Who is responsible for your data
The controller of personal data collected through databubble.co (“Databubble”, “we”) is [legal entity name: to be completed], [address: to be completed], registration number [registration number: to be completed].
For any question or request about your data, write to [email protected] or use the contact form.
What we collect and why
Most of Databubble works without an account and without giving us any personal data. This is everything we collect when you use the parts that need it.
- Account
- Your email address and password, handled by Supabase Authentication (we never see your password in readable form). If you sign in with Google or X, we receive the email address, name and profile picture that account shares. Used to create and secure your account and to provide the features you use while signed in. Legal basis: performance of the contract (our Terms).
- Watchlist
- The models you add to your watchlist and the email alert setting you choose for each. Legal basis: performance of the contract.
- Stack Watch emails
- Pro only. If you turn on email alerts for a model on your watchlist, we store that setting and the time you turned it on. We also store your email preferences (alerts on or off, weekly digest on or off, and whether and when you unsubscribed) with a random unsubscribe token that appears only in the unsubscribe link of your emails. A delivery record keeps which change notification we emailed to your account, when, and whether it was sent. The email address itself is read from your account when a message is sent and is not copied into these records. Used to send the alerts and digest you turned on, to avoid sending the same notification twice, to limit alerts to one alert email a day, and to stop sending when you unsubscribe or your Pro subscription ends. Every email carries a one-click unsubscribe link and a link to Settings. Unsubscribing turns off alerts and the digest for your account and keeps your per-model settings, so you can turn emails back on in Settings. Legal basis: performance of the contract.
Draft note: the legal basis and the wording above come from docs/stack-watch-spec.md, not from legal advice. Confirm them in the review.
- Votes and comments
- Your bullish or bearish votes on news articles and the comments you post. Comments are public: each one is shown with a handle derived from your account identifier, which does not reveal your email address. Your account identifier and email address are stored with the comment but not displayed. Legal basis: performance of the contract.
Draft note: this describes the server-side comments route in src/app/api/news/comments. If that change is not deployed, comments still show the start of the commenter's email address and this paragraph must say so.
- Newsletter
- Your email address, which form you signed up through, and the dates you signed up, confirmed and unsubscribed. We use double opt-in: you receive a confirmation email and nothing else is sent until you click it, and we may send reminders if you do not. Every email carries an unsubscribe link that works in one click. After you unsubscribe we keep your subscriber record, marked as unsubscribed, so you are not mailed again by mistake. Legal basis: your consent, which you can withdraw at any time.
- Contact form
- Your name, email address and message. They are stored in our database and emailed to us, and used only to answer you and keep a record of the exchange. Legal basis: our legitimate interest in answering requests, or steps you ask for before a contract.
- Subscription and billing
- If you buy Pro, Stripe collects your payment details and billing information on its own checkout page. We receive from Stripe a customer identifier and your subscription status, and store them with your account to switch Pro access on and off. We do not receive or store your full card number. Legal basis: performance of the contract, and our legal obligation to keep accounting records.
- API keys
- If you create an API key in Settings, we store a hashed copy of the key and the number of requests made with it, to apply rate limits. Legal basis: performance of the contract.
- Technical data
- Your IP address, browser type and the pages you request are processed by our servers and by Cloudflare to deliver the site, block abuse and apply rate limits (for example on the contact and newsletter forms). Legal basis: our legitimate interest in security and reliable operation.
- Analytics
- Only if you accept analytics cookies: Google Analytics 4 measures which pages are visited, roughly from where and on what kind of device. Nothing is sent to Google before you accept. Legal basis: your consent, which you can withdraw at any time (see Cookies and similar technologies below).
Who we share data with
These providers process data on our behalf or, for Stripe, under their own terms.
- Supabase
- Database and authentication: accounts, watchlists, email alert preferences and delivery records, votes, comments, newsletter list, contact messages.
- Stripe
- Payments and the customer portal where you manage or cancel Pro. See Stripe's privacy policy.
- Google Analytics 4
- Audience measurement, only after you accept analytics cookies.
- Postal
- The mail server we operate to send the newsletter and its confirmation emails and, for Pro subscribers who turn them on, Stack Watch alert and digest emails.
- Cloudflare
- DNS, caching and security filtering in front of the site, and routing of email sent to our databubble.co addresses.
