Privacy Policy

Effective Date: August 3, 2026  ·  Last Updated: August 3, 2026

Headlinne is a news app. To show you news worth your time, we need to learn what you find interesting — and that is the only reason we collect anything at all. This policy explains what we collect, what we do with it, and the control you have over it, in plain language. Here is where we stand before we get into the detail.

We never sell your information

We do not sell your personal information, and we do not share it with advertisers or ad networks for advertising across other companies’ sites and apps. We never have.

No ad trackers, no session recording

There are no advertising cookies, third-party ad tags, or tracking pixels on Headlinne. We do not record your screen and we do not automatically capture every click.

We collect what the product needs

We do not collect your precise location, contacts, photos, camera, microphone, biometrics, or government ID numbers. We do not ask for sensitive personal details.

Your credentials stay yours

We never see or store your password in readable form, and we never receive your full card details — payments are handled directly by Stripe.

Your reading stays private

Your personal reading history is never visible to your employer, to sponsors, or to other users. Workplace dashboards show group statistics only.

You stay in control

You can adjust or reset personalization at any time, request a copy of your information, or delete your account and data whenever you want.

In one line: we use your activity on Headlinne to personalize Headlinne, and for nothing else. If you ever want your information back or gone, email akwwogr3@gmail.com and we will handle it within 30 days.

1. Our Privacy Promises

The commitments at the top of this page are not marketing. They describe how the product is actually built, and we hold ourselves to them. In a little more detail:

We do not sell or share your information for advertising

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We have not done either in the preceding twelve months, and we have no plans to. These terms have specific legal meanings under the California Consumer Privacy Act and comparable state laws, and we use them in that sense deliberately: we do not disclose personal information to third parties for money or other value, and we do not disclose it so that other companies can advertise to you elsewhere.

We also do not knowingly sell or share the personal information of anyone under 16.

Your information is used to make Headlinne work

Everything we collect goes toward running the Service, personalizing what you see, keeping accounts secure, and improving the product. We do not repurpose your information for something unrelated without telling you first.

You can change your mind at any time

Personalization is adjustable and resettable. Your information is exportable. Your account is deletable. None of these require a reason, a form, or a phone call — see Section 4 and Section 6.

2. About This Policy

This Privacy Policy explains how Headlinne (operated as a sole proprietorship by Archit Khandelwal) (“Headlinne,” “we,” “our,” or “us”) handles personal information across the Headlinne website, applications, and services (the “Service”).

It covers everyone who uses Headlinne — readers, sponsors, ambassador applicants, and members of workplace accounts. It does not cover other websites you visit through our links; those have their own policies.

Who is responsible for your information

  • For individual users, we are the data controller (a “business” under US state privacy laws) — we decide how and why your information is handled, and you can bring any request straight to us.
  • For workplace accounts, the organization that set up the account is the controller and we act as its processor (“service provider”), following its instructions. See Section 13.

What you have to give us

An email address is needed to hold an account — without one we cannot sign you in or keep your preferences. Activity information is created as a by-product of using the app and is what makes personalization possible. Everything else — your name, avatar, bio, topic choices, ambassador application details — is optional, and skipping it only means the corresponding feature is less tailored.

Your use of the Service is also governed by our Terms of Service.

3. What We Collect and Why

We group this by what it is for, because that is the part that matters. A formal category-by-category breakdown, the legal basis for each purpose, and how long everything is kept are in Section 16.

To give you an account

  • Your email address
  • Your password, which is stored in scrambled form only — we never see or store it in readable form
  • A username, display name, avatar, and bio, if you choose to add them
  • If you sign in with Google: your name, email address, profile image, and Google account identifier

To personalize your feed

This is the heart of the product. Headlinne learns from what you actually engage with, so the feed gets better the more you use it. We use:

  • The preferences you set — topics and regions you are interested in or want less of, sources you prefer or have blocked, and how much variety and recency you want
  • How you interact with articles — which ones you swipe past, which you open, and how much of them you read. Reading for a while signals interest; skipping quickly signals the opposite
  • Which topics and sources you tend to return to, expressed as interest signals we calculate from the above
  • Articles you share, and which features you use

This information stays inside Headlinne. It is not sold, not shared with advertisers, and not sent to our AI provider.

To answer your questions

When you use Search or Dive Deeper, we process the question you type in order to find relevant articles and produce an answer. These features are powered in part by Google’s AI and web search services, so the text of your question is processed by Google as well as by us — Section 9 explains exactly how that works and what we do to keep it separate from your identity.

