Privacy
Privacy Policy
The Lede is built to need as little of your data as possible. This page explains exactly what that means.
Last updated: August 27, 2026
The short version.
- There is no account — no name or password to create, and the app never asks for your email. Joining our launch mailing list on this website is the one optional exception (see below).
- Your saved articles and highlights live in your own iCloud, not on our servers. We never receive your library.
- To write a brief, the article's title and text are sent to our AI provider (Anthropic). The article's web address goes too when you ask for a "Dig Deeper," or when the piece is opinion or commentary. Our contract bars model training on your text, and we don't keep the text.
- We collect a small amount of usage data — keyed to a random per-device identifier, never your name — to run the service and set fair pricing.
- No ads. No third-party trackers. We never sell your data.
What we don't collect
The app has no sign-up. We do not collect your name, phone number, password, precise location, contacts, photos, or any advertising identifier. The app contains no third-party advertising or analytics SDKs and no cross-app trackers. The one piece of contact information we ever collect is an email address — and only if you choose to give it to us on this website to be notified when The Lede opens to everyone (see The launch mailing list below). The app itself never asks for it.
Your article library stays in your iCloud
The articles you save, their briefs, your highlights, and your reading history are stored in your private iCloud account (Apple CloudKit) and synced across your devices by Apple. We do not store, copy, or have access to your library. We keep no list of the specific articles you read. For a saved story, our usage records hold the publisher's domain and a one-way keyed fingerprint of the web address, never the address itself and never the article's text. The full detail is under "Usage data" below. If you delete the app and remove its iCloud data, that content is gone.
What happens when you save an article
When you save an article, the app sends its web address, headline, and extracted text to our server so we can produce the brief. From there:
- The article's title and text are sent to our AI provider (Anthropic) to generate the brief. The article's web address is sent to Anthropic as well in two cases: when you ask for a "Dig Deeper," so the desk can research the piece, and when the piece is opinion or commentary, where the brief is written from the reporting the address points to. Our contract bars model training on your text. Anthropic deletes the text within 30 days, unless it flags a piece for safety review or the law requires a longer hold.
- For some stories we run a web search (via Tavily or Exa) using the headline to gather additional context.
- We never store the article's full text. We keep a short, one-way fingerprint (a hash) of the text, which can't be turned back into the article, so that an identical article isn't re-processed, alongside the brief we generated, in a temporary cache that automatically deletes itself (within 14 days for a brief, 7 days for a "Dig Deeper," 48 hours for redirected sources). And for sources your device can't read on its own, the server returns that same extracted text to your device so your copy saves alongside the brief — it passes through to you but is never stored on our servers; your saved copy lives only in your own iCloud.
- We keep a hash of the web address, not the address itself, so an identical article isn't re-processed. That cache entry has no name, no device identifier, and no account attached to it, and it deletes itself on the schedule above. The raw web address is never kept in our databases. It only passes briefly through our host's operational logs (see below).
To be plain about it: what we keep is a hash of the web address, not the address. We never store the article's text on our own servers. Our contract bars model training on your text, and Anthropic deletes the text within 30 days, unless it flags a piece for safety review or the law requires a longer hold. We don't keep the raw web address at all. Apart from the two cases above, where it goes to Anthropic, it appears only briefly in our hosting provider's operational logs, which we use to keep the service running.
Notifications and your device
To deliver "Dig Deeper" results, your device registers with our server using a random identifier we generate (never your Apple device's hardware ID) and an Apple push token. A device secret is stored only as a one-way hash. Push notifications are scoped so a result is only ever delivered to the device that requested it.
Usage data
We record a small amount of first-party usage data. It is pseudonymous: keyed to a random per-device identifier and to an opaque iCloud account identifier from Apple, never your name, your email, or your device's hardware ID. Because those identifiers are stable (the iCloud one persists even if you reinstall the app), Apple's App Store privacy label now counts this data as linked to you. We still never attach your name, and we never sell it. We use it to operate the service, watch for abuse and runaway costs, improve the app, and set fair pricing. This includes:
- Service events — such as "a brief was generated," the AI token and cost counts, the publication's domain, and a keyed fingerprint of the article address: a one-way code we can't turn back into the web address without a secret we hold.
- In-app usage & funnel events — such as which features you use, how far you get in onboarding, that a brief was opened, when an upgrade screen is shown, and subscription events (for example, a trial starting). These tell us where the app is working and where people get stuck. We log that a brief was opened, the publisher's domain, and the keyed fingerprint of the address. We don't store the addresses themselves, and we keep no list of the specific articles you read. These events are tied to the random identifier we generate for your device and to an opaque iCloud account identifier Apple provides. Neither carries your name or email.
