DeReal

Privacy Policy

Last updated: July 27, 2026

This Privacy Policy explains what personal data the DeReal website (thedereal.com) collects, why, where it is stored, and the rights you have under the General Data Protection Regulation (GDPR). It describes the specific tools the site uses and nothing more.

1. Who is responsible for your data

DeReal is a pre-incorporation project. It is not a registered company and has no legal entity, registration number, or business address to state here, so we do not invent one. The organisation that will act as the data controller for the personal data described in this policy is [DATA CONTROLLER TO BE CONFIRMED]. Until that entity is confirmed and named here, you can raise any question about your data with the people currently running the project by writing to contact@thedereal.com.

This policy covers the public website at thedereal.com, its newsletter, and its access-request form. It does not cover external websites we link to from our articles, which have their own privacy policies.

2. Newsletter signup

What we collect: your email address, and the date you subscribed.

How it is handled: the subscriber list is held and the newsletter is sent by MailerLite, our email provider. Your browser never contacts MailerLite directly; the site passes only your email address to it through a server-side request. No other field is collected when you sign up.

Purpose: to send you the DeReal email brief that you asked to receive.

Legal basis: your consent (GDPR Article 6(1)(a)), given when you tick the consent box on the form. You can withdraw it at any time through the unsubscribe link in every email, or by contacting us, without affecting processing carried out before you withdrew it.

3. Access requests and the private preview

What you provide: when you submit the access-request form, you give your email address (required) and, if you choose, your name, your company, the role you select (investor, press, partner, or other), and a short free-text note.

What is recorded with it: alongside your submission the site stores the page that referred you, any campaign parameters (UTM tags) present in the link you followed, your browser's user-agent string, and a one-way cryptographic hash of your IP address. We do not store your IP address itself. The hash exists only to rate-limit repeated submissions and to protect the form against abuse.

Where it is stored: in our database, hosted on Supabase in the European Union.

Purpose: to receive and review your request, decide whether to grant access to the private preview, keep a record of that decision, and keep the form secure.

Legal basis: our legitimate interests (GDPR Article 6(1)(f)) in assessing and responding to access requests and in protecting the service. Providing the optional fields is entirely your choice.

If your request is approved: we create a time-limited access record for your email, and you receive a one-time sign-in link by email, sent through our authentication provider, Supabase. Signing in sets a single strictly necessary cookie (named dr_session) that keeps you signed in to the preview; it holds your email address and an expiry time and nothing more. We also keep a short log of access events, such as a request being submitted, approved, or rejected, and the preview being opened, linked to your email, so that we can run and secure the preview.

4. Messages you send us

What we collect: if you email us, we receive your email address and whatever you write to us.

Purpose: to read your message, reply, and keep a reasonable record of the exchange.

Legal basis: our legitimate interests (GDPR Article 6(1)(f)) in responding to you.

5. Website analytics

What we collect: aggregate, non-identifying measurements of how the site is used, such as which pages are viewed, the referring source, an approximate country, and the type of device and browser.

How it works: analytics are provided by Plausible, a privacy-focused, EU-hosted tool that the site serves from its own domain. Plausible sets no cookies, stores no IP address, and creates no identifier that follows you between websites or from one day to the next. It therefore collects no personal data and needs no cookie consent banner. Analytics are not loaded on the private founder and preview areas of the site.

Purpose: to understand, in aggregate, how the site is used so we can improve it.

Legal basis: our legitimate interests (GDPR Article 6(1)(f)) in measuring and improving the site without tracking you personally.

6. Cookies

The public website sets no cookies, and the analytics described above are cookieless. The only cookie the site uses is a single strictly necessary session cookie (dr_session), set after you sign in to the private preview. It keeps you signed in and expires after a limited time or when you sign out.

Because the site uses no advertising, profiling, or other non-essential cookies, there is no cookie consent banner. You can still block or delete cookies in your browser; doing so would sign you out of the private preview.

7. Service providers we use

We rely on a small set of providers, each acting as a processor on our instructions and only as far as needed to run the site:

We do not sell your personal data, and we do not use it for advertising or for automated decisions that produce legal or similarly significant effects about you.

8. Where your data is stored, and international transfers

We keep personal data in the European Union wherever we can. Access-request data is stored on Supabase in the EU, and website analytics are EU-hosted. Some providers, or their sub-processors, may process limited data outside the European Economic Area, for example our transactional email provider and, for technical logs, our hosting provider. Where that happens, the transfer is covered by appropriate safeguards under the GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision, so that your data keeps an equivalent level of protection. You can ask us for more detail about the safeguards that apply.

9. How long we keep your data

We keep personal data only for as long as it is needed for the purpose it was collected for.

When personal data is no longer needed, we delete or anonymise it.

10. Your rights under the GDPR

In relation to your personal data, you have the right to:

To exercise any of these rights, contact us at contact@thedereal.com. We will respond within the time limits set by the GDPR. You also have the right to complain to your local data protection supervisory authority if you believe your data has not been handled in line with the law.

11. Children and special category data

The site is meant for a professional, adult audience. We do not knowingly collect personal data from children, and we do not knowingly collect special categories of personal data.

12. Changes to this policy

We may update this policy to reflect changes in the site, the tools it uses, or the law. When we do, we will change the date at the top of this page. Please check back from time to time.

13. Contact

For any question about this policy or about how your personal data is handled, or to exercise your rights, contact us at contact@thedereal.com.