What we hold, what we have promised, and what we do not have yet.
This page is about this website and the company behind it. Both apps are still in development and will publish their own privacy policies before they ship. Where something is not true yet, it says so.
Which pages get read, if you accept analytics — and a message, if you write to us.
No third-party request until you accept one, on servers in the Netherlands.
One person, one registration, one address. The registration and the address are in the imprint; the name goes there before launch.
We hold two things about you, and only if you choose them: which pages get read, if you accept analytics, and a message, if you write to us. That is the whole list, and the privacy policy carries it in full — what is stored, where, and for how long.
The analytics is Google Analytics 4, and it loads only after you accept it. We say the name because you would find it anyway.
Read the privacy policy →Five things we've tied our hands on.
No ads, no data sales — structurally
The apps are meant to be paid for by the people who use them, so there is no advertising business here to feed and nothing to sell. Neither app will carry an advertising SDK.
Why it holds: the money comes from people who buy the apps, so there is no advertising business to feed.
Delete now, or with 7 days to undo
In both apps you choose how your account is deleted: at once, or after a 7-day grace period in which you can still undo it.
Built in Readinity, which has not launched yet; planned for Cyberinity from its launch (Q4 2026). Checkable at each app's first release.
If we are acquired, you are told first
Any change of control triggers a notice before the transfer completes, with export and deletion available until then. Your data is not part of the sale by default.
A sole proprietorship cannot be bought the way a company can — but if the business changes hands, the notice comes first.
No fear tier
Bad news is never gated behind an upgrade. If we detect something, you see it in full on the plan you already have.
Nothing is sold yet, so there is no tier to gate anything behind. Stated now so it can be held against us later.
Breakage over silence
If a source or a feature stops being trustworthy, we say so in the changelog and pull it — as we did with the daily reminders.
The record so far: the changelog was emptied and three false claims removed from this site in one day, and each removal is written down.
Preparedness for the physical world: what your household depends on, and what to do when it stops working.
Your digital exposure: what the internet already holds about you, and what is worth doing about it.
Readinity and Cyberinity are in development, and how they handle data is still changing. Rather than publish a summary that is out of date in a fortnight, each will publish its own privacy policy at its own address before it ships — and this page will link to them.
Everything above is easier to believe next to this list.
No independent audit. Nobody outside has reviewed the code or the infrastructure.
No open source. Every repository is private, including this website.
No bug bounty. We offer credit for a report, not money, and we say so rather than implying otherwise.
No app you can install. Neither product has shipped, and the waitlist stores nothing.
The apps are not local-first. They are being built around a server.
One person, not a team. Self-funded, no investors, nobody to answer to except the people who pay for the apps.
Which rules apply, and where we stand.
Not a badge, and not legal advice: the list we work from, with the status we would have to defend. Where a row says less than “met”, it says what is missing and when it is due.
This is our reading of what applies to this website and this company; each app carries its own. If you think a row is wrong, the contact form reaches a person.
AI drafts and translates; a person decides what is published. English and Dutch are read by a person before they go out. Every other language is machine-translated from that reviewed version and checked by machine. The label that says so on the article itself is not built yet — it comes with the content system. Until then, this page is the only place it is stated.
Not yet: every article will carry a Content Credential — a signature saying what was published and when. It arrives with the first signed article, and it is worth knowing that a credential can be stripped by a careless re-save: it proves what is there, not what is missing.
There are no accounts yet, so today there is nothing to delete or export. Before launch we intend deletion that takes effect at once or after a 7-day grace period you can undo, an export you can run yourself, and a notice period before any shutdown. Until export is built, we answer a portability request by hand, which is your right either way.
The site is built to WCAG 2.2 AA: visible focus, targets of at least 24 pixels, a reduced-motion guard, a skip link, and text that carries its own direction. As a microenterprise we are exempt from the European Accessibility Act; we build to it anyway.
Phones get a menu, and inner pages reflow to one column on small screens. What is still true: nobody has opened this site with a screen reader or a switch device. Built to WCAG 2.2 AA means built to it — not tested against it by anyone who depends on it.
Pages, not PDFs — a page cannot go stale where nobody sees it.
Found something? Write to the address below. We acknowledge within 3 working days and send a status update within 10; the fix date is agreed with you rather than promised in advance. Good-faith research that does not degrade the service or touch other people’s data is welcome — we will not pursue you for it. We credit you when the issue is published, unless you would rather we did not. There is no bug bounty and no money.
Once an app ships, an actively exploited vulnerability goes to ENISA and the Dutch CSIRT within 24 hours. That is a duty under the Cyber Resilience Act, not a favour, and it applies to the apps and the servers behind them.
admin@novelapproaches.nl