To take payment

Payments run through Stripe. We keep the transaction record — amount, currency, date, and status — and the billing contact details. Your full card number, security code, and bank details go to Stripe directly and never reach us.

To keep the Service running and secure

  • IP address, browser, operating system, and device type
  • An approximate area — city or region — worked out from your IP address. We never collect precise or GPS location
  • Pages visited, referring page, and timestamps
  • Server logs and error diagnostics
  • Sign-in session identifiers

When you contact us or apply to a program

  • Support messages and feedback you send us
  • Ambassador applications — your email address, an Instagram handle or phone number so we can reach you, and your written answers
  • Sponsor campaigns — campaign copy, creative, destination link, topic targeting, and budget
  • Referrals — if you arrive through someone’s referral link, the code used and, if you sign up, the connection between your account and theirs

If you use Headlinne through your workplace

We hold your membership of the organization, your work email domain, and the department, role, and office your organization assigns to you, alongside your engagement with the organization’s content. This is kept separate from your personal account — see Section 13.

What we deliberately do not collect

  • Precise or GPS location
  • Contacts, photos, camera, or microphone
  • Biometric information
  • Government identification numbers
  • Full payment card details
  • Sensitive personal information — racial or ethnic origin, political opinions, religious beliefs, health, sex life, or sexual orientation. We do not ask for it and do not want it, so please keep it out of free-text fields

We also do not use session recording or automatic capture of every click. Analytics events are added one at a time, on purpose, by us.

4. Your Choices and Controls

Most of what people want to change, they can change themselves, right now:

  • Retune your feed — add or remove interested and disliked topics and regions in Settings
  • Block a source you do not want to see again
  • Widen your feed by increasing the diversity and recency settings
  • Reset your recommendation profile in Settings, which clears the interest signals Headlinne has learned and starts you fresh
  • Delete a share link you created, which stops it working
  • Manage cookies and stored data through your browser settings

And by emailing us: turn off personalization entirely, opt out of having your topic preferences used for sponsored placement matching, get a copy of your information, or delete your account. No explanation needed.

5. Your Privacy Rights

Wherever you live, we will honor the following. Some are legal rights in your region; we extend them to everyone rather than checking your address first.

  • Know and access — find out what personal information we hold about you and how we use it, and get a copy
  • Portability — receive that copy in a structured, machine-readable format, and have it sent to another provider where that is technically possible
  • Correction — have anything inaccurate or incomplete fixed
  • Deletion — have your personal information erased and your account closed
  • Restriction — have us pause processing while a question about accuracy or legitimacy is worked out
  • Objection — object to processing we carry out on the basis of legitimate interests, including personalization
  • Withdraw consent — where we rely on consent, take it back at any time, which does not affect anything already done lawfully beforehand
  • Limit sensitive information — we do not collect sensitive personal information for the purpose of inferring characteristics, so there is nothing here to limit, but you may still ask and we will confirm in writing
  • Non-discrimination — using any of these rights will never cost you access, price, or quality of service
  • Complain — raise a concern with your data protection authority at any point, whether or not you come to us first

Region-specific detail — including California, other US states, the EEA and UK, and India — is set out in Section 16.

6. How to Exercise Your Rights

Email akwwogr3@gmail.com

Put “Privacy Request” in the subject line and tell us what you would like and the email address on your account. That is the whole process.

What happens next:

  • We acknowledge your request within 10 business days
  • We confirm it is really you, usually just by checking you control the account email. Information you give us for this is used only to verify the request
  • We complete it within 30 days. For California requests the period is 45 days, extendable once by a further 45 days if genuinely necessary, and we will tell you if that happens
  • There is no charge. If a request were ever manifestly unfounded or excessive we would tell you before doing anything
  • If we cannot do part of what you asked, we will say why and explain how to appeal or complain

Deleting your account

Email us with “Delete My Account” in the subject line. Once we have confirmed it is you, we remove your profile, preferences, activity history, personalization signals, searches and research history, share links, and analytics identifiers, and close the account. Deleted information ages out of our backups within 90 days.

We keep only what the law requires us to keep — principally payment and tax records — along with aggregate figures that cannot identify you. Deletion is permanent and cannot be undone.

Someone acting for you

You can have an authorized agent make a request on your behalf. We will ask for written proof of authorization and may check with you directly.

7. How We Protect Your Information

Protections we have in place include:

  • Encryption in transit and at rest
  • Database-level access rules, so a request can only ever return the records the signed-in account is entitled to
  • Passwords stored in scrambled form that cannot be reversed
  • Least-privilege credentials and scoped API keys
  • Administrative access limited to those who need it
  • Signed, expiring links for image delivery
  • Input validation and rate limiting across our API

No system is perfectly secure, and we will not claim otherwise. Please use a strong, unique password, and tell us straight away if you think someone else has been in your account.

