Privacy Policy
Effective date: October 1, 2026
This Privacy Policy explains how Clinton McWilliams, an individual doing business as CybersecurityNews.us ("CybersecurityNews.us", "we", "us") collects, uses, shares and protects information when you use cybersecuritynews.us, its mobile apps, its alerts, and its Data API (together, the "Service"). By using the Service you agree to this policy and to our Terms of Service.
The short version
- You can read everything without an account. We ask for an email address only if you create an account, follow topics, get alerts, or use the API.
- No ads, no ad tracking, no analytics. The site loads no advertising, analytics or tracking scripts, and we do not use tracking pixels.
- We do not sell or rent your personal information, and we do not share it for cross-context behavioral advertising.
- We keep data only as long as we need it (see *How long we keep information*), and you can delete your account yourself at any time.
Information we collect
Information you give us
- Account information: your email address and, if you choose, a display name, your time zone, and the audiences you pick (for example "small business").
- Your technology profile: the vendors, products (and, optionally, versions), topics, vulnerabilities and stories you follow, stories you save, and your alert preferences. This tells us what technology you use, so we treat it as confidential account data.
- Browser notifications: if you turn them on, your browser's push subscription (an endpoint address and encryption keys issued by your browser's push service) and an optional device name you choose.
- Phone notifications (mobile apps): if you turn them on in our app, a push token that Google Firebase Cloud Messaging issues for the app on that phone (on iPhones, through Apple's push service).
- Billing information: if you subscribe to a paid plan, Stripe collects your payment details and billing information directly; we never receive or store your full card number. We receive and keep your plan, its price and billing interval, its status and renewal or end date, and Stripe's identifiers for your subscription.
- Developer (API) information: a project or company name, your API keys (we store only a one-way hash of each key, never the key itself), and records of your API use such as request counts and errors.
- Newsletter sign-up: your email address and the consent you gave.
- Messages you send us, for example to support@cybersecuritynews.us.
Information collected automatically
- Sign-in and session data: when you sign in, we record your IP address and your browser's user-agent string with your session, so you can see and end your sessions and so we can detect misuse.
- Mobile app sessions: when you sign in in our app, we also record the device name the app reports (for example "Google Pixel 9 (Android app)") with that session, so you can recognize and end it.
- Phone security check (mobile apps): the app can compare your phone's operating-system version and security patch level with public lists of security fixes, to tell you whether your phone is missing updates. The comparison happens on your phone: the app downloads the same public list for everyone, and we do not receive your phone's model, version or patch level. You can turn the check off in the app.
- Security and server logs: our servers and our hosting provider record requests to the Service, including IP address, date and time, the page or API endpoint requested, and the response. We use these logs to operate, secure and troubleshoot the Service.
- Security audit records: security-relevant events, such as sign-ins, failed sign-ins, account deletion and API key changes, are recorded with the time and IP address. Reader events are recorded against an internal account number, not your email address.
- Anti-abuse signals for API trials: to limit free trials to one per person, we keep a one-way hash of your normalized email address and a coarse network prefix (the first part of your IP address), not your full IP address.
- Email delivery information: we keep a log of the emails we send you and their delivery status. If an email to you bounces permanently or you mark our email as spam, our email provider tells us and we record that so we stop sending mail that isn't wanted.
- Browser security reports: if your browser blocks something on our pages under our security policy, it may send us a report. We remove query strings from the page addresses in these reports before storing them.
We do not use device fingerprinting, and we do not collect precise location, contacts, or any payment card data.
Cookies
We use a small number of cookies, all set by us, only for the purposes below. We do not use advertising or analytics cookies, so we do not show a cookie-consent banner.
| Cookie | Purpose | Lifetime |
|---|---|---|
__Host-csn_reader | Keeps you signed in to your reader account (strictly necessary) | Up to 90 days |
__Host-csn_admin | Keeps our staff signed in to the editorial console (strictly necessary) | Up to 8 hours |
__Host-csn_csrf | Protects staff forms against cross-site request forgery (strictly necessary) | Browser session |
csn-theme | Remembers your light or dark mode choice | 1 year |
csn_aud | Remembers the audience you picked to rank stories, without an account | 1 year |
The "are you human?" check on sign-in and sign-up forms is provided by Cloudflare Turnstile (see below) and may use Cloudflare's own storage in its frame. You can block or delete cookies in your browser; if you block the sign-in cookie, you won't be able to stay signed in.
How we use information
We use information to:
- provide the Service: sign you in, personalize your briefing, deliver the alerts and digests you ask for, and run the Data API;
- send service email you request (sign-in links, alerts, digests, API trial reminders) and, if you signed up, our newsletter;
- secure the Service: prevent fraud, spam, abuse and attacks, enforce rate limits and our Terms, and investigate incidents;
- operate and improve the Service, including fixing problems and understanding overall usage from aggregated counts;
- comply with law and respond to lawful requests, and establish or defend legal claims.
