Legal document
Privacy Policy
This Privacy Policy explains how Good News (the "App") processes your personal data.
The short version: we collect the minimum we need to send you a daily digest of positive news in your country. We do not show advertising inside the App, we do not personalise the content, we do not profile you, and we do not sell your data. The one exception to that minimisation is the measurement of our own acquisition campaigns on Meta, which we explain in §3.6 and which you can switch off in Settings.
1. Data Controller
The data controller responsible for processing your personal data is:
- Entity: TYP NETWORK PTE. LTD.
- UEN (Singapore Unique Entity Number): 202209033N
- D-U-N-S® (Dun & Bradstreet identifier): 659993981
- Registered office: 20 Collyer Quay #09-01, Singapore 049319
- Jurisdiction: Singapore
- Privacy contact: privacy@goodnewsapp.app
For the purposes of Regulation (EU) 2016/679 ("GDPR") and Spain's Organic Law 3/2018 ("LOPDGDD"), TYP NETWORK PTE. LTD. acts as the data controller.
2. EU Representative (GDPR Article 27)
GDPR Article 27 requires an EU representative for companies established outside the European Economic Area that offer services to EU users.
TO BE DESIGNATED. We will designate the EU Representative before the App becomes available to download in the European Union and publish the representative's name, EU postal address, and contact email here. Until then, you can contact the controller directly at privacy@goodnewsapp.app.
3. What Data We Process
Good News works without user accounts. We do not ask for your name, email, password, phone, or payment details. The only personal data or identifiers we process are:
3.1. Push notification token (Expo Push Token)
- What it is: A device-bound technical identifier issued by Expo / Apple (APNs) / Google (FCM) so we can deliver a daily push notification.
- When we get it: Only if you opt in to notifications via an in-App consent screen (shown before the operating-system prompt).
- Where it is stored: On our backend on AWS (region
us-east-1), associated with your country code and preferred hour. - How to revoke it: Tap "Delete my data" in the App's Settings screen, or disable notifications in your device's system settings.
- Google Play taxonomy: Categorised as "Device or other IDs", collected and shared with Expo, Apple (APNs), and Google (FCM) for the sole purpose of App functionality.
3.2. Country code
- What it is: A two-letter country code (e.g.
ES,FR). - How we obtain it: Auto-detected from your device locale at onboarding. You can override it manually inside the App at any time. We do not perform IP-based geolocation at all.
- Why: To select which country's news digest to serve you.
- Where it is stored: Locally in
AsyncStorageon your device, and on our backend associated with your push token only if you have enabled notifications.
3.3. Preferred notification hour
- What it is: The hour of the day (in your local time zone) at which you want to receive the daily digest.
- How it is stored: On the backend, associated with your push token, as the local-time hour plus an IANA time-zone identifier (e.g.
Europe/Madrid). The time-zone identifier reveals only your broad geographic region, not your precise location.
3.4. Favourites and dismissed stories
- What they are: The stories you mark as favourites or dismiss while reading.
- Where they live: On your device only (
AsyncStorage). They are never sent to our backend or to any third party, and they do not influence what anyone else sees. They disappear when you uninstall the App or clear its data.
3.5. Story reports
- What they are: When you tap "Report this story" (available from version 1.0.6), we send our backend the story identifier and the reason you pick (incorrect / inappropriate / other), via POST
/v1/reports. - Identity: The report carries no push token, no account, session, or device identifier. We cannot tell who sent it.
- Why: So we can review and, where warranted, remove or correct problematic content (see Terms §6).
- Google Play taxonomy: "App interactions" / "Product interaction".
3.6. Campaign measurement (Meta)
So we can tell whether our ads on Facebook and Instagram work, the App sends Meta measurement data over two independent paths. Both are described here, and both stop with the same switch: Settings > Campaign measurement.