If something goes wrong

If a data breach occurs that is likely to put your rights at risk, we will notify the relevant authority within 72 hours where the law requires it, and tell affected users without undue delay — what happened, what information was involved, what we are doing, and what you should do.

Reporting a security issue

Found something? Email akwwogr3@gmail.com with “Security” in the subject line. We will not pursue legal action against researchers who report in good faith, avoid privacy violations and service disruption, and give us reasonable time to fix the issue before going public.

8. How We Share Information

As set out in Section 1, we do not sell your information and we do not share it with advertisers. We disclose personal information only in these situations:

  • To the providers who help us run Headlinne — hosting, database, AI, analytics, payments, and image delivery. Each is contractually bound to handle information only on our instructions and to protect it. They are all listed by name in Section 16
  • When you ask us to — for example, creating a share link makes that article view reachable by anyone who has the link
  • Within a workplace account, in the grouped form described in Section 13
  • To comply with the law — in response to a valid legal request. Where we are permitted to, we will tell you first and give you a chance to object
  • To protect people — where genuinely necessary to look into fraud or abuse, enforce our Terms, or prevent harm
  • If the business changes hands — in a merger, acquisition, or sale of assets, information may transfer. We will tell you before your information becomes subject to a materially different policy, and any acquirer will be held to commitments no less protective than these
  • In aggregate or anonymized form that cannot reasonably identify you. We will not try to re-identify such data, and we require the same of anyone receiving it

Sponsors receive campaign totals — impressions, clicks, and rates. They never receive your identity, email address, reading history, or any record tied to an individual.

9. AI Features and How They Work

Headlinne uses AI to summarize articles, analyze them, and answer questions. We work with Google’s Gemini and Search services to power these features, which means some information is processed by Google as well as by us. Here is exactly what, so there are no surprises.

What is processed by Google

  • Article material and metadata, to produce summaries, insights, analysis, topics, and related-article matching. This is publisher content, not information about you
  • The text of your Search and Dive Deeper questions, so an answer can be generated
  • Search terms drawn from your question, because these features are grounded in live web results — which is what lets them cite current sources rather than guess

What is not

Your identity, email address, and reading history are never sent to our AI provider. Questions are sent without a user identifier attached, so they are not tied back to you at the other end.

As with any search or assistant tool, we suggest keeping personal details you would not type into a search engine out of your questions.

AI training

We do not sell your information to AI companies, and we do not train models on your personal information. Google’s handling of what we send it is governed by its terms for the paid Gemini API. We use a separate, dedicated key for research features to keep that traffic apart from everything else.

10. Personalization and Automated Decisions

Headlinne orders your feed automatically. It builds a picture of the topics and sources you find interesting from what you engage with, and uses it to decide what to show you first. Under the GDPR this counts as profiling, and we want to be straightforward about it.

What these decisions affect is the order of your news feed. They produce no legal effect for you and nothing comparably significant. We never use them for decisions about credit, employment, insurance, housing, education, or eligibility of any kind, and we never will.

You are in charge of it:

  • Change your topics, regions, and sources whenever you like
  • Turn up diversity to widen what you see
  • Reset the whole recommendation profile in Settings
  • Ask us to stop personalizing, or to delete your account

We also run automated checks for fraud and abuse, which can restrict an account. If that ever happens to you and it looks wrong, tell us — a person will review it.

11. Cookies and Similar Technologies

We keep this deliberately small. Full detail is in our Cookie Policy. In short:

  • Sign-in cookies (strictly necessary) — keep you signed in and protect your session. Without these the Service cannot work
  • Preference storage (functional) — remembers your theme and display settings, stored locally in your browser
  • Analytics storage — a pseudonymous identifier so we can count distinct sessions and see which features get used. Automatic click capture and session recording are switched off

There are no advertising cookies, cross-site tracking pixels, or ad network tags on Headlinne. You can clear or block cookies and local storage in your browser at any time, though blocking sign-in cookies will sign you out.

13. Workplace and Enterprise Accounts

If you use Headlinne through your employer or organization, that organization is responsible for the account data and its own privacy notice applies to you. We handle it on their instructions.

What administrators can and cannot see

Administrators see group statistics only — overall reading trends, popular topics and sources, and rollups by department, role, or office.

