Privacy Policy

Effective date: July 19, 2026 · Last updated: July 19, 2026

Newsletter Engine AI is a product and service of Extreme Results Technologies Inc. ("Extreme Results," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and protect personal data in connection with the Newsletter Engine AI website, application, subscriptions, support, integrations, and related marketing activities (together, the "Service"). See the Changes section below for how updates to this Policy are communicated.

1. Introduction

Extreme Results Technologies Inc., located at 1000 Brickell Avenue, Suite 1965, Miami, Florida 33131, United States, operates Newsletter Engine AI. This Policy applies to newsletterengineai.com, the Newsletter Engine AI web application, our subscription plans, customer support, product integrations, and our marketing campaigns. Effective date: July 19, 2026. Last updated: July 19, 2026. You can reach us at support@newsletterengineai.com with any question about this Policy or about your personal data.

2. Scope

This Policy applies to website visitors, account holders (free, trial, and paid), newsletter creators, team members on an account, prospective customers, people who submit a form on our site, people who interact with our marketing campaigns, recipients of our support communications, and individuals whose personal data may appear within content that our customers upload to the Service. When a customer uploads content containing another person’s personal data (for example, a newsletter that discusses named individuals, or a Knowledge Source containing a subscriber list), that customer is generally the data controller or business for that data, and Newsletter Engine AI acts as a processor or service provider acting on the customer’s instructions with respect to that data. Customers are responsible for having a lawful basis to provide us with that data.

3. Personal Data We Collect — Account and Identity Data

Name, email address, username, password credentials (stored in hashed form, never in plain text), account ID, profile information you choose to provide, language preference, country, and time zone.

4. Personal Data We Collect — Billing Data

Subscription tier, billing address, transaction status, invoice details, payment method type, and the last four digits of a payment card when made available to us by Stripe, our payment processor. We may also receive tax information and refund or dispute history related to your account. Full payment card details are collected and processed directly by Stripe. Newsletter Engine AI does not receive or store your full card number, CVC, or card expiration date.

5. Personal Data We Collect — User Content

The newsletters, articles, drafts, transcripts, PDFs, documents, audio, video, and other files you upload as Knowledge Sources; your Editorial Profiles; the Writer Brain and Editorial DNA data the Service builds from content you approve; analysis results, revisions, and Generate V2™ output; the prompts you submit; and your feedback, approvals, and rejections of AI-generated suggestions.

6. Personal Data We Collect — Usage and Technical Data

IP address, device type, operating system, browser type, pages viewed, clicks, session duration, login events, feature usage, timestamps, referral URLs, crash logs, performance data, account and session identifiers, cookies and similar technologies (see our Cookie Policy), and analytics events.

7. Personal Data We Collect — Communications

Support requests, emails you send us, chat or form messages, survey responses, demo requests, and sales communications.

8. Personal Data We Collect — Marketing and Advertising Data

We do not currently run advertising campaigns on Meta (Facebook/Instagram), Google, or similar platforms, and we do not currently use the Meta Pixel, Meta Conversions API, or Google Ads/Analytics tracking on our website. If we begin doing so, this category will include information such as campaign source, UTM parameters, advertising identifiers, conversion events, lead-form data, custom-audience matching data, and your consent and opt-out status — and this Policy, together with our Cookie Policy and consent tools, will be updated before any such tracking is activated. See Section 14 (Advertising and Marketing Platforms) for more detail on our current position and our commitments for the future.

9. Personal Data We Collect — Third-Party and Integration Data

Data we receive from our service providers in the course of operating the Service: Supabase (hosting, authentication, database, and file storage), OpenAI (AI processing), Stripe (payment processing), and Resend (transactional email delivery). See Section 16 for the full list of service providers and the categories of data each one processes.

10. How We Collect Data

Directly from you, when you create an account, upload content, contact support, or fill out a form. Automatically, through your use of the website and application, including through cookies and similar technologies described in our Cookie Policy. Through Stripe, in connection with billing and payment. Through our AI provider (OpenAI), when your content is processed to generate an analysis, rewrite, or other output. From authorized service providers acting on our behalf. We do not currently collect data through Meta Lead Ads, Meta Pixel, Meta Conversions API, or comparable Google tools, for the reasons explained in Section 8.

