Privacy Policy
Last updated: 1 October 2026
This policy explains what the Finally Some Good.News website (finallysomegood.news) and the Finally Some Good.News Android app do with data about you. The two share a codebase and a news feed, so one policy covers both — passages that apply to only one platform are marked Website or App.
The short version. There are no user accounts and nothing to sign up for. We don't run our own custom analytics or tracking backend, we don't ask for your name, email, or location (unless you choose to send us a message or suggest a news source through a form, and then only to answer you), and we don't sell data. The website uses Google Analytics to see how many people visit and what they read, shows a few clearly labelled sponsor links from an ad company, Monetag, plus one Monetag full-screen ad format on the shared-article page only, and runs on reader donations via a Ko-fi widget; a consent banner (Ketch) lets you choose which non-essential cookies are allowed. The Android app shows Google ads, and Google — not us — receives technical data such as your IP address and may use your device's advertising ID to serve and measure them; in the EEA and the UK the app asks you to consent before any personalised advertising happens, and you can decline.
1. Who is responsible
The Finally Some Good.News website and Android app are published by an individual developer based in the Czech Republic. For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, that person is the "data controller" for the limited processing described here.
You can reach the publisher at [email protected]. There is no separately appointed data protection officer; privacy questions go to that address.
2. What we don't collect
To be clear about the baseline, the website and the app do not: Website + App
- have user accounts, logins, profiles, or a sign-up of any kind;
- ask you for your name, email address, phone number, date of birth, or any other identifying detail — except your name and (optionally) your email address when you choose to contact us or suggest a news source through a form (see “Contact and source-request forms” in section 3);
- collect your GPS location or precise location;
- run our own custom analytics or event-logging backend — the website does use Google Analytics, a third-party tool, described in section 3;
- read your contacts, photos, files, camera, microphone, or calendar;
- sell, rent, or trade data about you to anyone;
- build our own advertising or behavioural profile of you across sites or apps.
Beyond Google Analytics and the donation script described in sections 3 and 6, the only thing the website itself stores on your device directly is a small localStorage entry remembering a light/dark theme override you've chosen — it is not an identifier, is never sent anywhere, and clearing your browser storage removes it. Website
"Check the news happening in your country." To offer you a one-tap link to stories from your country, the feed page reads your browser's own time-zone setting (for example “Australia/Sydney”) and matches it to a country, entirely inside your browser. Your time zone and the country we guess are never sent to us or anyone else, never stored, and never used for advertising or analytics; we don't look up your IP address or location. If the guess is wrong, just pick another country or close the suggestion. Website
3. What is collected, and by whom
Server request logs Website
Like every website, finallysomegood.news is served by a hosting provider whose servers automatically record standard technical information for each request: your IP address, the page or file requested, the time, the referring page, and your browser's user-agent string. These logs exist for security, abuse prevention, and basic traffic troubleshooting. They are held by the hosting/CDN provider, are not combined with anything else, and are not used to identify you as a person.
The app fetches its news data as a plain file (feed.json) from the same host, which produces the same kind of log entry. App
Website analytics — Google Analytics Website
Every page of the website loads Google Analytics (gtag.js). It sends Google page-view events (which pages you visit, the referring page, approximate location derived from your IP address, and device/browser type) and sets cookies (for example _ga) so Google can distinguish you as a returning visitor across sessions. It is processed under Google's Privacy Policy.
Contact and source-request forms Website
If you use the form on the Contact page or the “Request a new source” form, we receive what you type: your name, your email address if you give one, and your message or the outlet's name, website and country. It goes to a small service we run on Cloudflare (Workers), is stored in our private Cloudflare R2 storage (never published), and is forwarded to our own inbox by an automated job on GitHub Actions, which sends the email through our email provider (Zoho Mail). We use it only to read and answer your message, or to check the outlet you suggested and tell you the outcome — never for marketing, and it is never sold or shared. We don't store your IP address with it; Cloudflare uses it briefly to stop the forms being flooded with spam. A contact message is deleted from that storage 90 days after it reaches us (the email itself stays in our inbox, like any email you send us). For a source request, your email address is deleted as soon as we've told you the outcome, and the rest of the request 90 days after that; the outlet's name, website, country and our decision may appear on our Stats & FAQ page — never your name or email.
Data collected by Google Play App
When you install and run an app from the Google Play Store, Google automatically collects certain information regardless of what the app's own code does — for example app installs, uninstalls, crashes, and aggregate performance and device data. This collection is governed by Google's Privacy Policy and the Play Store terms, not by us, and we receive only aggregated, non-identifying reports from it in the Play Console.
