Privacy Policy

Effective: 2026-05-17 · Last updated: 2026-07-24

This policy explains what personal information consalsa.app ("we", "our", "us", "the Site") collects, why we collect it, how long we keep it, who we share it with, and your rights over it. It is written in plain English but addresses the requirements of the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA") and other US state privacy laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, and similar), as well as the EU and UK GDPR for visitors from those jurisdictions.

consalsa.app is operated by a United States company (Data Sauna LLC), and all personal information is stored and processed in the United States. We therefore apply US federal and state privacy law as our baseline framework, and the rights and disclosures below are written with that in mind first. We also extend the core privacy rights to visitors from the EU, the UK, Mexico, and elsewhere — those provisions are flagged where they apply. If you are outside the United States, by using the Site you understand that your information is transferred to and processed in the US.

This site is designed for adults, not children. The content covers colloquial and sometimes adult Mexican Spanish slang, and the Site is intended for users who are at least 18 years old. See Section 9 for details.

1. Who we are (data controller / business)

consalsa.app is operated by Data Sauna LLC, a single-member limited liability company formed in the State of Wyoming, United States, with a registered office at 30 N Gould St, Ste R, Sheridan, WY 82801, USA. For the purposes of this policy, Data Sauna LLC is the "business" under CCPA/CPRA and the "data controller" under GDPR and UK GDPR. The easiest way to reach us about anything in this policy is to email hola@consalsa.app.

2. Notice at collection: what we collect and why

We try to collect as little as possible. The full inventory, mapped to the CCPA's enumerated categories of personal information:

Newsletter signup

CCPA category: identifiers (email address, IP address) and internet/network activity (signup source page).

Purpose of processing: sending the newsletter you signed up for and preventing abuse of the signup form. Retention: see Section 6. Legal basis for EU / UK visitors (GDPR Art. 6): your consent under Art. 6(1)(a) for sending the newsletter, and our legitimate interest under Art. 6(1)(f) in keeping the signup form free from spam and abuse.

Analytics and advertising

CCPA category: internet/network activity (pages viewed, referrer, device), and online identifiers — the ad-serving cookies Google AdSense may set for every visitor, and, only if you accept cookies, the analytics and advertising cookies set by Google Analytics, Microsoft Clarity, and the Meta Pixel. The cookieless tools (Vercel Analytics, Cloudflare Web Analytics, and Google Analytics before you accept) are aggregated and not linked to you.

We use two cookieless, privacy-friendly tools — Vercel Analytics and Cloudflare Web Analytics — that run for every visitor. They record page views, referrer, country, device type, and browser, but set no cookies, write no localStorage, and store no personal identifier (IP, user ID) in a way that can be linked back to you. We use them to understand aggregate traffic patterns. Legal basis for EU / UK visitors: legitimate interest under Art. 6(1)(f) GDPR.

We also use Google Analytics 4. It runs for every visitor, but by default (before you accept cookies) it operates in a cookieless "consent denied" mode under Google Consent Mode — no cookies and no persistent identifier, only anonymized aggregated pings. It sets cookies and enables full measurement only after you accept. If you accept, we also load Microsoft Clarity (heatmaps and session replay, with text you type masked) and may load the Meta (Facebook) Pixel for campaign measurement and targeting; these do not load unless you accept. See our Cookie Policy for the full breakdown. Legal basis for EU / UK visitors: your consent under Art. 6(1)(a) GDPR for the cookie-based tools; legitimate interest under Art. 6(1)(f) for the cookieless GA4 pings. You can withdraw consent at any time.

Advertising (Google AdSense)

Display ads on this site are served by Google AdSense, which pays for running the site, so its script loads for every visitor, before and regardless of your cookie choice. Until you accept, we ask Google for non-personalized ads — selected from general context such as the page and approximate location rather than a profile of your browsing history — and Google's Consent Mode v2 signals for ad storage, ad user data, and ad personalization are set to denied. Non-personalized still involves storage: Google may set cookies on consalsa.app (for example __gads and __gpi) and on its own domains, and read device storage, for frequency capping, ad measurement, and invalid-traffic detection. Accepting cookies upgrades AdSense to personalized ads from your next page view; rejecting keeps them non-personalized.

Google requires AdSense publishers to state the following, so to put it plainly: third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website or to other websites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to this site and/or other sites on the internet. You can opt out of personalized advertising by visiting Google Ads Settings (My Ad Center), and you can opt out of some third-party vendors' use of cookies for personalized advertising at aboutads.info/choices, or at youronlinechoices.eu in Europe. Opting out this way stops the personalization, not the ads themselves.

Visitors in the EEA, the UK, and Switzerland see an additional consent message from Google before any ad personalization. Google requires a certified consent management platform in those regions, and we use Google's own, which records your choice under the IAB Transparency and Consent Framework (TCF v2.2). Our own cookie banner stays hidden there, so you get one prompt rather than two, and we read that same TCF signal to decide whether to run Google Analytics' cookie-based mode, Microsoft Clarity, and the Meta Pixel. In those regions Google's message is the consent record for everything on this page, not only for ads. An honest note on the limits: the AdSense script still runs before you make a choice, and ad serving involves device storage even in non-personalized mode, so a strict reading of the ePrivacy rules would require consent for that as well. See the Cookie Policy for how to block ad-related storage entirely.