Path 1 — The Meta (Facebook) SDK embedded in the App
- What is sent: Technical app-level events generated automatically by the SDK — install, app open, and session length — together with technical device data (model, OS version, language, IP address) and an anonymous install identifier generated by the SDK itself.
- When: From App start-up. The SDK starts muted and only begins recording once your preference has been read; if you have it switched off, nothing is ever recorded.
Path 2 — A relay from our own server (Meta Conversions API)
- What is sent: Two events —
first open(once ever per installation) andapp open(at most once a day) — carrying a random install identifier minted by your own device (32 random characters; not an advertising identifier and not tied to any account). - How: The App sends that event to our server (POST
/v1/attribution) and it is our server that relays it to Meta. The Meta credential never leaves our backend, and Meta does not receive your IP address or user agent on this path, because the request comes from our server rather than from your device. The payload explicitly declares a zeroed advertising identifier andadvertiser_tracking_enabled = 0. - Where the identifier lives: On your device only. It is erased by Settings > Delete my data and when you uninstall the App. If measurement is switched off, it is never even generated.
Common to both paths
- What is NOT sent: We do not collect the IDFA / advertising identifier (
advertiserIDCollectionEnabledis disabled), and we do not send Meta what you read, your push token, your country, your preferred hour, your favourites, or any contact detail. - Who is responsible: Meta processes this data as an independent controller under its own policy (
https://www.facebook.com/privacy/policy). - How to turn it off: Settings > Campaign measurement inside the App. Switching it off stops both paths from that moment; the App works exactly the same.
- Google Play taxonomy: "App activity" / "Other actions", shared with Meta for marketing analytics.
Our website (goodnewsapp.app) performs an equivalent measurement when you arrive from a Meta ad: if the URL carries thefbclidclick parameter, the site relays it through our server to close the attribution loop. No third-party cookies or pixels are installed on the site, and this measurement does not affect the App.
3.7. IP address
Any HTTP request to our backend transiently leaves the source IP in CloudFront / EC2 logs. We retain logs for at most 30 days, used only for security, abuse detection, and technical diagnostics. Legal basis: legitimate interest (GDPR Art. 6(1)(f)).
3.8. Update checks (Expo Updates)
The App uses expo-updates so we can fix bugs without waiting for a store review. On launch it asks Expo's server whether a newer JavaScript bundle exists.
- What Expo sees in that check: The device IP address, the installed app version, the platform, and the update channel. We do not send your push token, your country, your preferred hour, or what you read.
- Retention: Determined by Expo under its own policy (
https://expo.dev/privacy); we do not store those records. - Encryption: TLS in transit.
- We embed no crash-reporting SDK (Sentry, Crashlytics, or similar). The crashes we see reach us only in aggregate, anonymous form through App Store Connect and Google Play Console (see §3.9).
3.9. Aggregate store statistics
Apple App Store Connect and Google Play Console provide us with aggregate, non-identifying statistics: number of installs, uninstalls, app-version distribution, and crash-free session rate. These are aggregated by Apple and Google before reaching us and contain no user-level identifiers.
3.10. Apple "required reason" APIs (Privacy Manifest)
The App uses the UserDefaults API (via AsyncStorage) solely to store user preferences on-device (country code, notification hour). We declare this in PrivacyInfo.xcprivacy under reason code CA92.1.
3.11. What we do NOT collect
For full clarity:
- No accounts, passwords, or registration data.
- No payment information (the App is free with no in-app purchases).
- No GPS, no precise location.
- No access to contacts, photos, microphone, or calendar.
- No product-analytics SDK (Firebase Analytics, Mixpanel, Amplitude, Segment) and no crash-reporting SDK (Sentry, Crashlytics). The only third-party SDK with a marketing purpose is Meta's, limited to what §3.6 describes and switchable off in Settings.
- No advertising inside the App, and we do not pass your data to ad networks to target you.
- No advertising identifier (IDFA/AAID) and no individual behavioural profiling.
