Privacy Policy
Effective: 2026-05-17 · Last updated: 2026-07-24
This policy explains what personal information consalsa.app ("we", "our", "us", "the Site") collects, why we collect it, how long we keep it, who we share it with, and your rights over it. It is written in plain English but addresses the requirements of the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA") and other US state privacy laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, and similar), as well as the EU and UK GDPR for visitors from those jurisdictions.
consalsa.app is operated by a United States company (Data Sauna LLC), and all personal information is stored and processed in the United States. We therefore apply US federal and state privacy law as our baseline framework, and the rights and disclosures below are written with that in mind first. We also extend the core privacy rights to visitors from the EU, the UK, Mexico, and elsewhere — those provisions are flagged where they apply. If you are outside the United States, by using the Site you understand that your information is transferred to and processed in the US.
This site is designed for adults, not children. The content covers colloquial and sometimes adult Mexican Spanish slang, and the Site is intended for users who are at least 18 years old. See Section 9 for details.
1. Who we are (data controller / business)
consalsa.app is operated by Data Sauna LLC, a single-member limited liability company formed in the State of Wyoming, United States, with a registered office at 30 N Gould St, Ste R, Sheridan, WY 82801, USA. For the purposes of this policy, Data Sauna LLC is the "business" under CCPA/CPRA and the "data controller" under GDPR and UK GDPR. The easiest way to reach us about anything in this policy is to email hola@consalsa.app.
2. Notice at collection: what we collect and why
We try to collect as little as possible. The full inventory, mapped to the CCPA's enumerated categories of personal information:
Newsletter signup
CCPA category: identifiers (email address, IP address) and internet/network activity (signup source page).
- Email address — stored lowercased so we can send you the daily word.
- Signup source — the page you signed up from (homepage, a specific word page, a blog post). Used internally to see which placements actually convert.
- IP address — captured at the moment of signup. Used to rate-limit the form (maximum 6 signups per IP per hour) and to detect abuse. We don't use it to profile you or look up your location.
- Timestamp — when the row was created (proof of consent and an audit trail).
Purpose of processing: sending the newsletter you signed up for and preventing abuse of the signup form. Retention: see Section 6. Legal basis for EU / UK visitors (GDPR Art. 6): your consent under Art. 6(1)(a) for sending the newsletter, and our legitimate interest under Art. 6(1)(f) in keeping the signup form free from spam and abuse.
Analytics and advertising
CCPA category: internet/network activity (pages viewed, referrer, device), and online identifiers — the ad-serving cookies Google AdSense may set for every visitor, and, only if you accept cookies, the analytics and advertising cookies set by Google Analytics, Microsoft Clarity, and the Meta Pixel. The cookieless tools (Vercel Analytics, Cloudflare Web Analytics, and Google Analytics before you accept) are aggregated and not linked to you.
We use two cookieless, privacy-friendly tools — Vercel Analytics and Cloudflare Web Analytics — that run for every visitor. They record page views, referrer, country, device type, and browser, but set no cookies, write no localStorage, and store no personal identifier (IP, user ID) in a way that can be linked back to you. We use them to understand aggregate traffic patterns. Legal basis for EU / UK visitors: legitimate interest under Art. 6(1)(f) GDPR.
We also use Google Analytics 4. It runs for every visitor, but by default (before you accept cookies) it operates in a cookieless "consent denied" mode under Google Consent Mode — no cookies and no persistent identifier, only anonymized aggregated pings. It sets cookies and enables full measurement only after you accept. If you accept, we also load Microsoft Clarity (heatmaps and session replay, with text you type masked) and may load the Meta (Facebook) Pixel for campaign measurement and targeting; these do not load unless you accept. See our Cookie Policy for the full breakdown. Legal basis for EU / UK visitors: your consent under Art. 6(1)(a) GDPR for the cookie-based tools; legitimate interest under Art. 6(1)(f) for the cookieless GA4 pings. You can withdraw consent at any time.
