Privacy Policy
Last updated: June 15, 2026
This Privacy Policy explains what information Steeped ("Steeped", "we", "us", or "our") collects from users of steepednews.com (the "Service"), how we use it, and the choices you have. We try to collect as little personal data as possible — only what is needed to make the Service work for you.
Data Controller
The Service is operated by Kriss Phoha, an individual ("Steeped", "we", "us"), the data controller responsible for your personal data. You can reach us at [email protected] or by mail at:
Kriss Phoha
[STREET / PO BOX]
[CITY, STATE ZIP]
United States
We have not appointed a Data Protection Officer or an EU/UK representative; as a small US-based operator we do not meet the thresholds that require one. For any data-protection question, email us at the address above.
1. Information We Collect
1.1 Information you provide
- Native Account. If you sign up with an email and password, we store your email address, a salted hash of your password (we never store the plain-text password), and a one-time email verification token.
- Google Account. If you sign in with Google, we receive and store your email address, your display name, your profile picture URL, and a stable Google-issued user identifier ("sub"). We do not receive your Google password.
- Portfolio. If you save an article, we store the article's headline, source, URL, lean (left/center/right), the time you saved it, and your associated account ID.
- Profile. Optional details you choose to add: a public handle, display name, short bio, and interest tags. Your handle and anything you mark public appear on your public profile page.
- Friends & friend codes. We store an 8-character friend code for your account and the connections you form — which other accounts you have sent, accepted, or received friend requests from.
- Messages & shared articles. If you message a friend or share an article with them, we store the message content and the shared article's details so they can be delivered. Messages are stored in plain text and are visible to the recipient and, necessarily, to us as the operator.
- Game scores. If you play the Coffee Break games, we store your best score per game. Your display name and public handle appear next to your score on the global leaderboard, visible to other signed-in users. If you have not set a nickname, your account display name (which for Google sign-ins is your Google profile name) is shown — set a nickname on your account page to control this.
- Correspondence. If you email us, we keep that correspondence so we can respond and follow up.
1.2 Information collected automatically
-
Session cookie. When you sign in, we set a single
signed session cookie containing your user ID, an opaque per-login
marker, and a credential-version number that lets a password reset sign
out your other sessions. It is marked
Secure,HttpOnly, andSameSite=Lax. - Sign-in timestamps. We record the timestamp of your account creation and your last successful sign-in.
- Server & proxy logs. Standard web-server and proxy logs (IP address, user agent, request path, response status, timestamp) are recorded for operational, security, and abuse-prevention purposes and retained for a limited period.
- Aggregate page-view counts. We keep our own basic, privacy-preserving traffic stats (how many page views and roughly how many distinct visitors each day, which pages, and the referring site). This is done entirely on our own server — no cookie, no third-party service, and no script running in your browser. To count distinct visitors without identifying anyone, we store a one-way hash that is re-salted every day, so it cannot be reversed to you or linked to you across days. We do not build profiles or track individuals.
- Bot protection & network proxy. Cloudflare sits in front of the entire Service as our network proxy, so it receives the IP address and request metadata of every visit. Its Turnstile product additionally receives limited browser context (such as user agent and a challenge token) when you submit the sign-up or password-reset forms, to score the request as human or bot.
1.3 What we do not collect
- We do not run third-party advertising or analytics trackers.
- We do not record which articles you read inside the Service.
- We do not sell your data, ever.
1.4 Information that is public
Some information you choose to add is shown publicly and can be viewed by
anyone — including people who are not signed in and search engines — at your
profile page steepednews.com/u/<your-handle>:
- your public handle, display name, and the month/year you joined;
- your bio and interest tags, if you add them;
- your saved-article Portfolio, only if you turn on "Show my Portfolio publicly" (it is off by default);
- your display name and handle on the Coffee Break global leaderboard, if you submit a score, where they are visible to other signed-in users.
You control all of this: leave your handle, bio, and interests blank to stay private, keep your Portfolio private (the default), and avoid submitting game scores if you do not want to appear on the global leaderboard. Removing this information from your account removes it from the public page.
2. How We Use Information
We use the information described above only to:
- provide and operate the Service (sign-in, account management, Portfolio, friends, messaging, games);
- send transactional emails (welcome, email verification, password reset, account-deletion confirmation);
- protect the Service from abuse and fraud (rate limiting, bot challenge);
- respond to your support requests; and
- comply with legal obligations.
We do not use your personal information for marketing emails or advertising. Where the law (such as GDPR) requires a legal basis, we rely on: performance of a contract for the account and features you ask us to provide; our legitimate interests in operating, securing, and preventing abuse of the Service; your consent where you have given it (for example, making your Portfolio public); and compliance with legal obligations where applicable.
3. Third-Party Service Providers
We rely on a small number of service providers ("processors") to run the Service. Each processes only the information needed for its function, under our instructions:
- The application and our PostgreSQL database (account records, profiles, Portfolios, messages, scores) run on infrastructure we operate ourselves.
- Cloudflare sits in front of the Service as our DNS, proxy, and tunnel provider, so it processes the IP address and request metadata of every request; its Turnstile product provides CAPTCHA-style bot protection on the sign-up and password-reset forms.
