Privacy policy
What we collect, why, and how to get rid of it.
Pending legal reviewThis notice describes what the service actually does today, but it has not yet been reviewed by a solicitor and ICO registration is not yet complete. It should be treated as a working draft until both are done.
Who we are
The Research Brief is published by The Research Brief, London. For any question about your data, write to hello@theresearchbrief.co.uk and a person will answer.
What we collect
| Data | Why | Kept |
|---|---|---|
| Your email address | To send you the issue you asked for | Until you unsubscribe, then a suppression record (below) |
| Whether you confirmed it, and when | So we never email an address that did not ask | As above |
| Which page you signed up from | To know which parts of the site bring readers in | As above |
| That you unsubscribed, and by which route | To keep you off the list, and to tell a one-click opt-out from a link in an issue | Kept — it is what stops you being re-added |
| Subscription status and renewal date | To know whether you can read members’ sections | While you are a member, then as required for accounting |
| Your Stripe customer and subscription reference | To link your membership to the payment record, and to cancel it | As above |
| A one-time sign-in link (stored only as a hash) | To let you sign in without a password | Expires in 20 minutes; the record is deleted within the hour |
| A sign-in session cookie | To keep you signed in | 30 days, or until you sign out |
That is the complete list of what we hold about you. We do not use tracking pixels, we do not log which issues or sections you read, we do not build a profile of you, and we have never sold or shared a reader’s address with anyone.
Website statistics
We use Cloudflare Web Analytics to count how many people visit and which pages they land on. It is deliberately the least invasive option we could find: it sets no cookie and stores nothing on your device. It does not follow you between sites, and it cannot tell us that a particular person read a particular page.
What it records is aggregate and anonymous: page views, the page that referred you, rough country, and browser type. Nothing in it is linked to your email address or your subscription, and none of it is used for advertising.
This is also why this site has no cookie banner. Banners exist because most analytics store something on your device and need your consent to do it. Ours does not, so there is nothing to ask you about.
We do not track whether you open an issue and we do not track which links you click. Those things are possible — most newsletters do them using an invisible image — and we have chosen not to. It follows that we cannot tell you what our open rate is, because we genuinely do not know.
What happens when you unsubscribe
You come off the sending list immediately. We keep your address on a suppression record rather than erasing the row outright, because that record is the thing that prevents you being added back by a later import or a mistyped signup. It is used for nothing else: no email is sent to it, and it is never shared.
If you would rather be erased completely, say so and we will do it — see Your rights below. The one consequence worth knowing is that we then have no way to recognise the address, so nothing stops it being re-subscribed in future.
Card details
We never see them. Payments are handled entirely by Stripe on their own pages; your card number does not pass through our servers and is not stored by us at any point. We receive only your email address, whether the payment succeeded, and when the subscription renews.
Cookies
One cookie, rb_session, set only after you sign in. It holds your email address and an expiry, signed so it cannot be tampered with, and is marked HttpOnly so no script can read it. There are no advertising or analytics cookies, which is why this site has no cookie banner — there is nothing to consent to.
Who else processes your data
- Supabase — the database holding your address and subscription status.
- Stripe — payments and billing. Their privacy policy governs the card data they hold.
- Resend — sends the issue, the confirmation email, and sign-in links.
- Cloudflare — the anonymous, cookieless visitor statistics described above. It receives no email address and no subscription information.
Each is a processor acting on our instructions. None of them is permitted to use your address for their own purposes.
Your rights
Under UK GDPR you can ask for a copy of everything we hold about you, ask us to correct it, or ask us to delete it. Write to hello@theresearchbrief.co.uk. We will respond within one month. Deletion on request means the row is removed, not flagged — including the suppression record described above, if that is what you want.
One limit we cannot get around: where you have paid us, UK tax law requires the transaction record to be kept for six years. That is held by Stripe as well as by us, and it is the only category we cannot erase on request.
You can remove yourself at any time without asking us: every issue carries a one-click unsubscribe link, and it works without signing in.
Complaints
If you think we have handled your data badly, tell us first and we will try to put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk.