Legal
Privacy Policy
This Privacy Policy explains how Slantpoint collects, uses, discloses, and safeguards your personal data when you use our website and services. It is designed to comply with the EU General Data Protection Regulation (GDPR), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and the California Consumer Privacy Act (CCPA) as amended by the CPRA.
1. About this policy
This policy applies to all visitors and registered users of Slantpoint. By accessing or using our services, you consent to the practices described here. This policy is effective as of August 17, 2026, and may be updated as described in Section 16. Where we reference 'personal data,' 'personal information,' or 'personal information' we mean information that identifies or can reasonably be used to identify you.
This is a summary of our practices. It is not a legal contract and does not expand or limit any rights granted to you under applicable law.
2. Who we are (the data controller)
Slantpoint is the data controller and the organization responsible for your personal data under GDPR, the organization responsible for your personal information under PIPEDA, and the 'business' that collects and processes your personal information under CCPA. We determine the purposes and means of processing your personal data as described in this policy.
- Operating entity: Slantpoint.
- Role: Data controller (GDPR), organization responsible (PIPEDA), business (CCPA).
- Contact: Reach us at privacy@slantpoint.com for any privacy-related request.
3. Personal data we collect
We only collect the personal data we need to provide and improve our news-intelligence service. The categories we may collect include:
- Account data: your email address and password (stored as a hashed credential) when you register.
- Profile data: your display name and role within the app.
- Preference data: saved stories, followed topics, followed sources, keyword alerts, newsletter settings, and personalization toggles.
- Usage data: pages viewed, features used, and approximate interaction timestamps, collected through our analytics provider.
- Device and technical data: IP address, browser type, operating system, and similar information logged by our servers and infrastructure.
- Correspondence: the contents of messages you send us, such as support or privacy requests.
We do not knowingly collect sensitive personal data (such as health, racial or ethnic origin, political opinions, religious beliefs, or biometric data). If you believe we have received such data, contact us and we will delete it.
4. How we use your data
We process your personal data for the following purposes:
- To create and manage your account and authenticate you.
- To save and display your saved stories, followed topics, followed sources, and alerts.
- To personalize what you see — for example, surfacing developing stories first or highlighting coverage contrast — without altering the underlying facts or neutral summaries.
- To send the daily contrast briefing and other newsletters you have opted into.
- To operate, secure, monitor, and improve our services and infrastructure.
- To analyze aggregate usage trends and measure feature adoption.
- To respond to your requests and provide support.
- To comply with legal obligations and protect against fraud or abuse.
5. Legal basis for processing (GDPR)
Under GDPR, we rely on the following lawful bases to process your personal data:
- Consent (Article 6(1)(a)) — for newsletter delivery, analytics, and any optional personalization you enable. You may withdraw consent at any time.
- Contract (Article 6(1)(b)) — to provide the account and services you requested.
- Legal obligation (Article 6(1)(c)) — where we are required to retain or disclose data by law.
- Legitimate interests (Article 6(1)(f)) — for security, fraud prevention, service improvement, and analytics, balanced against your rights and reasonable expectations.
Where processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
6. Consent (PIPEDA)
Under PIPEDA, we obtain your consent to collect, use, and disclose your personal information for the purposes identified in this policy. Consent is obtained when you register, enable a feature, subscribe to a newsletter, or otherwise interact with the service in a way that makes your wishes reasonably clear. You may withdraw consent at any time, subject to legal or contractual restrictions, by contacting us or adjusting your settings.
- We identify the purposes for collecting personal information at or before the time of collection.
- We limit collection to what is necessary for those identified purposes.
- You can decline to provide personal information, though some features may then be unavailable.
8. Data retention
We retain your personal data only as long as necessary to fulfill the purposes described here, comply with legal obligations, resolve disputes, and enforce our agreements. Specifically:
- Account data is retained while your account is active and for a reasonable period after deletion to allow recovery and meet legal requirements.
- Preference data is retained for as long as your account exists and is deleted when you delete your account.
