Privacy Policy

How we handle your data

We collect only the account, device-profile, preference, purchase-status, saved-reference, service-activity, and limited product-analytics metadata needed to operate and improve Signal/noise. We do not sell it, share it with advertisers, or use it to train AI models. Publisher credentials, publisher cookies, and authenticated article bodies stay off Signal/noise servers and analytics.

Effective July 15, 2026 · Last updated July 15, 2026

1. Who we are

Signal/noise (“we,” “us,” “our”) operates s2n.news, the related email digest, and the Signal/noise iOS app. We are a news intelligence platform that organizes reporting and analyzes how media sources cover the same stories.

For questions about this policy or your data, contact us at [email protected].

2. What we collect and why

We follow the principle of data minimization: we collect only what is necessary to operate the Service, and nothing more.

2.1 Information you provide directly

DataPurposeLegal basis
Email addressAccount creation, digest delivery, account communicationsContractual necessity; consent for marketing
Password (hashed)Account authentication — stored only as a cryptographic hash, never in plain textContractual necessity
TOTP secret (encrypted)Two-factor authentication, if you enable itConsent
Topic preferencesPersonalizing your story feed and digest contentContractual necessity
Locality, source, publisher, subscription-claim, voice, and alert choicesBuilding and operating your personalized Yours feedContractual necessity
Custom source names or public URLsResolving a source you explicitly ask us to followContractual necessity
Prediction votesComputing your Forecaster Score and community statisticsContractual necessity
Bookmarks and reading interactionsSaving stories, computing blindspot reports, personalizing recommendationsContractual necessity
Reality Check submissionsProcessing your fact-check request — claim text is sent to our AI provider without your identity attachedContractual necessity
Referral activityCrediting referrals to the referring user’s accountLegitimate interest

2.2 Information collected automatically

DataPurposeRetention
Session cookie (sn-session)Keeping you logged in — contains only a session identifier, no tracking or advertising dataDuration of session
Email delivery metadataDelivery confirmations, bounce detection, open tracking for deliverability monitoring via our email provider (Resend)90 days
Server access logsSecurity monitoring and debugging — includes IP addresses, request timestamps, and user agents30 days, then automatically rotated and deleted
Pseudonymous device profile and installation IDResuming onboarding, enforcing membership, syncing preferences, and securing device-scoped requestsUntil profile deletion or reset
App version, platform, OS version, and device push tokenCompatibility, security, and alerts you enableUntil token replacement, profile deletion, or opt-out
App Store product, entitlement status, expiration, renewal state, and pseudonymous RevenueCat app-user IDPurchasing, restoring, and enforcing membershipFor the membership relationship and required transaction records
Saved article reference metadata and reading positionShowing your saved shelf and resuming on another deviceUntil you remove the save or delete the profile
Story opens and change acknowledgementsShowing ‘Since you looked’ and avoiding repeated change noticesUntil profile deletion
Website and iOS product-analytics eventsMeasuring feature use and reliability. iOS onboarding sends only an allowed event name, booleans, and coarse count/readiness buckets under a pseudonymous profile ID; it excludes raw location, searches, source names, headlines, URLs, article text, and reading content. Website events may include an in-memory session identifier, internal account ID and email after sign-in, public story/feature identifiers, coarse choices and counts, and browser/device metadataUnder our configured PostHog retention or until an applicable deletion request is completed

2.3 Information we do NOT collect

We do not collect your payment-card or bank details; Apple processes App Store purchases. We do not collect publisher passwords, one-time codes, publisher cookie values, or authenticated premium article bodies on Signal/noise servers. We do not request precise location, contacts, photo library, or biometric templates. We create a pseudonymous installation/profile identifier for service security and continuity, but do not use it for advertising or cross-company tracking.

We do not deploy third-party advertising trackers, retargeting pixels, cross-site tracking scripts, device fingerprinting, or behavioral-advertising technology. We use PostHog for limited first-party product analytics on the Signal/noise website and for a small allowlist of pseudonymous, coarse iOS product events. We disable automatic capture, session recording, geolocation enrichment for these mobile events, and person-profile creation; Signal/noise sends only explicit product events. PostHog is not used inside the authenticated publisher reader and never receives publisher credentials, cookies, premium article bodies, raw iOS searches, raw location, story headlines, or reading content from us.

