The Mobile Takeaway

Privacy

Last updated 13 August 2026.

This is the whole policy. The product collects an email address and a language, and it does not want anything else.

Who runs this

The Mobile Takeaway is run by one person, from Spain. For anything on this page, write to [email protected]. For anything else, [email protected].

What is stored

Your email address, so the brief can be sent to it.

The language you chose, so you get the right version.

The IP address and the time at which you clicked the confirmation link. That pair is the record that you asked for this, and it is the only reason it is kept.

A signup source tag, when the link you arrived through carried one. It says which post brought you, never who you are.

One row per issue sent to you: which issue, when, whether the mail provider accepted it, and the identifier it returned.

The delivery outcome of each message — delivered, delayed, bounced or reported as spam — is kept for 90 days. Each record holds the outcome and a one-way keyed hash of your address, not the address.

Counts of what the system did — a signup, a confirmation, a send, an unsubscribe — each tagged with the same one-way keyed hash so the steps can be joined without naming you. The hash cannot be reversed without a key that exists only on the server, and nobody outside the project holds it.

What is not stored

No open tracking pixel is embedded in any email, and no link in an issue is rewritten to count clicks. The send table has a column reserved for open times; nothing writes to it.

This site loads no analytics script, no font, and no image from anyone else. Nothing runs in your browser to watch you, and no cookie is set. The counts described above are recorded by the server, from what it did, and never carry your address.

There is no account, no password, and no profile. Your address is never sold, rented, or shared for marketing.

Anti-spam

The signup form sets no cookies and loads no scripts. It is protected by a hidden field that only automated submissions fill in, and by a limit on how many signups one connection may make.

Why it is allowed

The emails are sent on your consent, given by clicking the confirmation link (GDPR Article 6(1)(a)). You can withdraw it at any moment by unsubscribing.

The consent record and the delivery log are kept on legitimate interest: proving a subscription was asked for, and being able to tell whether mail is arriving. The notice that tells the operator you confirmed rests on the same basis.

Who else handles it

Cloudflare, Inc. — DNS, the proxy in front of this site, and the service that delivers the email. Your address passes through it to reach you, and it is also stored there: one copy of the nightly database backup is kept in Cloudflare R2.

Hetzner Online GmbH — the server and the database, in Germany, and a second copy of the nightly backup on Hetzner Storage Box.

Backblaze, Inc. — a third copy of the nightly backup. Three providers, because a backup that lives with the thing it is backing up is not a backup.

Google — the Gemini API writes and translates the issue. It receives article text only. No subscriber address, language, or IP is ever sent to it.

fk-ops — a private analytics service run by the same person, on separate hardware, which stores the counts described above. It receives the one-way hash, never the address.

Telegram — the operator keeps a private channel there. When you confirm your subscription, your email address is sent to that channel through the fk-ops relay, along with the language you chose and the signup source tag, so he knows who has subscribed. Nothing else about you is sent there, and your confirmation and unsubscribe links never are.

How long it is kept

Until you unsubscribe. Unsubscribing deletes the row immediately, along with the delivery history attached to it.

A signup that is never confirmed is deleted once its confirmation link expires, 48 hours after it was issued.

A database backup is taken every night. Seven daily copies are kept, four weekly and three monthly, so a deleted address can survive in a backup for up to three months before it is gone everywhere. On request, the counts tagged with your hash are deleted too.

Your rights

Under the GDPR you have rights of access, correction, erasure, portability and objection. To use any of them, write to [email protected] from the address you signed up with.

Erasure needs no email at all: the unsubscribe link at the bottom of every issue deletes the record on the spot.

If the answer does not satisfy you, you can complain to your national data protection authority.

Security

The site is served over HTTPS. Confirmation and unsubscribe links are 256-bit random tokens. Email addresses and tokens are stripped from application logs before they are written.

Changes

If this policy changes, the date at the top changes with it. A change that affects what is collected will be announced in an issue before it takes effect.

Contact

[email protected]
[email protected]