Aporia is operated by Andrew Anuichi, a sole proprietorship. For anything in this policy, write to andrew.anuichi@gmail.com.
Personal data lives in a separate database file from the news corpus. The corpus is a build artifact that is rebuilt and published as part of the application image; account data, reading history, support tickets and donation records are never part of that published artifact.
Nothing that identifies you.
The only thing recorded for a signed-out visit is an increment to a daily counter of how many times a kind of page was viewed, for example "the article page was viewed 40 times today". That counter holds no identifier, no address and nothing that could be tied back to you or to a session.
Clicks on buttons, tabs and toggles are not recorded at all for signed-out visitors. The endpoint that receives them answers successfully and stores nothing.
We do not ask for your real name, email address, date of birth or location, and there is nowhere to enter them.
This exists because it is the feature: an account's purpose is to keep this record for you. It is also read in two other ways, both described in clause 5.
Anything you write in a support ticket or feedback box, and the status and timestamps of that ticket.
If you donate: the amount, the currency, whether it recurs, the payment provider's reference numbers, the status of the payment, when it arrived, any note you attached, the name you gave if you gave one, and a link to your account if you were signed in. We never receive or store your card number. That is handled entirely by Stripe.
Each of these was a choice, and each is one line of code away from being otherwise:
Where the UK or EU General Data Protection Regulation applies, our legal bases are as follows. Where Canadian federal or provincial privacy law applies, the equivalent basis is your consent, given when you create an account and accept these terms, except where the law permits otherwise.
We do not sell personal data, we do not share it for advertising, and we do not use it for automated decisions that produce legal or similarly significant effects about you.
Your reading history can reveal what subjects interest you, which may include political ones. We treat it accordingly: it is never published in a form tied to you, never sold, and deletable by you at any time.
This site analyses published journalism, so it necessarily holds data about identifiable people: the bylines it extracts from articles, and the figures it derives about the work published under them.
For each byline, we hold the name as it appeared, the articles attributed to it, and figures aggregated from those articles such as beat, volume, claim counts, hedging rate and leaning. We do not collect contact details, employment records, private information, or anything not present in or derived from published articles.
We rely on our legitimate interest in analysing published journalism and in the public interest in understanding how news is reported, together with the exemptions that data-protection law provides for processing carried out for journalistic, academic, artistic or literary purposes, and for research and statistical purposes. We have weighed that interest against the rights of the people concerned, and the analysis is limited to their published professional work.
If you are named on this site, you may ask us to correct an error, to show a statement of your own on your page, to stop analysing your work, or to delete your page and the data behind it. You may also object to the processing entirely. Write to andrew.anuichi@gmail.com or andrew.anuichi@gmail.com. We aim to acknowledge within 5 working days. A request to correct an error or remove a page is acted on without requiring a reason.
One cookie, and it carries at most two things. It is a signed session cookie. Once you sign in it holds your account's internal identifier, so the site knows you are logged in; signing out clears that.
It is also set before you sign in, on the pages that carry a form you can submit — the sign-in and registration pages, and the donation form on the Support page. On those it holds a single random value with no meaning outside this site and no connection to you: the form carries a copy of it, and the site checks that the two match before acting on what was submitted. That is what stops another website from causing your browser to submit one of our forms without your knowledge. Pages with no such form do not set it.
Both uses are strictly necessary — one for the account feature, one for the security of the forms — and neither is used for tracking, profiling or advertising.
One item of local storage, named
aporia.intro.seen, set the first time you visit the home page.
It records only that you have already been shown the introduction, so you
are not shown it again. It holds no identifier, it is never sent to our
servers, and clearing your browser's site data removes it. It is strictly
necessary in the sense that matters here: without it the feature it supports
cannot work at all.
There are no analytics cookies, no advertising cookies and no third-party cookies, and nothing else is written to your device.
No AI provider. The language models that write summaries and score articles run locally on our own machine. No article text, no account data and no record of your activity is sent to OpenAI, Anthropic, Google or any other model provider.
We may disclose data where we are legally required to, or to establish or defend a legal claim.
Data is stored on servers operated by our hosting provider. Depending on the region we deploy to, that may be outside your country, including outside the UK, the EEA or Canada. Where personal data is transferred out of the UK or EEA, we rely on the UK International Data Transfer Agreement or the European Commission's standard contractual clauses, as applicable.
Passwords are stored only as scrypt hashes and are never recoverable, by us or by anyone else. The sign-in form does the same work whether or not the username exists, so it cannot be used to discover which accounts are real. Session cookies are cryptographically signed. Administrative areas are separately gated and excluded from search-engine crawling. Personal data is kept in a different database file from the published news corpus, so it cannot be published by accident.
No system is perfectly secure. If you find a vulnerability, please write to andrew.anuichi@gmail.com. We will not pursue a good-faith reporter.
Subject to the conditions in the law that applies to you, you may ask us to:
You can do most of these yourself and immediately, without asking us, from your history page: see everything held about your reading and searching, take a copy of all of it as a JSON export, delete individual entries, clear your search history, change your password, and delete the account itself along with everything personal attached to it.
Two things survive an account deletion, and the deletion page says so before you confirm rather than afterwards: support tickets you sent are kept but unlinked from you, because a ticket is half of a conversation we may still be answering, and payment records are kept for as long as tax record-keeping law requires (section 10). Neither can be traced back to your account once it is gone.
For anything else — correcting something inaccurate, restricting or objecting to a use, or a request about data we hold that is not tied to an account — write to andrew.anuichi@gmail.com. We aim to respond within 30 days and will not charge you.
The Service is not directed at children, and you must be at least 16 to create an account. We do not knowingly collect data from children. If you believe a child has created an account, write to andrew.anuichi@gmail.com and we will delete it.
We may update this policy. The version and effective date at the top of this page say which one is in force. For changes that materially affect you, we will give notice and, if you hold an account, ask you to accept the new version the next time you sign in.
Write to andrew.anuichi@gmail.com.
If you are not satisfied with our answer, you may complain to a data protection authority. In Canada that is the Office of the Privacy Commissioner of Canada; in the UK, the Information Commissioner's Office; in the EEA, your national supervisory authority. You may complain to them without contacting us first, although we would rather you gave us the chance to put it right.