Privacy
Privacy Policy
Last updated
Infolitico uses passwordless email sign-in only for its separate Reader Feed discussion. We do not sell reader data, display sign-in email addresses, or send local comments to Reddit.
Cookies and similar storage
infolitico-cookie-notice-dismissed— browserlocalStorageentry with the valuetruethat records your analytics consent choice. Selecting “Got it” closes the notice and records the consent used by the site’s PostHog product-analytics and return-visit measurement controls; it is not advertising consent.- PostHog product analytics, browser Sentry error and performance diagnostics, and Vercel Speed Insights performance metrics initialize only after you select “Got it” in the site notice. If you do not select it, those client telemetry tools remain off.
- Server-side error monitoring, hosting logs, and security logs are separate operational systems and may run without browser analytics consent.
infolitico_first_visit— browserlocalStoragetimestamp for the first visit in the current seven-day return-visit window.infolitico_first_referrer— browserlocalStorageentry for the first visit’s broad referrer category (for example, search, social, or direct), not a full referral URL.infolitico_return_fired— browsersessionStorageentry that prevents more than one return-visit event during a browser session.
Data we collect
- The referrer header on a request, classified only into broad traffic channels for aggregate analytics.
- Standard server logs retained by hosting and infrastructure providers for operations and abuse prevention.
- Aggregate product analytics events such as page views, story clicks, outbound source clicks, shares, and engagement buckets. Campaign attribution is limited to an allowlist of documented channel and campaign values; unexpected free-form UTM values are discarded.
- Email content and headers from messages you send to retractions@infolitico.com or hello@infolitico.com.
- For signed-in Feed readers, Supabase stores the account email and session data. Public comments display only a database-derived pseudonym such as
Reader-a1b2c3d4. - Local Feed comments, edit timestamps, report reason codes, and moderation audit records. Reports and audit records do not store comment text or email addresses.
- Account, profile, and comment records created before the current Reader Feed surface may remain in Supabase as legacy data. Owner-only database read policies for that legacy profile and comment data are owner-gated, so their live state must be verified separately rather than inferred from this policy.
- For the optional morning newsletter, Supabase stores the email address, consent version and timestamps, confirmation state, and suppression state. Legacy signup addresses are not treated as confirmed and must opt in again.
Morning newsletter
Newsletter signup uses double opt-in: submitting the form creates a pending record, and delivery is allowed only after the reader follows the confirmation link. Every message includes a one-click unsubscribe link; unsubscribing preserves a minimal suppression record so the address is not mailed again. Pending confirmation tokens expire after 24 hours. The first digest remains blocked until automated cleanup can delete unconfirmed records after 30 days; until that gate passes, confirmation delivery is not activated. Suppression and consent evidence are retained only as long as needed to honor the reader’s choice and demonstrate consent.
Newsletter engagement is measured only as aggregate subscribe, confirm, open, click, and return events. It is not used for political profiling. Digest items reuse the published Infolitico headline and links to the Infolitico story and original source; an email model does not rewrite news facts or Scripture.
Third-party services
- Vercel — hosting and edge delivery, plus consent-gated browser performance metrics through Speed Insights.
- PostHog — consent-gated product analytics for aggregate readership and feature usage.
- Sentry — server-side error reporting and consent-gated browser error and performance diagnostics.
- Supabase — story database, storage, passwordless authentication, and local Feed discussion.
- Resend — newsletter delivery processor. It sends the double opt-in confirmation email when a reader signs up and will deliver the morning digest once digest delivery is activated.
- Google Reader Revenue — after you select “Got it” in the site notice, we load Google’s Reader Revenue Manager (Subscribe with Google) to offer optional reader-support and newsletter choices through an on-page prompt on eligible story pages. When it loads, Google may set cookies and process related data under Google’s Privacy Policy. If you choose to contribute or subscribe through the prompt, Google Payments handles the transaction and shares the details needed to fulfill it (such as your email address) with us under its own terms. It is reader-revenue tooling, not display advertising, and it does not run before consent.
- Advertising — Google AdSense is the only approved display-ad provider. Our code requests exactly one labeled, fixed-size unit in the footer of eligible listing pages — never inside articles, Scripture, the Verse Index, policy pages, or account surfaces — and the ad elements and any pending ad queue entries are removed when you navigate away or withdraw consent — no new ad request can occur after that point (Google’s in-memory library unloads with the next full page load). Auto Ads formats (anchor, vignette, in-content insertion) stay off in our AdSense account configuration; the site itself only ever issues that single manual-unit request. Ads are contextual and non-personalized: the tag is configured with non-personalized requests and we do not build or use advertising audiences. An ad request is issued only after you select “Got it” in the site notice, and any Global Privacy Control signal (browser setting or Sec-GPC header) withholds all ad requests. Readers in the EEA, the United Kingdom, and Switzerland — including their associated territories — receive no ad requests at all because we do not operate a Google-certified consent-management platform for those regions. Google processes data under its own privacy policy, and you can manage Google ad personalization at My Ad Center. Advertising can be switched off globally at any time; when it is off, the site issues no ad requests and carries no ad code.
Children
Infolitico is intended for adult readers. We do not knowingly collect data from children.
Your choices
Signed-in readers can edit or delete their own visible Feed comments from the discussion page. Deleting a comment removes its text; privacy-safe report and moderation records may retain the comment identifier, reason/action, and timestamps for abuse prevention and accountability. To request account deletion or exercise other privacy rights, email hello@infolitico.com. Story removal requests belong at retractions@infolitico.com.
Contact
- Corrections and removal requests: retractions@infolitico.com
- General questions, press, partnerships: hello@infolitico.com