Complete policy
Mosaic News Privacy Policy
Mosaic News is independently operated by Josh Nelson in California, United States. This policy applies to the Mosaic News iPhone app and the public website at mosaicnews.app.
What this policy covers
This policy explains what Mosaic stores on your device, what is processed when the app or website makes a network request, why that processing is necessary, how long information is kept, and the choices available to you.
Mosaic does not require an account and does not ask for your name, email address, phone number, payment information, contacts, precise location, advertising identifier, or access to your photos. If you email Mosaic, the information in that message is handled as described below.
What stays on your device
Mosaic stores the information that makes the app personal in local app storage. This includes your reading history, reading time, Insights events, Feed Formula, topic and publisher choices, article-type preferences, Custom Moods, pinned sections, tutorial progress, and other app settings.
Insights is calculated on your iPhone from that local reading history and activity. Mosaic does not upload the history used to build Insights and has no server-side view of your personal Insights page.
The article reader also keeps local cache information and uses an app-specific website data store so publisher logins and cookies can work. Depending on your iPhone backup settings, Apple may include app data in a device backup. Mosaic cannot access or control your Apple backups.
Personalized feeds and search requests
To build your feed, the app sends Mosaic’s API the active formula weights, topic and publisher preferences, article-type preferences, Custom Topic identifiers, blocked domains, active Mood, and pinned-section choices needed for that request. These settings are processed to rank and compose the response. They are not saved as a Mosaic account or persistent user profile.
When you search in Discovery, the search term and current settings needed to choose personalized results are sent to the API. Mosaic processes the query to return results and does not add it to a personal search history.
Like any internet request, these calls carry ordinary technical information, including an IP address, timestamp, requested route, and short-lived request identifiers. Mosaic uses this information to deliver the response, diagnose failures, protect the service, and measure system performance. It is not used to build a record of the articles you read.
A specific exception worth understanding
Custom Topics
When you type a Custom Topic, Mosaic sends the phrase to its API. The phrase is converted into a semantic representation through the OpenAI API and compared with Mosaic’s shared topic taxonomy. If there is no clear match, OpenAI may also help decide whether the phrase should map to an existing topic, create a new recurring topic, or be rejected.
Mosaic keeps an internal audit record containing the phrase, the resolution outcome, similarity information, model identifier, and date. That record is used to review taxonomy quality and safety. It does not include a Mosaic account, name, email address, device identifier, or reading history. A topic created from the phrase becomes part of the shared taxonomy and may be available to other users.
Avoid entering private or sensitive personal information as a Custom Topic. OpenAI states that API content is not used to train its models by default and that API abuse-monitoring logs may be retained for up to 30 days. See OpenAI’s API data controls .
Publisher and external websites
When you open an original article, publisher page, methodology source, or another external destination, your device connects directly to that site. The site receives the information normally sent by a browser, such as your IP address, browser information, cookies, and the page requested. A publisher may use its own analytics, advertising, login, subscription, or tracking tools.
Mosaic does not control those independent websites. Their privacy policies apply to their collection and use of information. Mosaic’s reader blocks some common advertising and tracking resources for performance, but it cannot promise that every publisher tracker is blocked.
The Mosaic website and email
The Mosaic website does not use client-side analytics, advertising pixels, fingerprinting, or nonessential cookies. The website therefore does not show a cookie banner. The hosting provider still receives ordinary network metadata needed to serve and protect the site.
The Contact page opens your email app rather than submitting a hosted form. If you send a message, Mosaic receives the email address, message, attachments, and other information you choose to include. Your email provider and the receiving email provider process that message under their own terms. Correspondence is retained as needed to respond, maintain support records, or meet legal obligations.
Service providers
Mosaic relies on a small number of providers to operate the app and website:
- Railway hosts the public website, API, and database and processes infrastructure and request metadata. Read Railway’s privacy policy.
- OpenAI processes Custom Topic phrases for semantic matching and taxonomy decisions as described above.
- Google Favicon service supplies publisher icons. The iOS app may request an icon directly, which sends the publisher domain plus ordinary network information such as IP address, device/browser information, and request time. The public website instead requests and caches these icons through Mosaic’s server, so website visitors do not connect directly to Google for them. Read Google’s privacy policy.
- Apple and TestFlight distribute the beta and may process installation, diagnostic, account, or store information under your relationship with Apple. Read Apple’s privacy policy.
Mosaic does not authorize these providers to use information received from Mosaic for cross-context behavioral advertising. Providers may process information for security, abuse prevention, legal compliance, and other purposes described in their own terms.
Retention and deletion
- On-device information remains until you remove it through an available app control or delete the app. Deleting Mosaic removes information stored in Mosaic’s local app container from that device. Device backups are controlled through Apple’s backup settings.
- Feed and search request bodies are processed to answer the request and are not written to a Mosaic user profile.
- Infrastructure logs are kept only for operational, security, and troubleshooting needs. Under Mosaic’s current Railway hosting plan, logs available to Mosaic are retained for seven days. A provider may retain limited information longer when required by law or needed to protect its services.
- Custom Topic audit records are retained while needed to maintain, review, and protect the shared taxonomy. Because they are not tied to an account or device identifier, Mosaic may need the exact phrase and an approximate submission date to locate a record for a deletion request.
- Email correspondence is retained while needed to answer the message, preserve relevant support context, or meet legal obligations.
Your choices and privacy requests
You can change or remove preferences, Moods, pinned sections, and Custom Topics in the app. You can stop future network processing by not using the related feature. You can remove Mosaic’s local app data from a device by deleting the app.
Mosaic has no account to close. To ask a privacy question or request access, correction, or deletion of information Mosaic can reasonably identify, email josh@mosaicnews.app. Mosaic may ask for enough information to understand and verify the request, but will not ask for information that is unnecessary to complete it.
The Mosaic website does not track activity over time across unrelated websites, so browser Do Not Track signals do not change its behavior. Independent publisher sites and providers respond to privacy signals under their own policies.
Security, children, international processing, and changes
Security
Mosaic uses HTTPS for network requests, limits the information it asks for, and restricts operational access to the systems that run the service. No method of internet transmission or storage is completely secure, so Mosaic cannot guarantee absolute security.
Children
Mosaic is a general-audience news product and is not directed to children under 13. Mosaic does not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact Mosaic so it can be reviewed and deleted when appropriate.
International processing
Mosaic is operated from the United States. Its providers may process information in the United States and other countries, where privacy laws may differ from those where you live.
Changes to this policy
This policy may change as Mosaic changes. The effective date at the top will be updated whenever the policy changes. Material changes will also be communicated through a prominent website or in-app notice when appropriate. Information will not be repurposed in a materially incompatible way without additional notice or consent when required.
Contact
Mosaic News is independently operated by Josh Nelson in California, United States. Privacy questions and requests can be sent to josh@mosaicnews.app.