportunity research, scoring, report generation, and internal quality checks. Prompts and responses can include user-submitted ideas, research context, public-source summaries, operational metadata, and validation instructions. LLM calls are traced for model version, token budgets, finish reason, and cost so truncated or unsafe outputs can be detected.
Human review may be used for quality, fraud prevention, security investigation, payment disputes, and support. We do not treat generated output as legal, financial, tax, investment, or business advice.
Email, payments, hosting, and subprocessors
Transactional email is separated from marketing email. Transactional delivery uses the configured Mailgun EU region and transactional sending domain; marketing messages use the configured marketing domain and consent state. Stripe processes payments, invoices, refunds, and payment-method return behavior. Hosting, monitoring, database, LLM, vector, graph, and email providers may process limited data needed to deliver the service.
See Subprocessors for provider details and Security for security controls. Use Contact for privacy questions.
Your rights and choices
Depending on where you live, you may request access, export, correction, deletion, objection, restriction, or consent withdrawal. Change optional processing through Privacy choices. Use /account when signed in for account data requests, or use /contact if you cannot access your account. We verify requests before disclosing or deleting account-linked data.
Deletion may preserve limited records when required for security, fraud prevention, tax, payment disputes, legal compliance, or audit integrity. Privacy requests are handled without exposing raw API keys, payment secrets, connection strings, prompts that belong to another account, or internal exception details.
Summary rights: access, export, correction, deletion, objection, restriction, and consent withdrawal.