← Back

Privacy Policy

Effective: 14 September 2026

Gazette is a feed reader. It exists to show you what the sources you chose published, and it stores only what that job needs. This page lists exactly what that is. The short version is on the about page. Gazette is operated by Grovix LLC, based in the United States, which is the controller of the data described here.

Data we store

  • Account: your email address, display name and optional photo URL, as provided by Firebase Authentication when you sign in with email, Google or Apple. Gazette never sees your password.
  • Subscriptions: the sources you follow, your folders, custom feeds, filter rules, tracked pages and any inbound newsletter address we create for you.
  • Read state: which items you have marked read or starred, with timestamps, so unread counts stay in sync across your devices.
  • Settings: language, layout, theme, reading preferences and the “hide ads” flag. If you enable the sync API for third-party apps, a salted hash of the sync password you set.
  • Sign-in events: the time, IP address and browser of sign-ins and failed sign-ins, kept to detect abuse.
  • Operational: server logs with request ids and IP-derived rate-limit counters. Access tokens are redacted from logs.

What we do not do

  • No ranking, recommendation or interest profile is built from your reading.
  • No AI processing of what you read.
  • Your reading list and read history are never sold, rented or shared with advertisers.
  • We do not track you across other websites.

How we use it

  • To fetch your sources and show you their items.
  • To keep unread counts, stars and settings consistent across web, iOS and Android.
  • To detect abuse and enforce rate limits.
  • To count how the product is used in aggregate (see Analytics).

Where it lives

  • Neon hosts our Postgres database in AWS us-east-2 (Ohio, United States).
  • Google Cloud Run in us-central1 (Iowa, United States) runs the application and fetches feeds. It holds no persistent data of its own.
  • Firebase Authentication (Google) handles sign-in.
  • On your device: a session token, preferences and a small cache of recent items in local storage or the app's private storage.

If you are outside the United States, your data is therefore transferred to and processed in the United States by the providers above.

Analytics

We use Google Analytics 4. It runs by default and sets a first-party analytics cookie (_ga) to tell returning visits apart. It records page views and feature events (for example “opened an article” or “imported OPML”), never the content or source of what you read. When you are signed in, events carry a random account identifier, never your email or name, so we can count how many accounts reach each step of the product. That identifier is never joined to what you read. “Accept all” on the cookie banner additionally lets Google AdSense set cookies and personalise ads; “Essential only” keeps ads non-personalised.

Ads

The reader shows in-feed ads on the web (Google AdSense) and a small number of sponsored cards we place ourselves (web and apps). Ad storage and personalisation are off unless you choose “Accept all” on the cookie banner; with “Essential only” AdSense serves non-personalised ads. Sponsored cards record only impression and click counts per card, never per person. Nothing about your subscriptions is given to any advertiser.

Cookies and local storage

Gazette uses your browser's local storage for the session token, your preferences and your cookie choice. Google Analytics sets its first-party analytics cookie by default, as described above. AdSense cookies are only set after you choose “Accept all” on the banner.

Third parties

We share data only with these processors, and only what each one needs:

  • Google Cloud / Firebase: hosting and authentication.
  • Neon: database hosting.
  • Google Analytics and Google AdSense: as described above, subject to your consent choice.
  • Sentry: error reports, and only when an error occurs, a replay of the interaction that led to it with all text masked and media blocked. Active only when the site is built with a Sentry DSN.
  • Apple: Sign in with Apple, if you use it.

When Gazette fetches a source for you, the request goes from our servers to that publisher with our crawler user agent, not from your device, so publishers do not see your IP address.

Your rights

You can export your subscriptions as OPML at any time from Settings. To access, correct or delete your account and all data attached to it, email privacy@trygazette.com from the address you signed up with. We respond within 30 days, as required by GDPR and CCPA.

Retention

Account data, subscriptions and read state are kept while your account exists and deleted when you ask us to delete the account. Sign-in events and server logs are kept for a short period for abuse detection and then discarded.

Children

The Service is not directed at children under 13.

Changes

If this policy changes in a way that matters, we will post the new version here with a new effective date.

Contact

Grovix LLC · privacy@trygazette.com