3. How we use your information

We use your information for the following purposes only:

Service operation. Delivering your daily digest email, generating personalized analyses, displaying your prediction history and scores, computing blindspot reports, and maintaining your account.

Service improvement. Analyzing aggregate and account-linked engagement data (such as overall open rates and feature adoption) to improve content quality and product features. We do not use this data for advertising or build behavioral profiles for sale or cross-company marketing.

Communications. Sending your daily digest, weekly blindspot reports, product updates, and essential account notices (password resets, security alerts, material Terms changes). Every non-essential email includes an unsubscribe mechanism.

Security. Monitoring for unauthorized access, abuse, and fraudulent activity.

We do not use your personal information for any purpose not listed above.

4. AI processing

Signal/noise uses artificial intelligence (currently Anthropic’s Claude) to analyze news coverage, generate framing analyses, produce digest content, and power features including Reality Check, Deep Dive, and micro-predictions.

Your personal data and authenticated publisher content are not sent to AI providers.Our AI pipeline processes publicly available news headlines and article metadata — not your identity, email address, publisher credentials, cookies, or premium article body. Your preferences may influence which public analysis you see, but they are not included in model prompts or used in AI training datasets.

Reality Check.When you submit a claim for fact-checking, the text you provide is sent to our AI provider for analysis. We strip all user-identifying information before sending the request. The claim text itself is processed under Anthropic’s API data usage policy, which does not use API inputs for model training.

5. Data sharing and third parties

We do not sell, rent, lease, or trade your personal information. We do not share your data with third parties for their marketing or advertising purposes.

We use a limited number of third-party services to operate Signal/noise:

ServicePurposeData shared
ResendEmail deliveryEmail address, delivery metadata
AnthropicAI-powered analysisNews headlines and article metadata only — no personal data
DigitalOceanServer hostingStandard server logs (IP addresses)
Apple App StoreIn-app purchase, billing, renewal, cancellation, and restorePurchase and subscription records under Apple’s policies; Signal/noise does not receive payment-card details
RevenueCatSubscription entitlement infrastructurePseudonymous app-user ID, product and entitlement status, transaction and expiration dates, app/platform metadata
Apple Push Notification serviceDelivering alerts you enableDevice push token and notification metadata; no premium article body
PostHogLimited website and pseudonymous iOS product analytics, plus email-funnel measurementExplicit events and coarse choices/counts. Website events may use an internal account ID and email for identified users; iOS onboarding uses a keyed pseudonym and excludes raw location, searches, source names, headlines, URLs, article text, reading content, publisher credentials, cookies, and premium article bodies
ElevenLabsPodcast audio generationAI-generated script text only — no personal data
PolymarketPrediction market dataNo user data sent — we only read publicly available market data
Let’s EncryptSSL/TLS certificateDomain name only

We require all service providers to process data only for the purposes we specify and in accordance with applicable data protection laws.

Publisher websites are separate services. When you open or sign in to a publisher inside the visible iOS web session, your device connects directly to that publisher and any identity provider it uses. The publisher may receive your IP address, browser/device information, article URL, login information you enter, and cookies under its own privacy policy. Signal/noise does not proxy that login, read your password, or upload the publisher session or authenticated article body to our servers.

We may disclose your information if required by law, subpoena, or court order, or if we reasonably believe disclosure is necessary to protect our rights, your safety, or the safety of others.

6. Cookies and tracking

The Signal/noise website uses one strictly necessary first-party session cookie:

CookieNamePurposeTypeDuration
Sessionsn-sessionAuthentication — keeps you logged inStrictly necessary (first-party)Session

Signal/noise does not use advertising cookies, analytics cookies, or cross-site tracking. Our website analytics configuration keeps its temporary analytics state in memory rather than cookies, local storage, or session storage; it is not designed to recognize an anonymous visitor after the page session ends. If you sign in, explicit events may still be associated with your Signal/noise account ID as described above. Separately, publisher webpages opened in the iOS app may set their own cookies in a persistent on-device WebKit profile so you do not have to sign in every time. Those publisher cookies are controlled by the publisher’s policy, remain on the device, are not sent to Signal/noise servers, and can be cleared with Disconnect; uninstalling the app also removes app-held website data.

