Last updated July 30, 2026
Scope
This policy covers NewsletterIdea.com, customer account pages, the public API, free scans, paid research, support, transactional email, marketing email, and operational logs.
How NewsletterIdea collects, uses, protects, and deletes account, scan, payment, email, API, support, and operational data.
Last updated July 30, 2026
This policy covers NewsletterIdea.com, customer account pages, the public API, free scans, paid research, support, transactional email, marketing email, and operational logs.
NewsletterIdea uses AI/LLM processing for opportunity research, scoring, report generation, and internal quality checks. Prompts and responses can include user-submitted ideas, research context, public-source summaries, operational metadata, and validation instructions. LLM calls are traced for model version, token budgets, finish reason, and cost so truncated or unsafe outputs can be detected.
Human review may be used for quality, fraud prevention, security investigation, payment disputes, and support. We do not treat generated output as legal, financial, tax, investment, or business advice.
Transactional email is separated from marketing email. Transactional delivery uses the configured Mailgun EU region and transactional sending domain; marketing messages use the configured marketing domain and consent state. Stripe processes payments, invoices, refunds, and payment-method return behavior. Hosting, monitoring, database, LLM, vector, graph, and email providers may process limited data needed to deliver the service.
See Subprocessors for provider details and Security for security controls. Use Contact for privacy questions.
Depending on where you live, you may request access, export, correction, deletion, objection, restriction, or consent withdrawal. Use /account when signed in, or use /contact if you cannot access your account. We verify requests before disclosing or deleting account-linked data.
Deletion may preserve limited records when required for security, fraud prevention, tax, payment disputes, legal compliance, or audit integrity. Privacy requests are handled without exposing raw API keys, payment secrets, connection strings, prompts that belong to another account, or internal exception details.
Summary rights: access, export, correction, deletion, objection, restriction, and consent withdrawal.