1. Overview
the site operator operates Regional Industry & News (the “Service”). This Privacy Policy explains what information we collect, how we use it, and your rights. By using the Service, you agree to this policy. If you do not agree, please do not use the Service.
2. Information we collect
2.1 Information you provide
- Account data — If you sign in (magic link, Google OAuth, or similar via Supabase Auth), we receive your email address and basic profile identifiers needed for authentication.
- API / developer access — If you request MCP or REST access, we may store your email, subscription tier, API key metadata (hashed keys, prefixes, usage logs), and billing identifiers from our payment processor.
- Communications — If you contact us (email, GitHub issues, support forms), we receive the content you send.
2.2 Information collected automatically
- Usage and logs — Our hosting provider (e.g., Vercel) and database (Supabase) may log IP addresses, user agents, request paths, timestamps, and error diagnostics needed to operate and secure the Service.
- API usage — Authenticated API calls may be logged (endpoint, time, key prefix, rate-limit counters) to enforce quotas and detect abuse.
- Analytics — We use Vercel Web Analytics to understand which features are used (e.g., page views and interactions such as selecting a state, opening an article, or viewing the compare page). It is cookieless: visitors are identified by a short-lived anonymous hash, no cross-site tracking is performed, and we do not attach names, emails, or other personal identifiers to analytics events.
- Local storage — Your theme preference may be stored in your browser’s
localStorageand is not sent to our servers unless we add features that sync settings to an account.
2.3 Information we do not intentionally collect
The public dashboard does not require an account. We do not knowingly collect sensitive categories (health, precise geolocation from your device, government IDs) through normal browsing. Do not submit such information in support requests.
3. How we use information
- Provide, maintain, and improve the Service.
- Authenticate users and manage API access, invites, and subscriptions.
- Enforce rate limits, prevent abuse, and protect security.
- Respond to support requests and legal obligations.
- Generate aggregated, non-identifying statistics about usage.
We do not sell your personal information. We do not use your data to train third-party AI models.
4. Legal bases (EEA/UK users)
Where GDPR or UK GDPR applies, we process personal data on bases including: (a) contract — to provide accounts, API access, or billing you request; (b) legitimate interests — security, abuse prevention, and service improvement, balanced against your rights; (c) consent — where required for optional features; and (d) legal obligation — when law requires retention or disclosure.
5. Service providers
We use trusted processors to run the Service, including:
- Vercel — application hosting, edge delivery, and privacy-friendly web analytics (Vercel Web Analytics).
- Supabase — database, authentication, and server-side data access.
- Stripe — payment processing when paid plans are enabled (we receive subscription status and customer IDs, not full card numbers).
- Tally — feedback form hosting (EU-based, GDPR-compliant). If you submit the feedback form, your responses are processed and stored by Tally.
- GitHub Actions — scheduled data pipelines (no visitor PII in routine cron jobs).
- AWS Lambda — optional article extraction and bias classification (article text sent for processing; not your account data).
Processors are bound by their own terms and data protection agreements. We share only what is necessary for them to perform their function.
6. Cookies and similar technologies
We use essential cookies or similar storage for authentication sessions when you sign in (typically managed by Supabase Auth). We may use local storage for theme preferences. Our analytics (Vercel Web Analytics) does not use cookies or persistent device identifiers — it relies on a short-lived, anonymized hash that cannot track you across sites or sessions. If we ever add analytics that require non-essential tracking, this policy will be updated and, where required, we will request consent first.
7. Retention
We retain personal data only as long as needed for the purposes above: account and billing records while your account is active and for a reasonable period afterward; security logs for a limited window; API usage logs for quota enforcement and abuse investigation. Public dashboard data (news articles, scores) is retained according to operational needs, not as personal data about visitors.
8. Your rights and choices
Depending on where you live, you may have the right to:
- Access, correct, or delete personal information we hold about you.
- Object to or restrict certain processing.
- Data portability (structured copy of account data).
- Withdraw consent where processing is consent-based.
- Lodge a complaint with a supervisory authority (EEA/UK).
California residents (CCPA/CPRA): You may request disclosure of categories of personal information collected, deletion, and correction. We do not sell personal information. To exercise rights, contact us using the details below. We will not discriminate against you for exercising privacy rights.
To delete an account or API access, contact us or use available self-serve tools on the API page when provided.
9. International transfers
The Service is operated from the United States. If you access it from other regions, your information may be processed in the U.S. or where our providers operate. We rely on appropriate safeguards (such as standard contractual clauses where applicable) when transferring data internationally.
10. Children
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal data, contact us and we will delete it.
11. Security
We use industry-standard measures (HTTPS, access controls, hashed API keys, row-level security where configured) to protect data. No method of transmission or storage is 100% secure; use the Service at your own risk.
12. Changes
We may update this Privacy Policy. Material changes will be reflected by updating the date at the top of this page. Continued use after changes constitutes acceptance.
13. Contact
Privacy requests and questions: contact via GitHub. See also our Terms of Use and Disclaimer.