Privacy Policy
This describes what data ZONDED collects, why, and who receives it. The data controller is Thirteen Lab (“we”).
1. What we collect
We collect only what the product needs to work. We run no advertising or behavioural analytics.
- Your email address — it is both your login and the delivery address for digests.
- Login codes. We store an irreversible hash of the code, not the code itself; it lives 15 minutes and burns on use.
- Your session: a random identifier in a cookie, valid for 30 days.
- The profile you fill in yourself: role, what you work on, what you track, timezone, email frequency, language and theme.
- The sources you connect: the type and address of each channel or RSS feed.
- Material read from those public sources: post text, links, publication time, view and reaction counts.
- Your actions in the product: 👍/👎 votes and saved signals — these tune the order of your feed.
- Brute-force protection: an irreversible hash of “request origin + email”. We do not store the IP address itself.
2. Why we use it
The data serves the service and nothing else.
- To build your feed and digest from the sources you connected.
- To email you login codes and issues.
- To rank signals against your topics and votes.
- To protect sign-in from code guessing and the mailer from being pointed at other people’s addresses.
- To meet legal obligations where they apply to us.
3. Who receives it
We do not sell your data or hand it to third parties for their own purposes. To make the product work, some processors handle parts of it, each in a narrow role:
- A language-model provider (currently DeepSeek) — it receives post text from your sources and your own description of your work, in order to write the “why it matters” line. Your email address is not sent there.
- An email provider (Resend, or your own SMTP server) — recipient address and message body.
- Application hosting (Vercel) and the database (MongoDB Atlas) — storage and processing.
- Government authorities — only where the law requires it.
4. Storage and security
Traffic to the site runs over HTTPS. Login codes are stored as irreversible hashes, sessions expire after 30 days, and repeated wrong codes are rate-limited.
Requests to addresses you supply yourself (RSS feeds, for instance) are validated before they are sent, so the server cannot be used to reach an internal network.
Data is kept while your account exists. Deleting a source also removes the material read from it.
5. Your rights
You may obtain a copy of your data, correct it, delete it, object to processing, or request portability. Some of this is available in the interface directly: the profile is editable in settings, a source is removed with a button.
Deleting the whole account is currently done on request — write to hello@zonded.com and we will remove the account and everything tied to it.
6. Cookies
We set three cookies, all of them functional:
- zonded_session — what keeps you signed in.
- zonded_locale — your chosen interface language.
- zonded_theme — your chosen colour theme.
7. Changes to this policy
We may change this policy. The new version is published on this page with a new “last updated” date at the top.
8. Contact
Questions about this policy — Thirteen Lab, hello@zonded.com.