- No social graph, and no connection between the App and your Facebook or Instagram account (the Meta SDK is used for measurement only; the App offers no Facebook login).
4. Why We Process Your Data
We process the data above strictly to:
- Deliver the daily digest as a push notification at your chosen hour.
- Serve articles relevant to your country.
- Review and correct the content you report to us.
- Diagnose crashes and technical errors, and deliver updates to you.
- Detect and prevent abuse of the backend.
- Measure, in aggregate, how many installs and opens our acquisition campaigns generate (§3.6).
We do not show you advertising, we do not carry out individual commercial profiling, and we do not sell your data to third parties.
5. Legal Bases (GDPR)
| Data | Legal basis |
|---|---|
| Expo Push Token + notification hour | Consent (GDPR Art. 6(1)(a)). You give it in the App before the OS prompt, on an informational screen showing purposes, sub-processors, and transfers. |
| Country code (on-device only) | Necessity to perform the service you requested by installing the App (Art. 6(1)(b)): we store your country so we can serve the correct digest. |
| Country code (on backend, when notifications enabled) | Consent, bundled with the notification opt-in. |
| Story reports | Legitimate interest (Art. 6(1)(f)) in removing or correcting problematic content. The report is anonymous: we do not link it to you. |
| IP in logs / abuse detection | Legitimate interest (Art. 6(1)(f)) in App security. |
| Update checks (Expo) | Necessity to perform the service (Art. 6(1)(b)): delivering App fixes to you. |
| App events sent to Meta (§3.6) | Legitimate interest (Art. 6(1)(f)) in measuring the effectiveness of our acquisition campaigns. A documented Legitimate Interest Assessment (LIA) is available on request at privacy@goodnewsapp.app. You can object at any time by switching "Campaign measurement" off in Settings — no reason needed, no loss of functionality. |
You can withdraw consent at any time. Withdrawal does not affect the lawfulness of prior processing (Art. 7(3) GDPR).
6. Data Retention
- Push token + country + hour: As long as the token is valid. Deleted automatically when you revoke it ("Delete my data" or uninstall), or after 90 days of failed delivery attempts.
- Country code, hour, favourites and dismissals on-device: Until you uninstall the App or clear its data.
- Story reports: Up to 24 months, in anonymous form, so we can spot patterns of filtering failure.
- Update-check records: Retained by Expo under its own policy; we do not store them.
- App events sent to Meta: Retained by Meta under its own data policy; we receive no user-level copy, only aggregate campaign reports.
- Server logs (including IP): 30 days maximum.
7. Processors, Recipients, and Sub-Processors
We do not sell or rent your data. To operate the App we use the following providers. Each processes only the data strictly necessary for its function.
7.1. Data processors (GDPR Art. 28)
| Provider | Location | Function | Data shared |
|---|---|---|---|
| Amazon Web Services, Inc. | United States (us-east-1) | Backend hosting (EC2, S3, CloudFront, SSM) | Push token, country, hour, anonymous story reports |
| Anthropic, PBC | United States (US endpoint) | Article classification and rewriting via the Claude API. Zero-retention mode enabled via Anthropic Trust Center; prompts are not used for training. | Only the public content of the source article. No user data. |
| OpenAI, L.L.C. | United States (US endpoint) | Cover-image generation (gpt-image-2) when an article lacks a usable image. We have signed the zero-data-retention agreement. | No user data. |
| Expo, Inc. | United States | Push-notification dispatch + OTA JavaScript bundle updates. | Push token, dispatch timestamp, digest payload, delivery status. For OTA, the device IP at update-check time (not stored by us; subject to Expo's privacy policy at https://expo.dev/privacy). |
In addition, we use Apify Technologies s.r.o. (Czech Republic, EU) to crawl public news websites. Apify does not receive or process any personal data of App users.
