Privacy Policy
Cover365 is free to read and paid for by advertising. That is the honest place to start a privacy page, because an ad-supported site touches more reader data than a subscription one. Part of the money arrives through other companies’ systems, and those systems set things on your device. Last updated: August 2026.
We wrote this ourselves rather than pasting in a template. Where the law needs an exact term we use it and then explain it. If a paragraph here is unclear, that is a fault, and the address at the foot of the page is where to report it.
What we collect, and what we never ask for
Every visit produces log data, the way a visit to any web server does: your IP address, the rough location worked out from it, your browser and device, the page that sent you here, and which pages you opened when. Our analytics provider adds page views, scroll depth and time on page, which we read in aggregate.
The rest depends on what you do. Subscribe and we hold your email, the date, and whether our sends are opened. Comment and we hold your display name, email, the comment and its IP. Write to the newsroom and we keep the email, because a correction thread is a record we may have to produce later.
Advertising partners set cookies recording that a browser saw an ad, which can feed a profile built across sites, and our cookie policy covers that layer. We never ask for your date of birth, phone number, income, Aadhaar or PAN, or anything about your politics, health or religion. Holding data you do not need is how newsrooms become the story.
Why we process it, and on what legal footing
For log data, security, abuse prevention and aggregate analytics we rely on legitimate interest. Running a site that works, and knowing which stories were read to the end, is a reasonable expectation for a publisher and does not require stopping you at the door. We keep the amount small and the retention short. That is the trade.
The newsletter runs on consent, and every send carries an unsubscribe link that works on the first click. Advertising and measurement cookies run on consent collected through the consent manager and nothing else. We also process the minimum needed to meet a legal obligation or defend a claim, usually a copyright complaint or a dispute about a correction. That basis nobody chooses.
Who else touches it
We describe vendors by what they do rather than by brand, because the list changes and a name that went stale eighteen months ago is worse than a pointer to the live one. The categories are hosting and delivery network, analytics, the email service behind the newsletter, the comment platform, and the exchanges and ad server that fill our display inventory.
The consent manager names every advertising vendor currently allowed to set anything, generated from what is running rather than from what somebody typed once. Programmatic advertising is the part of this we control least, and pretending otherwise would be the sort of thing this site was started to complain about. We do not sell reader lists, and our advertising page carries the terms.
Cookies, and changing your mind about them
Cookies, pixels and browser storage are how the advertising and measurement layer works, and how the site remembers you wanted dark mode. Categories, purposes and lifespans sit in the cookie policy, so this page does not have to carry a table.
The consent manager is in the footer of every page, not only on your first visit. Withdrawing consent is as easy as giving it and applies from the next page load. Where consent is not legally required, that control still works, because a refusal you honour only when a regulator is watching is not a policy.
Your rights in the EU and the UK
In the European Economic Area and the United Kingdom the GDPR gives you rights over what we hold and a route to enforce them. They apply whether or not you ever commented or subscribed, because log data about your visit counts as personal data.
Write to us and we act inside one month, and say so if a request needs longer. We may ask you to confirm the address a request concerns. We will not demand a passport scan before deleting a newsletter subscription.
- Access: a copy of what we hold.
- Rectification: correction of anything inaccurate.
- Erasure: deletion, where nothing overrides it.
- Restriction: a pause while a dispute is settled.
- Portability: your data in a machine-readable form.
- Objection: a refusal of anything based on legitimate interest, advertising profiling included.
- Withdrawal of consent: at any time, without a reason.
- Complaint: to your data protection authority, without coming to us first.
One limit belongs here rather than in a footnote. Asking us to delete personal data does not oblige us to unpublish accurate reporting that names you. Journalism has an exemption for that collision, and where the two meet we apply our corrections policy, which covers the narrow cases where something does come down.
California, and Do Not Sell or Share
Under the California Consumer Privacy Act as amended by the CPRA, passing cookie identifiers to advertising partners for cross-context behavioural advertising counts as selling or sharing personal information, even though nobody wires us a payment for your data specifically. We would rather write that than hide behind the technicality.
California residents can ask what we collected and why, ask for a copy, ask for correction or deletion, opt out of that selling and sharing, and limit the use of sensitive personal information. None of it changes what you can read here. The opt-out is in the consent manager, labelled Do Not Sell or Share My Personal Information, and we honour the Global Privacy Control signal. An authorised agent may ask on your behalf with written proof.
How long we keep it, and where it sits
Server logs are held for 90 days, long enough to investigate an abuse pattern and short enough that they are not an archive. Analytics data is held in identifiable form for no more than 14 months, after which only aggregate counts remain. A newsletter address stays until you unsubscribe. Comments stay with the article, and correspondence for two years.
Our hosting, delivery network and vendors run servers outside India, so data crosses borders as routine plumbing rather than as a decision anyone took about you. For readers in the EEA and the UK we rely on the standard contractual clauses, and vendors are held by contract to process reader data only for the service they provide us. We cannot audit a global exchange from the inside, which is the honest limit of that.
Children
This is a general news site written for adults. It is not directed at children under 13, or under 16 where local law draws the line there, and we do not knowingly collect data from them. Creative aimed at children is a category we refuse to sell.
If you are a parent or guardian and think a child gave us an address or posted a comment, write and we will delete the account and the data behind it. There is no form to fill in first.
Changes to this page, and where requests go
The date at the top moves when the text does. If we change something material, meaning what we collect, who we share it with, or the basis we rely on, we say so on the site before it takes effect and mention it in the newsletter, rather than editing a line and letting the timestamp do the work.
Privacy requests go to support@cover365.in with PRIVACY at the front of the subject line. One inbox reaches the editors and they triage it themselves. Our contact page explains how to label other mail, and the rules covering your use of the site are in our terms of service. If we refuse a request we will name the exemption we relied on, and you can take it to your regulator from there.