Privacy Policy
Last updated: July 27, 2026
This Privacy Policy explains what personal data the DeReal website (thedereal.com) collects, why, where it is stored, and the rights you have under the General Data Protection Regulation (GDPR). It describes the specific tools the site uses and nothing more.
1. Who is responsible for your data
DeReal is a pre-incorporation project. It is not a registered company and has no legal entity, registration number, or business address to state here, so we do not invent one. The organisation that will act as the data controller for the personal data described in this policy is [DATA CONTROLLER TO BE CONFIRMED]. Until that entity is confirmed and named here, you can raise any question about your data with the people currently running the project by writing to contact@thedereal.com.
This policy covers the public website at thedereal.com, its newsletter, and its access-request form. It does not cover external websites we link to from our articles, which have their own privacy policies.
2. Newsletter signup
What we collect: your email address, and the date you subscribed.
How it is handled: the subscriber list is held and the newsletter is sent by MailerLite, our email provider. Your browser never contacts MailerLite directly; the site passes only your email address to it through a server-side request. No other field is collected when you sign up.
Purpose: to send you the DeReal email brief that you asked to receive.
Legal basis: your consent (GDPR Article 6(1)(a)), given when you tick the consent box on the form. You can withdraw it at any time through the unsubscribe link in every email, or by contacting us, without affecting processing carried out before you withdrew it.
3. Access requests and the private preview
What you provide: when you submit the access-request form, you give your email address (required) and, if you choose, your name, your company, the role you select (investor, press, partner, or other), and a short free-text note.
What is recorded with it: alongside your submission the site stores the page that referred you, any campaign parameters (UTM tags) present in the link you followed, your browser's user-agent string, and a one-way cryptographic hash of your IP address. We do not store your IP address itself. The hash exists only to rate-limit repeated submissions and to protect the form against abuse.
Where it is stored: in our database, hosted on Supabase in the European Union.
Purpose: to receive and review your request, decide whether to grant access to the private preview, keep a record of that decision, and keep the form secure.
Legal basis: our legitimate interests (GDPR Article 6(1)(f)) in assessing and responding to access requests and in protecting the service. Providing the optional fields is entirely your choice.
If your request is approved: we create a time-limited access record for your email, and you receive a one-time sign-in link by email, sent through our authentication provider, Supabase. Signing in sets a single strictly necessary cookie (named dr_session) that keeps you signed in to the preview; it holds your email address and an expiry time and nothing more. We also keep a short log of access events, such as a request being submitted, approved, or rejected, and the preview being opened, linked to your email, so that we can run and secure the preview.
4. Messages you send us
What we collect: if you email us, we receive your email address and whatever you write to us.
Purpose: to read your message, reply, and keep a reasonable record of the exchange.
Legal basis: our legitimate interests (GDPR Article 6(1)(f)) in responding to you.
5. Website analytics
What we collect: aggregate, non-identifying measurements of how the site is used, such as which pages are viewed, the referring source, an approximate country, and the type of device and browser.
How it works: analytics are provided by Plausible, a privacy-focused, EU-hosted tool that the site serves from its own domain. Plausible sets no cookies, stores no IP address, and creates no identifier that follows you between websites or from one day to the next. It therefore collects no personal data and needs no cookie consent banner. Analytics are not loaded on the private founder and preview areas of the site.
Purpose: to understand, in aggregate, how the site is used so we can improve it.
Legal basis: our legitimate interests (GDPR Article 6(1)(f)) in measuring and improving the site without tracking you personally.
6. Cookies
The public website sets no cookies, and the analytics described above are cookieless. The only cookie the site uses is a single strictly necessary session cookie (dr_session), set after you sign in to the private preview. It keeps you signed in and expires after a limited time or when you sign out.
Because the site uses no advertising, profiling, or other non-essential cookies, there is no cookie consent banner. You can still block or delete cookies in your browser; doing so would sign you out of the private preview.
7. Service providers we use
We rely on a small set of providers, each acting as a processor on our instructions and only as far as needed to run the site:
- Supabase (European Union region): the database that stores access requests and access records, and the authentication service that issues sign-in links.
- MailerLite: holds the newsletter subscriber list and delivers the newsletter.
- Resend: sends operational email. In practice, when a new access request arrives, Resend delivers a notification of it to our own contact address so we can review the request.
- Plausible Analytics (EU-hosted): cookieless, aggregate website analytics.
- Netlify: hosts and serves the website, runs its serverless functions, and processes the technical request logs needed to deliver the site reliably and securely.
We do not sell your personal data, and we do not use it for advertising or for automated decisions that produce legal or similarly significant effects about you.
8. Where your data is stored, and international transfers
We keep personal data in the European Union wherever we can. Access-request data is stored on Supabase in the EU, and website analytics are EU-hosted. Some providers, or their sub-processors, may process limited data outside the European Economic Area, for example our transactional email provider and, for technical logs, our hosting provider. Where that happens, the transfer is covered by appropriate safeguards under the GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision, so that your data keeps an equivalent level of protection. You can ask us for more detail about the safeguards that apply.
9. How long we keep your data
We keep personal data only for as long as it is needed for the purpose it was collected for.
- Newsletter data is kept for as long as you stay subscribed. When you unsubscribe, your address is removed, apart from the minimal record an email provider keeps to make sure you are not contacted again.
- Access-request data, access records, and access-event logs are kept for the period needed to run and secure the preview and to keep a reasonable audit record: [RETENTION TO CONFIRM].
- Messages you send us are kept for as long as needed to handle them and keep a record: [RETENTION TO CONFIRM].
- Analytics are aggregate only and are retained for a limited period: [RETENTION TO CONFIRM].
When personal data is no longer needed, we delete or anonymise it.
10. Your rights under the GDPR
In relation to your personal data, you have the right to:
- Access: confirm whether we hold data about you and obtain a copy.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure: have your data deleted where there is no continuing need to keep it.
- Restriction: limit how we process your data in certain circumstances.
- Objection: object to processing based on our legitimate interests.
- Portability: receive certain data in a structured, commonly used, machine-readable format.
- Withdraw consent: withdraw your newsletter consent at any time, including through the unsubscribe link in every email.
To exercise any of these rights, contact us at contact@thedereal.com. We will respond within the time limits set by the GDPR. You also have the right to complain to your local data protection supervisory authority if you believe your data has not been handled in line with the law.
11. Children and special category data
The site is meant for a professional, adult audience. We do not knowingly collect personal data from children, and we do not knowingly collect special categories of personal data.
12. Changes to this policy
We may update this policy to reflect changes in the site, the tools it uses, or the law. When we do, we will change the date at the top of this page. Please check back from time to time.
13. Contact
For any question about this policy or about how your personal data is handled, or to exercise your rights, contact us at contact@thedereal.com.