- Resend delivers our transactional emails. Resend receives the recipient email address, the message content, and delivery metadata.
- Google handles authentication if you choose "Sign in with Google".
- Anthropic processes the public news headlines we send to its Claude API to generate the "Homebrew" summary. No user personal data is included in those requests.
4. Cookies
We use cookies sparingly and only for purposes that are strictly necessary to run the Service you have asked for, so we do not display a cookie-consent banner:
- Session cookie (set by us). A single signed cookie that keeps you logged in. Strictly necessary; set only after you sign in.
- Cloudflare Turnstile (bot protection). When you submit the sign-up or password-reset form, Cloudflare may set a short-lived cookie to tell humans from bots. This is a security measure necessary to provide the action you requested.
- Google sign-in. If you choose "Sign in with Google", Google sets its own cookies to complete authentication. These are necessary for the sign-in you initiated; see Google's privacy policy for details.
We do not set advertising, analytics, or cross-site tracking cookies. Because the cookies above are strictly necessary or functional for actions you initiate, applicable EU/UK rules (ePrivacy/PECR) do not require us to obtain prior consent for them. If we ever add a non-essential cookie, we will ask for your consent first.
5. Data Retention
Account data is retained for as long as your account exists. Direct messages are kept while your account exists, up to a maximum of 365 days per message, after which older text messages are purged; shared-article previews go cold and are removed after 30 days.
When you delete your account, everything tied to it is removed from our active database promptly: your profile, Portfolio, friend connections and friend code, your game scores, and the direct messages and shared articles in your conversations. Because a conversation belongs to both people in it, deleting your account also removes those messages from the other person's view, and removes you from your friends' friend lists and from the leaderboards. Residual copies may persist for a limited period (up to 30 days) in routine database backups, and in Resend's email-delivery logs in accordance with that provider's retention policy. Standard server and proxy logs (including IP addresses) are retained by us and by Cloudflare for a limited period — typically no more than 30 days for our own application logs; Cloudflare's retention is governed by its own policies. We do not keep a separate archive of deleted accounts.
6. Security
All traffic to the Service is served over HTTPS with HSTS enabled.
Passwords are stored as salted hashes using a slow KDF
(pbkdf2:sha256); we never see or store your plain-text
password. We apply a strict Content Security Policy and standard
web-application defenses (rate limiting, CSRF protection, secure
session cookies). No system is perfectly secure, but we treat account
data with reasonable industry-standard care. If we ever become aware of a
data breach affecting your personal data, we will notify you and any
relevant regulator as required by applicable law.
7. Your Rights and Choices
You can exercise any of the rights below by emailing [email protected] from your account email. We will respond within 30 days (we may ask you to verify your identity first).
- Access. Request a copy of the personal data we hold about you.
- Portability / export. Request your account data (profile, Portfolio, messages, friends, scores) in a portable, machine-readable format (e.g. JSON). We fulfill export requests manually by email.
- Rectification. Correct inaccurate data — most fields you can edit yourself by signing in; for anything else, email us.
- Deletion. Delete your account at any time from the account menu, or ask us to do it. See Section 5 for what is removed.
- Restriction & objection. Ask us to restrict or stop certain processing, including any processing we carry out on the basis of legitimate interests.
- Withdraw consent. Where we rely on your consent (e.g. making your Portfolio public, or any future optional cookies), you can withdraw it at any time without affecting prior processing.
- Complaint. You have the right to lodge a complaint with a data-protection or privacy regulator. If you are in the EEA, UK, or Switzerland, you may complain to your local supervisory authority; California residents may contact the California Privacy Protection Agency or the Attorney General.
- California users (CCPA/CPRA). If you are a California resident, you have the right to (a) know the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties we disclose to; (b) delete personal information; (c) correct inaccurate personal information; (d) opt out of the sale or sharing of personal information; (e) limit the use of sensitive personal information; and (f) not be discriminated against for exercising these rights. The categories we collect are identifiers (email, account/Google ID), internet activity (server logs), and user-generated content (profile, Portfolio, messages, scores); our sources are you and our authentication/bot-protection providers; our purposes are described in Section 2; and the only third parties we disclose to are the service providers listed in Section 3. We do not sell or share your personal information as those terms are defined under the CPRA, and we do not use it for cross-context behavioral advertising, so we do not offer a "Do Not Sell or Share My Personal Information" link. We do not collect sensitive personal information for the purpose of inferring characteristics. To exercise any right, email [email protected].
8. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, email [email protected] and we will delete it. Depending on where you live, the minimum age for consenting to data processing may be higher than 13; you must meet the minimum age required by your local law.
9. International Transfers
Steeped is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States and other countries where our service providers operate. Where we transfer personal data of EEA, UK, or Swiss users, we rely on appropriate safeguards or applicable derogations under data-protection law (including your consent and the necessity of the transfer to provide the Service you requested).
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date above, and for material changes we will provide reasonable notice via the Service or by email.
11. Contact
Questions about this Privacy Policy or your data? Email [email protected], or write to us at the Data Controller address above.