The data stays on our own servers; it is not shared with any third party, used for advertising, or combined with data from other apps or websites. It carries nothing that identifies you by name — no name, email address, or contact details — and we never sell it. The app contains no third-party advertising or analytics SDKs. If you joined our launch mailing list, that email address is stored separately and is never linked to this usage data.
Subscriptions
Subscriptions are processed entirely by Apple through the App Store. We never see your name, card, or payment details. To understand how well the app converts and to set fair pricing, Apple sends our server automatic notifications about subscription lifecycle events — a free trial converting to paid, a renewal, a cancellation, a refund, or a subscription lapsing. We record these as events tied only to the random identifier we generate for your device (never your name or payment information); a random app-account token, set to that same device identifier, lets Apple's notification be matched to your device without identifying you. We retain the Apple-issued transaction identifier for your subscription while it is active and for a limited period afterward, so we can correctly handle refunds, cancellations, and billing disputes that Apple reports to us. We may keep this identifier even if you ask us to delete your usage data, where retaining it is necessary to handle these subscription events — it is an Apple reference that contains no name or payment details.
One more thing about renewals: the app shows every Member an annual renewal notice. If you have ever emailed support@theledeapp.com, we may also send that year's notice to the address you wrote from — a legal notice about your subscription, never marketing. Your address stays in our support mailbox, where your message put it; we don't add it to any database or mailing list.
The launch mailing list
On this website you can ask to be told when The Lede opens to everyone by giving us your email address. This is entirely optional and separate from the app — the app never asks for an email, and you do not need to join the list to use The Lede.
- What we collect: only the email address you type in, plus the date you signed up. Nothing else — no name, and we don’t track whether you open or click our messages.
- Why: to send you a small number of messages about The Lede’s launch — typically a single notification when it’s available. We will not use your address for anything else, or share it, without asking you first.
- Where it’s stored: on our own servers (our database, Neon, and our host, Railway). We do not use a third-party email-marketing or tracking service, and we never sell or rent your address.
- How long: we keep your address until you unsubscribe or ask us to delete it, or until the launch list has served its purpose — whichever comes first.
- Unsubscribe & deletion: every message we send includes a one-click way to unsubscribe, and you can ask us to delete your address at any time by emailing support@theledeapp.com. We honor opt-out requests promptly — always within 10 business days, and in practice much sooner.
By submitting your email you consent to receiving these launch messages. You can withdraw that consent at any time using the unsubscribe link or by emailing us.
Who processes your data
We rely on a small set of service providers, each handling only what's described above: Anthropic (AI briefs), Tavily and Exa (web search context), Apple (iCloud storage, push notifications, and subscriptions), Neon (our database), and Railway (server hosting). We do not sell or rent your information to anyone. Each of these providers acts only on our instructions. We do not share your data with any provider that does not protect it to the same standard this policy sets out. That includes Anthropic: our contract bars model training on your text, limits Anthropic to writing the brief we asked for, and sets the deletion terms described under Data retention below.
Data retention
The temporary AI cache deletes itself on the schedule above. We never store the article's text ourselves. Anthropic deletes the text within 30 days, unless it flags a piece for safety review or the law requires a longer hold. Usage records are retained for up to 13 months and then automatically deleted. Your device registration is kept while the app is installed and registered. Subscription transaction identifiers that Apple reports to us are kept while your subscription is active and for a limited dispute-and-refund period afterward.
Your choices and your rights
Deleting the app removes its local data; removing its iCloud data deletes your library. You can also stop the sending described above at any time:
- Turn the desk off. In the app's own Settings, under Privacy, switch off Sending articles to the desk. From then on, articles you save stay on your phone and land without a brief, and nothing goes to our AI provider. You can switch it back on whenever you like, and the same screen shows the full list of what leaves your phone.
For the pseudonymous usage records on our servers, you can:
- Request deletion — email us and we will delete the usage records associated with your device. (We may retain the Apple transaction identifier tied to an active or recently-ended subscription where doing so is necessary to process refunds, disputes, or required financial records, as described under Subscriptions above.)
- Request a copy — email us and we will provide the usage records we hold for your device.
Because this data is keyed to a random device identifier, we may ask you to make the request from the device so we can locate the right records. Wherever you live, you may ask us about the data we hold and request its deletion. California residents: we do not sell or share your personal information, and you may exercise the access and deletion rights above by contacting us.
Children
The Lede is not directed to children under 13, and we do not knowingly collect information from them.
Changes
If we change this policy we'll update the date above and, for material changes, note it in the app.
Who runs The Lede
The Lede is built and operated by Charles Klein LLC. For any privacy question or request, email support@theledeapp.com.