Privacy Policy

The Hard Copy ("we", "us") operates the subscription service at thehardcopy.org that aggregates articles you read online into a regularly printed book. This policy explains what data we collect, how we use it, and which third parties process it on our behalf.

Data we collect

  • Account data — your email address, name, and authentication identifiers from any OAuth provider you sign in with.
  • Subscription and billing data — plan selection, billing status, and payment metadata. We do not store full card numbers; payment instruments are held by Stripe.
  • Shipping data — the postal address you provide for book delivery.
  • Content sources you connect — RSS feeds you add, and, if you connect a Gmail account, message metadata and message bodies needed to extract newsletter content for your book.
  • Operational logs — minimal request and error logs needed to run the service.

How we use your data

We use your data only to operate the service: authenticating you, building and printing your monthly book, charging your subscription, shipping the book, and providing customer support. We do not sell your account data. The only advertising-related measurement we do is the opt-out-able marketing pixel described under "Analytics and advertising" below.

Analytics and advertising

On our public marketing pages we use two measurement tools:

  • Plausible — privacy-friendly, cookieless website analytics (aggregate traffic and conversion counts). It sets no cookies and collects no personal information.
  • Meta (Facebook) pixel — used to measure and improve our advertising. It loads only for visitors outside the EU, EEA, and UK, where it sets cookies and shares limited event data (such as page views and whether you signed up) with Meta. We do not enable "advanced matching," so we do not send Meta your email address or phone number.

Your choices. If you are in the EU, EEA, or UK, the advertising pixel never loads. Everyone else can opt out at any time below, and we honor the browser Global Privacy Control signal automatically. Opting out stops the pixel from loading on subsequent visits.

This stops the advertising pixel from loading. We remember the choice for about 13 months.

An opt-out you record here is stored in that browser, so if you use more than one browser or device you will need to record it in each. Global Privacy Control, by contrast, we honor everywhere you send it.

Email communications

We send two kinds of email, and you control the optional ones:

  • Essential emails keep your subscription working and cannot be turned off while your account is active — account verification and password resets, a failed-payment or invalid-address notice, and other alerts where missing the message would disrupt your book or billing.
  • Optional emails can be turned off at any time from Manage account → email preferences in your dashboard. These are the shipping and delivery notifications for each issue, and the monthly digest that summarizes lower-priority items (such as articles trimmed for space or a source that failed to update) before your next book. Optional emails include a "Manage email preferences" link and an unsubscribe header.

Google user data — Limited Use disclosure

If you connect a Google account, The Hard Copy's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • Scopes requested. We request two Gmail scopes, gmail.modify and gmail.settings.basic. Together they let us read the newsletter messages you have chosen to include in your book, create a "Hard Copy" label and a filter that applies it to those messages, and — only if you turn that option on — archive them out of your inbox. We do not request the ability to send mail as you, and we never delete a message: archiving moves mail out of the inbox, it does not remove it from your account. We ask for gmail.modify rather than a read-only scope because it already covers the label access we need. Requesting it on its own means asking for one permission where the alternative would have been two.
  • Use limited to user-facing features. Gmail data is used solely to fetch and lay out the newsletter content that appears in your printed book and the corresponding previews in your account.
  • No transfer to third parties. We do not transfer Gmail data to third parties except as necessary to provide or improve user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
  • No advertising. We do not use Gmail data for serving advertisements, including retargeting, personalized, or interest-based advertising.
  • No human reading. We do not allow humans to read Gmail data except with your explicit consent for specific messages, as necessary for security purposes (such as investigating abuse), to comply with applicable law, or where the data has been aggregated and anonymized.
  • No ML training. We do not use Gmail data to develop, improve, or train generalized machine learning models.
  • Encryption. Gmail data is encrypted in transit (TLS) and at rest.
  • Retention and deletion. You can disconnect your Google account at any time from your account settings. Disconnecting removes the label and filter we created, stops us collecting any further mail, and revokes our access to your Google account. Newsletter content we have already gathered stays with your account — it is what your past and upcoming issues are made of — and is deleted when you delete your account. See "Data retention" below. You can also revoke access directly at myaccount.google.com/permissions.

Third-party data processors

We rely on the following sub-processors to operate the service. Each one receives only the data it needs for its specific function.

  • Google — OAuth sign-in and the Gmail API, used to authenticate you and to fetch newsletter content from accounts you connect.
  • Stripe — payment processing and subscription billing. Stripe receives your name, email, billing address, and payment instrument details.
  • Our print-on-demand partner — book manufacturing and shipping. Receives your shipping name and address along with the rendered book PDF for each order.
  • Mailgun — transactional email delivery. Mailgun receives your email address and the contents of the account, billing, shipping, and digest messages we send you.
  • Plausible — cookieless website analytics for our marketing pages. Receives only aggregate, non-identifying page-view data.
  • Meta (Facebook) — advertising measurement via the pixel described above, for non-EU/EEA/UK visitors who have not opted out. Receives limited event data (page views, sign-up/subscribe events); not enabled for connected-account (Gmail) data.
  • Cloudflare — application hosting, including Cloudflare Workers and the D1 database where account, subscription, and fetched newsletter content are stored. Cloudflare encrypts D1 data at rest.
  • EasyPost — delivery tracking for shipped books. Receives the shipment and tracking identifiers associated with your order.
  • Oxylabs — proxy infrastructure used when fetching article pages. Receives the addresses of articles being fetched for your book.
  • Amazon Web Services — compute for the monthly build that assembles your book, which processes the newsletter content going into it, and storage for our own service configuration.
  • Infisical — secrets management for our service credentials. Receives no reader data.

Data retention

  • Newsletter content — the articles gathered for your book are retained while your account is active. They are what your issues are built from and what your issue history shows.
  • Print-ready files — the PDFs we send to the printer are kept while the print job needs them and are deleted one month after delivery.
  • Cover and spine images — kept for your issue history, so past issues stay visible on your shelf. They contain no article text.
  • On account deletion — all reader-owned articles and stored files are deleted, along with your account record and any connected-account tokens. Billing records may be retained as required by law.

Security

Data is encrypted in transit using TLS and at rest in our hosting and database providers. Access to production systems is restricted to the operators of the service.

Your rights

You can access, export, correct, or delete your account data at any time from your account settings, or by emailing us. Deleting your account removes your account record, cached content, and OAuth tokens; billing records may be retained as required by law.

Changes

We will update the lastUpdated date above when this policy changes. Material changes will be communicated by email to active subscribers.

Contact

Questions about this policy: cooper@thehardcopy.org.