Privacy notice
Text version 2026-09-v1 · effective 2026-09-12 · applies to theagentsignal.com, the newsletter emails and the account pages. Written for readers in the UK and EU (UK GDPR / GDPR), Canada (CASL, PIPEDA), Australia (Spam Act 2003, Privacy Act 1988), California (CCPA / CPRA) and everywhere else. Plain-text copy: privacy.txt.
The short version
- We collect your email address when you sign up. We only send after you confirm by clicking the link we email you (double opt-in). Every email has a one-click unsubscribe that works immediately.
- We keep a record of your consent (when, which text version, a coarse network prefix of your IP, and your browser family) because the law asks us to be able to prove it.
- We measure which links get clicked and estimate opens in our emails so we know what to write more of. You can switch email tracking off on your account page; after that nothing is recorded when you open or click.
- On the website we only measure visits if you press Accept on the banner. Reject is one click and the same size. Global Privacy Control is honoured as Reject.
- No third-party analytics, no ad pixels, no data brokers, no sale or sharing of personal data (CCPA). Payments are handled by Stripe; we never see your card.
- Raw IP addresses are never stored: we keep a truncated IP (/24 for IPv4, /48 for IPv6) and a hash keyed with a secret that rotates monthly, then delete both on the schedule below.
- You can download everything we hold about you or delete your account from your account page. Deletion completes within 30 days and keeps only a hash of your address so we never email you again.
Who we are
THE AGENT SIGNAL (formerly THE AI SIGNAL) is published by TODO-HIS-ENTITY (legal name), registered address TODO-HIS-ENTITY. That entity is the data controller. Privacy contact and Data Protection Officer contact: privacy@theagentsignal.com. Every message with the word privacy or unsubscribe in the subject is answered within 30 days, usually much sooner. Data is stored in Amazon Web Services, region us-east-1 (United States). Transfers from the UK and EU rely on the AWS Data Processing Addendum with the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
What we collect, why, and for how long
This table is the source of truth: if a field is not here, we do not collect it. It mirrors the retention job that runs hourly on our servers, which is the only thing that ever deletes data.
| Field | When | Why (lawful basis) | Retention |
|---|---|---|---|
| email address | sign-up | consent for marketing email (UK GDPR art. 6(1)(a); CASL express consent; Spam Act s.16) and contract for a paid subscription (art. 6(1)(b)) | until you unsubscribe and ask for erasure; a SHA-256 hash of the address stays on the suppression list forever so we never email you again |
| subscriber id (random ULID) | sign-up | service: used in links and cookies instead of your email | with the account |
| consent record: timestamp, text version, method (magic link), truncated IP (/24 or /48), IP hash, browser family (e.g. windows/chrome) | confirmation click | legal obligation: proof of consent (UK GDPR art. 7(1), CASL s.13, Spam Act s.16) | 3 years after your last activity |
| status per newsletter list (pending / active / unsubscribed) | sign-up, preferences, unsubscribe | legal obligation: honour unsubscribe (we do it immediately; the law allows CASL 10 days, AU 5 business days) | with the account |
| IP hash (HMAC with a monthly rotating key) | sign-up, click, open, website visit | legitimate interest: abuse and bot detection, rate limiting | 90 days |
| truncated IP (/24 IPv4, /48 IPv6) | sign-up, click, website visit | legitimate interest: abuse detection and coarse geography | 13 months |
| country and region (derived on our own servers from the IP with a local MaxMind GeoLite2 database, no third-party call), device type, OS and browser family | derived at sign-up and clicks | legitimate interest: product analytics (which countries, mobile vs desktop) | 24 months, then aggregated counts only |
| user-agent hash, full referrer URL | sign-up | legitimate interest: abuse forensics and attribution | 30 days |
| utm_source / utm_medium / utm_campaign / utm_content / utm_term, referrer host, landing path, referral code used | sign-up and checkout | legitimate interest: knowing which channel brought you; a referral reward is a contract with the person who referred you | 24 months, then aggregated |
| anonymous visitor id (first-party cookie signal_anon) and page views on our site | website | consent (PECR / ePrivacy): only after you press Accept on the banner; Reject or Global Privacy Control means nothing is set | cookie 13 months; events 24 months |
| estimated opens (a tracking image in the email) and link clicks in our emails, with edition id and link host | legitimate interest with an opt-out toggle on your account page; opens are labelled "estimated" because Apple Mail Privacy Protection and some corporate scanners pre-load images | 24 months, then aggregated | |
| sends ledger: which edition was sent to you, delivery, bounce and complaint timestamps | every send | legal obligation and deliverability (bounce and complaint handling; a complaint unsubscribes you at once) | 24 months |
| reviews and one-tap feedback you choose to leave on a paid product: rating, your text, whether you had access at the time, timestamps (shown publicly as "Member" or "Verified member", never with your name or email; every review is read by a person before it shows) | the review form on your account page; the two links in a receipt email | consent (you post it); editing is on your account page, erasure removes it | while the review is live; removed with erasure |
| Stripe customer id, subscription id, invoice ids, plan, dates, amounts | checkout and billing webhooks | contract; tax and accounting. Stripe holds the card; we never see card numbers. Webhook payloads are stored redacted: ids, status, dates and amounts only | 7 years (tax); redacted webhook copies 90 days |
| preferences: tracking opt-out, newsletter choices, channel preferences | account page | service | with the account |
| erasure request and completion (subscriber id only, no personal data) | account deletion | legal obligation: proof we honoured the request | 3 years |
IP addresses: truncated and hashed, never raw
When a request reaches us the raw IP address is used once, inside that request, and thrown away. Two things survive: a truncated IP (the last byte of an IPv4 address is zeroed, so 203.0.113.42 becomes 203.0.113.0/24; IPv6 keeps only the first 48 bits) and an IP hash (HMAC-SHA256 with a secret key that changes every calendar month, so hashes from different months cannot be linked and nobody, including us, can turn a hash back into an address). The truncated IP lets us say "roughly which network and country"; the hash lets us rate-limit and spot bots within a month. Country and region come from a GeoLite2 database on our own servers, so the lookup never leaves them.