Advertising identifiers and cookies
On the website, our sponsor links set no cookies and run no code. The shared-article page (read.html) also loads Monetag's own script for a full-screen ad (described in the next section), which may set cookies or similar device storage of its own to serve, measure, and prevent fraud on its ads; and if you click a sponsor link you go to Monetag's site, which may do the same. We don't control what Monetag or its advertisers store or for how long. In the app, Google AdMob uses the device's resettable advertising ID to select and measure ads. Details, and how to limit or switch these off, are in the next section. Website + App
4. Advertising
On the website Website
The website (finallysomegood.news) shows a few sponsor links, each clearly labelled “Ad”: a thin strip after every fifth story in the feed, a card in the side rail on wide screens, and a line under “Go to Article” on the shared-article page (read.html). They are ordinary links written by us that run no code: only if you click one does your browser go to Monetag, which chooses an advertiser's page to send you on to. In addition, the shared-article page alone loads Monetag's “vignette” script, which can show a full-screen ad you can close when you move between pages; loading that page therefore sends Monetag technical data such as your IP address, browser and device information. Monetag and its advertisers are independent controllers of the technical data (such as your IP address, browser, and device information) and any cookies they use, under their own privacy policies (Monetag's privacy policy). Sponsor links never affect which stories we publish or how they are ranked. The site is funded by these links alongside voluntary reader donations.
In the app: Google AdMob App
The Android app shows ads served by Google AdMob. We do not operate an ad server or a data-management platform; Google acts as an independent controller for the ad data it collects. AdMob uses your device's advertising ID and related technical data to serve ads, limit repetition, detect invalid activity, and — where permitted — show personalised ads and measure them. In its current configuration the app is set up to allow personalised ads where you have not opted out or declined consent. Google's handling of this data is described in the same document linked above and in AdMob's data-disclosure guidance.
Your choices about ads
- In the app — EEA and UK consent. Before any personalised advertising or non-essential ad storage takes place in the app, you are shown a consent request through Google's certified consent mechanism. You can refuse; if you do, ads are still shown but are non-personalised. You can change your choice later via the app's privacy/consent option in settings where offered, or by reinstalling. App
- On the website — cookie consent. A consent banner (served by Ketch, a consent management platform) lets you choose which non-essential cookies and similar storage — Google Analytics, the Ko-fi widget, and Monetag's script on the shared-article page — are allowed (the sponsor links themselves set none), and you can change your choice at any time by reopening it. Your browser's own ad-blocking or tracking-protection settings and extensions apply on top of that, as they would on any site. Website
- Industry opt-outs. You can opt out of personalised advertising from many vendors, on the website or in the app, at optout.aboutads.info, youronlinechoices.eu, and the NAI opt-out page.
- App advertising ID. In Android Settings → Privacy → Ads you can "Delete advertising ID" (after which apps can no longer use it for ads) or reset it and opt out of ad personalisation. App
5. Diagnostics and crash reporting
To find and fix bugs, the app may report crashes and basic technical diagnostics (for example the device model, Android version, and a stack trace) through Google's standard developer tooling — at minimum the crash reporting built into Google Play, and possibly Google/Firebase crash reporting. This data is tied to a random, app-scoped identifier rather than to you, is used only to keep the app working, and is not used for advertising. It is processed under Google's Privacy Policy. App
6. Other third-party services and content
Displaying a global news feed means your device talks to servers other than ours. In each case that third party receives your IP address and user-agent simply because your browser or the app is making the request; we don't send them anything extra.
- Google Fonts. The website loads its typefaces from Google's font CDN (
fonts.googleapis.com/fonts.gstatic.com), so Google receives the request for those files. Website - Article thumbnail images. Story thumbnails are loaded directly ("hotlinked") from each news outlet's own servers — they are never copied onto our host. When a thumbnail loads, that outlet's server sees your IP address and user-agent. We don't control those outlets or their privacy practices. Website + App
- Outbound links to articles. Opening a story sends you to the publisher's own website, which has its own privacy policy. For stories not in English, the "read" link routes through Google Translate (
translate.google.com) to provide an English rendering; that request is handled by Google. Website + App - Hosting and CDN provider. The static files are served by a third-party hosting/CDN provider that processes the request logs described in section 3 on our behalf as a processor. Website
- Google Play. Distribution of the app, and its update mechanism, run through the Google Play Store. App
- Ketch consent banner. The website loads a script from Ketch to show the cookie consent banner and remember your choice. Ketch receives your IP address and browser/device information to do this, and stores your consent choice (for example in a cookie or local storage) so it doesn't ask again every visit. Website
- Newsletter (Buttondown). If you subscribe to our email newsletter, your email address is sent to and stored by Buttondown, the service that sends it. You'll get a confirmation email first (nothing is sent until you confirm), every email has an unsubscribe link, and unsubscribing stops all newsletter email. We use your address only to send the newsletter — never sold or shared for anyone else's marketing. Buttondown's own privacy policy covers how it processes the address on our behalf. The legal basis is your consent, which you can withdraw at any time by unsubscribing. Website
- Automated short videos. Our Facebook Page also publishes short videos produced automatically from the same curated summaries you see on this site, using licensed stock footage (labelled "Illustrative footage" on screen) and original graphics and music. They link back here with tracking tags (for example
utm_source=facebook) so we can see which videos bring readers to the site; that measurement uses the same Google Analytics described above. Website - Ko-fi donation widget. The website embeds a small "Support me" widget from Ko-fi so readers can leave a one-off tip. Loading it sends Ko-fi your IP address and browser/device information. If you click through to actually donate, that happens entirely on Ko-fi's own site, under Ko-fi's own privacy policy and payment terms — we never see your payment details. Website
- Automated Facebook posting. We operate a Meta developer app, "FinallySomeGood.News Feeder" (this page is that app's registered Privacy Policy URL), which automatically posts our current top-ranked story (its headline, summary, and image) to our own Facebook Page, "Finally Some Good News," whenever that top story changes. This is outbound only: we publish our own content to our own Page and do not collect, read, or store any information from Facebook/Meta in the process — no follower, insights, comment, or interaction data. If you interact with that Facebook Page or post (like, comment, share), that interaction is with Meta's platform and is governed by Meta's own privacy policy as well as this one. Backend
7. App permissions
The app requests only network access (INTERNET / network state), which it needs to download the news feed, thumbnails, and its ads. It does not request location, storage, camera, microphone, contacts, phone, or SMS permissions. App
8. Legal bases for processing (GDPR)
Where the GDPR or UK GDPR applies, the processing above rests on these legal bases:
- Legitimate interests (Art. 6(1)(f)) — keeping the service running and secure: server request logging, abuse and fraud prevention, crash diagnostics, and serving non-personalised ads with basic frequency capping. You may object to processing based on legitimate interests (see "Your rights").
