FairDinkum News

Privacy Policy

Last updated: 23 September 2026

This policy explains how FairDinkum News handles personal information for readers and Supporters on iOS, Android, and web.

1. Scope and our approach

FairDinkum News operates a news aggregation and media-literacy service. We do not use advertising networks, sell personal information, or use cross-service behavioural advertising.

We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

2. Information we collect

If you create an account, we collect account and profile information such as email address, display name, verification state, accepted legal-document versions, and optional biography, social handle, state or territory, interests, profile photo, and self-assessed political leaning.

Before a new password is submitted to Supabase Auth, the app hashes it on your device and sends only a five-character hash prefix to Have I Been Pwned's Pwned Passwords service. Neither the password nor its complete hash is sent there; the returned padded range is compared on your device to block known compromised passwords.

Political leaning is treated as sensitive political-opinion information. If supplied, it is linked to your account only for app functionality and product personalisation. It is not sold, used for advertising, or included in product analytics.

We may store article identifiers, source and category metadata, meaningful-read timestamps, Saved Stories, Read Later records, tags, settings, accessibility choices, reading goals, notification preferences, community posts, reactions, reports, Civic votes, moderation history, and subscription entitlement state.

After you explicitly enable notifications, we store the device and delivery information needed to provide them. Operational diagnostics are designed to exclude passwords, tokens, request bodies, article text, comments, and other user-submitted content.

3. Analytics and personalisation

Product analytics is off by default and requires opt-in consent. If enabled, it is limited to allowlisted coarse feature outcomes. When first-party article traffic measurement is enabled, we keep anonymous daily counts by public article identifier, headline, publisher, and broad entry screen for article opens and publisher-link handoffs. A handoff does not confirm a completed publisher visit. Revoking consent stops future measurement but cannot subtract a past action from an anonymous daily total. We do not send headlines, article text, article URLs, search terms, comments, chat content, email addresses, political preferences, or reading-history contents to analytics providers, and do not use session replay, touch capture, or automatic interaction capture.

You can revoke analytics consent immediately in Settings. A list of community profiles you block is stored only in an account-scoped area on that device and is not sent to our server.

4. How we use information

We use information to authenticate accounts; synchronise saved reading, history, and settings; provide requested personalisation; operate subscriptions and notifications; moderate community features; prevent abuse; and keep the service reliable.

When you deliberately choose an AI-assisted feature, FairDinkum may send the headline, short publisher preview, source name and source-position context, plus text you deliberately enter, to OpenAI. We do not send passwords, payment-card details, private account settings, complete reading history, private appeals, or unrelated comments for that request.

5. Service providers and overseas processing

Depending on the feature you use, necessary data may be processed by Supabase, Render and managed PostgreSQL, RevenueCat and its web payment provider Stripe, Apple, Expo and Apple Push Notification service, Have I Been Pwned's Pwned Passwords service, OpenAI when you choose an AI-assisted feature, and - only when configured and applicable - Sentry and consent-gated PostHog.

Providers may process information in Australia, Singapore, the United States, the European Union, or other locations described in their current terms. We limit disclosure to the fields needed for the relevant service.

6. Community safety

Community participation requires an account. Published comments show the display name, content, and timestamp, but not the author's email, private reading history, or account settings.

Comments publish under post-moderation after a narrow provider-free safety check. Users can report content and block an author on their device; authorised moderators can hide, restore, or remove content and manage account restrictions with recorded reasons.

7. Storage, security, and retention

Account credentials and sessions are managed by Supabase Auth. Linked app data is stored in managed PostgreSQL when production services are configured. Local offline records remain in the app's sandboxed storage.

We retain information while needed to provide the service, propagate synchronised deletions, resolve billing and disputes, prevent abuse, meet legal duties, and maintain time-limited backups. No storage or transmission method is completely secure.

8. Your choices and rights

You may request access to or correction of personal information, export available saved-reading data, clear local data, and request account deletion. Some moderation, fraud-prevention, billing, legal, and backup records may need to be retained for a limited period or anonymised.

Contact privacy@fairdinkumnews.com.au. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.

9. Children and policy changes

FairDinkum is not directed to children under 13. Users aged 13 to 17 should review this policy with a parent or guardian.

We may update this policy as practices, providers, or legal requirements change. Material changes will be identified in the app or another reasonable notice and the updated date will change.