Good News

Privacy Policy

This Privacy Policy explains how Good News (the "App") processes your personal data.

The short version: we collect the minimum we need to send you a daily digest of positive news in your country. We do not show advertising inside the App, we do not personalise the content, we do not profile you, and we do not sell your data. The one exception to that minimisation is the measurement of our own acquisition campaigns on Meta, which we explain in §3.6 and which you can switch off in Settings.


1. Data Controller

The data controller responsible for processing your personal data is:

For the purposes of Regulation (EU) 2016/679 ("GDPR") and Spain's Organic Law 3/2018 ("LOPDGDD"), TYP NETWORK PTE. LTD. acts as the data controller.

2. EU Representative (GDPR Article 27)

GDPR Article 27 requires an EU representative for companies established outside the European Economic Area that offer services to EU users.

TO BE DESIGNATED. We will designate the EU Representative before the App becomes available to download in the European Union and publish the representative's name, EU postal address, and contact email here. Until then, you can contact the controller directly at privacy@goodnewsapp.app.

3. What Data We Process

Good News works without user accounts. We do not ask for your name, email, password, phone, or payment details. The only personal data or identifiers we process are:

3.1. Push notification token (Expo Push Token)

3.2. Country code

3.3. Preferred notification hour

3.4. Favourites and dismissed stories

3.5. Story reports

3.6. Campaign measurement (Meta)

So we can tell whether our ads on Facebook and Instagram work, the App sends Meta measurement data over two independent paths. Both are described here, and both stop with the same switch: Settings > Campaign measurement.

Path 1 — The Meta (Facebook) SDK embedded in the App

Path 2 — A relay from our own server (Meta Conversions API)

Common to both paths

Our website (goodnewsapp.app) performs an equivalent measurement when you arrive from a Meta ad: if the URL carries the fbclid click parameter, the site relays it through our server to close the attribution loop. No third-party cookies or pixels are installed on the site, and this measurement does not affect the App.

3.7. IP address

Any HTTP request to our backend transiently leaves the source IP in CloudFront / EC2 logs. We retain logs for at most 30 days, used only for security, abuse detection, and technical diagnostics. Legal basis: legitimate interest (GDPR Art. 6(1)(f)).

3.8. Update checks (Expo Updates)

The App uses expo-updates so we can fix bugs without waiting for a store review. On launch it asks Expo's server whether a newer JavaScript bundle exists.

3.9. Aggregate store statistics

Apple App Store Connect and Google Play Console provide us with aggregate, non-identifying statistics: number of installs, uninstalls, app-version distribution, and crash-free session rate. These are aggregated by Apple and Google before reaching us and contain no user-level identifiers.

3.10. Apple "required reason" APIs (Privacy Manifest)

The App uses the UserDefaults API (via AsyncStorage) solely to store user preferences on-device (country code, notification hour). We declare this in PrivacyInfo.xcprivacy under reason code CA92.1.

3.11. What we do NOT collect

For full clarity:

4. Why We Process Your Data

We process the data above strictly to:

  1. Deliver the daily digest as a push notification at your chosen hour.
  2. Serve articles relevant to your country.
  3. Review and correct the content you report to us.
  4. Diagnose crashes and technical errors, and deliver updates to you.
  5. Detect and prevent abuse of the backend.
  6. Measure, in aggregate, how many installs and opens our acquisition campaigns generate (§3.6).

We do not show you advertising, we do not carry out individual commercial profiling, and we do not sell your data to third parties.

5. Legal Bases (GDPR)

DataLegal basis
Expo Push Token + notification hourConsent (GDPR Art. 6(1)(a)). You give it in the App before the OS prompt, on an informational screen showing purposes, sub-processors, and transfers.
Country code (on-device only)Necessity to perform the service you requested by installing the App (Art. 6(1)(b)): we store your country so we can serve the correct digest.
Country code (on backend, when notifications enabled)Consent, bundled with the notification opt-in.
Story reportsLegitimate interest (Art. 6(1)(f)) in removing or correcting problematic content. The report is anonymous: we do not link it to you.
IP in logs / abuse detectionLegitimate interest (Art. 6(1)(f)) in App security.
Update checks (Expo)Necessity to perform the service (Art. 6(1)(b)): delivering App fixes to you.
App events sent to Meta (§3.6)Legitimate interest (Art. 6(1)(f)) in measuring the effectiveness of our acquisition campaigns. A documented Legitimate Interest Assessment (LIA) is available on request at privacy@goodnewsapp.app. You can object at any time by switching "Campaign measurement" off in Settings — no reason needed, no loss of functionality.

You can withdraw consent at any time. Withdrawal does not affect the lawfulness of prior processing (Art. 7(3) GDPR).

6. Data Retention

7. Processors, Recipients, and Sub-Processors

We do not sell or rent your data. To operate the App we use the following providers. Each processes only the data strictly necessary for its function.

