Privacy Policy
In short. This site sets no cookies, runs no analytics scripts, profiles nobody and asks you to register for nothing. The only data concerning you is the technical data needed to deliver a page or an audio file, and it is handled by the hosting providers listed below.
Who processes the data
Data controller: Michele Mondora. Contact: michele@mondora.com.
Signal.Brief is a personal project publishing podcasts and videos generated with artificial-intelligence tools. It is not a commercial service, it does not sell data and it has no advertisers.
What this site does not do
- No cookies of any kind.
- No analytics scripts — no Google Analytics, no tracking pixels, no third-party tools in the pages.
- No remote fonts and no third-party iframes: pages load only what is served from the domains listed below.
- No accounts, no sign-up, no newsletter.
- No profiling and no automated decision-making concerning you.
Links to articles cited in episodes point to third-party sites with their own policies: following them takes you off this site.
What data is processed, and by whom
When you visit the site
Pages are hosted on GitHub Pages (GitHub, Inc.), which keeps technical service logs: IP address, user agent and requested resource. Those logs are processed by GitHub under the GitHub Privacy Statement. We have no access to them.
When you listen to an episode
Audio and video files are stored on Cloudflare R2
(media.casamon.dev), which keeps similar technical logs —
Cloudflare Privacy Policy.
Before reaching the file, the request passes through OP3
(op3.dev), an open-source podcast analytics service. OP3 receives
the IP address and user agent in order to count downloads according to the IAB
standard, and processes them under its
own privacy
policy.
| Purpose | knowing how many listens each episode receives |
|---|---|
| Legal basis | legitimate interest (GDPR art. 6(1)(f)): measuring the reach of what is published |
| What we see | aggregate figures only — counts per episode, client and region. We do not receive IP addresses |
If you listen through a podcast app or through Spotify, that platform applies its own policy, over which we have no control.
If you donate
The button leads to PayPal, which is an independent data controller. We neither receive nor store your payment details: we only get the notification that a donation occurred.
If you write to us
Your address and the content of your message stay in the mailbox for as long as needed to reply and to keep a record of the exchange.
AI-generated content
Episode summaries, voices and images are generated with AI tools from public sources, which are cited with their URL in every episode. Every publication declares this, both on the site and on the video platforms. It is not personal data about you, but it is something you are entitled to know before listening.
Use of platform APIs
Signal.Brief publishes automatically to its own YouTube, TikTok and Instagram accounts. It never accesses, collects, stores or transfers data belonging to other users of those platforms.
The OAuth credentials required are stored only on the
controller's own server, in files with restricted permissions
(~/.config/signal-brief/, mode 0600). They are never
sent to third parties and never pass through a browser.
YouTube
This application uses YouTube API Services to upload videos to the controller's own channel. By using it — and this site more generally — the YouTube Terms of Service and the Google Privacy Policy apply.
You may revoke this application's access to your Google account data at any time through Security → Third-party apps with account access (security.google.com).
| Scope | uploading videos to the controller's channel
(youtube.upload) |
|---|---|
| Data processed | OAuth token for the controller's channel |
| Viewer data | none: the application does not read analytics, comments or subscribers through the API |
TikTok
The application uses the Content Posting API with the
video.upload scope: it places the video in the drafts inbox of the
controller's own account, which the controller then publishes manually from the
app. It does not publish autonomously and does not access other users' data.
To revoke: in the TikTok app, Settings and privacy → Security and permissions → Manage app permissions.
Instagram and Meta
When enabled, the application uses the Instagram Content Publishing API to publish reels to the controller's own account. It does not access other users' data, messages, followers or comments.
To revoke: Settings → Security → Apps and websites on the linked Instagram or Facebook account.
Data deletion
We hold no personal data belonging to third-party users, so there is nothing about you to delete through the platform APIs.
For any data a platform may have associated with the authorisation granted to this application: revoking access as described above invalidates the token on the platform side, and the token is deleted from our server.
For any other deletion request — email correspondence, for instance — write to michele@mondora.com. Requests are handled within 30 days.
Your rights
Under articles 15-22 GDPR you may request access to your data, its rectification or erasure, restriction of processing, portability, and you may object to processing based on legitimate interest. Write to michele@mondora.com.
You also have the right to lodge a complaint with the Italian Data Protection Authority or your local supervisory authority.
Transfers outside the European Union
The providers named above (GitHub, Cloudflare, OP3, PayPal, Google, TikTok, Meta) are based on or use infrastructure outside the European Economic Area. Each operates under its own transfer safeguards — standard contractual clauses or Data Privacy Framework participation — described in their respective policies, linked above.
Minors
The content is not directed at children under 16, and we do not knowingly collect data concerning them.
Changes
The date at the top marks the last update. The full revision history is public in the project repository: every change to this page is a dated commit.