Data we keep
We keep the normalized email address, subscription state and timestamps, and immutable consent events. A request event records this notice version (2026-07-28-v2) so the disclosure shown at consent can be audited. Confirmation, unsubscribe, and provider-event identifiers are stored only as cryptographic digests where the raw value is not operationally required.
Purpose and sharing
We use the address only to confirm, manage, and deliver the PubMeta Dispatch. Brevo receives the address for transactional confirmation messages and would receive an approved recipient address only if PubMeta separately authorizes and enables an audience delivery. Cloudflare Turnstile processes browser and device signals to deter automated abuse under Cloudflare’s own privacy terms. PubMeta does not sell newsletter addresses or use them for advertising profiles.
Abuse controls
Turnstile is verified server-side before a public request can be stored. PubMeta does not persist the Turnstile token. Network hints are used transiently as input to a keyed one-way digest for rate limiting; raw IP addresses and user-agent strings are not stored in newsletter tables.
Retention and choice
Active enrollment records remain while the subscription is active. Unconfirmed addresses are pseudonymized after 30 days; the replacement is non-routable and contains no digest of the original address. Expired tokens are removed after a seven-day grace period, and confirmation/provider-event ledgers after 400 days. Unsubscribe links invalidate outstanding links and retain a suppression state and consent evidence so the address is not accidentally re-enrolled.
Privacy requests
For access, correction, deletion, consent withdrawal, unsubscribe problems, or suspected misuse, email privacy@pubmeta.org. This monitored address is handled as PubMeta Privacy. We normally verify control of the relevant address where practical, aim to acknowledge requests within two business days, and aim to resolve ordinary requests within 30 calendar days, subject to applicable law.
Broadcast remains disabled
PubMeta has a separately controlled broadcast capability, but it is disabled and has never been used for a subscriber audience. Enrollment does not authorize delivery: any future audience message requires an inspected exact seed, explicit issue-and-audience approval, separate enablement, and a supervised send.
Return to newsletter status