Privacy Policy
No cookies. No trackers. Just a newsletter.
We collect the minimum data needed to run the newsletter. We never sell your information, and we do not use cookies or client-side tracking on this site.
What we collect
When you subscribe to Feedfree Digest, we collect your email address and the topic categories you choose. That's it. We do not collect names, IP addresses, browsing behavior, device fingerprints, or any other personal data.
How we use your data
- To send you the newsletter issues you signed up for.
- To confirm your subscription via a one-time confirmation email.
- To measure the overall performance of our newsletter (e.g., how many subscribers we have in each topic).
Third-party services we rely on
We use the following services to operate the newsletter. Each receives only the data it needs to perform its function:
- Listmonk — stores your email, topic preferences, and subscription status so we can send you issues. Listmonk privacy policy.
- Supabase — hosts our signup database and runs the server-side functions that process subscriptions. Supabase privacy policy.
- Resend — delivers the confirmation email when you first sign up. Resend privacy policy.
- GitHub Pages — hosts this website's static files; GitHub may collect standard server logs. GitHub privacy statement.
Ad conversion measurement
We occasionally run ads on platforms like X (Twitter) to let people know about the newsletter. When someone subscribes after clicking one of those ads, we want to know whether the ad was effective — so we do not waste money on ads that do not work.
Here is exactly how that measurement works, and what it does not:
What happens
- If you arrive via an ad on X, the URL may contain a click identifier (
twclid) and UTM parameters (utm_source=x,utm_medium=cpc). Our website reads these from the URL in memory only — nothing is written to disk or stored in a cookie. - When you submit the signup form, your email is sent to our server. The server hashes your email using SHA-256 before it ever leaves our infrastructure.
- If the signup came from a paid X ad (determined by the UTM parameters), our server sends only the hashed email and the click identifier back to X's Ads API. X uses these to confirm that someone who clicked the ad later subscribed — which helps us understand whether the ad was worth running.
What does NOT happen
- We do not set cookies or use any form of browser storage for tracking.
- We do not build advertising profiles or audience segments.
- We do not retarget visitors with ads elsewhere on the web.
- We do not send your email or hashed email to any ad platform unless you arrived via an ad on that specific platform.
- We do not store click identifiers in our database — they are used once, in memory, for the conversion API call.
Why we believe this does not require cookie consent
This measurement is entirely server-to-server. No information is stored on your device. The hashed email sent to the ad platform is a one-way pseudonymous identifier that only the ad platform can reconcile — it cannot be reversed by anyone else. Under both GDPR (legitimate interest — measuring ad effectiveness) and the ePrivacy Directive (no storage or access to the end user's device), this approach does not require a cookie banner.
No cookies. No consent banner.
This site does not use cookies, localStorage, fingerprinting, or any other form of client-side tracking. Because we do not store or access information on your device, we do not display a cookie consent banner.
Your privacy rights
Depending on where you live, you may have rights under laws like the GDPR (EU/UK), CCPA/CPRA (California), or similar regulations. These can include the right to:
- Know what personal data we hold about you.
- Request that we delete your personal data.
- Opt out of the "sharing" of personal data for cross-context behavioral advertising.
California residents (CCPA/CPRA)
Under California law, the forwarding of a hashed email address to an ad platform for conversion measurement may be considered a "share" for cross-context behavioral advertising in some interpretations. While we believe our limited server-side measurement falls under the "service provider" and "business purpose" exceptions (since we are measuring our own ad performance, not building behavioral profiles for others), we want to make opting out simple.
To opt out of all data sharing, simply unsubscribe from the newsletter. Every issue includes a one-click unsubscribe link. Once unsubscribed, your email is removed from our mailing list and no further data about you is processed or shared with any third party. You can also email privacy@feedfree.tech to request immediate deletion of your data.
We do not and will not sell personal information for money. The only "sharing" that occurs is the hashed-email conversion measurement described above, and only when you arrived via an ad from that platform.
EU/UK residents (GDPR)
Our legal basis for processing your email address is your consent (you chose to subscribe) and our legitimate interest in measuring whether our ads are effective (for the limited conversion measurement described above). You can withdraw consent at any time by unsubscribing. To request a copy of your data or its deletion, email privacy@feedfree.tech.
Data retention
We keep your email address and topic preferences for as long as you remain subscribed. When you unsubscribe, your data is removed from our mailing list. Database backups may retain your information for up to 30 days after deletion.
Contact
For privacy questions or data requests, email privacy@feedfree.tech.
Last updated: July 16, 2026.