7.2. Independent controllers / recipients
| Recipient | Location | Function |
|---|---|---|
| Apple Inc. | United States / global | App Store distribution and APNs push delivery. Apple operates APNs under its own policies and is a controller for the token at that layer. |
| Google LLC | United States / global | Google Play distribution and FCM push delivery. Same regime as Apple. |
| Meta Platforms Ireland Ltd. (EEA users) / Meta Platforms, Inc. (elsewhere) | Ireland / United States | Acquisition-campaign measurement, both via the SDK embedded in the App and via the relay from our server to the Conversions API (§3.6). Meta acts as an independent controller under its own data policy. Switchable off in Settings. |
7.3. Contractual safeguards
We have either signed a Data Processing Addendum (DPA) with each sub-processor or accepted their published Data Processing Terms as part of the platform agreement. This applies to: AWS GDPR DPA, Anthropic Trust Center, OpenAI DPA, Expo Terms, Apple Developer Program License Agreement Schedule 2, and Google Play Developer Distribution Agreement. In each case the sub-processor commits to equivalent GDPR-level protections, including Standard Contractual Clauses for non-EU transfers.
8. International Transfers
Some processors are in the United States and in Singapore. We comply with Chapter V of the GDPR as follows:
- United States: Transfers rely on (a) the EU-US Data Privacy Framework where the provider is certified, and/or (b) Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). As of the policy date, AWS, Anthropic, OpenAI, Apple, Google, and Meta are DPF-certified; we will update this clause if any of them ceases certification. Expo is not DPF-certified and transfers to Expo's backend rely on SCCs.
- Ireland (Meta Platforms Ireland): Within the EU. Meta's onward transfers to the United States are governed by its own safeguards, over which we have no control.
- Singapore (controller's location): Singapore has no EU adequacy decision, so the controller's access to data from Singapore relies on SCCs (controller-to-controller module).
- Czech Republic (Apify): Within the EU; no additional safeguards required.
We have carried out a Transfer Impact Assessment (TIA) in line with the Schrems II ruling, with additional technical and organisational measures (encryption in transit and at rest, data minimisation). You can request a copy of the safeguards by writing to privacy@goodnewsapp.app.
9. Your Rights
You have the following rights over your personal data (GDPR Arts. 15-22 and LOPDGDD Arts. 11-18):
- Access: know what data we hold about you.
- Rectification: correct inaccurate data.
- Erasure ("right to be forgotten").
- Restriction of processing.
- Portability in a structured format.
- Objection to processing based on legitimate interest.
- Withdrawal of consent at any time without affecting the lawfulness of prior processing (Art. 7(3) GDPR).
- Not to be subject to automated individual decisions producing legal or similarly significant effects (see Section 11).
- Lodge a complaint with the Spanish Data Protection Agency (AEPD):
www.aepd.es, C/ Jorge Juan 6, 28001 Madrid.
For users in California (CCPA/CPRA): rights to know, delete, correct, and opt out of the sale or sharing of your personal data. We do not sell or share personal data within the meaning of the CCPA/CPRA.
For users in Singapore (PDPA): rights of access and correction under PDPA sections 21 and 22.
Under Art. 11(2) GDPR, if we cannot identify you from the data you provide, we may ask for minimal additional information solely to confirm your identity (typically your push token).
10. How to Exercise Your Rights
The fastest way to delete your data:
- Open Settings > Delete my data inside the App. This single tap deletes your push token, country preference, and notification hour from the backend within seconds.
- As a fallback, email privacy@goodnewsapp.app and we will action the deletion within 7 days.
For any other right (access, rectification, portability, etc.), email us at the same address. We will ask for minimal information to confirm your identity, typically your push token (you'll find it under Settings > About inside the App). We will respond within one month, extendable by two additional months in complex cases.
If you believe we are processing your data unlawfully, you may file a prior complaint with us (privacy@goodnewsapp.app) or directly with the AEPD.