11. Purposes of Processing

We process personal data to: create and manage accounts; authenticate users; provide editorial analyses and AI-generated output; build and update your Editorial DNA™ and Living Writer Brain™; generate revisions through Generate V2™; store and organize Knowledge Sources™; provide Editorial Strategy™ and Research Intelligence™ recommendations; process payments and administer subscriptions; prevent fraud and secure the platform; provide customer support; improve product quality and debug issues; perform analytics and product research; send transactional messages; send marketing messages where you have agreed to receive them or where otherwise permitted by law; measure and, if adopted, manage advertising; comply with applicable law; enforce our Terms of Service; and protect the rights, safety, and property of Extreme Results Technologies Inc., our users, and third parties.

12. Legal Bases Under the GDPR (EU/EEA and UK Users)

Where the GDPR or UK GDPR applies, we rely on the following legal bases, summarized by processing activity: Account creation and authentication — Account/Identity Data — Providing the Service you requested — Performance of a contract — Retained for the life of the account plus the period described in Section 18. Billing and subscription management — Billing Data — Charging for and administering your subscription — Performance of a contract; compliance with legal obligations (tax and accounting law) — Retained per Section 18. AI-generated analysis, Writer Brain, Generate V2™ — User Content — Delivering the core features you subscribed to — Performance of a contract — Retained until you delete the content or close your account, per Section 18. Product analytics and debugging — Usage/Technical Data — Understanding and improving the Service — Legitimate interests (improving a product you use, balanced against your privacy — see below) — Retained per Section 18. Fraud prevention and security monitoring — Account, Billing, Usage Data — Protecting the Service and its users — Legitimate interests; compliance with legal obligations — Retained per Section 18. Marketing emails (where you have opted in) — Contact/Communications Data — Sending you product updates or promotions — Consent — Until you withdraw consent. Responding to legal process or protecting legal rights — Any relevant category — Compliance with law; establishment, exercise, or defense of legal claims — As required by the applicable proceeding. We do not rely on consent as the legal basis for every processing activity described in this Policy — where performance of a contract or a legitimate interest better describes why we process your data, we say so above. Where we rely on legitimate interests, we have considered whether our interest in the processing is outweighed by your rights and interests, and you may object to that processing as described in Section 21.

13. Legal Bases Under the LGPD (Brazil)

For users in Brazil: under the Lei Geral de Proteção de Dados (LGPD), we process personal data (dados pessoais), depending on the activity, based on: performance of a contract or preliminary steps requested by the data subject (titular); compliance with a legal or regulatory obligation; the regular exercise of rights in judicial, administrative, or arbitration proceedings; legitimate interest, where applied to legitimate and specific purposes; and consent, where that is the applicable basis (for example, for marketing emails). Depending on the context, Newsletter Engine AI acts as the controller (controlador) of account holders’ identity and billing data, and as the processor (operador) with respect to any third-party personal data our customers include in content submitted to the platform — that processing (tratamento) is carried out on the customer’s instructions, with the customer acting as the controller (controlador) of that data. The contact channel for exercising rights and questions about the processing of personal data is support@newsletterengineai.com. We do not intentionally process sensitive personal data (dados pessoais sensíveis, LGPD art. 5, II) as a feature of the Service, except to the extent a customer includes it in content they submit at their own risk — see Section 17 (Sensitive Data) below.

14. United States Privacy Framework

Depending on your state of residence and on whether Extreme Results Technologies Inc. meets the applicable thresholds for a given law, you may have rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Colorado Privacy Act, the Connecticut Data Privacy Act, the Virginia Consumer Data Protection Act, the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act, the Oregon Consumer Privacy Act, and other state privacy laws as they take effect. We do not claim that every one of these laws applies automatically to every user — applicability depends on your residency, our business activity, and the legal scope of each statute. Where applicable based on residency, business thresholds, and legal scope, these laws may give you the right to: know what personal information we collect, use, and disclose about you; access a copy of that information; correct inaccurate information; delete your personal information; obtain a portable copy of your data; opt out of the "sale" of personal information; opt out of "sharing" for cross-context behavioral advertising; opt out of targeted advertising; limit the use of sensitive personal information where applicable; and appeal a denied privacy request. Newsletter Engine AI does not sell personal information for monetary consideration. We do not currently use advertising or audience-matching tools that would constitute "sharing" or "sale" under California law, because we do not currently run Meta, Google, or comparable ad campaigns (see Section 8). If we adopt advertising cookies or audience-matching tools in the future that could constitute "sharing" under the CCPA/CPRA, we will disclose that plainly here and provide an opt-out control before doing so — we do not make an absolute "we never share data" claim, because that would foreclose our ability to describe such tools accurately if we adopt them later. To exercise any of these rights, contact support@newsletterengineai.com. See Section 21 for identity verification and response timing.