- Legitimate interests / your request — answering a message you send through the contact form, and checking a news source you suggest and telling you the outcome (Art. 6(1)(f), and Art. 6(1)(b) where you're asking us to do something).
- Consent (Art. 6(1)(a)) — in the app, personalised advertising and any storage of, or access to, information on your device that is not strictly necessary; this is collected through Google's consent request shown in the EEA and UK, and you can withdraw it at any time with future effect. On the website, non-essential cookies from Google Analytics and the Ko-fi widget are likewise gated on your choice through the Ketch consent banner described in "Your choices about ads" above, which you can reopen to change your choice at any time.
Monetag (on the shared-article page, and once you click a sponsor link), Google (Analytics and, in the app, advertising), Ko-fi, and Ketch each independently determine the legal basis for their own further use of the data they collect, as separate controllers.
9. How long data is kept
We do not maintain our own database of users or events. The one exception is what you choose to send through our forms, kept as described under “Contact and source-request forms” in section 3: contact messages for 90 days; for source requests, your email address only until we've told you the outcome. Server request logs are kept by the hosting/CDN provider for a short period (typically a few weeks) for security and troubleshooting, then rotated out. Google retains Analytics, ad, Play, and diagnostics data according to its own retention schedules, described in Google's Privacy Policy and its data retention page. Ko-fi retains data related to the widget and any donation according to its own policy, and Ketch retains your consent choice according to its own policy.
10. International data transfers
Google is headquartered in the United States and processes data globally. When Google receives data through website analytics, app advertising, Play, fonts, translation, or diagnostics services described above, it may transfer that data outside the EEA/UK. Google states that it relies on the European Commission's Standard Contractual Clauses and equivalent safeguards for those transfers; see Google's ads services data transfer information. Monetag (once you click a sponsor link), Ko-fi, Ketch, the hosting/CDN provider, and the services that carry our forms (Cloudflare, GitHub, Zoho) may likewise process data outside your country under their own terms and safeguards.
11. Your rights
If you are in the EEA, the UK, or another region with comparable law, you have the right to request access to, correction of, deletion of, or restriction of your personal data; to object to processing based on legitimate interests; to data portability; and to withdraw any consent you have given.
An important practical point: because we hold almost no information that identifies you (see section 2), we usually cannot single you out in the little data we do have, and the GDPR does not require us to collect more just to enable a request (Art. 11). For the app's advertising data, Play data and diagnostics the controller is Google (requests are best made through your Google Account and My Ad Center). For what happens after you click a sponsor link on the website, the controllers are Monetag and the advertiser, not us — we don't hold that data ourselves. We will still help where we can — write to [email protected].
You also have the right to lodge a complaint with a data protection authority. The publisher's lead authority is the Czech Úřad pro ochranu osobních údajů (ÚOOÚ); you may also complain to the authority in your own country of residence.
12. Children
Neither the website nor the app is directed to children, and we do not knowingly collect personal data from children under the age of 16 (or the applicable age of digital consent in your country). The app is rated and distributed accordingly on Google Play. If you believe a child has provided personal data, contact us and we will address it.
13. Security
The website and the feed are served only over HTTPS. Because there are no accounts and no user-submitted data, there is no user database to breach on our side. Third-party providers (Google, the hosting provider) maintain their own security programmes for the data they hold.
14. Changes to this policy
This policy may be updated as the site or app changes — for example if the ad configuration changes or a new service is added. The "Last updated" date at the top always reflects the current version. For a significant change affecting how your data is used, we will make the update prominent (for example a notice on the feed page or in the app) before it takes effect where required.
15. How to contact us
For any question about this policy or about your data, email [email protected]. The publisher is an individual developer based in the Czech Republic; a postal address for formal data-protection correspondence is available on request.
This document is provided for transparency and to meet Google Play and advertising disclosure requirements. It is not legal advice. — Finally Some Good.News · Feed · Translated news · Take a break · Good news today · Support · Stats & FAQ · Contact