The Defense Feed

Legal

Privacy policy

Last updated · August 2026

1 · Who we are

The Defense Feed (“we”, “us”) is a daily defense-intelligence service published from France. This policy explains what personal data we collect, why we collect it, and how you can control it. It applies to thedefensefeed.com and every related subdomain.

For any question about your data or this policy, contact contact@thedefensefeed.com.

2 · What we collect and why

We collect only what the service actually needs. There are two categories.

Account data (only if you sign up)

  • Email address — used for sign-in and account emails.
  • Password — stored only as a bcrypt hash by Supabase Auth. We never see or store the cleartext.
  • Optional onboarding fields: first name, last name, job title, company, role, country. These help us calibrate the feed and shape aggregate sponsor reporting (never individual disclosure).
  • Digest preference (weekly / none) — used to decide whether to send you our Monday briefing digest.

Usage data (everyone, aggregated)

  • Anonymous page-view and event counts via Plausible Analytics. No cookies, no cross-site tracking, no personal identifiers. We use it to understand what content works.
  • Server logs (IP address, request path, timestamp) kept for up to 30 days for security and abuse-prevention purposes.

3 · Legal basis

Under GDPR Article 6, our processing rests on:

  • Contract (Art. 6.1.b) for account creation, authentication, and the free-tier product itself.
  • Legitimate interest (Art. 6.1.f) for anonymous usage analytics (Plausible), server logs, and fraud prevention. Balanced against your privacy interests — cookieless, minimal, retention-bounded.
  • Consent (Art. 6.1.a) for the optional weekly digest and any future marketing.

4 · Who processes your data

We work with a small number of data processors, each bound by a data processing agreement:

ProcessorPurposeRegion
SupabaseAuthentication + primary databaseEU
ResendTransactional and digest email deliveryEU (Ireland)
VercelApplication hosting + edge networkGlobal (EU-first routing)
AnthropicArticle summaries + deduplication verificationUS
Voyage AIArticle embeddings (semantic dedup)US
PlausibleCookieless analyticsEU (Germany)

Anthropic and Voyage AI process only article content (title + summary), never your personal account data. Transfers to the US are covered by Standard Contractual Clauses (SCCs) with each provider.

5 · Retention

  • Account data: kept for as long as your account exists.
  • Server logs: 30 days rolling.
  • Analytics events (Plausible): 90 days aggregated, anonymous.
  • Premium waitlist emails: kept until Premium launch, deleted 6 months after your last notification.

6 · Your rights

Under GDPR you can, at any time, request to:

  • Access — receive a copy of the data we hold about you.
  • Rectify — correct any inaccuracy (do this directly at /account).
  • Erase — delete your account and all associated data. Do this yourself at /account (bottom section, type “DELETE” to confirm). Immediate and permanent.
  • Portability — receive your data in a machine-readable format.
  • Object — object to processing based on legitimate interest.
  • Complain — lodge a complaint with the CNIL (France) or your local data-protection authority.

For access, portability, or objection requests, email contact@thedefensefeed.com. We respond within 30 days.

7 · Cookies

We use one essential cookie set by Supabase Auth to keep you signed in. No advertising cookies, no third-party tracking cookies, no analytics cookies (Plausible is cookieless).

8 · Changes

We'll post any material change to this policy on this page and update the date above. If the change affects rights you actively rely on, we'll email you.