Privacy Policy

Short version: we collect what the product needs to work, we never see your card details, we never sell or share your data, and your saved pitches are visible only to you.

Last updated: 1 August 2026

1. Scope

This policy covers the data Newshook (“we”, “us”) handles when you use www.newshook.io and the product behind it. It sits alongside our Terms of Use. Questions or requests: support@newshook.io.

2. What we collect

  • Account data. Your email address and password. Authentication runs on Supabase Auth; passwords are stored only as salted hashes and we never see them in plain text.
  • Profile data you enter. Name, title, bio, areas of expertise, industries, niches and target markets. This is what the matching engine scores requests against, so it is the core of the product.
  • Pitches and drafts you save. Optional — see section 4.
  • Settings and integrations. Notification preferences and frequency, your minimum match score, and muted outlets. If you connect Slack, Discord or Teams, we store what is needed to deliver alerts to the channel you picked — a webhook URL, or the workspace, channel and access token issued to us by that platform. Disconnecting an integration removes it.
  • Usage data. When you last used the platform, which requests you opened, and clicks on outbound links to source platforms (destination host, timestamp, referrer, browser user-agent). We use this to keep the feed useful, to spot broken sources — and, concretely, to honour the refund promise in our terms for a month you did not use.
  • Subscription data. Plan, status, renewal date and the identifiers LemonSqueezy gives us for your subscription and orders. No card data — see section 3.
  • Server logs. Standard request logs from our hosting provider (IP address, timestamp, path), kept short-term for security and debugging.

We do not ask for and do not want special-category data (health, political views, and so on). Please keep it out of your profile and pitches.

3. We never collect your card details

Newshook does not collect, process or store card numbers, CVCs or bank details. That happens entirely at our payment provider, LemonSqueezy, which acts as the merchant of record for our sales. Checkout takes place on their infrastructure under their own privacy terms, and your card details never pass through Newshook’s systems.

What comes back to us from LemonSqueezy is limited to what we need to run your account: which plan you are on, whether the subscription is active, when the period ends, and the subscription and order IDs used to manage or refund it.

4. Your pitches stay private

You can save pitches and drafts in Newshook if you find it useful — a history of what you sent, to whom and when. Saving is optional and exists purely for your convenience.

  • Saved pitches are visible only to you. They are scoped to your account, including on team plans: other members of your team cannot read your drafts, and you cannot read theirs.
  • We do not share pitches with anyone. Not with journalists, not with other users, not with partners, not as examples, not in marketing. We do not publish them and we do not sell them.
  • We do not send them for you. A saved pitch stays a draft in your account until you send it yourself.
  • You can delete them. Delete individual pitches in the app at any time, or ask us to remove all of them.

The one processing that happens is on your instruction: when you ask for a draft or for feedback, the request text and the relevant parts of your profile are sent to the AI provider that generates it (section 6).

5. We do not sell or share information about our users

We do not sell, rent, trade or otherwise share your personal data, your profile or your activity with third parties for their own purposes. There is no data-broker relationship, no list-selling and no advertising use of your profile content.

Your profile is not a public directory entry — journalists do not browse Newshook profiles. Matching runs server-side: a journalist’s request is matched against your profile, and you decide whether to reach out. Nothing about you is disclosed to a journalist unless you send them a pitch yourself.

The only situations in which your data leaves our systems are:

  • Service providers that operate parts of the product on our behalf, listed in section 6. They process data under contract, only on our instructions.
  • Delivery channels you configure — if you connect a Slack, Discord or Teams webhook, your match alerts are delivered there by design.
  • Legal obligation — if we are legally required to disclose something. We will tell you unless we are prohibited from doing so.

6. Service providers we use

  • Supabase — database and authentication. Your account, profile, matches and saved pitches live here, hosted in the EU (AWS, Ireland).
  • Vercel — application hosting and server logs.
  • LemonSqueezy — payments and subscription management as merchant of record (section 3).
  • Resend — sending transactional and notification email (match alerts, account email).
  • AI providers — matching, scoring and pitch drafting. We use several large-language-model APIs, including Anthropic, Google and OpenAI, with a fallback chain so the product keeps working when one is down. We send only what the task needs: request text plus the relevant parts of your profile, or the draft you asked for help with. We never send your email address, password or payment data, and these providers are used solely to produce the output you asked for. Some of them process data outside the EU. Ask us and we will tell you the exact set of providers in use at any time.
  • Google Ads — conversion measurement on our marketing pages (section 7).

We also query domain-authority data from Moz and OpenPageRank. Those requests contain outlet domain names only — never anything about you. Authority scores shown in the app are provided by Open PageRank.

7. Cookies and analytics

Inside the app we use only the cookies needed to keep you signed in and to remember your theme preference. No third-party advertising or analytics scripts run in the dashboard.

On our public marketing pages we load Google’s tag to measure whether an ad led to a signup. It is limited to conversion measurement, and it does not have access to your profile, your matches or your pitches.

8. Data about journalists

Newshook aggregates media requests that journalists publish on other platforms, plus requests journalists post with us directly. For those we hold the request text, the outlet, the source link, and the contact details the journalist chose to make public.

We do not publish a journalist’s email address unless it is already public — the rules we follow are set out in section 3 of our Terms of Use. Journalists can have their details removed or a request unpublished at any time by emailing support@newshook.io; we act on those requests without asking for a reason.

9. How long we keep data

Account, profile, match and pitch data is kept while your account exists. Aggregated requests expire from the feed once their deadline passes and are cleaned up on a rolling basis. Server logs are short-lived. Click and activity records are kept while they are useful for support, refunds and product decisions.

When you close your account we delete your personal data within 30 days, except anything we are required to retain for accounting or legal reasons (for example, invoice records held by our payment provider).

10. Your rights and controls

  • Access and export. Your profile, matches and pitch history are visible in the app at any time (the journalist database can also be exported to CSV or XLSX). Ask us if you want a copy of everything we hold on you.
  • Correction. Edit your profile and settings at any time.
  • Deletion. Delete individual pitches in the app; email support@newshook.io to delete your account and data entirely.
  • Email preferences. Turn match notifications off in Settings, or use the unsubscribe link in any notification email. Essential account email (billing, security) still applies.
  • Complaints. Write to us first — we would rather fix it. Depending on where you live, you may also have the right to complain to your local data protection authority.

11. Security

Data is encrypted in transit, access to production data is restricted to what is needed to operate the service, and per-row access rules in the database keep each account’s data separated from every other account’s. No system is perfect; if a breach ever affects your data we will notify you promptly and tell you what happened.

12. Changes to this policy

If we change how we handle your data, we will update this page and change the date at the top. For material changes we will notify account holders by email before they take effect.

13. Contact

Anything about your data — questions, exports, deletion: support@newshook.io.