Privacy
This describes how CoreNewsletter actually behaves, not how we would like to be seen. Where something cannot be promised, it says so.
The short version
- Your data is never sold, never used for advertising, and never used to train anything.
- Nothing you send is shown to anyone outside the newsletter it was sent to.
- Articles are deleted once they have been published, not kept.
- You can have everything about you deleted without holding an account.
What is stored, and why
If you run a newsletter
Your email address, the name of your newsletter and its settings, and the lists of people who write for it and read it. A payment reference is held once you pay; card numbers never reach this service at all, because payment is handled on the payment provider's own page.
If you write for a newsletter
Your email address, the name you appear under, and the articles and pictures you send in — for as long as it takes to publish them.
If you read a newsletter
Your email address, and which newsletters you receive. Nothing else. We do not record whether you opened an issue or what you clicked.
How long it is kept
- The email you send in is deleted as soon as it has been read and turned into an article.
- Articles and pictures are deleted once they have appeared in every newsletter they were waiting for. Something sent to two newsletters on different schedules survives until the later one has published it.
- Anything never published is deleted after 60 days.
- A compiled issue exists only long enough to be sent, then it is deleted. There is no archive of past issues, and no way for anyone to be sent one again.
- Account data — the lists and settings — is deleted 30 days after a newsletter ends.
What deletion cannot do
Pictures are embedded in the email itself rather than linked from a server. Once an issue has been delivered, a permanent copy sits in every recipient's inbox, beyond anything this service controls. Deleting data here reduces what could be exposed if this service were ever breached; it does not make anything disappear from the inboxes it has already reached.
That is true of any email, and it is why nothing here is described as private in a stronger sense than an ordinary email to your family is private.
Encryption
Everything stored is encrypted at rest, and everything in transit uses TLS. Email itself cannot be end-to-end encrypted here, because the newsletter has to be assembled and delivered in a form your family's email programs can read. Your data is as private as an email you send to someone yourself — no more, and no less.
Who it is shared with
Nobody, other than the infrastructure needed to run the service: Amazon Web Services, which stores the data and sends the mail, and the payment provider, which sees only what is needed to take a payment from the person running a newsletter. Neither is permitted to use it for their own purposes. Your data is never sold, and never handed to advertisers.
Your choices
- Stop receiving one newsletter — the unsubscribe link at the bottom of every issue. It asks before it acts, and it never stops working.
- Stop receiving everything — the same link offers leaving every newsletter on the service, including ones you are added to later.
- Delete everything about you — Delete my information. No account needed. You enter your address, confirm through a link sent to it, and you are removed from every list with your stored content deleted.
Children
People who run a newsletter must be 18 or older; people who write for one must be 14 or older. There is no age limit on receiving one, since a reader gives us nothing but an address somebody else supplied. We do not knowingly collect anything from a child under 14. If you believe we have, write to support and it will be deleted.
Where this applies
The service is operated in the United States and intended for people there. Data is stored in the United States.
Changes
If this changes in a way that affects what happens to your data, the people running newsletters will be told by email before it takes effect.