- Usage and analytics data is generally retained in aggregate or de-identified form and may be kept longer for trend analysis.
- You may request early deletion of your data subject to legal retention obligations.
9. Data sharing and third parties
We do not sell your personal data. We may share personal data with the following categories of recipients, only as necessary to operate the service:
- Service providers: hosting, authentication, email delivery, and analytics providers that process data on our behalf under written agreements requiring confidentiality and appropriate safeguards.
- Infrastructure providers: cloud and content-delivery networks that serve the application.
- Legal authorities: where required by law, court order, or to protect rights, property, safety, or security.
- Business transfers: in connection with a merger, acquisition, or asset sale, with assurances that your data will remain protected under this policy or a comparable one.
All service providers and processors are bound by agreements requiring them to protect your personal data and to process it only on our instructions.
10. International data transfers
Your personal data may be processed in countries other than your own, including the United States and Canada, where our service providers operate. Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses, or another transfer mechanism recognized under GDPR, and we require the same protections from our service providers.
11. Data security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit, access controls, regular reviews, and vendor due diligence. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Your privacy rights
Depending on where you live, you may have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: correct inaccurate or incomplete personal data.
- Right to erasure (right to be forgotten): request deletion of your personal data, subject to legal exceptions.
- Right to restriction: limit our processing of your personal data in certain circumstances.
- Right to data portability: receive your personal data in a structured, machine-readable format and, where technically feasible, have it transmitted to another controller.
- Right to object: object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent: withdraw consent for processing that relies on it.
- Right to know (CCPA): know what personal information we collect, use, disclose, and sell, and the categories of sources.
- Right to delete (CCPA): request deletion of your personal information.
- Right to correct (CCPA): correct inaccurate personal information.
- Right to opt-out of sale or sharing (CCPA): opt out of any sale or sharing of personal information — we do not sell your data.
- Right to non-discrimination (CCPA): receive equal service and pricing even if you exercise your rights.
- Right to limit use of sensitive personal information (CCPA): limit use of sensitive personal information — we do not collect sensitive personal information.
Under PIPEDA, you also have the right to access your personal information, challenge its accuracy, and withdraw consent, and we will respond within a reasonable time and at minimal or no cost.
13. Exercising your rights
To exercise any of the rights above, contact us at privacy@slantpoint.com. We will verify your identity before acting on your request to protect your account and prevent unauthorized access. We aim to respond within the timeframes required by applicable law — generally within one month under GDPR, 45 days under CCPA, and 30 days under PIPEDA. If we cannot fulfill your request, we will explain why.
- You can manage many preferences directly in your account settings without contacting us.
- You can delete your account and associated data from your account page.
- Authorized agents may submit requests on your behalf with proof of authorization.
14. Opt-out of sale or sharing (CCPA)
Slantpoint does not sell your personal information, as 'sale' is defined under CCPA, and we do not share it for cross-context behavioral advertising. Because we do not sell or share your data, there is no opt-out to exercise; however, you may still request deletion or correction of your data at any time, and you will not be treated differently for doing so.
15. Children's privacy
Our services are not directed to children under 16 (or the applicable age in your jurisdiction), and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will take steps to delete it and prevent further collection.
16. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated policy on this page and update the 'effective as of' date at the top. For material changes, we may also provide notice through the service or by email where appropriate. We encourage you to review this page periodically.
17. Contact us
If you have questions about this Privacy Policy, wish to exercise your rights, or have a complaint about how we handle your personal data, contact us at privacy@slantpoint.com. We will investigate and respond to your concern. You also have the right to lodge a complaint with your local data protection authority (GDPR), the Office of the Privacy Commissioner of Canada (PIPEDA), or the California Attorney General (CCPA) if you are unsatisfied with our response.
Effective date: August 17, 2026. This policy is provided for informational purposes and describes how Slantpoint is designed to handle your personal data.
These policies describe how Slantpoint is designed to behave.
