Status as of June 8, 2026
Compliance & Trust
Where LearnSomethin stands against the standard newsletter compliance checklist. We publish this honestly — including the gaps — because transparency about what we do and don’t do is itself a trust signal.
Roughly 35 of 50 items are solidly in place. The rest break down into 5 items handled manually, a handful of deliberate omissions documented below, and a small list of planned closures we’re working through.
Corporate & Legal
- YesTerms of Service published
- YesPrivacy Policy published
- YesContact email for privacy requests
- N/ALegal entityOperating under the LearnSomethin trade name as a sole proprietor in India. Permissible at this scale; formalize as the project grows.
Subscriber signup
- YesUser actively enters their email
- YesNo pre-checked consent boxes
- YesClear explanation of what you're subscribing to
- YesDouble opt-in confirmation flow
- YesSignup timestamp recorded
- YesConsent version stampingEvery signup and re-opt-in is tagged with the published policy version (currently 2026-06-08) for a defensible audit trail of which terms you accepted.
- YesSource / referrer loggingEach signup records the HTTP referrer (the page you came from, if your browser sent it) and any utm_* campaign tags on the landing URL. Used to understand which channels bring subscribers. Disclosed in the privacy policy.
- PlannedAnti-bot protectionPlanned: Cloudflare Turnstile on the signup form.
- Deliberate omissionIP address (not stored)The checklist suggests recording it; we don't persist it anywhere we control. Data minimization is a feature — the IP isn't needed to deliver the service.
Email sending
- YesUnsubscribe link in every email
- YesUnsubscribe works immediately (RFC 8058 one-click)
- YesSender identity clearly visibleFrom: LearnSomethin <daily@mail.learnsomethin.com>
- YesValid reply-to addresshello@learnsomethin.com — replies reach a real human.
- YesNo purchased or scraped lists
- PlannedPhysical business address in footerActive gap. Required for CAN-SPAM and a recommended Gmail deliverability signal. Will add once a real address is finalized.
Your rights
- YesWithdraw consent at any timeOne-click unsubscribe link in every email.
- PartialDelete your dataEmail hello@learnsomethin.com with subject “delete my data.” We respond within 30 days. A self-service flow is planned.
- PartialExport your dataSame path as deletion — email us and we'll send back a copy of what we hold.
- PartialCorrect your dataSame path as above.
Security
- YesHTTPS everywhere
- YesDatabase access restrictedService-role key only; row-level security enabled with no policies (service-role-only access pattern).
- YesDaily backups, encrypted at restManaged by the database provider on AWS.
- PartialAudit loggingRuntime logs and email-event webhooks flow into operational dashboards. No consolidated audit table yet.
- PlannedMFA on admin accountsNot currently enabled across every vendor account (Vercel, Supabase, AWS, GoDaddy, OpenAI, GitHub). Planned: enable on all six and document in our internal runbook.
- N/AStrong password policyLearnSomethin is passwordless — you sign in by clicking a link in your inbox.
Vendors & data storage
All four sub-processors are disclosed in the privacy policy along with what each one does and where data is stored. Subscriber data lives in AWS us-east-1.
- YesVendor list maintained and publicly disclosed
- YesStorage location documented
- YesCross-border transfer disclosed
- YesData retention policy statedActive subscribers indefinitely while active; unsubscribed addresses retained in suppressed state to prevent accidental re-mailing.
What we're working on
The active gaps above, in rough priority order:
- Physical mailing address in the email footer (blocked on finalizing the address).
- Anti-bot protection on the signup form (Cloudflare Turnstile).
- Documented data subject request runbook plus a self-service export endpoint.
- MFA enabled on every vendor account that touches subscriber data (Vercel, Supabase, AWS, GoDaddy, OpenAI, GitHub).
Spot something we’ve missed? Email hello@learnsomethin.com.