Steeped

News

Privacy Policy

Last updated: June 15, 2026

This Privacy Policy explains what information Steeped ("Steeped", "we", "us", or "our") collects from users of steepednews.com (the "Service"), how we use it, and the choices you have. We try to collect as little personal data as possible — only what is needed to make the Service work for you.

Data Controller

The Service is operated by Kriss Phoha, an individual ("Steeped", "we", "us"), the data controller responsible for your personal data. You can reach us at [email protected] or by mail at:

Kriss Phoha
[STREET / PO BOX]
[CITY, STATE ZIP]
United States

We have not appointed a Data Protection Officer or an EU/UK representative; as a small US-based operator we do not meet the thresholds that require one. For any data-protection question, email us at the address above.

1. Information We Collect

1.1 Information you provide

1.2 Information collected automatically

1.3 What we do not collect

1.4 Information that is public

Some information you choose to add is shown publicly and can be viewed by anyone — including people who are not signed in and search engines — at your profile page steepednews.com/u/<your-handle>:

You control all of this: leave your handle, bio, and interests blank to stay private, keep your Portfolio private (the default), and avoid submitting game scores if you do not want to appear on the global leaderboard. Removing this information from your account removes it from the public page.

2. How We Use Information

We use the information described above only to:

We do not use your personal information for marketing emails or advertising. Where the law (such as GDPR) requires a legal basis, we rely on: performance of a contract for the account and features you ask us to provide; our legitimate interests in operating, securing, and preventing abuse of the Service; your consent where you have given it (for example, making your Portfolio public); and compliance with legal obligations where applicable.

3. Third-Party Service Providers

We rely on a small number of service providers ("processors") to run the Service. Each processes only the information needed for its function, under our instructions:

4. Cookies

We use cookies sparingly and only for purposes that are strictly necessary to run the Service you have asked for, so we do not display a cookie-consent banner:

We do not set advertising, analytics, or cross-site tracking cookies. Because the cookies above are strictly necessary or functional for actions you initiate, applicable EU/UK rules (ePrivacy/PECR) do not require us to obtain prior consent for them. If we ever add a non-essential cookie, we will ask for your consent first.

5. Data Retention

Account data is retained for as long as your account exists. Direct messages are kept while your account exists, up to a maximum of 365 days per message, after which older text messages are purged; shared-article previews go cold and are removed after 30 days.

When you delete your account, everything tied to it is removed from our active database promptly: your profile, Portfolio, friend connections and friend code, your game scores, and the direct messages and shared articles in your conversations. Because a conversation belongs to both people in it, deleting your account also removes those messages from the other person's view, and removes you from your friends' friend lists and from the leaderboards. Residual copies may persist for a limited period (up to 30 days) in routine database backups, and in Resend's email-delivery logs in accordance with that provider's retention policy. Standard server and proxy logs (including IP addresses) are retained by us and by Cloudflare for a limited period — typically no more than 30 days for our own application logs; Cloudflare's retention is governed by its own policies. We do not keep a separate archive of deleted accounts.

6. Security

All traffic to the Service is served over HTTPS with HSTS enabled. Passwords are stored as salted hashes using a slow KDF (pbkdf2:sha256); we never see or store your plain-text password. We apply a strict Content Security Policy and standard web-application defenses (rate limiting, CSRF protection, secure session cookies). No system is perfectly secure, but we treat account data with reasonable industry-standard care. If we ever become aware of a data breach affecting your personal data, we will notify you and any relevant regulator as required by applicable law.

7. Your Rights and Choices

You can exercise any of the rights below by emailing [email protected] from your account email. We will respond within 30 days (we may ask you to verify your identity first).

8. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, email [email protected] and we will delete it. Depending on where you live, the minimum age for consenting to data processing may be higher than 13; you must meet the minimum age required by your local law.

9. International Transfers

Steeped is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States and other countries where our service providers operate. Where we transfer personal data of EEA, UK, or Swiss users, we rely on appropriate safeguards or applicable derogations under data-protection law (including your consent and the necessity of the transfer to provide the Service you requested).

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date above, and for material changes we will provide reasonable notice via the Service or by email.

11. Contact

Questions about this Privacy Policy or your data? Email [email protected], or write to us at the Data Controller address above.

Back to Steeped