Legal bases (EEA and UK visitors). We process personal data to perform our contract with you (providing your account, alerts and API access), for our legitimate interests in operating and securing the Service, with your consent where we ask for it (browser notifications, newsletter), and to comply with legal obligations.
How we share information
We do not sell your personal information. We share it only as follows:
- Service providers who run the Service for us, under contracts that limit their use of the data:
- Amazon Web Services hosts the Service and stores our data and backups in the United States, delivers the site through its content-delivery network and firewall, and sends our email (Amazon SES receives the recipient address and email content).
- Stripe processes subscription payments. It receives your email address, your payment details, the plan you buy, and the IP address and device information of the browser you pay from, and uses them under its own privacy policy, including for fraud prevention.
- Cloudflare provides the Turnstile bot check. When you submit a protected form, your browser and our server send Cloudflare the verification token and your IP address. Cloudflare's use of this data is described in its own privacy policy.
- Browser push services (for example those operated by Google, Mozilla, Microsoft or Apple) deliver the browser notifications you turn on. Notification content is encrypted end to end between us and your browser.
- Google (Firebase Cloud Messaging) and Apple (Apple Push Notification service) deliver the phone notifications you turn on in our app. They receive the push token and the notification: the alert title, the headline and a link.
- Legal and safety: when we believe in good faith that disclosure is required by law, court order or legal process, or is necessary to protect the rights, property or safety of our users, the public or us.
- Business transfers: if the Service is involved in a merger, acquisition, financing or sale of assets, information may be transferred as part of that transaction, subject to this policy.
- With your direction: for example, when you publish our data through your own application under the API terms.
How long we keep information
| Information | How long |
|---|---|
| Sign-in links | Deleted within about a day of expiring (links expire after 15 minutes) |
| Sessions (with IP address and user agent) | Deleted 30 days after they expire or you sign out |
| Email content we sent you | Content erased after 30 days; the delivery record (address, subject, type, status) is kept while your account exists |
| API sign-up IP address | Erased after 90 days |
| API error records | Deleted after 90 days |
| Free-trial anti-abuse hashes | Deleted after 12 months |
| Server and application logs | 90 days (sign-in system logs: up to 1 year) |
| Database backups | Up to 35 days, including copies that cannot be altered or deleted for 30 days |
| Security audit records | Kept as long as needed for security, fraud prevention and legal purposes |
| Bounce and spam-complaint records | Kept so we never email that address again against the recipient's wishes |
| Your plan and billing status | Until you delete your account. Stripe keeps payment and invoice records for as long as tax and financial laws require |
| Your account and profile | Until you delete your account |
Your choices and rights
- Access and correct: you can see and edit your email preferences, follows, saved stories, devices, sessions and API keys in your account.
- Delete: you can delete your account at any time from your account settings. This removes your profile, follows, saved stories, preferences, notifications, devices, sessions and API accounts and keys, and anonymizes our email log for you. We keep the limited records described above (security audit records, trial anti-abuse hashes, and bounce/complaint records), and backups age out on the schedule above.
- Email: every alert and digest has an unsubscribe link, and you can change alert settings at any time. Sign-in links are sent only when you request them.
- Browser notifications: you can turn them off in your account or in your browser settings at any time.
- Other requests: to ask for a copy of your data, for deletion of newsletter-only sign-ups, or for anything else, email support@cybersecuritynews.us. We may need to verify your identity before acting on a request.
U.S. state privacy rights. Depending on where you live (for example California, Colorado, Connecticut, Virginia and other states with consumer privacy laws), you may have the right to know, access, correct, delete and obtain a portable copy of your personal information, and to opt out of its sale, targeted advertising or profiling. We do not sell personal information, do not share it for targeted advertising, and do not use it for profiling that produces legal or similarly significant effects. We will not discriminate against you for exercising your rights. You may use an authorized agent, and you may appeal a decision by replying to our response.
EEA and UK rights. If you are in the European Economic Area or the United Kingdom, you may also have the right to object to or restrict processing, to withdraw consent at any time, and to lodge a complaint with your data protection authority.
Global Privacy Control and Do Not Track. Because we do not sell or share personal information for advertising and do not track you across other sites, no further action is needed for these signals.
Security
We protect information with encryption in transit (HTTPS) and at rest, access controls, least-privilege systems, security monitoring and regular updates. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we learn of a breach that affects your personal information, we will notify you as required by law.
Where information is processed
The Service is operated from the United States, and information is stored and processed in the United States. If you use the Service from outside the United States, you understand that your information will be transferred to, stored and processed in the United States, where data protection laws may differ from those in your country.
Children
The Service is intended for adults and is not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 where local law requires). If you believe a child has given us personal information, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. We will post the new version here with a new effective date and, if the changes are material, notify account holders by email or on the Service before they take effect.
Contact
Clinton McWilliams, doing business as CybersecurityNews.us
Email: support@cybersecuritynews.us
Security issues: security@cybersecuritynews.us