- Hosting
- [hosting company: to be completed] hosts the servers that run the site, which we manage with Coolify.
- Groq
- Language-model API we use to tag public news articles. It receives public article text only, never visitor or account data.
- Google and X
- Only if you choose to sign in with them. They tell us who you are; we tell them you signed in.
Your browser also loads some images (organisation logos, article thumbnails) directly from third-party hosts such as Hugging Face, GitHub and the news publishers. Those hosts can see your IP address when they serve the image.
We do not sell personal data. At the time of writing the site does not show advertising and does not load advertising scripts. We may disclose data where the law requires it.
Transfers outside the European Economic Area
Some of these providers are based outside the European Economic Area, for example in the United States. Where personal data is transferred, we rely on the safeguards those providers put in place, such as the European Commission's standard contractual clauses or the EU-US Data Privacy Framework, where they apply.
How long we keep data
- Account data
- Kept while your account is open, then for [account retention period: to be completed].
- Newsletter
- Kept until you unsubscribe. The subscriber record (your email address, the form you signed up through, and the dates you signed up, confirmed, unsubscribed and were last emailed) is then kept for [subscriber record retention period: to be completed] so we do not mail you again by mistake.
- Stack Watch preferences
- Kept while your account is open and deleted with it.
- Stack Watch delivery records
- Kept for 13 months, then deleted, or earlier if your account is deleted.
Draft note: the 13-month period is the design default in docs/stack-watch-spec.md and is not confirmed. No job deletes these rows: the spec leaves it to a manual SQL statement, so someone must run it periodically or this sentence must change. Confirm the period, then add a field for it in src/lib/legal.ts.
- Stack Watch change log
- The log of changes to models (price, context window, catalogue) is about models, not people. It contains no personal data and is kept indefinitely.
- Contact messages
- [contact message retention period: to be completed]
- Billing records
- [billing record retention period: to be completed], as required by accounting law.
- Server and security logs
- [log retention period: to be completed]
- Analytics
- [analytics retention period: to be completed], as configured in Google Analytics.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected;
- have your data erased, where the law allows;
- restrict how we use your data, or object to a use based on our legitimate interest;
- receive the data you gave us in a portable format;
- withdraw a consent you gave (newsletter, analytics) at any time, without affecting what was done before.
To use any of them, email [email protected], preferably from the address linked to your account so we can verify it is you. We answer within one month; the law allows an extension in complex cases, and we would tell you why.
There is no self-service button to delete an account yet. Email us from your account address and we will delete the account and the data linked to it, apart from records we must keep by law, such as billing records. You can unsubscribe from the newsletter at any time from the link in any email.
We do not take decisions about you based solely on automated processing. If you think we have not respected your rights, you can complain to the CNIL (cnil.fr) or to the data protection authority of your country of residence.
Cookies and similar technologies
Some items are needed for the site to work or are stored only because of something you did; they do not need consent. Analytics cookies are set only if you accept them.
- Sign-in session
- Cookies whose names start with sb-, set by Supabase when you sign in, to keep you signed in. Necessary.
- Cookie choice
- The item databubble_consent_v1 in your browser local storage remembers whether you accepted or declined analytics. Necessary.
- Newsletter prompts
- The nl_widget_dismissed and nl_exit_intent_dismissed cookies (14 days each), the nl_subscribed item in local storage and the nl_exit_intent_fired item in session storage remember that a newsletter prompt was shown, closed or used, so it is not repeated. Necessary.
- Checkout resume
- If you click Upgrade while signed out, the db_pending_plan item in session storage keeps the plan you chose (monthly or yearly) and a timestamp so checkout can continue after you sign in. It is removed once used, expires after 30 minutes and disappears when you close the tab. Necessary.
- Google Analytics
- The _ga and _ga_ cookies, set by Google Analytics 4 only after you accept. They tell visits apart. See Google documentation for their lifetimes.
You can change your choice at any time with here or in the footer of any page. Declining or withdrawing stops measurement and removes the Google Analytics cookies from this site. You can also block cookies in your browser, but sign-in will then not work.
Children
Databubble is not aimed at children and we do not knowingly collect their data.
Changes to this policy
We may update this policy. The date at the top of the page shows the current version, and we will highlight material changes on the site.