Skip to content

Privacy

What we collect, and what we don't.

Signal is an AI news newsletter and reading service. This page explains the account information, preferences, reading history, and technical data used to provide it, and the choices you have.

Last updated 25 September 2026

What we collect

You can read the public newsletter without an account. If you create one or use account features, we store:

  • Your email address and sign-in information. Passwords are hashed by Supabase; Signal does not store plaintext passwords. If you continue with Google, Google shares the basic account information needed to sign you in.
  • Your preferences. These include questionnaire answers about your role, decisions, active work, subjects you must not miss, and explicit exclusions. Optional settings can include topic controls and followed companies or people where those features are available.
  • Your reading activity. We record saved stories, story opens, relevance feedback, and which stories were shown in your newsletter. This supports personalization, saved-story access, and avoiding repeats in later editions.
  • Email choices and subscription records. We store opt-in status. If you use a standalone email signup, we also store your address, signup source, confirmation and unsubscribe status, timestamps, and hashed link tokens. Newsletter email delivery is currently paused.
  • Feedback and technical information. Feedback submissions and operational logs help us respond to problems. Hosting and analytics providers process request information, page views, performance measurements, and usage events such as opening a story or completing onboarding.

Payments are currently paused. If hosted billing is enabled and you choose to purchase a subscription, the payment provider collects checkout details; Signal stores provider references, subscription status, currency, and billing dates, not full card, bank-account, or UPI credentials. We do not buy data about you or sell or rent your personal data to advertisers or data brokers.

How your feed gets personalized

Your newsletter is selected by code from a shared daily pool using your decisions, active work, must-not-miss subjects, and exclusions. Role can help frame the edition, but does not qualify a story on its own. Explicit exclusions remove matching candidates. The edition also includes broadly important developments and may include clearly labelled continuing context from the preceding day when fresh coverage is thin.

Where Browse is available, its personalized view uses your preferences and relevance signals to rank and filter eligible coverage. Other Browse sections provide broader coverage. Saved stories, opens, and more-or-less-relevant feedback can contribute learned topic or event preferences. Newsletter history records the stories shown to you so later editions can avoid repeating them; it does not mean that you read every story.

You can review and change your answers under Account → Preferences. These automated selections concern news recommendations, not decisions with legal or similarly significant effects on you. We do not use them for cross-site advertising.

Who processes your data

Signal relies on third-party infrastructure. The data each receives depends on the feature you use:

  • Supabase: account authentication and the application database, including preferences, saves, interactions, subscription records, feedback, and edition history.
  • Google: optional authentication when you choose Continue with Google. Google receives the sign-in request and shares basic account information with Supabase.
  • Vercel: hosting, request and error logging, Web Analytics, and Speed Insights. Analytics include page views and custom usage events. Client event properties do not include your email address or the free text you enter in preferences. Vercel describes its analytics identifiers and data handling in its analytics privacy documentation.
  • PostHog: where configured, Web Analytics processes public page views, page exits, performance measurements, and traffic sources. Signal does not send form contents, account identifiers, or URL query strings to PostHog. Admin, account, and authentication pages are excluded.
  • Cloudflare: Turnstile bot verification on public account, newsletter, and feedback forms. It processes browser and request signals needed to distinguish people from automated submissions; Signal does not send the text entered in those forms to Turnstile.
  • Email providers: Supabase and its configured mail infrastructure handle account messages such as confirmation and password resets. Resend is configured for application email where enabled and receives recipient addresses and message content. Pausing newsletter delivery does not stop necessary account messages.
  • Razorpay: hosted checkout and recurring payments if billing is enabled. It receives billing information entered at checkout; Signal receives provider references and status events rather than full payment credentials. Payments are currently paused.
  • Language model providers: the configured free-tier cascade can use Google Gemini, Cerebras, Groq, NVIDIA, Mistral, Z.ai, and OpenRouter as available. Active article-processing calls send public source material and editorial instructions to screen and describe stories, create summaries, and check possible duplicates. These article calls do not send your account details, saved stories, or reader-entered preferences. Code matches the resulting editorial material to readers; a model does not write a separate edition from your account data.

Providers operate under their own privacy and retention practices, and may process data outside your country. Signal does not claim that its application retention rules also control copies in provider systems.

Cookies

Supabase authentication uses cookies to maintain your signed-in session. Signal also uses local storage in your browser to remember your theme, the date you last opened the newsletter, dismissed reading prompts, and your last visit. The last-visit timestamp supports an aggregate return-visit event; it is not an account identifier.

Vercel Web Analytics is cookie-free. Where enabled, PostHog uses its cookieless server hash mode without storing an analytics identifier in your browser. PostHog processes IP address and browser information to count visits, then removes the IP address from analytics events. Signal does not set advertising cookies or use cross-site advertising identifiers. Cookie-free analytics still process technical information and usage events, as described above. You can clear local storage and cookies through your browser; clearing authentication cookies signs you out.

How long we keep things

Published story metadata and editorial summaries are retained as the archive. The application retention routine applies these rules when it runs:

  • Raw source text of published items is cleared after 30 days; summaries and metadata remain.
  • Hidden records and raw records with prior processing attempts are deleted after 90 days. This is not a blanket deletion rule for all failed or pending work.
  • Account preferences, interactions, edition history, and saved-story snapshots are retained until removed through supported controls or an account-deletion request.
  • Unsubscribing changes your email status rather than deleting your account or automatically erasing the subscription record. You can separately request deletion.

Operational and provider logs have separate retention practices. The existence of a retention routine does not guarantee that every deletion happens at an exact daily time.

Your choices

  • Read the public newsletter anonymously. Browse is available in the full-site version; some features are still in build in the newsletter-only version.
  • Review and change your questionnaire answers under Account → Preferences.
  • Where newsletter email is enabled, unsubscribe using its email link without signing in. Account confirmation and password-reset messages are separate.
  • Ask us to export or delete your account and everything attached to it.

For access, correction, export, or deletion requests, write to dhonabhoovan@gmail.com.

Depending on where you live, you may have additional rights over your data, including under the GDPR or comparable laws. We honour those requests regardless of where you are.

Security, and its limits

Access to your data is enforced at the database level: row-level security means ordinary reader accounts can access only their own private saves and preferences. Authorized administrators and service processes have privileged access needed to operate the service. Traffic is served over HTTPS with a strict content security policy. No system is perfectly secure, and we will tell you promptly if we ever learn of a breach affecting your account.

Children

Signal is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children; if you believe we have, contact us and we will delete it.

Changes

If this policy changes in a way that materially affects you, we will say so on this page and, where the change is significant, by email to opted-in readers. The date at the top always reflects the current version.