7. Data storage and security

Signal/noise server data is stored on secured infrastructure hosted by DigitalOcean in the United States. RevenueCat and Apple process subscription information on their own infrastructure under their policies. Device-local publisher sessions and explicitly saved premium bodies remain in protected iOS app storage.

Security measures include:

No method of electronic storage or internet transmission is 100% secure. We implement industry-standard protections appropriate to the sensitivity of the data we hold, but cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify affected users and applicable regulatory authorities in accordance with applicable law.

8. Data retention

Data typeRetention period
Account data (email, preferences, scores)Until you delete your account
Reading interactions and predictionsUntil you delete your account
Device-scoped profile, preferences, alert settings, and publisher-connection statusUntil you delete the profile or linked account
Saved reference metadata and reading positionUntil you remove the save or delete the profile
APNs device tokenUntil replacement, alert opt-out, or profile deletion
Device-local publisher cookies and explicitly saved premium bodiesUntil Disconnect, local-clear/delete action, app deletion, or operating-system removal
Purchase and entitlement recordsAs needed to provide access and meet Apple, RevenueCat, accounting, fraud-prevention, and legal requirements
Email delivery logs90 days
Server access logs30 days (auto-rotated)
PostHog product-analytics events and identified user propertiesUnder our configured PostHog retention or until an applicable deletion request is completed; aggregate or deidentified statistics may remain
Anonymized aggregate dataIndefinitely (cannot identify individuals)

When you delete your account, we delete your personal data within 30 days. Some data may persist in encrypted backups for up to 90 days, after which backups are cycled out.

9. Your rights

We provide the following rights to all users regardless of location. These rights meet or exceed the requirements of GDPR, CCPA/CPRA, and other applicable privacy frameworks.

Right to access. You can request a copy of all personal data we hold about you.

Right to correction. You can update your email address and preferences through your account settings at any time.

Right to deletion. You can delete a device-scoped profile or linked account through the iOS app, or contact us. The app also clears its local saved premium bodies and publisher sessions within the selected deletion scope. Server-held personal data is deleted within 30 days, subject to required transaction, security, fraud-prevention, and backup retention. Profile deletion does not cancel an Apple subscription.

Right to data portability. You can request an export of your data (account information, prediction history, reading history) in a machine-readable format (JSON).

Right to restrict processing. You can request that we limit how we process your data while we address a concern.

Right to object. You can object to any processing based on legitimate interest. We will honor your objection unless we have compelling grounds to continue processing.

Right to opt out of email. You can disable the daily digest and product updates through your account settings. You will still receive essential account communications (password resets, security alerts, material policy changes).

Right to non-discrimination. We will never provide a lesser service to users who exercise their privacy rights.

For California residents (CCPA/CPRA):We do not sell or share your personal information as defined by the CCPA. We do not use your personal information for cross-context behavioral advertising. Because we do not sell or share personal information, a “Do Not Sell or Share” opt-out is not applicable, but we will honor any such request as a matter of policy.

For EU/EEA residents (GDPR): Our lawful bases for processing are contractual necessity (operating the Service you signed up for), consent (where explicitly obtained, such as marketing emails), and legitimate interest (security monitoring, service improvement). You have the right to withdraw consent at any time without affecting the lawfulness of processing performed prior to withdrawal.

To exercise any of these rights, contact [email protected]. We will respond within 30 days (or within the timeframe required by applicable law). We will not charge a fee for reasonable requests. We may request identity verification before processing your request.

10. International data transfers

Our servers are located in the United States. If you are accessing Signal/noise from outside the United States, your data will be transferred to and processed in the United States. We rely on the following safeguards:

11. Children’s privacy

Signal/noise is not directed at children under the age of 16. We do not knowingly collect personal information from anyone under 16. If we become aware that we have collected data from a child under 16, we will delete it promptly. If you believe we have inadvertently collected data from a minor, contact us at [email protected].

12. Changes to this policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or for other operational reasons. If we make material changes, we will notify you via email or a prominent notice on the website at least 14 days before the changes take effect. The effective date at the top of this policy indicates when it was most recently revised.

Your continued use of the Service after the effective date of a revised policy constitutes acceptance of the updated terms.

13. Contact and complaints

For questions, data requests, or complaints regarding this Privacy Policy:

Email: [email protected]

Website: https://s2n.news

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection authority.