Novel ApproachesPre-launch
Trust

What we hold, what we have promised, and what we do not have yet.

This page is about this website and the company behind it. Both apps are still in development and will publish their own privacy policies before they ship. Where something is not true yet, it says so.

Website and companyApps publish their own policiesChecked 22 Sep 2026
Two rows of data

Which pages get read, if you accept analytics — and a message, if you write to us.

Nothing loads uninvited

No third-party request until you accept one, on servers in the Netherlands.

A person, not a brand

One person, one registration, one address. The registration and the address are in the imprint; the name goes there before launch.

What we hold

We hold two things about you, and only if you choose them: which pages get read, if you accept analytics, and a message, if you write to us. That is the whole list, and the privacy policy carries it in full — what is stored, where, and for how long.

The analytics is Google Analytics 4, and it loads only after you accept it. We say the name because you would find it anyway.

Read the privacy policy →
Commitments

Five things we've tied our hands on.

01

No ads, no data sales — structurally

The apps are meant to be paid for by the people who use them, so there is no advertising business here to feed and nothing to sell. Neither app will carry an advertising SDK.

Why it holds: the money comes from people who buy the apps, so there is no advertising business to feed.

02

Delete now, or with 7 days to undo

In both apps you choose how your account is deleted: at once, or after a 7-day grace period in which you can still undo it.

Built in Readinity, which has not launched yet; planned for Cyberinity from its launch (Q4 2026). Checkable at each app's first release.

03

If we are acquired, you are told first

Any change of control triggers a notice before the transfer completes, with export and deletion available until then. Your data is not part of the sale by default.

A sole proprietorship cannot be bought the way a company can — but if the business changes hands, the notice comes first.

04

No fear tier

Bad news is never gated behind an upgrade. If we detect something, you see it in full on the plan you already have.

Nothing is sold yet, so there is no tier to gate anything behind. Stated now so it can be held against us later.

05

Breakage over silence

If a source or a feature stops being trustworthy, we say so in the changelog and pull it — as we did with the daily reminders.

The record so far: the changelog was emptied and three false claims removed from this site in one day, and each removal is written down.

The two apps

Readinity and Cyberinity are in development, and how they handle data is still changing. Rather than publish a summary that is out of date in a fortnight, each will publish its own privacy policy at its own address before it ships — and this page will link to them.

What we do not have

Everything above is easier to believe next to this list.

No audit

No independent audit. Nobody outside has reviewed the code or the infrastructure.

Not open source

No open source. Every repository is private, including this website.

No bug bounty

No bug bounty. We offer credit for a report, not money, and we say so rather than implying otherwise.

Nothing shipped

No app you can install. Neither product has shipped, and the waitlist stores nothing.

Not local-first

The apps are not local-first. They are being built around a server.

One person

One person, not a team. Self-funded, no investors, nobody to answer to except the people who pay for the apps.

Legal register

Which rules apply, and where we stand.

Not a badge, and not legal advice: the list we work from, with the status we would have to defend. Where a row says less than “met”, it says what is missing and when it is due.

GDPR2016/679
What it asksA plain notice of what is collected, why, on what ground, and your rights.
MetThe notice is on the privacy page; analytics loads only after you accept it.
ePrivacy / Dutch Telecommunications ActTw 11.7a
What it asksConsent before anything is read from or written to your device.
MetThree named entries, all of them yours, and nothing measured before Accept.
Dutch Civil Code, information dutyBW 3:15d
What it asksWho provides this service, where it is registered, and a second way to reach us.
PartlyAddress, KVK, VAT and the contact form are published. The owner’s name is not — it goes on the imprint before public launch.
AI Act, art. 502024/1689
What it asksSay when text is artificially generated or manipulated, and mark it in a machine-readable format.
PartlyThis site says how articles are drafted and who reviews them. Machine-readable marking ships with the content system.
Cyber Resilience Act2024/2847
What it asksReport an actively exploited vulnerability in 24 hours, 72 hours and 14 days.
Not triggered yetNothing has shipped, so nothing is in scope yet. The disclosure route already exists.
European Accessibility Act2019/882
What it asksConsumer services accessible to EN 301 549, which is WCAG 2.2 AA.
Exempt, built to itA microenterprise service is exempt. Built to it anyway, and the remaining gap is named on this page.
Unfair commercial practicesBW 6:193
What it asksNo claim about a product that is not true.
MetA claim goes on this site with what makes it true, as a dated intention, or not at all. What could not be backed up — placeholder testimonials, prototype posts, features that do not exist — has been taken down.
Copyright in the digital single market, art. 42019/790 art. 4
What it asksA machine-readable reservation if you opt out of text and data mining.
MetNo reservation: text and data mining, AI training included, is allowed (/rights/1). robots.txt, /.well-known/tdmrep.json and a meta tag on every page say so; the IETF Content-Usage line is there too, but it is still a draft.
Digital Services Act · NIS22022/2065 · NIS2
What it asksDuties for intermediaries and for essential entities.
Out of scopeNo intermediary service, no user content, below every size threshold. Said out loud, because silence reads as evasion.

This is our reading of what applies to this website and this company; each app carries its own. If you think a row is wrong, the contact form reaches a person.

How what we publish is made

AI drafts and translates; a person decides what is published. English and Dutch are read by a person before they go out. Every other language is machine-translated from that reviewed version and checked by machine. The label that says so on the article itself is not built yet — it comes with the content system. Until then, this page is the only place it is stated.

Not yet: every article will carry a Content Credential — a signature saying what was published and when. It arrives with the first signed article, and it is worth knowing that a credential can be stripped by a careless re-save: it proves what is there, not what is missing.

If we shut down

There are no accounts yet, so today there is nothing to delete or export. Before launch we intend deletion that takes effect at once or after a 7-day grace period you can undo, an export you can run yourself, and a notice period before any shutdown. Until export is built, we answer a portability request by hand, which is your right either way.

Accessibility

The site is built to WCAG 2.2 AA: visible focus, targets of at least 24 pixels, a reduced-motion guard, a skip link, and text that carries its own direction. As a microenterprise we are exempt from the European Accessibility Act; we build to it anyway.

Phones get a menu, and inner pages reflow to one column on small screens. What is still true: nobody has opened this site with a screen reader or a switch device. Built to WCAG 2.2 AA means built to it — not tested against it by anyone who depends on it.

Policies and documents

Pages, not PDFs — a page cannot go stale where nobody sees it.

Security & disclosure

Found something? Write to the address below. We acknowledge within 3 working days and send a status update within 10; the fix date is agreed with you rather than promised in advance. Good-faith research that does not degrade the service or touch other people’s data is welcome — we will not pursue you for it. We credit you when the issue is published, unless you would rather we did not. There is no bug bounty and no money.

Once an app ships, an actively exploited vulnerability goes to ENISA and the Dutch CSIRT within 24 hours. That is a duty under the Cyber Resilience Act, not a favour, and it applies to the apps and the servers behind them.

admin@novelapproaches.nl