7.1. Data processors (GDPR Art. 28)

ProviderLocationFunctionData shared
Amazon Web Services, Inc.United States (us-east-1)Backend hosting (EC2, S3, CloudFront, SSM)Push token, country, hour, anonymous story reports
Anthropic, PBCUnited States (US endpoint)Article classification and rewriting via the Claude API. Zero-retention mode enabled via Anthropic Trust Center; prompts are not used for training.Only the public content of the source article. No user data.
OpenAI, L.L.C.United States (US endpoint)Cover-image generation (gpt-image-2) when an article lacks a usable image. We have signed the zero-data-retention agreement.No user data.
Expo, Inc.United StatesPush-notification dispatch + OTA JavaScript bundle updates.Push token, dispatch timestamp, digest payload, delivery status. For OTA, the device IP at update-check time (not stored by us; subject to Expo's privacy policy at https://expo.dev/privacy).

In addition, we use Apify Technologies s.r.o. (Czech Republic, EU) to crawl public news websites. Apify does not receive or process any personal data of App users.

7.2. Independent controllers / recipients

RecipientLocationFunction
Apple Inc.United States / globalApp Store distribution and APNs push delivery. Apple operates APNs under its own policies and is a controller for the token at that layer.
Google LLCUnited States / globalGoogle Play distribution and FCM push delivery. Same regime as Apple.
Meta Platforms Ireland Ltd. (EEA users) / Meta Platforms, Inc. (elsewhere)Ireland / United StatesAcquisition-campaign measurement, both via the SDK embedded in the App and via the relay from our server to the Conversions API (§3.6). Meta acts as an independent controller under its own data policy. Switchable off in Settings.

7.3. Contractual safeguards

We have either signed a Data Processing Addendum (DPA) with each sub-processor or accepted their published Data Processing Terms as part of the platform agreement. This applies to: AWS GDPR DPA, Anthropic Trust Center, OpenAI DPA, Expo Terms, Apple Developer Program License Agreement Schedule 2, and Google Play Developer Distribution Agreement. In each case the sub-processor commits to equivalent GDPR-level protections, including Standard Contractual Clauses for non-EU transfers.

8. International Transfers

Some processors are in the United States and in Singapore. We comply with Chapter V of the GDPR as follows:

We have carried out a Transfer Impact Assessment (TIA) in line with the Schrems II ruling, with additional technical and organisational measures (encryption in transit and at rest, data minimisation). You can request a copy of the safeguards by writing to privacy@goodnewsapp.app.

9. Your Rights

You have the following rights over your personal data (GDPR Arts. 15-22 and LOPDGDD Arts. 11-18):

For users in California (CCPA/CPRA): rights to know, delete, correct, and opt out of the sale or sharing of your personal data. We do not sell or share personal data within the meaning of the CCPA/CPRA.

For users in Singapore (PDPA): rights of access and correction under PDPA sections 21 and 22.

Under Art. 11(2) GDPR, if we cannot identify you from the data you provide, we may ask for minimal additional information solely to confirm your identity (typically your push token).

10. How to Exercise Your Rights

The fastest way to delete your data:

  1. Open Settings > Delete my data inside the App. This single tap deletes your push token, country preference, and notification hour from the backend within seconds.
  2. As a fallback, email privacy@goodnewsapp.app and we will action the deletion within 7 days.

For any other right (access, rectification, portability, etc.), email us at the same address. We will ask for minimal information to confirm your identity, typically your push token (you'll find it under Settings > About inside the App). We will respond within one month, extendable by two additional months in complex cases.

If you believe we are processing your data unlawfully, you may file a prior complaint with us (privacy@goodnewsapp.app) or directly with the AEPD.

11. Automated Decisions and Profiling

We use AI (Anthropic Claude and OpenAI) to classify articles as positive and rewrite headlines and summaries.

If we ever introduce per-user personalisation, we will update this policy and notify you.

12. Push Notifications and ATT

Notifications are opt-in. Before the operating-system prompt appears, the App shows a screen explaining what they are for, linking this full Privacy Policy, and letting you choose between turning them on or continuing without them ("Not now"). If you decline, the operating-system prompt never fires and we never generate a token.

If you enable notifications:

Apple ATT framework: The App does not present an ATT prompt because it does not access the advertising identifier (IDFA): IDFA collection is disabled in the Meta SDK configuration (advertiserIDCollectionEnabled = false), we use no other advertising identifier, and we do not share data with data brokers. The campaign measurement described in §3.6 is carried out through app-level events without the IDFA, within the aggregated framework Apple permits without ATT consent.

13. Minors

The App is intended for users aged 16 or older. This is the default GDPR Art. 8 digital-consent age and is at or above the lower national thresholds applicable in the EU (e.g. 14 in Spain under Art. 7 LOPDGDD), providing equivalent or stronger protection across the EEA.

14. Security

15. Changes to this Policy

We may update this policy to reflect legal, technical, or operational changes. When we do:

If we continue using the same data for the same purposes, no new consent is required. Where a change affects a new purpose or a different legal basis, we will request fresh, explicit consent (Art. 6(4) GDPR).

16. Contact

privacy@goodnewsapp.app

TYP NETWORK PTE. LTD.
20 Collyer Quay #09-01
Singapore 049319