Protections built into the product

  • No individual reading histories. No administrator view returns a name, email address, or any one person’s article-level activity
  • A five-person minimum. Any figure that would represent fewer than five people is withheld, so an administrator cannot narrow a filter until only one person is left
  • Rankings are anonymous. Where activity leaderboards appear, they show positions without identities
  • Enforced in the database. These limits live in the data layer, not just the interface, so they hold even for direct API access
  • Separate from your personal account. Workplace activity is stored separately and never touches your personal Headlinne feed. Your personal reading is never visible to your employer

Your organization’s responsibilities

Under our Terms, the organization must tell its people that the account produces grouped engagement statistics, and obtain any notice, consent, or employee consultation its local law requires. If you were not told, raise it with them — and you are welcome to contact us as well.

For requests about workplace data, start with your organization’s administrator. If you come to us, we will pass the request to them, as our role requires, and help them answer it.

14. Children and Teens

Headlinne is for people aged 13 and over. It is not directed to children under 13 and we do not knowingly collect their personal information.

If you are between 13 and 18, please read this policy with a parent or guardian — you need their permission to use the Service.

The ambassador program asks for contact details, including a phone number or social handle. If you are under 18, do not apply without your parent or guardian’s permission, and never give us contact details belonging to someone else.

If we learn we have information from a child under 13, we delete it and close the account promptly. Parents and guardians can email akwwogr3@gmail.com to have a child’s information removed — no formality required, and we will act on it.

15. Where Your Information Is Processed

Headlinne runs primarily on infrastructure in the United States, and our providers may process information in other countries. If you are outside the US, using the Service involves your information being transferred to a country whose data protection laws may differ from your own.

Where information moves out of the EEA, UK, or Switzerland, we rely on recognized safeguards, which may include:

  • The European Commission’s Standard Contractual Clauses, and the UK International Data Transfer Addendum
  • An adequacy decision, where one covers the destination
  • A provider’s certification under the EU–US Data Privacy Framework and its UK extension, where applicable

You are welcome to ask us for a copy of the relevant safeguards at akwwogr3@gmail.com.

16. Additional Detail and Regional Disclosures

This section holds the full technical and legal detail behind the summaries above. Nothing here contradicts what has come before — it is the same information, set out formally for those who want it and for the regulations that require it.

16.1 Purposes and legal bases

For users in the EEA, UK, and other regions requiring a stated legal basis for each purpose.

PurposeLegal basis
Create and maintain your account; sign you inPerformance of a contract
Deliver the feed, reading view, search, and research featuresPerformance of a contract
Personalize recommendations from your activity and stated preferencesPerformance of a contract — personalization is the core service you signed up for
Generate AI summaries, analysis, and research reportsPerformance of a contract
Process payments and manage subscriptionsPerformance of a contract; legal obligation for tax and accounting records
Understand product usage and improve the ServiceLegitimate interests
Improve ranking and recommendation quality in aggregateLegitimate interests
Detect, investigate, and prevent fraud, abuse, and security incidentsLegitimate interests; legal obligation
Enforce our Terms and protect our rights and our usersLegitimate interests
Respond to your support requestsPerformance of a contract; legitimate interests
Review ambassador applications and run the programsSteps taken at your request before entering a contract; consent
Match sponsored placements to topicsLegitimate interests — topic matching only, with no data shared externally
Send service and transactional emailsPerformance of a contract
Send optional marketing emails, where offeredConsent — withdrawable at any time
Comply with law and respond to lawful requestsLegal obligation

Where we rely on legitimate interests, we have assessed that our interest does not override your rights and freedoms. You can object at any time — see Section 5.

16.2 Service providers and sub-processors

ProviderPurposeInformation involvedLocation
SupabaseDatabase, sign-in, file storageAccount and profile information, preferences, and activity dataUnited States
VercelApplication hosting and deliveryIP address, request headers, device information, server logsUnited States / global edge
Google (Gemini API)AI summaries, analysis, search answers, and research reportsArticle text and metadata; the text of your searches and research questionsUnited States
Google (Search)Live web results that ground AI Search and Dive Deeper answersSearch terms derived from your questionUnited States / global
Google (Sign-In)Optional sign-in with your Google accountName, email address, profile image, Google account identifierUnited States
PostHogProduct analyticsPageviews, feature events, device and browser information, a pseudonymous identifierUnited States
StripePayment processingPayment details collected by Stripe directly, billing contact, transaction recordsUnited States
ImageKitImage optimization and deliveryIP address and request information when images loadGlobal CDN

We may add or change providers as the Service develops, and will update this table when we do. If you would like advance notice of changes, email us and we will add you to the list.