15. AI Processing

Your content may be processed by our AI provider, OpenAI, to deliver editorial analysis, scoring, rewriting, coaching, strategy recommendations, and related capabilities. OpenAI processes this content as our service provider, under contractual terms that restrict its use of the data to providing services to us; we do not control OpenAI’s infrastructure directly and cannot guarantee that no data is retained by OpenAI for any period, beyond what OpenAI’s own terms with us specify — we describe this in qualified terms because retention behavior depends on the specific API configuration in effect at any given time, not because we are withholding information. Your content is not used to train Newsletter Engine AI’s own generalized, cross-customer models unless you expressly opt in to that use. Content you approve within the product (for example, approving a Learning Candidate) may be used to update your own Writer Brain™ or Editorial DNA™ — that update only affects your own account’s model, never another customer’s. AI-generated content — including analyses, scores, research suggestions, and rewrites — is not automatically treated as authoritative or as verified fact. Human review by you is required before you rely on, publish, or act on any AI output. We do not use automated decision-making to produce legal or similarly significant effects about you (for example, we do not use AI to automatically approve, deny, or price your subscription) unless we specifically disclose that to you first. If you have questions about how your content is processed by our AI provider, contact support@newsletterengineai.com.

16. User Content and Confidentiality

You retain ownership of the original content you submit to the Service. You grant Extreme Results Technologies Inc. a limited license to host, process, reproduce, transform, and transmit your content solely as necessary to provide and improve the Service you have contracted for. We do not claim ownership of your newsletters or uploaded documents. You must have the rights necessary to upload any material you submit, and you must not upload confidential, illegal, infringing, or otherwise unauthorized content. You must not upload sensitive personal data (see Section 17) unless doing so is necessary for your use of the Service and legally permitted. You remain responsible for providing any notices to, and obtaining any consents from, third parties whose personal data appears in content you upload.

17. Sensitive Data

The Service is not designed or intended to store highly sensitive categories of data. Please do not upload health records, government identification numbers, financial account credentials, biometric data, precise real-time geolocation data, children’s data, criminal history records, or other special-category personal data, unless a specific feature expressly supports that data type and you have a valid legal basis to process it. We may remove or restrict access to content that appears to contain this kind of data, and we may apply additional safeguards to any such data we become aware of.

18. Children

You must be at least 18 years old to create a paid account or enter into a contract with us. The Service is not directed to children under 13, and we do not knowingly collect personal data from children under 13. In the European Economic Area and the United Kingdom, individuals below the locally applicable age of digital consent should not use the Service without valid parental or guardian authorization. If we ever run advertising campaigns, we will not intentionally target minors. If you believe a child has provided us with personal data, contact support@newsletterengineai.com and we will investigate and take appropriate action, including deletion where required.

19. Cookies and Similar Technologies

We currently use two categories of cookies: strictly necessary authentication cookies (set by Supabase, our authentication provider, to keep you signed in) and a preference cookie that remembers your selected language (set by next-intl, our internationalization framework). We do not currently set analytics or advertising cookies. The full name, provider, purpose, and duration of every cookie we use is listed in our separate Cookie Policy. If we introduce analytics or advertising cookies in the future, we will not activate them for EU, UK, or Brazil users before obtaining the consent required under the ePrivacy Directive/GDPR or the LGPD, we will provide accept, reject, and granular manage-preferences controls, we will retain a record of your consent choice, and we will let you withdraw consent at any time. We do not yet operate that consent-management infrastructure — building it is a tracked next step before any non-essential cookie is introduced, consistent with our permanent governance rule in Section 26.

20. Meta Pixel and Conversions API

We do not currently use the Meta Pixel or the Meta Conversions API on our website or application. If we adopt these tools in the future — for example, to measure signups, checkout starts, purchases, or subscription events driven by advertising — we will update this Policy, our Cookie Policy, and our consent tools before activating them, and Meta may process the resulting data under its own terms and privacy policy in addition to this one.

21. Meta Lead Ads and Custom Audiences

We do not currently run Meta Lead Ads campaigns or use Meta Custom Audiences. If we do so in the future, we commit to the following: lead data will be collected only for the purpose stated on the lead form at the point of collection; required disclosures will be shown at collection, with any additional-marketing consent kept separate from and not bundled with the core purpose consent; lead data will not be sold; any customer list uploaded for Custom Audiences matching will be hashed before transmission and uploaded only where we have sufficient rights, permissions, and legal basis to do so; individuals who have opted out of advertising or audience use will be excluded; audiences will not be sold; and Meta may act as either a processor or an independent controller depending on the specific tool and jurisdiction involved. See our separate Meta Advertising and Marketing Data Notice for the form of disclosure we intend to use if and when a Meta Lead Ads campaign is launched.

