BlueEM Privacy Policy
This Privacy Policy explains what personal data BlueEM collects, why we collect it, how we use it, who we share it with, how long we keep it, and the rights you have over it.
By using BlueEM you acknowledge the practices described below. If you do not agree, you should not use BlueEM. This Policy supplements the BlueEM Terms of Use.
1. Who We Are
“BlueEM,” “we,” “us,” and “our” refer to the operator of the BlueEM news discovery service. BlueEM is the controller of the personal data described in this Policy in the contexts where it determines the purposes and means of processing.
For privacy questions, data-subject requests, or to contact our data controller, please email privacy@blueem.ai.
2. Data We Collect
We collect personal data in three main ways:
(a) Data you provide directly.
- Account data: name, email address, password (stored as a salted hash, never in plain text), and optionally your company.
- Preferences: your investment focus description, ranking prompt, sector / region selections, sector display order, per-sector article cap, alert keywords, and other settings you configure on your profile.
- Communications: messages you send us, support requests, and free-text responses (for example, the reason you give when unsubscribing).
(b) Data we collect automatically when you use BlueEM.
- Login events: timestamp and user ID for each successful sign-in.
- Send events: records of each newsletter or transactional email we send to you, including whether the send succeeded.
- Technical data: IP address, browser user-agent, and standard server-side request metadata captured by our hosting provider.
- Session cookies: a single HMAC-signed cookie set by the Flask web framework so you stay logged in. We do not use third-party tracking or advertising cookies.
(c) Data we receive from third parties.
- Google Sign-In (OAuth): if you choose to sign in with Google, we receive your verified email address, name, and Google account identifier. We do not receive your Google password.
- Stripe (billing): if you subscribe to a paid plan, Stripe processes your payment details on its own servers. We receive only the subscription identifiers, status, billing cycle, current period end, and customer reference necessary to administer your subscription. We do not store full payment-card numbers.
3. How We Use Your Data
We use your personal data for the following purposes:
- Service delivery: to authenticate you, deliver the newsletter, render personalised summaries, run watchlists and alerts, and operate the platform.
- Personalisation: to rank, filter, translate, and summarise articles based on your sector and region preferences and your free-text investment focus.
- Billing: to manage paid subscriptions, including initiating charges via Stripe and handling upgrades, downgrades, cancellations, and renewals.
- Communications: to send transactional messages (email verification, password resets, billing notices, approval notices, the daily newsletter) and to reply to support requests.
- Security and abuse prevention: to detect and respond to suspicious activity, enforce our Terms of Use, and protect the integrity of the service.
- Service improvement: to understand how the service is used in aggregate (sign-ups, logins, email deliveries, unsubscribe reasons) and to improve features.
- Legal compliance: to comply with applicable laws, regulations, and lawful requests.
4. Legal Bases for Processing (EEA / UK / Brazil)
Where data-protection law requires a lawful basis, we rely on:
- Performance of a contract with you (creating your account, delivering newsletters you subscribed to, billing your paid plan).
- Legitimate interests in operating, securing, and improving BlueEM, where those interests are not overridden by your rights.
- Consent, where required (for example, when you choose to receive optional communications). You may withdraw consent at any time without affecting prior processing.
- Legal obligation, where we are required to retain or disclose data by law.
5. Sub-Processors
BlueEM relies on a small number of third-party processors to operate the service. These providers process personal data on our behalf under written terms that require appropriate security and confidentiality:
- Anthropic (Claude API) — classifies, ranks, summarises, and translates news articles. We send article text and your ranking prompt to Anthropic for processing. We do not share your password, billing data, or account identifiers with Anthropic.
- Stripe — processes subscription payments and stores your payment instrument on its own infrastructure under PCI-DSS controls.
- Google (Gmail SMTP and Google Sign-In) — sends transactional and newsletter email on our behalf, and (if you choose it) authenticates your sign-in.
- Render — hosts the BlueEM web application, database, and the AI "Blue Note" pages linked from your newsletter (served from our own domain). Render processes data on our behalf in the United States.
- xAI (Grok API) — retrieves public posts from X (Twitter) relevant to monitored entities. We do not send your personal data to xAI.
6. Sharing and Disclosure
We do not sell your personal data. We do not share it for cross-context behavioural advertising.
We may disclose personal data only in these limited circumstances:
- to the sub-processors listed above, to operate the service;
- to comply with applicable law, court orders, or lawful requests from public authorities;
- to enforce the Terms of Use or protect the rights, property, or safety of BlueEM, our users, or others;
- in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honour this Policy or notify you of any material change;
- with your consent or at your direction.
7. International Transfers
BlueEM is operated from the United States. By using the service, you understand that your personal data may be transferred to, stored, and processed in the United States or in any other country where our sub-processors operate. Where required, transfers from the EEA, UK, or Brazil rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or equivalent mechanisms made available by the relevant sub-processor.
8. Data Retention
We keep personal data only as long as we need it for the purposes described in this Policy. Specifically:
- Account data is retained while your account is active and for a reasonable period thereafter to handle deletion requests, billing reconciliation, and legal obligations.
- Login and send events are retained for operational and security purposes, typically for up to twenty-four months.
- Unsubscribe records are retained to honour your opt-out and prevent re-subscription against your wishes.
- Backups may persist for a limited period beyond active deletion; deleted records are overwritten in the normal course of backup rotation.
9. Your Rights
Depending on where you live, you may have the right to access, correct, update, port, restrict, or delete your personal data, to object to certain processing, and to withdraw consent. Specifically:
- Access and portability: request a copy of your personal data in a structured, machine-readable format.
- Correction: update your account fields directly from the Basic Settings page, or ask us to correct data you cannot edit yourself.
- Deletion: request deletion of your account and associated data. You can unsubscribe from the newsletter via the link at the bottom of every email.
- Objection and restriction: object to processing based on legitimate interests, or ask us to restrict processing while a request is evaluated.
- Complaint: lodge a complaint with your local data-protection authority. In Brazil this is the Autoridade Nacional de Proteção de Dados (ANPD); in the EU it is your national supervisory authority; in the UK it is the Information Commissioner’s Office (ICO).
To exercise any of these rights, email privacy@blueem.ai from the address associated with your account. We will respond within the time limits required by applicable law.
10. Security
We use industry-standard technical and organisational measures to protect personal data, including encryption in transit (HTTPS), salted password hashing, restricted administrative access, and auditing of authentication events. No system is perfectly secure; we cannot guarantee absolute security, but we will notify affected users and competent authorities of personal-data breaches as required by applicable law.
11. Children
BlueEM is not directed to children and is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
12. Automated Decision-Making
BlueEM uses automated processing — including AI-assisted ranking, classification, and summarisation — to personalise the news you receive. These processes do not produce legal effects or similarly significant effects on you. You can adjust the inputs to this personalisation at any time from your Preferences page, or contact us to opt out of automated personalisation.
13. Cookies
BlueEM uses a single first-party session cookie to keep you signed in. This cookie is strictly necessary for the service to function and does not require consent under most cookie laws. We do not use advertising, analytics, or cross-site tracking cookies.
14. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will update the “Last updated” date above and, where appropriate, notify you by email or through the service. Your continued use of BlueEM after the changes take effect constitutes acceptance of the updated Policy.
15. Contact
Questions, requests, or complaints about this Policy or our handling of your personal data should be sent to privacy@blueem.ai.