11. Automated Decisions and Profiling
We use AI (Anthropic Claude and OpenAI) to classify articles as positive and rewrite headlines and summaries.
- These models operate on public content from news publishers, not on your personal data.
- Every user in a given country receives exactly the same digest. The App does not personalise content per user: what you save as a favourite or dismiss stays on your device (§3.4) and does not alter anyone's selection, not even your own on later days.
- Story reports are anonymous and serve to let us review specific content, not to classify you.
- We do not take automated decisions producing legal or similarly significant effects on natural persons (Art. 22 GDPR), and we do not carry out individual profiling.
If we ever introduce per-user personalisation, we will update this policy and notify you.
12. Push Notifications and ATT
Notifications are opt-in. Before the operating-system prompt appears, the App shows a screen explaining what they are for, linking this full Privacy Policy, and letting you choose between turning them on or continuing without them ("Not now"). If you decline, the operating-system prompt never fires and we never generate a token.
If you enable notifications:
- We generate an Expo Push Token and associate it on the backend with your country and hour.
- We send one notification per day with the digest, at your chosen hour.
- We may, in exceptional circumstances, send a single additional operational notification if the service has been materially disrupted for more than 24 hours.
- We never use the push channel for advertising or cross-promotion, in line with Apple App Store Review Guideline 4.5.4 and Google Play's Developer Program Policy on Disruptive Notifications.
- You can revoke notifications at any time from the App's Settings or your OS settings; the token is invalidated and deleted from the backend within seconds.
Apple ATT framework: The App does not present an ATT prompt because it does not access the advertising identifier (IDFA): IDFA collection is disabled in the Meta SDK configuration (advertiserIDCollectionEnabled = false), we use no other advertising identifier, and we do not share data with data brokers. The campaign measurement described in §3.6 is carried out through app-level events without the IDFA, within the aggregated framework Apple permits without ATT consent.
13. Minors
The App is intended for users aged 16 or older. This is the default GDPR Art. 8 digital-consent age and is at or above the lower national thresholds applicable in the EU (e.g. 14 in Spain under Art. 7 LOPDGDD), providing equivalent or stronger protection across the EEA.
- App Store and Google Play age ratings are set accordingly (12+ / Teen).
- We do not request your age because we do not collect identifying data.
- If we detect or are notified that a child under 16 is using the App with an active token, we delete the token and associated data.
- If you are a parent or guardian and believe a minor in your care is using the App, email privacy@goodnewsapp.app and we will act immediately.
14. Security
- In transit, all communications use HTTPS with TLS 1.2 or higher (TLS 1.3 where available), including connections to Expo, AWS, Anthropic, OpenAI, and Meta.
- At rest on the backend, data is encrypted using AWS-managed KMS keys.
- API keys and secrets are stored in AWS SSM Parameter Store, encrypted at rest.
- On your device, your preferences (language, country, hour), your favourites, your dismissed stories and the article cache are stored in AsyncStorage, with no encryption beyond what the operating system itself applies. We do not exclude this data from iOS/Android system backups, so it may be present in iCloud Backup or Google One Backup, encrypted under your Apple/Google account.
- Access to the push-token dataset is limited to a small set of operators.
15. Changes to this Policy
We may update this policy to reflect legal, technical, or operational changes. When we do:
- We will publish the new version at
https://goodnewsapp.app/en/privacy.html. - We will update the "Last updated" date at the top.
- If the change is significant, we will notify you inside the App.
If we continue using the same data for the same purposes, no new consent is required. Where a change affects a new purpose or a different legal basis, we will request fresh, explicit consent (Art. 6(4) GDPR).
16. Contact
privacy@goodnewsapp.app
TYP NETWORK PTE. LTD.
20 Collyer Quay #09-01
Singapore 049319
English-language version. In case of discrepancy with the Spanish version for users resident in Spain or the EU who installed the App in Spanish, the Spanish version prevails. Version 1.0.
Also available as markdown: privacy.en.md.