Advertising (Google AdSense)
Display ads on this site are served by
Google AdSense,
which pays for running the site, so its script loads for every visitor, before and
regardless of your cookie choice. Until you accept, we ask Google for
non-personalized ads — selected from general context such as the
page and approximate location rather than a profile of your browsing history — and
Google's Consent Mode v2 signals for ad storage, ad user data, and ad
personalization are set to denied. Non-personalized still involves storage:
Google may set cookies on consalsa.app (for example __gads and
__gpi) and on its own domains, and read device storage, for frequency
capping, ad measurement, and invalid-traffic detection. Accepting cookies upgrades
AdSense to personalized ads from your next page view; rejecting keeps them
non-personalized.
Google requires AdSense publishers to state the following, so to put it plainly: third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website or to other websites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to this site and/or other sites on the internet. You can opt out of personalized advertising by visiting Google Ads Settings (My Ad Center), and you can opt out of some third-party vendors' use of cookies for personalized advertising at aboutads.info/choices, or at youronlinechoices.eu in Europe. Opting out this way stops the personalization, not the ads themselves.
Visitors in the EEA, the UK, and Switzerland see an additional consent message from Google before any ad personalization. Google requires a certified consent management platform in those regions, and we use Google's own, which records your choice under the IAB Transparency and Consent Framework (TCF v2.2). Our own cookie banner stays hidden there, so you get one prompt rather than two, and we read that same TCF signal to decide whether to run Google Analytics' cookie-based mode, Microsoft Clarity, and the Meta Pixel. In those regions Google's message is the consent record for everything on this page, not only for ads. An honest note on the limits: the AdSense script still runs before you make a choice, and ad serving involves device storage even in non-personalized mode, so a strict reading of the ePrivacy rules would require consent for that as well. See the Cookie Policy for how to block ad-related storage entirely.
Server logs
CCPA category: identifiers (IP), internet activity (URLs, user-agent).
Like any website, our host (Vercel) generates short-lived server logs that include request IP, user-agent, timestamp, and the URL requested. These are used for delivery, performance debugging, and abuse prevention, and are retained according to Vercel's standard log retention. Legal basis for EU / UK visitors: legitimate interest in operating and securing the Site.
"Cookies" notice
Google AdSense aside — it can set ad-serving cookies on this domain for every
visitor, as described above — the Site sets no tracking cookies unless you accept
non-essential cookies. The only other client-side storage used by default is a small
set of first-party values in your browser's localStorage:
-
cookie-consent— stores whether you accepted or rejected non-essential cookies (grantedordenied). -
cs_popup_shown_at— a timestamp so the newsletter signup popup doesn't show again for 30 days after you've seen it. -
cs_subscribed— set after a successful newsletter signup so we stop showing you the signup popup on future visits.
None of these contain personal information — they are short strings, timestamps, or
boolean flags. The two cs_* entries are written whether or not you
accept cookies: they are what stops the newsletter popup showing again, so they
have to work for someone who declined. The popup itself is our own — it sets no
cookie and loads nothing from a third party — and it never opens over a consent
prompt. If you accept, additional third-party cookies from
Google Analytics, Microsoft Clarity, and the Meta Pixel may be set — see our
cookie policy for the full breakdown, legal basis, and how to
clear them.
3. Sale and sharing of personal information
We do not sell personal information for money, and we do not disclose your email address or the content of messages you send us to anyone for their own marketing. Advertising works differently: if you accept cookies, personalized advertising through Google AdSense — and the Meta (Facebook) Pixel, where we run it — involves disclosing online identifiers and browsing activity to those companies, and under the CCPA/CPRA that likely qualifies as a "sale" and/or "sharing" for cross-context behavioral advertising. You can opt out at any time using the "Cookie settings" link in the footer to reject cookies. We also treat a Global Privacy Control (GPC) signal from your browser as a valid opt-out that overrides a stored Accept: when GPC is present we keep advertising non-personalized and do not load the consent-gated tools, on every page load, without you having to do anything else.
