Private beta
Privacy Policy
Approved for the private beta · prepared 19 July 2026 · not yet published externally
Bulletin is a small, India-first private beta operated by Sougandh Manoj. This policy explains, in plain language, what the service collects and why.
1. Information you provide
When you create a Bulletin, we collect your name, email address, country, state or region, optional city, language, selected categories, custom and excluded topics, desired story count, frequency, delivery day where relevant, delivery time, timezone, theme, and consent record.
Google and Supabase Auth provide the identity and session information needed to sign you in. Apple sign-in may be added later; if enabled, Bulletin will use the verified address or Hide My Email relay address Apple provides. Bulletin also keeps short-lived owner-access records for securing operations access. OAuth credentials and raw session tokens are not stored in the subscriber database.
2. Why we use it
- to authenticate your account and prevent duplicate Bulletins;
- to select and schedule a briefing from your explicit choices;
- to deliver and manage your email briefing;
- to pause, resume, or delete the service when you ask; and
- to protect the service, enforce rate limits, diagnose failures, and prevent duplicate delivery.
Bulletin does not use click tracking, targeted advertising, hidden interest profiles, or behavioural personalization.
3. News and automated processing
Bulletin processes public RSS and Atom news metadata, including titles, descriptions, publisher names, publication times, categories, and original links. It uses automated rules to normalize, classify, group related reports, assess evidence, and match verified stories to subscriber preferences.
A configured AI provider may create a shared summary or localization from public-news evidence. Subscriber names, email addresses, private links, tokens, delivery identifiers tied to a person, and preferences are not sent to that provider. Automated checks can reject unsupported or conflicting output. Original publisher links remain visible.
4. Service providers and transfers
Bulletin expects to use Supabase for its hosted database; Vercel for the website and stateless worker functions; Google Gmail for email delivery; and Groq for public-news summarization and localization. These providers may process data outside India under their own terms and security arrangements.
When you access Bulletin, Vercel may process hosting and security information such as your IP address, approximate location derived from it, request and diagnostic information, browser or device information, and date and time of access. Bulletin does not enable behavioural advertising or add third-party tracking merely because the service is hosted on Vercel.
Groq receives only selected public-news evidence. Its published controls say ordinary inference data is not retained by default, may be kept for up to 30 days for reliability or abuse investigation, and can be placed under Zero Data Retention where enabled. Bulletin will enable the narrowest available data controls before production.
5. Retention and deletion
- previous preference versions: up to 30 days;
- personal delivery records: up to 90 days;
- subscriber profile and active preferences: until confirmed deletion; and
- authentication sessions, owner-access tokens, rate-limit records, and logs: only for their documented security or operational period.
Confirmed deletion removes your subscriber-related personal data from the primary database.
Public article metadata, source records, shared clusters, and summaries may remain because they are not created from subscriber identity.
6. Your controls
After signing in, you can use Manage briefing to view or change preferences, change theme, pause, resume, or deliberately confirm deletion. You may also contact the operator to ask about your data, correct it, withdraw consent, or report a concern. Email delivery can be stopped at any time through Manage briefing.
7. Security
Bulletin uses HTTPS, Google OAuth, Supabase Auth sessions, server-only credentials, secure cookies, rate limits, database row-level security, bounded worker leases, and safe operational logs. No internet service can guarantee absolute security. Please keep your sign-in account secure.
8. Adults-only beta and current Indian law
Bulletin’s private beta is intended only for people aged 18 or older. Bulletin does not ask for age or date of birth, use an age-verification popup, profile children, or show targeted advertising. By deliberately confirming a beta subscription, a participant confirms that they are at least 18. If the operator learns that a participant is under 18, the subscription and associated personal data will be deleted.
As of 19 July 2026, India’s Digital Personal Data Protection Act, 2023 has commenced only in part. The principal duties concerning notice, consent, data-fiduciary obligations, individual rights, and children are scheduled to commence 18 months after 13 November 2025. Bulletin is being designed toward those requirements before they take effect. This statement records the current commencement schedule; it is not legal advice.
9. Changes and contact
We may update this policy as the private beta, providers, or law change. A material change will be dated and communicated where appropriate. Questions or privacy requests may be sent to sougandh.manoj4@gmail.com.