Privacy Policy
Last updated August 19, 2026
Scope
This policy covers the Rail Funding Brief newsletter, public website, and the organization platform (together, the “Services”). It doesn’t cover third-party sites we link to.
What we collect
If you subscribe to the newsletter: your email address, and optionally your name and organization if you provide them; the topics and states you choose to follow; and, through our email delivery provider, whether you opened or clicked an issue, and bounce/complaint status (used only to keep our sending reliable and to honor unsubscribes).
If you subscribe to Rail Funding Brief Premium: the same information as any newsletter subscriber, plus your subscription status, current billing period, and identifiers Stripe assigns to your customer and subscription record. We never receive or store your card number or other payment details — those go directly to Stripe.
If your organization has a platform account: your name and email, your role in the organization, and whatever your organization enters about itself and its projects — including, for organization owners specifically, financial information that’s deliberately restricted to owner-level access within your own organization and never visible to other organizations. Content you or your team draft in the application workspace is stored so you can return to it and so version history works.
Automatically: basic product-usage analytics (pages viewed, features used) and, if something breaks, diagnostic error data. We don’t use session recording or any tool that captures your screen or keystrokes — several platform pages display real financial figures, and that’s deliberately kept away from any tool that could record it.
AI-assisted features
A few features (drafting narrative application sections, checking a draft application for internal consistency) send the relevant text you’ve entered to a third-party AI model provider (Google, via its Gemini API) to generate a draft or a finding. We don’t send this data anywhere for the model to be trained on beyond what our agreement with that provider specifies. Every figure a draft states is mechanically checked against your own data before it’s shown to you.
How we use it
- Send the newsletter and manage your subscription and preferences
- Operate the platform: compute matches, generate gap analysis, reports, and drafts for your organization
- Keep the Services secure and working, and provide support
- Understand aggregate usage so we can improve the product
- Comply with legal obligations
Who we share it with
We use the following service providers to operate the Services. None of them get more of your data than they need to do their specific job:
- Resend — sends newsletter and account-related email
- Supabase — hosts our database
- Vercel — hosts the application
- PostHog — product analytics
- Sentry — error monitoring only; no session replay, no page-content capture
- Google (Gemini API) — powers the AI-assisted drafting and consistency-check features, only when you use them, and the investigations research feature’s web search, for Premium subscribers’ articles
- Stripe — processes payment for Rail Funding Brief Premium; handles your card details directly, we never see or store them
We do not sell your personal information. If we run sponsorships in the newsletter, sponsors receive only aggregated, non-identifying performance statistics about their own placement (for example, how many people opened an issue) — never your individual subscriber data.
Data retention
We keep your information for as long as your subscription or account is active, and afterward for as long as reasonably needed for the purposes described above or as required by law.
Your choices
Every newsletter email includes one-click unsubscribe and preference-management links. For platform accounts, contact us at the address below to request a copy of your data or to have it deleted — this is a manual process today; a self-service version is planned but not yet built, and we’d rather tell you that plainly than imply a button exists that doesn’t.
Security
We use reasonable technical and organizational measures to protect your information, including strict data isolation between organizations at the database level, so one organization’s data is never reachable from another’s account. No method of transmission or storage is perfectly secure, and we can’t guarantee absolute security.
Children's privacy
The Services aren’t directed at children, and we don’t knowingly collect information from anyone under 13.
Changes to this policy
We’ll post updates here with a new “last updated” date, and notify account holders directly of a material change.
Contact
Questions, or a data access/deletion request: hello@railfundingbrief.com.