Privacy Policy
NewsletterScriv is operated by GlyphStack LLC (P.O. Box 494, Benton, PA 17814). Privacy questions and requests: legal@glyphstack.com.
The two kinds of people we hold data about
Authors—our customers, who create accounts. For authors, we decide how account data is handled, and this policy describes it.
Readers—the subscribers on an author’s list. A reader’s data belongs to the author who collected it; we process it only to provide the service, on that author’s instructions. If you’re a reader with a question about a newsletter you’re on, the author is the right first stop—the unsubscribe link in any of their emails works instantly, no login, no questions. We’ll help with anything they can’t resolve.
What we collect about authors
- Account data: name, email address, and sign-in credentials (managed by our authentication provider, Clerk).
- Billing data: handled by Stripe. We see your plan, billing status, and invoices—never your full card number.
- Content and settings: your audiences, emails, forms, books, branding, and configuration.
- Usage and technical logs: the operational records any web service keeps—requests, errors, send activity—used to run and debug the service.
What we process about readers, for authors
- Email address, name, country, and any fields the author imports or collects.
- Consent records—when and how a reader opted in, preserved through imports, because proof of permission protects readers and authors alike.
- Engagement events—deliveries, opens, clicks, bounces, complaints, unsubscribes. Emails sent through NewsletterScriv include standard open/click tracking. We filter automated machine activity (like inbox-provider prefetching) out of engagement metrics rather than counting it as human interest.
- Suppression records—who unsubscribed, bounced, or complained. We retain these even if a contact is deleted, because forgetting them is how people get emailed again after saying no.
What we never do
- Sell anyone’s data—authors’ or readers’.
- Use an author’s subscriber list for our own marketing, or let anyone else.
- Mix data between accounts.
- Run advertising or analytics trackers anywhere a reader goes, or inside your dashboard. Those live only on our own marketing pages—see Cookies below.
- Send an author’s or reader’s email address to an advertising network.
Who helps us run the service
These providers process data on our behalf, under their own contractual commitments:
- Amazon Web Services (email delivery via SES; United States)
- Google Cloud (application hosting and file storage; United States)
- Neon (database hosting; United States)
- Clerk (authentication)
- Stripe (payments)
AI assistance is different, and opt-in. The writing assistant in the campaign editor runs on your own API key, which you add yourself in settings. If you turn it on, the text you ask it to work on is sent to the provider you chose—Anthropic, OpenAI, or Google—under your account with them and their terms, not ours. Add no key and nothing is ever sent. We don’t train models on your content, and we don’t send your subscriber list to any AI provider.
Data is processed in the United States. If you use NewsletterScriv from elsewhere, you understand your data (and your readers’ data) is transferred to and processed in the U.S.
Cookies, site analytics, and advertising
We use the session cookies our authentication requires, and your browser’s local storage for preferences like the light/dark theme.
If you reach us from one of our ads, we also set a cookie that remembers which of our pages you arrived on—so that if you go on to create an account, we can tell which page brought you. It holds a single word, it expires after 30 days, and it is never sent to anyone else. If you have opted out of measurement below, or your browser sends a Global Privacy Control signal, we don’t set it at all.
Our own marketing pages use Google Analytics—the homepage, the public documents like this one, the help pages, and the sign-in and sign-up pages. It tells us how many people visited and which page they arrived on, and it sets its own cookies to do that. What Google does with it is covered by Google’s privacy policy.
It does not run anywhere a reader goes. Hosted landing pages, the web version of an email, book pages, the newsletter archive, magnet downloads, and the unsubscribe and preference pages carry no analytics of ours—an author’s readers are that author’s business, not ours to measure. It is off inside the signed-in dashboard as well, so an author’s working session isn’t marketing data either.
Those same marketing pages also carry the Meta (Facebook) pixel, so we can tell which of our ads brought someone to the site. That is advertising technology: it sets its own cookies and lets Meta recognise a browser it has seen elsewhere, under Meta’s privacy policy. It runs on exactly the same pages as the analytics above and nowhere else—never where a reader goes, never inside the dashboard—and we do not send it anyone’s email address or phone number. If you would rather not be measured this way, a tracker-blocking browser extension stops it, and nothing on the site behaves differently when it is blocked.
When you create an account, we may also send Meta a CompleteRegistration event from our servers(the Conversions API). The browser pixel often cannot fire inside an in-app browser, so the server event is how we know an ad led to a signup. That event includes your IP address and browser user-agent, plus Meta’s own cookies if your browser already has them—not your email, not your phone, and not any other identifying account field. The opt-out below, and a Global Privacy Control signal, stop both the pixel and the server event.
Retention
- Account and content data: for the life of the account. If you cancel or go inactive, we hold everything for five years from your last activity, and email you three warnings before anything is removed—so a lapsed account never quietly costs you your list.
- What you delete yourself is a different thing. The five-year hold is a limit on what we remove, not a spare copy we keep for you. If you delete an audience, a campaign, or a contact from inside the app, it goes then and there—and we can’t promise to recover it for you afterward. Export before you delete; the button is always there and never gated.
- Suppression records: retained permanently, by design (see above).
- Backups and logs: kept on rolling windows appropriate to operating the service, then aged out.
- If you ask us to delete your data outright, we complete it within 30 days—see Deleting your data for exactly what that removes and what survives it.
Security
Traffic is encrypted in transit. Credentials are handled by dedicated providers, stored secrets (like API keys you connect) are encrypted at rest, and production access is limited to what operating the service requires. No one can promise perfect security; if a breach affects your data, we’ll tell you promptly and plainly.
Your rights
- Authors: you can access and export everything, correct your details, or close your account—see Deleting your data for how erasure works and what it removes. Email us for anything the dashboard doesn’t already let you do yourself.
- Readers: unsubscribe links work instantly in every marketing email. For access, correction, or deletion requests, contact the author who runs the list—or us at legal@glyphstack.com, and we’ll route and assist. Depending on where you live, laws like GDPR or state privacy acts may give you specific rights; we honor them.
Children
NewsletterScriv is intended for adults and is not directed at children under 16, and we don’t knowingly collect their data. If you believe a child’s data has reached us, tell us and we’ll remove it.
Changes
If this policy changes in a way that matters, we’ll notify authors by email or in the dashboard before the change takes effect. The “last updated” date above always tells you the current version.