Privacy Policy
Last updated: September 2026.
This page explains what CLSTR collects, why, and the choices you have. We try to collect as little as possible.
CLSTR is operated as an independent project based in the EU. For privacy or legal questions, contact info@clstr.news.
What we collect
Account data. When you sign in we store your email address, display name, and (if provided by Google) profile picture URL. We use this to authenticate you and to send service emails.
Subscription data. If you upgrade to a paid plan, billing is handled by Stripe. We store a Stripe customer/subscription identifier and the plan status. We do not see or store card details.
Product data. Items you create on the service (followed topics, briefing and monitor preferences) are stored against your account.
API keys and usage. If you create API keys for the developer API or MCP server, we store a cryptographic hash of each key (never the key itself), its label and creation date, and per-account usage counters (daily and per-minute request counts) used to enforce your plan's limits. Usage counters are aggregate numbers and expire with their time windows. For the developer API and MCP server we also keep per-request usage records, to understand how the service is used and to improve it. For applications you connect with OAuth, those records identify the request by an internal identifier for your account rather than by a key. These records never include your search params, IP address or raw user agent.
Logs. Our infrastructure processes standard request data such as IP address and user agent for security, abuse prevention, and rate limiting. These logs are short-lived.
Cookies
CLSTR only sets cookies that are strictly necessary to run the service. We do not use advertising or cross-site tracking cookies.
- Session cookie: keeps you signed in after authentication. Expires after 7 days of inactivity.
- Sign-in state cookie: set briefly during Google sign-in to protect against CSRF. Discarded right after sign-in completes.
For analytics we use Simple Analytics, which is cookieless and does not profile visitors.
Referral memory. Your browser may keep a local note of how you first found CLSTR (a referral tag or the referring site's name, nothing else). It stays on your device, expires after 90 days, and is sent to us only if you sign up, so we can tell which channels bring readers. It is never shared and never used to identify you.
Third parties that receive your data
- Cloudflare: hosting and web services.
- Google: sign-in, only when you choose to sign in with Google.
- Stripe: subscription payments, only for paying users.
- Simple Analytics: privacy-friendly, cookieless usage statistics.
- Turso: database hosting; stores account and product data.
Some of these providers process data in the United States, under their standard data protection terms.
If you sign in by magic link, we send a one-time link to your email. If you enable briefings or Pro monitors, we send those emails on the schedule and triggers you configure (with links to unsubscribe without signing in). You can change this anytime from Automations in your account.
Connected applications
You can authorize third-party applications (such as AI assistants) to read CLSTR news data on your behalf using OAuth. When you connect one, we store the application's identifier, the authorization you granted, and hashed tokens; we never share your email or profile with the application beyond what the consent screen states. Connected applications can read news data through the MCP server on your behalf and share your plan's usage limits; they cannot manage your account, keys, or billing. You can revoke a connection at any time from Settings, and revoked access stops working within about a minute.
Retention
We keep account and product data for as long as your account exists. If you delete your account, associated personal data is removed; minimal billing records may be retained where required by law.
Your rights
Depending on your jurisdiction (including the EU/UK under GDPR), you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To request account deletion or to exercise any of these rights, email support@clstr.news and we will action your request.
Children
CLSTR is not directed at children under 16 and we do not knowingly collect their data.
Changes
We may update this policy as the service evolves. Material changes will be reflected in the "Last updated" date above.