Privacy
What we store
The current alpha stores the account information needed for email-code sign-in and the minimum moderation records needed to operate the corpus. Site suggestions retain the website URL and moderation records. To limit repeated suggestions, signed-in submissions use a hash of the account identifier; anonymous submissions use a hashed submitter key. These attribution hashes and submission-attempt records are cleared after twenty-four hours. Site suggestions are reviewed manually and are not sent to AI classifiers.
Search content
We retain bounded plain text from public feeds and article pages to make their content searchable. Results show short excerpts and link to the publisher. Retained text can also support article classification under the input rules below. Source removal clears retained article bodies.
Article classification
When AI classification is enabled, elseweb sends public feed titles, excerpts and publisher tags from accepted sources to the configured AI service to suggest categories. The operator can use OpenAI, OpenRouter, a local Ollama model or another compatible service. OpenRouter passes requests to an inference provider. Public text can contain personal information. Retained article text can be processed locally. Sending it to a hosted classifier requires separate operator approval and a documented provider/input policy. We do not include account information, personal-feed preferences or private moderation notes. Hosted services apply their own retention policies; OpenAI requests disable response storage, but may still be retained for abuse monitoring. A locally hosted model can process this text without sending it to a hosted AI service. Contact the operator through the removal page for this deployment’s provider details. Language and category decisions can come from local analysis or the configured classifier.
Retained subscriptions and exports
Subscriptions saved before the category feed remain private to your account. You can export retained public feed URLs as OPML or delete your account; deletion revokes sessions and removes private preferences and personal-feed settings. Exports are generated directly and are not stored by elseweb.
Personal-feed preferences
Saved interests, reading languages, exclusions and publisher blocks are private to your account. They remain until you change them or delete your account. A publisher block retains its recorded URL scope even if the source is removed, until you explicitly unblock it. Account deletion removes these settings and blocks. They are not sent to classifiers.
Seen articles and site icons
We store which articles you have seen, and when they were first marked, privately with your account. An article is marked seen after its headline and description are visible for one second in an active tab, or when you open its original link. This does not mean you read it. You can mark an article unseen from its menu. Seen indicators apply only to articles within a 90-day window. Older articles show no seen or unseen status. Expired history is removed in scheduled batches; your site-icon preference remains until you change it or delete your account. They are not sent to publishers or classifiers. Publisher icons are fetched by Elseweb and served from our cache; your browser does not contact publishers for them.
Private RSS
When enabled, anyone possessing your RSS URL can read its current articles. Elseweb stores only a hash of its random credential and shows the URL once when you create or replace it. Replacing or revoking it disables the old URL. Account deletion removes the credential and its linked request counters. Short-lived hashed network counters protect request limits and are cleared by bounded cleanup. RSS readers may keep articles they already downloaded, even after a correction or revocation.
Topic suggestions and match reports
When enabled, these private forms send your proposed topic or match issue and optional note to the administrator for review. They are not sent to classifiers and do not automatically change an article’s classification. Pending records expire after thirty days without an editorial decision; resolved records are removed after thirty more days. Account deletion removes your submissions and reporting allowances. Non-identifying category definitions and editorial revisions can remain.
Browser preferences
Unsaved personal-feed selections can remain in this tab’s session storage for up to fifteen minutes so you can recover them after sign-in or a failed save. The draft is tied to your account and is cleared after a successful save, sign-out or account deletion. It is never saved to your account automatically. Feed navigation keeps the filter in the URL and the reading position in browser history; it does not store article copies there. Clearing browser storage removes the draft.
Error reporting
When error monitoring is configured, technical error reports are sent to Sentry to help diagnose failures. Reports contain code locations, the application version and the affected service. We remove account details, sign-in codes, request contents, article text and raw error messages. Session replay, activity breadcrumbs and performance tracking are disabled. As with any direct network connection, the receiving service can see the connection’s IP address. Retention is controlled by the operator’s Sentry project settings.
Deletion and recovery
Contact the operator through the removal page for source concerns. Operational records are minimized. Account deletion retains a one-way email-derived SHA-256 identifier, opaque account identifier and timestamp so a restored backup cannot silently revive the deleted account or a stale authentication request. A fresh email code is required before an erased address can register again. Our backup policy uses Railway only, with scheduled database backups retained for up to 89 days and point-in-time recovery covering approximately four weeks once enabled. Deleted data may remain in those backups until they expire. Before restored data is served, we must reapply subsequent account deletions and source removals. If those records cannot be verified, the restored service stays offline.