Click and open tracking in emails
Links in our emails go through go.theagentsignal.com so we can count clicks per link and per edition. We record the edition, the link host, and the time. We also include a one-pixel image; when your mail client loads it we count an "estimated open". If you switch off email tracking on your account page, links become plain redirects and the image records nothing. Unsubscribe links are never tracked. We never use tracking to build a profile of you or to price anything differently.
Consent, cookies, Global Privacy Control and opting out
The website sets one optional cookie, signal_anon (a random id, 13 months), and only after you press Accept on the banner. The banner has an Accept and a Reject button of the same size; Reject sets nothing. If your browser sends the Global Privacy Control signal we treat that as Reject without asking. The account page uses a strictly necessary session cookie, signal_session (7 days), set when you sign in through your email link. There are no third-party scripts, fonts or images on this site.
Your marketing consent is the tick box at sign-up plus the confirmation click in the email; we store the exact text version you agreed to. Changing your mind is one click:
- Unsubscribe: the link at the bottom of every email, or the account page. It works immediately, with no login and no "are you sure". Our emails also carry the RFC 8058 one-click unsubscribe headers, so the Unsubscribe button in Gmail, Apple Mail and Outlook works too.
- Email tracking opt-out: a toggle on your account page.
- Website measurement opt-out: press Reject on the banner, or turn on Global Privacy Control in your browser. Clearing the signal_anon cookie also stops it.
Export and erase
- Access and portability: "Download my data" on your account page gives you a JSON file of everything in the table above, immediately.
- Erasure: "Delete me" on your account page (type DELETE to confirm). Your paid subscription is cancelled, every row is wiped within 30 days, and we keep only the hashed address on the suppression list and Stripe invoices required by tax law. Two audit events (erasure requested, erasure completed) stay under your random subscriber id, which identifies nobody.
- Rectify, restrict, object: change your email or preferences on your account page, or write to privacy@theagentsignal.com.
Your rights by region and who to contact
- UK and EU (UK GDPR / GDPR, PECR): access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent at any time. Write to privacy@theagentsignal.com. If you are not happy with our answer you can complain to the ICO (ico.org.uk) or your local supervisory authority.
- Canada (CASL, PIPEDA): we only send with your express consent, every email identifies the sender and carries a working unsubscribe, and unsubscribes are actioned immediately (the law allows 10 days). Complaints: the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the CRTC for spam.
- Australia (Spam Act 2003, Privacy Act 1988): consent before sending, sender identification in every email, a functional unsubscribe honoured immediately (the law allows 5 business days). Complaints: the Office of the Australian Information Commissioner (oaic.gov.au) or the ACMA for spam.
- California (CCPA / CPRA): the right to know, to delete, to correct, to opt out of sale or sharing, and to non-discrimination. We do not sell or share personal information, and we honour Global Privacy Control as an opt-out signal. Requests: privacy@theagentsignal.com.
- Everyone else: the same tools and the same address. We do not treat readers differently by country.
Who else sees your data
Amazon Web Services (hosting and email delivery, us-east-1) and Stripe (payments) act as our processors under their standard data processing terms. Nobody else. We do not use third-party analytics, advertising networks, or data brokers, and we never sell or share personal data — including mobile numbers and SMS opt-in records, which are never shared with third parties or affiliates.
Text messages (SMS)
If you give us your mobile number and tick the SMS box, we will text you only what you asked for: a sign-in code, or a short alert when a new issue is out. Mobile numbers and SMS opt-in consent are never shared with, sold to, or rented to third parties or affiliates for their marketing or any other purpose. They are used solely by The Agent Signal to send the messages you opted in to. Message frequency varies (at most one per issue). Message and data rates may apply. Reply STOP to any message to opt out immediately, or HELP for help; you can also email privacy@theagentsignal.com. Carriers are not liable for delayed or undelivered messages.
Consent text shown at sign-up (version 2026-09-v1)
Yes, send me THE AGENT SIGNAL by email. I can unsubscribe with one click in any email. See the privacy notice for what is recorded.
Changes to this notice bump the text version; your consent record keeps the version you agreed to, and we will email you before any change that affects what we collect.