If you do not accept, ads stay non-personalized: Google still receives your IP address, user agent, and the page you are viewing in order to serve and measure an ad and detect invalid traffic, but that data is not used to build cross-context advertising profiles with our authorization, and we do not otherwise sell or share your information.
We do not knowingly sell or share the personal information of consumers under 16 (or under any other age that may apply under state law).
4. How we use your information
- To send you the daily newsletter you signed up for.
- To rate-limit signups and prevent spam and abuse.
- To understand, in aggregate, how the Site is used and improve it.
- To serve and measure the display ads that pay for the Site — non-personalized by default, personalized only if you accept cookies.
- To respond to your requests (e.g. unsubscribe, deletion).
- To comply with applicable law and protect our legal rights.
We do not use your personal information for automated decision- making or profiling that would produce legal or similarly significant effects on you (GDPR Art. 22). We do not process "sensitive personal information" as that term is used under the CPRA.
5. Who we share information with (service providers)
We rely on a small set of vendors ("service providers" under CCPA/CPRA; "processors" under GDPR) that process information on our behalf, under contract. Each only sees what it needs to do its job.
- Vercel Inc. (United States) — hosting and serverless functions that run the signup endpoint. Sees: requests to the Site, server logs. Vercel privacy policy.
- Vercel Analytics (Vercel Inc., United States) — cookieless, aggregate analytics. Runs for all visitors.
- Cloudflare (Cloudflare, Inc., United States) — Cloudflare Web Analytics, cookieless aggregate traffic measurement. Runs for all visitors, sets no cookies and no identifier. Cloudflare privacy policy.
- Google (Google Ireland Ltd.) — Google Analytics 4, aggregate traffic measurement. Runs for all visitors in a cookieless "consent denied" mode by default; sets analytics cookies only if you accept. Google privacy policy.
- Google (Google Ireland Ltd.) — Google AdSense, the display advertising that funds the Site. Runs for all visitors; ads are non-personalized until you accept cookies. Sees: your IP address, user agent, the page you are viewing, and its own ad-serving cookies. How Google uses cookies in advertising.
- Microsoft (Microsoft Corp.) — Microsoft Clarity, aggregate heatmaps and session replay (typed text masked). Loads only if you accept cookies. Microsoft privacy statement.
- Meta (Meta Platforms Ireland Ltd.) — Meta / Facebook Pixel, campaign measurement and audience building. Loads only if you accept cookies. Meta privacy policy.
- Supabase Inc. (United States; database hosted in our chosen region) — Postgres database that stores newsletter signups. Sees: your email, signup source, and IP as described above. Supabase privacy policy.
- Resend, Inc. (United States) — transactional email provider that delivers the daily newsletter. Sees: your email address and the content of messages sent to you. Resend privacy policy.
We don't add or change vendors casually. If we do, we'll update this list and the "Last updated" date at the top.
6. International data transfers and retention
Our service providers are based in the United States. When personal information is transferred from the EEA, UK, or Switzerland to the US, we rely on appropriate safeguards under GDPR Art. 46 — typically the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and/or the EU–US Data Privacy Framework where the provider is certified. Each provider's privacy page (linked above) describes the transfer mechanism they offer.
How long we keep things:
- Newsletter subscription record (email, source, IP, timestamp) — kept while you are subscribed. If you unsubscribe, we keep a minimal suppression record (your email, hashed where feasible) so we don't accidentally re-add you. If you request full deletion, the record is removed entirely.
- Cookieless analytics aggregates (Vercel Analytics, Cloudflare Web Analytics) — retained per each provider's standard retention; anonymized at collection and not linked to you.
- Consent-based analytics and advertising cookies (Google Analytics, Microsoft Clarity, Meta Pixel, set only if you accept) — retained for the individual cookie lifetimes listed in our Cookie Policy.