16.3 How long we keep information

InformationKept for
Account and profile informationWhile your account is open; deleted or anonymized within 30 days of closure
Preferences and personalization signalsUntil you reset them or close your account
Activity data (articles swiped, opened, and read)Up to 24 months, then deleted or reduced to non-identifying counts
Searches and research questionsUp to 12 months, then deleted
Share links and their view countsUntil you delete the share or close your account
Product analytics eventsUp to 24 months
Server and security logsUp to 90 days, or longer where needed to look into a security issue
Payment and transaction recordsUp to 7 years, as tax and accounting law requires
Sponsor campaign recordsCampaign duration, plus 7 years for the financial records
Ambassador applicationsUp to 24 months from submission, then deleted
Support correspondenceUp to 24 months
Workplace account dataPer the organization’s instructions; 30-day export window after termination, then deleted
BackupsOn a rolling cycle — deleted records age out of backups within 90 days

Ingested articles are removed from the active feed shortly after publication, and permalink pages age out on their own cycle. We may keep information longer where the law requires it, or where it is needed to resolve a dispute, enforce our agreements, or look into fraud or abuse. When a period ends we delete the information or anonymize it irreversibly.

16.4 Categories of personal information (California)

The statutory categories collected in the preceding twelve months. All come from you directly, from your use of the Service, or from a provider you chose to sign in or pay with. Each is collected for the business purposes in 16.1 and disclosed only to the providers in 16.2.

CategoryExamples
IdentifiersName, username, email address, account identifier, IP address, device identifier
Customer recordsBilling contact and transaction records; applicant contact details
Commercial informationSubscription tier, purchase history, sponsor campaign records
Internet or network activityArticles viewed and read, feature usage, searches run, pages visited, browser and device information
Geolocation dataApproximate city- or region-level area inferred from IP address only
Professional informationFor workplace accounts: department, role, and office, as assigned by your organization
InferencesTopic and source interest signals used to order your feed

We have not sold or shared any category of personal information, and we do not collect sensitive personal information for the purpose of inferring characteristics about you.

16.5 Rights by region

European Economic Area, United Kingdom, and Switzerland

You hold the rights in Section 5 under the GDPR and UK GDPR, including access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You may also lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner’s Office. We would welcome the chance to resolve things first, but that is your choice, not a requirement.

California

Under the CCPA as amended by the CPRA you have the rights to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and not be discriminated against for exercising them. Because we do not sell or share personal information, there is no opt-out to exercise — but you are welcome to submit a request and we will confirm this to you in writing. Categories collected are in 16.4, purposes in 16.1, recipients in 16.2, and retention in 16.3. Under California’s “Shine the Light” law: we do not disclose personal information to third parties for their own direct marketing.

Other US states

Residents of states including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Delaware, and Montana have comparable rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. We honor these for all US residents regardless of state. Where your state gives you a right to appeal a refused request, simply reply to our decision; we will respond within 45 days and, if we still say no, tell you how to reach your state attorney general.

India

Where the Digital Personal Data Protection Act, 2023 applies, you have the rights to obtain a summary of your personal data and how it is processed, to correction and erasure, to grievance redressal, and to nominate someone to exercise your rights if you are unable to. Grievances may be sent to akwwogr3@gmail.com and will be acknowledged within 10 days. We process personal data for the lawful purposes described in this policy, and for consent-based processing you may withdraw consent at any time as easily as you gave it.

Everyone else

We extend the substance of these rights to all users, wherever you are. Ask, and we will help.

16.6 Opt-out preference signals

Because we do not sell or share personal information and run no cross-site advertising, a signal such as Global Privacy Control has nothing to opt you out of — you are already in the position it would put you in. We nonetheless treat a GPC signal as a request to minimize non-essential analytics. Browser “Do Not Track” signals have no agreed standard, so we do not respond to them separately.

17. Changes to This Policy

We will update this policy as Headlinne develops, and will always revise the “Last Updated” date at the top when we do.

For a material change — collecting a new category of information, using information for a meaningfully different purpose, or adding a new kind of recipient — we will give you at least 30 days’ notice by email or a prominent notice in the app before it takes effect, and will ask for your consent where the law requires it.

We keep earlier versions and will send you one on request.

18. Contact and Complaints

For any privacy question, request, or concern — including grievances under India’s DPDP Act — reach us at:

akwwogr3@gmail.com

We take concerns seriously and will give you a real answer, not a form letter. If you are not satisfied with our response, you can complain to your data protection authority — the Information Commissioner’s Office in the UK, your national supervisory authority in the EEA, the Data Protection Board in India, or your state attorney general in the US. You do not have to come to us first, but we would like the chance to put things right.

Related: Terms of Service  ·  Cookie Policy