Privacy policy
DRAFT — for owner review
The sections describing how Newtrly actually processes data are complete and match the product's behavior. The bracketed [TO BE COMPLETED: …] markers are facts only the site owner can supply — fill them in before relying on this page.
Who is responsible for your data
[TO BE COMPLETED: company name and legal form], with registered office at [TO BE COMPLETED: address], is the data controller for the processing described on this page. Contact for privacy matters: [TO BE COMPLETED: privacy contact email].
Data linked to your account
If you create an account, we store what is needed to run it: your email address, your name, an optional avatar, the sign-in method you used, and your product preferences (interface language, theme, display density, default reading level, and the personalization setting described below). We use this data only to provide the service you signed up for, and we keep it for as long as your account exists. You can read and change your profile at any time from your account page.
If you use Newtrly without an account, none of this exists.
Audience measurement — only with your consent
To understand how Newtrly is read, we can record anonymous usage events. None of them is collected unless you consent to audience measurement — through the cookie banner on the website, or the in-app consent prompt in the mobile app. If you refuse, or simply never answer, no event is created, stored, or sent at all: the product works exactly the same, you just don't contribute to the statistics.
With your consent, two kinds of events are recorded:
- Reading events — a story was displayed (view), read to the end (complete), or shared (share). Each event can carry technical reading context: the reading level in use (discovery / standard / expert), where the story was opened from (Trending, For you, a custom feed, search, or a direct link), the platform (web, Android, iOS), and the interface language.
- Navigation events — eight events describing how readers move through the product: a story card became visible in a feed (feed impression), a story was opened (story open), the reading level was switched (level switch), a summary was opened (summary open), a link to an original source article was followed (source click), a search was run (search), the feed tab was changed (feed switch), and a topic filter was applied (topic filter).
The identifier behind these events
Audience events are grouped by a random identifier with no link to your identity — newtrly_sid, stored in your browser on the website, or anon_session_id, stored by the mobile app. This identifier:
- is created only after you consent, at the moment the first event is sent — never before;
- lives at most 13 months, then is replaced by a fresh one;
- is deleted immediately if you withdraw consent (Cookie settings in the website footer, or Settings → Data & privacy in the app), and event collection stops with it.
What we deliberately do not collect
- Navigation events carry no user identifier: the table that stores them has no user column at all, so they cannot be linked to your account — even if you are signed in.
- The text you type into search is never stored. A search event records only the length of the query and the number of results it returned.
Personalization ("For you") — signed-in readers only
If you are signed in, the stories you actually read generate read events (with the time spent reading and how far you scrolled). They feed your personal interest profile, which powers the For you feed. This is part of the service you signed up for — it works without any advertising tracker and does not depend on the cookie banner.
It is controlled by the Personalization setting on your account page (on by default, disclosed at signup):
- turning it off stops read events immediately and visibly disables the For you tab — nothing degrades silently;
- turning it back on resumes where your profile stood.
If you have not accepted audience measurement, your read events are sent with a random one-off identifier that exists only for the current page and is never stored on your device. Anonymous visitors never send read events: without an account there is nothing to personalize, and no reading profile is built about you.
How long we keep usage data
- Raw audience-measurement and reading events are deleted after at most 25 months (the ceiling recommended by the CNIL, the French data protection authority, for audience measurement).
- Beyond that, we keep only daily aggregates — counts per day, per event type, per platform, and so on — that contain no identifier of any kind (no session id, no user id, no timestamps within the day). These are anonymous statistics.
Cookies and local storage
The website only sets strictly necessary cookies and storage without asking: your session when you are signed in, your language, theme, and display-density choices, and the record of your consent decision itself. These are exempt from consent.
The audience-measurement identifier described above is only stored after you opt in. The consent banner also declares an advertising purpose, but no advertising tracker is currently loaded — the choice exists ahead of any such script ever shipping.
Your consent decision is remembered for 6 months, after which the banner asks again. You can change your mind at any time via Cookie settings in the website footer, or Settings → Data & privacy in the app.
Your rights
You can ask for access to, correction of, or deletion of your personal data, object to a processing operation, or ask for your data in a portable format. To exercise these rights, contact [TO BE COMPLETED: privacy contact email / postal address]. You can also lodge a complaint with your supervisory authority — in France, the CNIL (cnil.fr).