Privacy Policy
What we know about you, and what we do with it.
Last updated 29 July 2026
The short version
- We ask for one thing: your email address. Nothing else is required, ever.
- We never sell it, rent it, or hand it to advertisers. There are no advertising trackers on this site.
- We measure how the site is read — pages, clicks, roughly where in the world you are — but we do not store your IP address and we do not know your name.
- Our servers are in the United States, so your email address is stored outside Europe. Section 5 explains what protects it.
- You can leave in one click, and you can ask us to delete everything by sending one email. We will do it within 30 days.
1. Who is asking
This site is run by Nadia Sadegh, who publishes the Market Briefs newsletter and the writing at nadia-sv.com. In data protection language she is the data controller: the person who decides what is collected and why, and the person answerable for it.
For anything on this page — a question, a request, a complaint — write to nadia@nadia-sv.com. A person reads it.
2. What we actually collect
If you subscribe
Your email address, the date you signed up, and which form you used. If you arrived from a link with campaign tags on it, or from another website, we keep that too — it tells us which of the things we write actually brings people in.
After that we record what the emails do: whether one was delivered, whether it was opened, whether a link in it was clicked, and whether it bounced. Opens are measured with a small invisible image, which is the standard method and an unreliable one — Apple Mail and several others load it whether or not you looked. We treat opens as a weak signal for exactly that reason.
If you only visit
We record which pages were opened, what was clicked, how far down the page you got, and how long you were actually reading rather than merely parked. Each visit gets a random ID stored in your browser so that three pages in a row are recognisable as one visit instead of three strangers.
We also record an approximate location — country, region, city, and coordinates rounded to about ten kilometres. This is worked out by our host from your connection at the moment of the request. Your IP address is never stored; there is no column in our database that could hold one.
One thing worth being explicit about, because it is the part a reader could not guess: if you subscribe, we connect that random browsing ID to your subscription. It lets us see which article persuaded someone to sign up. It also means that from that point on, the browsing record is no longer anonymous to us. If you would rather it was not connected, say so and we will unlink it.
If you email us
Your message and your address, kept as long as the conversation is useful.
3. Why we are allowed to
European law says we need a specific reason for each thing we do, not a general one. Here they are:
Sending you the newsletter
Your email address
Consent — you asked for it, and confirmed by clicking the link in the first email. You can take it back at any time.
Knowing which issues get read
Opens, clicks, bounces
Legitimate interest — a newsletter nobody opens is a newsletter that needs rewriting. You can switch this off by asking.
Understanding how the site is used
Pages, clicks, scroll depth, approximate location
Legitimate interest in improving the site, balanced against a design that stores no IP address and no name.
Answering an email you send us
Whatever is in your email
Legitimate interest — you wrote to us and would like a reply.
4. Cookies, and what we use instead
We do not use advertising cookies, and there is no Google Analytics, no Meta pixel and no third-party tracker on this site. The measurement described above is our own, and it runs on our own servers.
It stores two random IDs in your browser’s local storage — not cookies, but the same idea and the same rules apply. They contain no name and no address, only random characters. Staff signing in to the admin area also get a normal login cookie, which does not apply to readers.
Turning it off. If your browser sends a Global Privacy Control or Do Not Track signal, we detect it and record nothing at all — no ID is even created. Most privacy-focused browsers and extensions send one. You can also ask us directly and we will exclude you.
5. Who else touches it, and where it goes
We do not sell or rent your data, and we do not share it for anyone else’s marketing. We do rely on four companies to run the service. They act on our instructions, under contract, and may not use your data for their own purposes.
Supabase
Hosts the database: subscriber list, site analytics.
United States (us-west-1)
Vercel
Hosts and serves the website itself.
United States, with edge servers worldwide
Resend
Delivers the newsletter and records delivery, opens and clicks.
United States
Anthropic
Helps draft newsletter copy from public news sources. It never receives your email address or any other subscriber data.
United States
All four are in the United States, which means your data leaves the European Economic Area. That transfer is covered by the European Commission’s Standard Contractual Clauses in each supplier’s data processing agreement — the mechanism European law provides for exactly this situation. We would rather tell you plainly than bury it.
We would also hand data over if the law genuinely required it — a court order, for instance. Nothing else.
6. How long we keep it
7. Your rights, and how to use them
If the GDPR applies to you, you have the right to see what we hold, correct it, delete it, get a copy in a portable format, restrict what we do with it, object to it, and withdraw your consent at any time. Withdrawing consent does not undo what was lawful before you withdrew it.
How to actually do it: send one email to nadia@nadia-sv.com. Say what you want. You do not need to cite an article number or use any particular wording. We will reply within 30 days, and it is free.
To just stop the newsletter, the unsubscribe link at the bottom of every issue is faster than emailing us, and it takes effect immediately.
If we get it wrong, you can complain to the data protection authority where you live. In the Netherlands that is the Autoriteit Persoonsgegevens. We would rather you came to us first, but that right is yours regardless.
8. Where AI comes into it
We use AI, and it seems only fair to say exactly how. Draft newsletter copy is prepared with the help of a large language model working from public news sources. Every issue is then read, edited and approved by Nadia before it is sent, and she takes editorial responsibility for what goes out under her name.
No subscriber data is sent to any AI model. Not your address, not what you clicked, nothing. The drafting works from published news and nothing else.
Nothing here makes automated decisions about you. There is no profiling that affects what you are offered, no automated pricing, and no algorithm deciding anything with a legal or similarly significant effect. Under the EU AI Act, content that has been genuinely reviewed by a person who takes editorial responsibility does not require an AI-generated label — we are telling you anyway, because you should not have to look it up.
9. Security, and an honest word about standards
Data is encrypted in transit and at rest. Access to the subscriber list is restricted to Nadia and one administrator, enforced in the database itself rather than only in the interface, so a bug in a page cannot expose a list the database will not serve. The keys that could bypass those rules exist only on the server and never reach your browser.
We are not ISO 27001 certified, and we do not claim to be. It is an audited certification for an organisation of a certain size, and saying otherwise to look reassuring would be the sort of thing this policy exists to avoid. The companies we build on — the four named above — hold their own independent security certifications, which is a real thing but is theirs, not ours. What we can tell you is what we do: keep the data minimal, keep the access narrow, and write down honestly what we hold.
If something ever goes wrong in a way that puts you at risk, we will tell the relevant authority within 72 hours and tell you without undue delay.
10. Children
This site is written for adults and is not directed at children under 16. We do not knowingly collect their data. If you believe a child has subscribed, tell us and we will remove it.
11. If this page changes
We will update the date at the top. If a change actually matters — a new company handling your data, a new purpose — we will say so in the newsletter rather than quietly editing the page and hoping you re-read it.
Questions about any of this go to nadia@nadia-sv.com. If you came here from the signup form, you can go back to it.