Legal
Privacy
How AI Lately handles data about readers and about the people it covers, including data-subject requests.
Effective Sept. 4, 2026. This page explains what data AI Lately handles, why, and how you can exercise your rights. Two distinct groups appear here: readers of the site, and people covered by its journalism. Each group gets its own section, because the law treats them differently and so do we.
Readers
What the site collects by default. ailately.com is a static publication served through Vercel. Reading it requires zero accounts, zero cookies set by us, and zero tracking scripts. Vercel's infrastructure logs standard request data (IP address, user agent, requested URL, timestamp) for security and delivery, retains it for a short period under Vercel's own policy, and shares it with us only as aggregate traffic figures.
Analytics. If the editor turns on Vercel Web Analytics, it measures page views and referrers through a cookie-free method that hashes request data and discards it within a day; a note will appear here when that happens.
Email. A newsletter, when it launches, will run on a dedicated sending subdomain through a platform that supports one-click unsubscribe under RFC 8058. Every address on the list will have opted in directly. Subscriber data lives in that platform, apart from the editorial research base, and is used only to deliver the issues you asked for and to keep the list healthy: addresses with zero engagement over ninety days get suppressed. You can unsubscribe with a single click in any issue, and the request takes effect within two days.
Payments. If paid tiers launch, payments will run through Stripe. Card data stays with Stripe, apart from our systems.
Your rights as a reader. Wherever you live, you can ask what we hold about you, request a copy, seek correction or deletion, and object to marketing. Residents of the EU, the UK, and California hold specific statutory rights, and we honor them in full. Write to privacy@ailately.com; we answer within thirty days and confirm identity in proportion to the sensitivity of the request.
People covered by our journalism
What we publish. AI Lately reports on named people in their professional capacity: who joined which company, in which role, from where, and when. The allowlist is deliberately short: name, role, employer, public source, and date. Home addresses, personal contact details, ages, nationalities, health information, family details, and protected characteristics stay out of the record in every circumstance.
Where the information comes from. Company announcements, regulatory filings, government disclosure data, public job boards, academic preprints, the person's own public statements, and reporting from publications of record. Each piece cites its sources, and each Signal entry links to one.
Legal basis. Processing for journalistic purposes falls under the freedom-of-expression provisions of data-protection law, including Article 85 of the GDPR and the equivalent provisions of the UK Data Protection Act 2018. AI Lately operates as a journalistic enterprise with a masthead, published editorial standards, a corrections policy, and bylines, and that purpose is documented here in advance.
Your rights as a person we cover. You can ask what the editorial record holds about you and receive a copy. Pointing out an error prompts a check of the source and a prompt correction under the corrections policy. A request to add a response or an update gets published with the same prominence as the original claim. Requests for erasure of accurate, sourced, professional information get a considered reply; where the journalistic exemption applies, the record stays, and the reply explains why. Write to privacy@ailately.com.
Source protection. Confidential sources stay out of the editorial research base entirely. Requests that would reveal a source receive the response that the publication protects its sources.
Data architecture
Editorial research data and any future subscriber data live in separate systems with separate access controls and separate retention rules. Research material is retained for as long as it serves the archive. Subscriber data is retained for as long as you remain subscribed, plus a short suppression record after you leave so we honor your unsubscribe permanently.
Security
Multi-factor authentication protects the registrar, hosting account, code repository, and any future email and payment platforms. Backups are encrypted. A breach involving subscriber data would trigger notification to affected people and, where required, to regulators within seventy-two hours.
Children
The Service is written for professionals and is directed at adults. We collect zero data from children knowingly, and we delete any such data on notice.
International transfers
AI Lately is operated from the United States. Readers and subjects elsewhere should expect their data to be processed in the United States under this policy and, where applicable, under standard contractual clauses maintained by our service providers.
Changes
Updates to this page appear at this address with a new effective date. Material changes get a note on the site.
Contact
Privacy requests: privacy@ailately.com. Corrections: corrections@ailately.com. Everything else: editor@ailately.com.