Privacy for source-linked AI radar.
How AI on Radar collects, stores, and protects subscriber data, source records, and security logs.
The AI on Radar operator is the data controller for digest subscriptions.
AI on Radar is an automated AI news radar. The entity operating this deployment is the data controller for any personal data processed through it. Public surfaces (articles, GitHub, models, papers, benchmarks, tools) and the native iOS/iPadOS app do not require an account. Contact the operator at privacy@aionradar.com for any privacy matter.
Digest subscriber records and operational/security logs.
Digest subscribers: email address, subscription status (pending / confirmed / unsubscribed / bounced), verification and unsubscribe token hashes, signup source, double opt-in timestamps, last delivery timestamp, and per-issue delivery status.
Platform records: source snapshots, article evidence, automated review decisions, AI assistance audit trails, and reliability logs. These records are about the platform and its sources, not about visitors.
Server logs: request IP, user-agent, path, status, and timing. Logs are retained for up to 30 days for security, abuse prevention, and debugging.
Growth events: article views, subscribe clicks, RSS clicks, source clicks, search queries, share clicks, and waitlist interest are stored with sanitized paths, source labels, and daily hashed visitor keys. Raw IP addresses, feed tokens, subscriber emails, API keys, and passwords are not stored in growth event rows.
iOS/iPadOS notifications: only after notification permission is granted, the native app sends an APNs device token, a random installation identifier, app version, locale, time zone, and notification preferences to the AI on Radar server. This information is not linked to an account or used for advertising or tracking. Inputs entered in the app's LLM selector, API cost calculator, and GPU/VRAM calculator stay on the device and are not sent to the server.
Consent for the digest; legitimate interests for operational logs.
Digest emails are processed on the basis of explicit consent (Article 6(1)(a) GDPR; KVKK Art. 5(1) açık rıza). Operational, security, and aggregate growth logs are processed on the basis of legitimate interest (Article 6(1)(f) GDPR) to keep the service running, prevent abuse, measure which public surfaces are useful, and meet basic audit requirements.
Digest and notification delivery, source attribution, reliability, and abuse prevention.
Subscriber email addresses are used solely to confirm subscriptions, send digest emails when delivery is enabled, record delivery status, and process unsubscribe requests. AI on Radar does not sell or share subscriber email addresses, does not use them for advertising, and does not profile subscribers.
Native notification registration data is used only to deliver the notification categories selected in the app, maintain delivery reliability, rotate invalid APNs tokens, and prevent abuse. Notification registration is removed when notifications are disabled in the app, and invalid or unregistered APNs tokens are removed when Apple reports them.
A small, transparent set of subprocessors.
Hosting: the operator's chosen infrastructure provider (VPS / managed PostgreSQL). Stores all subscriber and operational data at rest.
Resend (resend.com): transactional email delivery when the digest is active. Receives subscriber email address, digest content, and delivery status. Subject to Resend's own privacy policy and DPA.
Google (Gemini API): server-side language model used to summarize source-linked items. Input is source details and short excerpts only; subscriber data is never sent to Gemini. Subject to Google's API terms and privacy notice.
Google Analytics: public pages load Google tag measurement G-K8E3ZH5W4D to understand aggregate traffic and page performance. Digest subscriber data is not sent to Google Analytics by AI on Radar.
X (twitter.com) API: only when the operator explicitly enables auto-posting. AI on Radar uses the official X API; subscriber data is never sent to X.
Apple Push Notification service (APNs): receives the device token and notification payload required to deliver optional native notifications. AI on Radar does not place contact information, tool inputs, or other private user content in notification payloads.
Necessary cookies plus Google Analytics on public pages.
Public pages may set Google Analytics cookies for aggregate usage measurement. The admin panel may set a session cookie scoped to HTTP Basic Authentication for the duration of the operator's browser session. AI on Radar does not load advertising, session replay, or cross-site marketing pixels.
Transfers occur only via the subprocessors listed above.
Where a subprocessor (e.g., Resend, Google) processes data outside the European Economic Area, transfers rely on the subprocessor's Standard Contractual Clauses and additional safeguards. The operator does not independently transfer subscriber data outside the deployment region.
Kept only as long as necessary.
Confirmed subscribers are retained until unsubscribe. Pending (unconfirmed) subscriptions expire automatically after the double opt-in window (default 72 hours) and are purged. Unsubscribed records are retained for 90 days for audit / re-subscribe handling, then anonymized. Server access logs are retained for up to 30 days. AI assistance audit records and reliability logs are retained for up to 30 days for troubleshooting and then purged.
Native notification registration data is retained while notifications remain enabled. It is deleted when the app unregisters the installation, or when Apple reports that the APNs token is no longer valid.
Access, rectification, erasure, restriction, portability, objection.
Under GDPR / UK GDPR / KVKK you have the right to access your data, request correction or erasure, restrict or object to processing, request data portability, and withdraw consent at any time without affecting prior lawful processing. Under CCPA you have the right to know, delete, and opt out of sale or sharing (we do not sell or share).
To exercise any right, email privacy@aionradar.com. We respond within 30 days. You may also lodge a complaint with your local supervisory authority (e.g., EU DPA, ICO, KVKK Kurumu).
Defense in depth, minimal exposure.
Secrets are stored server-side only and never returned in public responses. Admin endpoints require HTTP Basic Authentication with timing-safe comparison. Cron endpoints require a shared secret in a request header. Database traffic is internal to the deployment network. Backups are encrypted at rest. The operator is responsible for keeping infrastructure patched and rotating credentials regularly.
We will note material changes here.
This policy was last updated on 2026-07-29. Material changes will be reflected on this page along with the updated date. Continued use of AI on Radar after a change indicates acceptance of the revised policy.