22. Advertising Campaign Compliance

If we run advertising campaigns in the future, they will be operated to comply with Meta’s Advertising Standards and applicable platform policies. We will not run misleading, deceptive, discriminatory, or prohibited advertisements. Advertising platforms may reject, restrict, or suspend ads or accounts at their own discretion, and we do not guarantee any campaign’s delivery, reach, cost, or performance. Newsletter Engine AI is not affiliated with, endorsed by, or sponsored by Meta, Google, or any other advertising platform unless we expressly state otherwise.

23. Stripe and Payment Processing

Stripe, Inc. processes payments on our behalf. Depending on the activity, Stripe may act as an independent controller and/or as our processor. Stripe processes payment card data, fraud-prevention signals, billing information, and transaction details; we receive only limited payment information back from Stripe, such as your subscription status, the last four digits of your card, and transaction outcomes. Your card data is not stored directly on Newsletter Engine AI’s own systems. Stripe may process data internationally, and by subscribing to a paid plan you are also subject to Stripe’s own applicable terms and privacy practices. Payment failures, fraud reviews, chargebacks, and identity checks may occur as part of Stripe’s standard processing, and we may collect and remit applicable taxes where legally required.

24. Service Providers and Subprocessors

We use the following categories of service providers to operate the Service: cloud hosting, database, authentication, and file storage (Supabase); AI processing (OpenAI); payment processing (Stripe); and transactional email delivery (Resend). We do not currently use a separate analytics platform, error-monitoring tool, advertising platform, or third-party CRM/support tool beyond these four providers. We maintain a current list of our subprocessors, including each provider’s name, service, general location, the categories of data it processes, and the international-transfer mechanism that applies, in our public Subprocessors list (see Section 27 for how to request it) — we commit to notifying customers with a Data Processing Addendum in place before adding a new subprocessor that will process their personal data.

25. International Data Transfers

Your data may be transferred to, and processed in, the United States and other countries where our service providers operate, including countries that may not have data protection laws equivalent to those in your home jurisdiction. For transfers subject to the GDPR, we rely on one or more of the following depending on the recipient and location: the European Commission’s Standard Contractual Clauses, an applicable adequacy decision, the EU-U.S. Data Privacy Framework where the recipient is certified under it, and supplementary contractual and technical safeguards. For transfers subject to the LGPD, we rely on contractual safeguards, applicable adequacy mechanisms, consent where appropriate, and compliance with the rules issued by Brazil’s Autoridade Nacional de Proteção de Dados (ANPD). We do not rely on a single transfer mechanism for all data — the mechanism used depends on the specific recipient and the data involved.

26. Data Retention

Account data — retained for the life of your account, and for a limited period after closure to allow reactivation and to comply with the obligations described below. Billing records — retained as required by applicable tax and accounting law, generally several years after the transaction. Uploaded and generated content (Knowledge Sources, analyses, revisions, Writer Brain, Editorial DNA) — retained until you delete it or close your account, subject to the backup and legal-hold provisions below. Analytics data — retained for a limited period sufficient for product improvement purposes, then aggregated or deleted. Advertising data — not currently applicable; if introduced, retention will be disclosed here before activation. Support tickets and communications — retained for a limited period to allow us to handle related follow-up requests. Security logs — retained for a limited period sufficient for incident investigation and fraud prevention. Deleted accounts — removed from active systems within a reasonable period after a verified deletion request, subject to the items below. Backups — deletion from our active, production systems does not necessarily mean immediate removal from encrypted backups, which are retained for a limited period and rotated out of existence in the ordinary course. Legal holds — data subject to a legal hold, dispute, or regulatory obligation is retained for as long as that hold or obligation applies, regardless of the periods described above.

27. Security

We use reasonable technical and organizational safeguards appropriate to the data we process, including encryption of data in transit (TLS), encryption at rest where supported by our infrastructure providers, role-based access controls, database-level row-level security policies scoped per account, access logging, regular backups, monitoring, an incident-response process, and review of our service providers’ own security practices. No system can be guaranteed to be completely secure, and we cannot promise that unauthorized access, loss, misuse, or alteration of data will never occur.

