The Daily Dispatch

Privacy Policy

The Daily Dispatch is committed to protecting your privacy. This Privacy Policy explains how the Application collects, uses, shares, and protects your personal data. Since the app is in beta, this page may be updated as features evolve. Last updated: August 3, 2026.

Data Controller

The data controller responsible for processing your personal data under the EU General Data Protection Regulation (GDPR) is Roman Tesliuk, Zimmerstraße 96, 10117 Berlin, Germany. You can reach the controller at roman@pixelwrld.co. Full contact details are listed in the Imprint.

What We Collect

Account Information: Your Apple ID email address and display name, provided through Sign in with Apple. This is used to create and manage your account.

Device Tokens: A push notification token associated with your device, used solely for delivering your briefings. We do not use this data for any other purpose.

Briefing Data: The topics, accounts, and interests you describe when creating an Edition, along with the AI-generated issues we produce for you. This data is stored to personalize your daily briefings.

Feedback: Any feedback you submit through the app to help us improve the experience.

Usage Analytics (in-app): While you use the app, we collect anonymized interaction events (such as screens viewed and features used) so we can understand how the product is used. Inside the app, these events are associated with your account so we can debug issues for individual users when needed.

Operational Logs: Backend logs of activity, errors, and background jobs, retained for a limited period to support debugging and abuse prevention.

Subscription & Purchase Data: When you buy a subscription or a token top-up, Apple processes the payment through the App Store. We receive a transaction identifier, the product you bought, and your subscription status and renewal dates, and so does RevenueCat, the service we use to manage subscriptions. We use this only to add your tokens, keep your subscription in sync across your devices, and handle renewals, cancellations, and refunds. We never see or store your card or bank details. Those stay with Apple.

Legal Basis for Processing (GDPR Art. 6)

Performance of contract (Art. 6(1)(b)): Account creation, briefing generation, push delivery, and feedback handling are necessary to provide the service you signed up for.

Legitimate interests (Art. 6(1)(f)): Product analytics, abuse prevention, security monitoring, and operational logging, based on our legitimate interest in maintaining and improving the service. You may object to processing under this basis at any time (see Your Rights below).

Consent (Art. 6(1)(a)): Optional cookies and analytics on the marketing website are only set after you give consent through the cookie banner.

What We Don't Collect

We do not serve advertisements. We do not sell, rent, or share your personal data with third parties for marketing purposes. We do not collect location data, contacts, photos, microphone, camera, health data, or any sensitive data beyond what is listed above. We do not track you across other apps or websites.

Sub-processors

We use the following third-party processors to operate the service. Where applicable, transfers to processors outside the European Economic Area are governed by the EU Standard Contractual Clauses, and for US-based processors by the EU-US Data Privacy Framework where they are certified.

Supabase for database, authentication, and file storage. Privacy policy.

Vercel for backend hosting and serverless functions. Privacy policy.

Apple for Sign in with Apple and the Apple Push Notification service. Privacy policy.

RevenueCat to manage in-app subscriptions and verify purchases. It receives subscription and transaction details, but never your payment information. Privacy policy.

Google Gemini for AI-generated briefing summaries. The topics and interests you configure are sent to Google so it can generate your content. AI terms.

Apify for collecting public social media content related to the topics and accounts you configure. Privacy policy.

CORE API for retrieving open-access research papers when your Edition includes academic topics. Privacy policy.

Twelve Data for stock and market data when your Edition includes tickers. Privacy policy.

Upstash as a job queue used to schedule and run briefing generation. Only minimal identifiers are passed, never your content. Privacy policy.

PostHog for product analytics. On the marketing website we run PostHog in a cookieless mode so no information is stored on your device. Inside the app, events are associated with your account so we can support and improve the experience. Privacy policy.

Slack for internal operational alerts. Only minimal identifiers are sent to a private channel, never your content.

AI Processing

The Daily Dispatch uses large language models to generate briefing summaries from publicly available sources. When you create an Edition, your topic descriptions are sent to our AI provider so it can generate your content. Briefing summaries are produced by AI and may contain inaccuracies, omissions, or hallucinations. See the Terms of Service for the full disclaimer.

We do not use AI to make decisions that produce legal effects concerning you, or that similarly significantly affect you (GDPR Art. 22). The AI's role is purely to summarize and present news content for your reading.

Data Retention

Account & profile: kept while your account is active.

Briefings & issues: kept while your account is active.

Device tokens: kept while your device is registered for push; expired tokens are pruned automatically.

Feedback: kept while your account is active.

Operational logs: up to 90 days.

Deleted accounts: when you delete your account, all of the above data is removed within 30 days. Backups are rotated within 30 days.

Cookies & Local Storage

Marketing website: we run our analytics in a cookieless mode that does not store cookies or any other identifiers on your device. Because nothing is stored or accessed on your device for this purpose, we do not show a cookie consent banner.

iOS app: The Daily Dispatch app does not use cookies. Authentication tokens and local cache are stored securely on your device.

Data Security

All network communication uses HTTPS encryption. Credentials are stored securely on your device. Backend access requires authentication and your data is scoped to your account. Backups are encrypted at rest. Despite our efforts, no method of transmission or storage is 100% secure and we cannot guarantee absolute security.

Your Rights (GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights regarding your personal data:

  • Access: obtain a copy of the personal data we hold about you.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure (the "right to be forgotten"): delete your account and all associated data from the Profile screen in the app.
  • Restriction: ask us to limit how we use your data.
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interests, including analytics.
  • Withdraw consent for any processing based on consent, at any time.
  • Right to lodge a complaint with a supervisory authority. For users in Berlin, this is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.

To exercise any of these rights, contact roman@pixelwrld.co. We will respond within 30 days.

California Residents (CCPA)

We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act (CCPA). California residents have the right to request access to, deletion of, or correction of their personal data, and to be free from discrimination for exercising these rights. To make a request, contact roman@pixelwrld.co.

Children's Privacy

The Daily Dispatch is not intended for children. We do not knowingly collect personal information from children under the age of 13 (United States, COPPA), under the age of 16 (most of the European Union), or under the age of 14 (Germany, § 25 TTDSG / DDG). If you become aware that a child has provided us with personal information without parental consent, please contact us immediately so we can remove it.

Updates to This Policy

We may modify this policy from time to time as the product evolves or regulations change. Material changes will be communicated through the app or via email. Your continued use of the Application after the effective date of the updated policy signifies your acceptance.

Contact

For privacy-related questions or to exercise any of your rights, contact roman@pixelwrld.co. We aim to respond within 30 days.