- Ad-serving cookies (Google AdSense, set for every visitor,
including in non-personalized mode) — retained for the lifetimes Google sets,
typically up to ~13 months for the first-party
__gadsand__gpicookies. Listed in our Cookie Policy. - Server logs — short-lived, retained per Vercel's standard log-retention windows.
7. Your rights
You have rights over the personal information we hold about you. We honor these rights for everyone, regardless of jurisdiction:
- Right to know / access — request a copy of, or details about, the personal information we hold about you.
- Right to correct / rectify — ask us to correct inaccurate information.
- Right to delete / erasure — ask us to delete your information.
- Right to portability — ask for your information in a structured, machine-readable format.
- Right to opt out of sale or sharing — we don't sell your personal information for money. If you accept cookies, personalized advertising through Google AdSense and our use of the Meta Pixel may qualify as a "sale" and/or "sharing" for cross-context behavioral advertising; you can opt out at any time via the "Cookie settings" footer link or by submitting a Global Privacy Control (GPC) signal, which we honor and which overrides a stored Accept.
- Right to limit use of sensitive personal information — we don't process it; this right is non-applicable here.
- Right to non-discrimination — we will not penalize you for exercising any privacy right.
- For EU/UK visitors: the rights to restriction, objection, and to withdraw consent at any time (with no effect on the lawfulness of past processing).
To exercise any of these, email hola@consalsa.app from the address subscribed (or otherwise reasonably identify yourself). We aim to respond within 45 days (CCPA/CPRA) or 30 days (GDPR/UK GDPR). You may also designate an authorized agent to make a request on your behalf in accordance with applicable law. You can unsubscribe from the newsletter at any time using the link in any email we send.
8. Right to lodge a complaint
If you believe we've mishandled your personal information, you can lodge a complaint with the relevant authority:
- California residents — California Privacy Protection Agency at cppa.ca.gov, or the California Attorney General at oag.ca.gov.
- Other US state residents — your state Attorney General.
- EEA residents — your local Data Protection Authority. A list is maintained by the European Data Protection Board at edpb.europa.eu.
- UK residents — the Information Commissioner's Office at ico.org.uk.
We'd appreciate the chance to address concerns directly first, but you're under no obligation to come to us before contacting an authority.
9. Children
The Site is designed for adults, not children. It is intended for users who are at least 18 years old, and we do not knowingly collect personal information from anyone under 18. The newsletter is not directed at children, and we comply with the Children's Online Privacy Protection Act (COPPA) by not knowingly collecting personal information from children under 13 in the United States, and with applicable digital-consent rules in other jurisdictions. If you believe a minor has provided us with personal information, contact us and we will delete it.
This applies to advertising too. Because the Site is a general-audience site for adults, it is not tagged as child-directed in Google AdSense, and Google's ad serving here is not subject to the restricted, child-directed treatment. We do not knowingly serve personalized ads to anyone we know to be under 16, and we do not knowingly sell or share their personal information for advertising.
10. Security
Information is transmitted over HTTPS. Newsletter records are stored in our service provider's database (Postgres on Supabase) with access restricted to authenticated server requests. No system is perfectly secure, but we take reasonable steps to protect the small amount of information we hold. If we ever experience a security incident that affects your personal information, we will notify you and any relevant authority where required by law.
11. About AI-assisted content
We use AI tools to draft and research the words, examples, and blog posts on the Site. All content is fact-checked and edited by a human before publication. AI is not used to make decisions about you, to profile you, or to process your personal information — it is used to help write the content you read on the Site.
12. Changes to this policy
We may update this policy from time to time. Material changes will be reflected in the "Effective" and "Last updated" dates at the top, and significant changes will be flagged in the newsletter. Continued use of the Site after changes take effect means you accept the updated policy.
13. Contact
Questions, requests, or complaints? Email hola@consalsa.app, reply to any newsletter email, or use the contact page.