This policy explains what personal data Colophon collects when you use the Colophon website, the web app and the apps for iOS, iPadOS, Android, Windows, macOS and Linux, why we collect it and what your rights are.
In short
- We collect only what we need to write your editions and run your account.
- No advertising, no tracking cookies, no analytics that profile you. We never sell your data.
- Your calendar connections are encrypted with a key that belongs to your account alone.
- You can download all your data or delete your account at any time, from Preferences.
Who we are
The controller of your personal data is [LEGAL_NAME], [LEGAL_ADDRESS]. For any question or request about your data, write to [[LEGAL_EMAIL]](mailto:[LEGAL_EMAIL]).
What we collect and why
Waitlist
If you join the waitlist on our website: your email address, the language of the page, your invitation code, the code of whoever invited you and where you came from (for example a link on X). We use them to tell you when Colophon opens and to let invitations move people up the list. Legal basis: your consent (Art. 6(1)(a) GDPR), which you give by confirming your email. Every email has a link to leave the list, which deletes your entry at once.
Account
Your email address, when you created the account and last signed in, your sign-in sessions (30 days) and the one-time sign-in links and codes we email you (valid for 15 minutes; we store only a cryptographic fingerprint of the code). We use them to let you sign in. Legal basis: performance of the contract with you (Art. 6(1)(b) GDPR).
Reading preferences
Language, country, time zone, topics, places and depth, reading time, rhythm (Morning Sun, Triple Rush, The Aftermath), the topics you track, outlets you exclude, perspective mode, notification choices and, if you add one, the city for the weather. We use them to build your editions. Legal basis: contract.
Editions and reading
The editions written for you, the stories you have read and the status of each generation. We use them to show your archive and to avoid repeating stories. Legal basis: contract.
Work & Private Life (optional)
Only if you turn it on and connect a source: an Outlook calendar link (ICS), Microsoft To Do and Outlook calendar (through Microsoft Graph, read-only) or Google Calendar (read-only). We import the title, times, location and busy/free status of events, and the title, due date and importance of tasks. Never attendees, descriptions or attachments. Private events arrive as "Private appointment", and you can keep only busy times for any calendar. Calendar links and access tokens are encrypted (AES-256-GCM) with a key unique to your account. We keep events from yesterday to 14 days ahead and your priorities for 30 days. Legal basis: contract, because you ask for the feature. You can disconnect a source or delete all agenda data with one button.
Notifications
If you allow them: the push token of your device (Apple Push Notification service, Firebase Cloud Messaging or Web Push), its platform and when it was last used. Legal basis: contract. You can turn notifications off in Preferences or in your device settings.
Subscriptions and payments
If you subscribe: plan, subscription status, renewal and expiry dates, the store you bought from and a customer identifier. We never see your full card details: payments are processed by Apple, Google or Stripe. Legal basis: contract and legal obligations (tax and accounting records).
Technical data and security
Our hosting providers record technical data such as IP address, date and time, the page requested and the browser type, to keep the service secure and working. For every request to the AI model we record the model, the number of tokens, the cost and your account identifier, to control costs and apply usage limits. Legal basis: our legitimate interest in a secure and sustainable service (Art. 6(1)(f) GDPR).
Support
If you write to us: your message and our reply. Legal basis: contract or legitimate interest.
Artificial intelligence
Editions are written by an AI model (Claude, by Anthropic) from articles published by news outlets, and every edition says so. To write them we send the model the articles and your reading preferences (topics, language, country, perspective): not your name or email address.
If you turn on the summary sentence of Work & Private Life, the model also receives that day's event titles and times, tasks and priorities; calendars set to "busy only" send times alone. The temporary file is deleted right after, and you can switch the sentence off.
Anthropic acts as our processor. Under its commercial terms it does not use this data to train its models and keeps it only for a limited period. We do not use your data to train AI models. No decision with legal or similarly significant effects on you is taken automatically.
Who receives your data
We share data only with providers that help us run Colophon, under data processing agreements and only as far as needed:
- Supabase (database, EU region): account, preferences, editions, encrypted agenda data.
- Fly.io and our website hosting provider: the servers that write editions and serve the site.
- Anthropic (United States): writing editions, as described above.
- Our email delivery provider: sign-in links and edition emails.
- Apple and Google: push notifications and, for subscriptions bought in their stores, payments under their own privacy policies.
- Stripe and RevenueCat: payments on the web and subscriptions shared across your devices.
- Microsoft and Google: only if you connect your calendar or tasks, to read them on your behalf.
- Open-Meteo: to find the city you choose for the weather and its forecast. It receives the city name or coordinates, not who you are.
We may disclose data when the law requires it. We never sell or rent personal data and never share it for advertising.
Transfers outside the EU
Some providers (for example Anthropic, Stripe and RevenueCat) process data in the United States or in other countries outside the European Economic Area. These transfers rely on an adequacy decision of the European Commission (including the EU-U.S. Data Privacy Framework, for certified companies) or on the Standard Contractual Clauses, with additional safeguards where needed. You can ask us for a copy at [[LEGAL_EMAIL]](mailto:[LEGAL_EMAIL]).
How long we keep data
- Waitlist: until you leave it, or until six months after launch; unconfirmed sign-ups are deleted after 30 days.
- Account, preferences and editions: until you delete the account.
- Sign-in links and codes: 15 minutes. Sessions: 30 days, or until you log out.
- Agenda: events from yesterday to 14 days ahead, priorities for 30 days, connected sources until you remove them.
- AI usage records: up to 24 months, linked only to an account identifier.
- Payment and invoicing records: as long as tax law requires (10 years under Italian law).
- Server logs: for the short periods set by our hosting providers.
When you delete your account we erase your data from our systems straight away (the files used to write your editions within an hour). Copies in backups disappear as the backups rotate, within 30 days.
Cookies and storage on your device
We only use what is strictly necessary for the service you ask for, so we do not need a consent banner:
u2d_session: keeps you signed in (30 days).u2d_lang: remembers the language you chose (1 year).u2d_ms_oauthandu2d_google_oauth: protect the connection of your calendar (10 minutes).- Storage on your device: the discreet mode of the agenda and, in the apps, your sign-in token.
- On the web, a service worker keeps your latest editions readable offline. It is emptied when you log out.
No third-party cookies, no advertising or analytics trackers. Fonts are served from our own domain.
Your rights
You have the right to access your data, to have it corrected or erased, to restrict or object to its processing and to receive it in a portable format (Articles 15 to 21 GDPR), and to withdraw consent at any time.
In the app: Preferences, Your data, to download everything (JSON) or delete your account. For anything else write to [[LEGAL_EMAIL]](mailto:[LEGAL_EMAIL]). We reply within one month.
You can also lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali, or with the authority of the country where you live or work.
Wherever you live (for example in the United Kingdom, California or Brazil), we give you the same rights. We do not sell or share personal information as defined by California law.
Children
Colophon is not intended for anyone under 16. We do not knowingly collect data from children: if you believe a child has given us personal data, write to us and we will delete it.
Security
Encrypted connections (TLS), encryption of calendar secrets with a key for each account, sign-in codes stored only as fingerprints, a strict content security policy and access limited to what each part of the system needs. No system is perfectly secure: if a breach affects your data, we will tell you and the authority as the law requires.
Changes to this policy
We publish every update on this page with a new date. For significant changes we tell you by email or in the app before they take effect.