Server logs

CCPA category: identifiers (IP), internet activity (URLs, user-agent).

Like any website, our host (Vercel) generates short-lived server logs that include request IP, user-agent, timestamp, and the URL requested. These are used for delivery, performance debugging, and abuse prevention, and are retained according to Vercel's standard log retention. Legal basis for EU / UK visitors: legitimate interest in operating and securing the Site.

"Cookies" notice

Google AdSense aside — it can set ad-serving cookies on this domain for every visitor, as described above — the Site sets no tracking cookies unless you accept non-essential cookies. The only other client-side storage used by default is a small set of first-party values in your browser's localStorage:

None of these contain personal information — they are short strings, timestamps, or boolean flags. The two cs_* entries are written whether or not you accept cookies: they are what stops the newsletter popup showing again, so they have to work for someone who declined. The popup itself is our own — it sets no cookie and loads nothing from a third party — and it never opens over a consent prompt. If you accept, additional third-party cookies from Google Analytics, Microsoft Clarity, and the Meta Pixel may be set — see our cookie policy for the full breakdown, legal basis, and how to clear them.

3. Sale and sharing of personal information

We do not sell personal information for money, and we do not disclose your email address or the content of messages you send us to anyone for their own marketing. Advertising works differently: if you accept cookies, personalized advertising through Google AdSense — and the Meta (Facebook) Pixel, where we run it — involves disclosing online identifiers and browsing activity to those companies, and under the CCPA/CPRA that likely qualifies as a "sale" and/or "sharing" for cross-context behavioral advertising. You can opt out at any time using the "Cookie settings" link in the footer to reject cookies. We also treat a Global Privacy Control (GPC) signal from your browser as a valid opt-out that overrides a stored Accept: when GPC is present we keep advertising non-personalized and do not load the consent-gated tools, on every page load, without you having to do anything else.

If you do not accept, ads stay non-personalized: Google still receives your IP address, user agent, and the page you are viewing in order to serve and measure an ad and detect invalid traffic, but that data is not used to build cross-context advertising profiles with our authorization, and we do not otherwise sell or share your information.

We do not knowingly sell or share the personal information of consumers under 16 (or under any other age that may apply under state law).

4. How we use your information

We do not use your personal information for automated decision- making or profiling that would produce legal or similarly significant effects on you (GDPR Art. 22). We do not process "sensitive personal information" as that term is used under the CPRA.

5. Who we share information with (service providers)

We rely on a small set of vendors ("service providers" under CCPA/CPRA; "processors" under GDPR) that process information on our behalf, under contract. Each only sees what it needs to do its job.

We don't add or change vendors casually. If we do, we'll update this list and the "Last updated" date at the top.

6. International data transfers and retention

Our service providers are based in the United States. When personal information is transferred from the EEA, UK, or Switzerland to the US, we rely on appropriate safeguards under GDPR Art. 46 — typically the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and/or the EU–US Data Privacy Framework where the provider is certified. Each provider's privacy page (linked above) describes the transfer mechanism they offer.

How long we keep things:

7. Your rights

You have rights over the personal information we hold about you. We honor these rights for everyone, regardless of jurisdiction:

To exercise any of these, email hola@consalsa.app from the address subscribed (or otherwise reasonably identify yourself). We aim to respond within 45 days (CCPA/CPRA) or 30 days (GDPR/UK GDPR). You may also designate an authorized agent to make a request on your behalf in accordance with applicable law. You can unsubscribe from the newsletter at any time using the link in any email we send.

8. Right to lodge a complaint

If you believe we've mishandled your personal information, you can lodge a complaint with the relevant authority:

We'd appreciate the chance to address concerns directly first, but you're under no obligation to come to us before contacting an authority.

9. Children

The Site is designed for adults, not children. It is intended for users who are at least 18 years old, and we do not knowingly collect personal information from anyone under 18. The newsletter is not directed at children, and we comply with the Children's Online Privacy Protection Act (COPPA) by not knowingly collecting personal information from children under 13 in the United States, and with applicable digital-consent rules in other jurisdictions. If you believe a minor has provided us with personal information, contact us and we will delete it.

This applies to advertising too. Because the Site is a general-audience site for adults, it is not tagged as child-directed in Google AdSense, and Google's ad serving here is not subject to the restricted, child-directed treatment. We do not knowingly serve personalized ads to anyone we know to be under 16, and we do not knowingly sell or share their personal information for advertising.

10. Security

Information is transmitted over HTTPS. Newsletter records are stored in our service provider's database (Postgres on Supabase) with access restricted to authenticated server requests. No system is perfectly secure, but we take reasonable steps to protect the small amount of information we hold. If we ever experience a security incident that affects your personal information, we will notify you and any relevant authority where required by law.

11. About AI-assisted content

We use AI tools to draft and research the words, examples, and blog posts on the Site. All content is fact-checked and edited by a human before publication. AI is not used to make decisions about you, to profile you, or to process your personal information — it is used to help write the content you read on the Site.

12. Changes to this policy

We may update this policy from time to time. Material changes will be reflected in the "Effective" and "Last updated" dates at the top, and significant changes will be flagged in the newsletter. Continued use of the Site after changes take effect means you accept the updated policy.

13. Contact

Questions, requests, or complaints? Email hola@consalsa.app, reply to any newsletter email, or use the contact page.