Privacy policy
Effective 2026-08-22. Operated by FeedAtom.
This policy explains what FeedAtom stores about you, why, and what you can ask us to do about it. It is written to meet India's Digital Personal Data Protection Act 2023, and follows the GDPR's basics for readers outside India.
Who is responsible
FeedAtom, at PLACEHOLDER - postal address not yet set, decides what personal data FeedAtom collects and why - the data fiduciary under the DPDP Act, and the controller under the GDPR. Reach us at [email protected].
What we store
Your account email address and the display name your sign-in provider gives us; your preferences (the topics you follow, your delivery time, your timezone and how many stories you want); delivery records (that a digest was sent to you, and whether it was accepted, bounced or failed); engagement events - that a digest was opened, and that a link in it was clicked, measured by a small image loaded when the message is displayed and by links that pass through us on their way to the publisher; and your subscription record (which plan, which state, which coupon). We do not store your password - your sign-in provider does. We collect no payment details, because no payment processor is connected yet.
Why we store it
To sign you in, to select and send the digest you asked for, to know whether it arrived so we can stop sending to an address that bounces, to measure in aggregate which stories are read so ranking can improve, and to keep an honest record of your subscription.
On what basis
Under the DPDP Act we rely on your consent, given when you create an account and set up your digest, and on legitimate uses for keeping the service running and secure. Under the GDPR the equivalent bases are performance of our contract with you and our legitimate interest in a working, secure product. You may withdraw consent at any time by unsubscribing or closing your account.
Who else touches it
We use a small set of processors, each bound to act only on our instructions. Hetzner (servers, in Germany) hosts the application and the databases. Coolify runs our deployments onto those servers. Zitadel handles sign-in and therefore holds your credentials and your email address. Resend delivers email and therefore sees your address and the digest we send. Backblaze B2 stores files, including rendered digests. Infisical holds our secrets and never your data. If you choose Telegram as a delivery channel, Telegram sees your Telegram account and the digest. We also use artificial-intelligence providers - Microsoft Azure (for OpenAI and Anthropic models), Google, OpenRouter and Anthropic - which read published news articles; the next section explains why your own data never reaches them. We do not sell personal data, and we do not share it for advertising.
Artificial intelligence and your data
We use AI to read news articles that publishers have already published, to pull out what they report, to group articles covering the same event, and to translate. Those are the only things our AI providers receive. We do not send them your email address, your name, your preferences, your reading history or anything else about you, and no AI system profiles you or decides anything about you. If that ever changes we will say so here before it does.
How long we keep it
Account, preference and subscription data lasts while your account exists and for 90 days after you close it, so an accidental closure can be undone. Delivery and engagement events are kept for 12 months and then removed. Records we must keep for tax or legal reasons are kept for as long as that law requires, and no longer.
Your rights
You may ask us for a copy of what we hold, ask us to correct it, ask us to erase it, withdraw your consent, and nominate somebody to exercise these rights if you cannot. Under the GDPR you may also object to processing, ask us to restrict it, and receive your data in a portable form. Write to [email protected] and we will answer within 30 days.
How we protect it
Traffic is encrypted in transit. Access to the database is limited to the one service that owns it, and rows are scoped to their owner inside the database itself rather than only in application code. Secrets live in a vault, never in the codebase. If a breach affects you, we will tell you and the Data Protection Board as the DPDP Act requires.
Children
FeedAtom is not for children under 18. We do not knowingly create accounts for them, and we do not profile or target advertising at any user. If you believe a child has an account, write to [email protected] and we will remove it.
Changes to this policy
We will post any change here before it takes effect, and the effective date at the top says which version is in force.
Grievance officer
Under the DPDP Act you may raise a complaint with our grievance officer, PLACEHOLDER - grievance officer not yet named, at [email protected], or by post to FeedAtom, PLACEHOLDER - postal address not yet set. We acknowledge every complaint within 24 hours and aim to resolve it within 15 days. If we do not resolve it, you may take it to the Data Protection Board of India.