Newsletter privacy

BaitaPhish Security Weekly is a public, opt-in email newsletter operated by Bryan. For replies, privacy requests, or deletion, contact bryan@baitaphish.com.

We use your email address and consent record to deliver the newsletter through Resend, and AWS to hold subscription and delivery state. We record delivery, bounce, complaint, and unsubscribe events. Open and click tracking are off. We do not join your email identity to website browsing.

Opening an unsubscribe link shows a confirmation page. Confirming it stops future newsletter sends. Email clients may also submit a one-click unsubscribe request. We send no goodbye email.

We keep subscription details while subscribed, minimal consent evidence for up to 12 months after withdrawal, and a minimal address exclusion record to prevent unwanted resubscription. Delivery and authorization linkage is retained for no more than 90 days. Cohort and authorization linkage is removed within 90 days. Webhook deduplication receipts last up to 90 days, and dedicated newsletter worker and suppression logs 14 days. The website retains its existing application logs for 30 days; newsletter tokens, addresses, and message bodies are excluded from those logs. Backups cover seven days; restoration must replay exclusions and deletion records before use.

Resend also processes message bodies and recipient information. Requests concerning provider-held data are handled through the same contact. Public signup requires email confirmation. Pending requests and confirmation links expire after 24 hours. Opening a confirmation link does not subscribe you; selecting Confirm subscription does. We store the confirmation time and consent wording version. Requests are rate-limited to prevent unwanted email.