28. Security Incidents

If we become aware of a security incident affecting your personal data, we will investigate the incident, take reasonable steps to contain it, and notify affected individuals and applicable regulators where required by law, within the timeframes that law requires. We will cooperate with our processors and service providers as needed to investigate and respond to any such incident.

29. Your Rights — GDPR (EU/EEA and UK)

If the GDPR or UK GDPR applies to you, you have the right to: access your personal data; request rectification of inaccurate data; request erasure of your data in certain circumstances; request restriction of processing; object to processing based on legitimate interests or for direct marketing; request portability of data you provided to us; withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal; lodge a complaint with your local supervisory authority; and not be subject to decisions based solely on automated processing that produce legal or similarly significant effects, except as described in Section 15.

30. Your Rights — LGPD (Brazil)

If the LGPD applies to you, you have the right to: confirm the existence of processing; access your personal data; correct incomplete, inaccurate, or outdated data; request the anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in violation of the LGPD; request portability of your data to another service or product provider; be informed about the public and private entities with which we share your data; be informed about the possibility of refusing consent and the consequences of that refusal; withdraw consent at any time; and request review of decisions made solely on the basis of automated processing of personal data that affect your interests, as applicable.

31. Your Rights — United States

Where applicable based on your state of residence, you have the right to: know what personal information we collect, use, and disclose; access a copy of your personal information; request correction of inaccurate information; request deletion of your personal information; request a portable copy of your data; opt out of sale or sharing, where applicable; and appeal a denied request. If you use an authorized agent to submit a request on your behalf, we may require proof of the agent’s authorization and may still need to verify your identity directly. To submit any request under this Section, this Policy, or our Terms of Service, email support@newsletterengineai.com with the subject line "Privacy Request — Newsletter Engine AI." We will verify your identity before acting on a request. Because different laws set different response deadlines, we do not promise a single universal timeline for every request — we will confirm the applicable deadline once we have identified which law governs your request, and in all cases we will respond as promptly as reasonably possible.

32. Marketing Communications

We send transactional messages (for example, account confirmations and billing receipts) as part of operating your account; you cannot opt out of these while maintaining an active account, because they are necessary to the Service itself. We may send product updates, newsletters, and promotional email where you have provided the required consent or where otherwise permitted by law (for example, existing-customer marketing under CAN-SPAM). Every marketing email includes an unsubscribe mechanism. Where GDPR/ePrivacy or LGPD consent is required for a given message, we obtain it before sending and keep a record of your opt-in and opt-out choices.

33. Do Not Track and Global Privacy Control

Some browsers offer a "Do Not Track" signal, and some browser extensions send a Global Privacy Control (GPC) signal. We do not currently have technical infrastructure in place to detect or automatically act on either signal, because we do not currently operate any advertising or cross-context tracking that these signals are designed to limit. We are not claiming support for a control we have not built. If we introduce advertising or tracking technology that GPC is designed to govern, we will implement GPC recognition, consistent with applicable law, before or at the same time as that technology is activated.

34. Business Transfers

If Extreme Results Technologies Inc. is involved in a merger, acquisition, reorganization, financing, sale of assets, or insolvency proceeding, personal data may be transferred as part of that transaction. Any recipient of that data will remain bound to protect it in a manner consistent with applicable law and, where required, with this Policy.

35. Legal Disclosure

We may disclose personal data where necessary to comply with applicable law, respond to a valid legal process (such as a subpoena or court order), enforce our Terms of Service, prevent fraud or security threats, protect the rights, safety, or property of our users or the public, or establish, exercise, or defend legal claims.

36. Data Processing Addendum

If you are a business customer acting as a data controller or business under applicable law and you require a Data Processing Addendum (DPA) reflecting Standard Contractual Clauses, subprocessor commitments, and applicable security and breach-notification terms, contact support@newsletterengineai.com with the subject line "DPA Request — Newsletter Engine AI." We will provide our standard DPA for review and execution.

37. Changes to This Privacy Policy

We may update this Policy from time to time. The "Last updated" date above reflects the most recent revision. If we make a material change, we will provide notice by email or an in-product notice before the change takes effect, and, where required by law, we will seek your renewed consent. Your continued use of the Service after a change takes effect constitutes acceptance of the updated Policy, to the extent permitted by applicable law.

38. Contact Us

Extreme Results Technologies Inc. Newsletter Engine AI 1000 Brickell Avenue, Suite 1965 Miami, FL 33131 United States Email: support@newsletterengineai.com — for a privacy request, please use the subject line "Privacy Request — Newsletter Engine AI." We have not appointed a formal Data Protection Officer; the contact above is our general privacy inquiries channel.