Legal
Privacy Policy
Last updated: 9 June 2026
1. Who we are
Newsweaver is a B2B SaaS tool that turns weekly team updates into a clean digest for the rest of the company. This policy explains what we collect, how we use it, and the choices you have. It applies to newsweaver.app and any related services.
"We," "us," or "Newsweaver" means the entity operating this service. "You" means the person using it, either as an individual user or on behalf of a company.
2. What we collect
Account information
- Your name, email address, and (if you sign in with Google or Microsoft) the profile information that provider returns: name, email, avatar URL.
- Company name and team setup details you enter during onboarding.
- Authentication metadata: hashed passwords (never plaintext), session tokens, login timestamps.
Content you submit
- Weekly updates you write into Newsweaver: wins, blockers, next-week priorities, free-text fields.
- Glossary terms, prompt customizations, content filter rules, and any configuration you save.
- Content pulled from third-party integrations you explicitly connect (Linear, GitHub, Notion, Jira, Asana, Monday). We only pull what you authorize at connection time.
Usage data
- Logs of feature usage, errors, and performance metrics. Used to keep the service running.
- IP address and basic device info captured by our hosting provider.
What we do not collect
- Payment card details. Billing is handled by Stripe, which stores card data on its side under its own privacy policy.
- Any data from integrations you have not connected.
- Tracking pixels or third-party advertising identifiers.
3. How we use it
We use your information to:
- Provide the service: generate digests, route emails, persist your settings.
- Authenticate you and keep your account secure.
- Communicate with you about your account, billing, and product changes.
- Investigate bugs, monitor reliability, and improve performance.
- Detect abuse and comply with legal obligations.
We do not sell your data. We do not share it with advertisers. We do not use it to build profiles outside Newsweaver.
4. AI and your content
Newsweaver uses third-party AI providers to turn raw weekly updates into a readable digest. When we send your content to these providers:
- No training. Your content is not used to train any AI model, ours or the provider's. We use enterprise API endpoints that contractually prohibit training on submitted data.
- Transient processing. Content is sent, a response is generated, and the request ends. The provider does not retain your content beyond what is required to deliver the response.
- No human review. Outputs are generated programmatically. No Newsweaver employee or provider employee reads your weekly updates as part of normal operation.
You can see the exact AI subprocessor in section 5 below.
5. Sharing and subprocessors
We share your data only with the third-party services we use to run Newsweaver. Each is a subprocessor under a written data processing agreement.
- Railway: cloud hosting for our app and database (United States).
- Anthropic: AI provider for digest generation. Enterprise tier, no training on submitted data.
- Resend: transactional email delivery (password resets, invites, digests).
- Google Cloud Identity: OAuth sign-in for users who choose Google.
- Microsoft Identity Platform: OAuth sign-in for users who choose Microsoft.
- Stripe: payment processing for paid plans.
- Sentry: error reporting (only error metadata, not your content).
We may also disclose data if required by law, to protect our rights or yours, or as part of a corporate transaction (merger, acquisition). We will notify you in advance where the law permits.
6. Storage, security, retention
- Storage. Data is stored in encrypted Postgres databases hosted on Railway, with daily backups.
- In transit. All traffic is encrypted via HTTPS (TLS 1.2 or higher).
- At rest. Database storage is encrypted by our hosting provider. Passwords are hashed with bcrypt (work factor 12).
- Access. Only authorized Newsweaver staff with operational need can access production systems. Access is audited.
- Retention. We keep your data for as long as your account is active. If you delete your account, we delete personal data within 30 days, except where retention is required for legal, accounting, or fraud-prevention purposes.
7. Your rights
Depending on your jurisdiction (Singapore PDPA, EU/UK GDPR, California CCPA), you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your account and data.
- Export your data in a portable format.
- Object to certain processing.
- Withdraw consent at any time.
To exercise any of these, email [email protected]. We respond within 30 days.
8. Cookies
We use a small number of cookies that are strictly necessary for the service to function. We do not use advertising or analytics cookies.
- Session cookie. Set after you sign in. Used to keep you logged in. HttpOnly, Secure, SameSite=Lax.
- OAuth state cookie. Set during sign-in with Google or Microsoft. Prevents CSRF on the OAuth callback.
You can clear these any time from your browser. Doing so will sign you out.
9. International transfers
Newsweaver is operated from Singapore. Our subprocessors are located in Singapore, the United States, and the European Union. Where data is transferred out of your jurisdiction, we rely on the legal mechanisms available (standard contractual clauses, adequacy decisions, or your consent at sign-up).
10. Children
Newsweaver is a workplace tool not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify account admins via email at least 14 days before the change takes effect. Continued use after the effective date constitutes acceptance.
Questions or requests: