Privacy Policy

Covering newscatcherapi.com, the News API, CatchAll, and NewsMCP

Effective date: September 2, 2026. This Policy supersedes all prior versions of NewsCatcher's privacy policy, including the version last updated September 21, 2020.

Scope

This Privacy Policy (“Policy”) applies to: (i) our corporate website at newscatcherapi.com; (ii) the CatchAll Web Search API and its platform; (iii) the News API and its associated documentation, dashboards, and platform; and (iv) NewsMCP, including newsmcp.com, its platform, and its API endpoints (together, the “Services”), each operated by NewsCatcher, Inc. (“NewsCatcher,” “we,” “us,” or “our”).

Where we act as a data processor or service provider on behalf of a business customer — for example, when a customer's application submits search queries, or when a customer's own end-user data passes through our API — our processing of that data is governed by our Data Processing Addendum and our agreement with that customer, not by this Policy. This Policy governs our processing of personal information as a controller: information about visitors to our sites, prospective and current customers and their authorized users, job applicants, and other individuals who contact us directly.

Your Agreement to This Policy

By using any of the Services, you agree to the collection, use, and disclosure of information as described in this Policy. Where applicable law requires your specific consent for a particular processing activity — for example, non-essential cookies or certain marketing communications — we will ask for that consent separately, and using the Services on their own will not be treated as consent to that specific activity.

Information We Collect

Information you provide to us

  • Contact and account information: name, work email address, company name, job title, and password (stored as a salted hash), when you create an account, request a demo, or contact sales or support.
  • Billing information: billing name, billing address, and payment details, collected on our behalf by Stripe, our payment processor. We do not store full card numbers on our own systems. Subscription and usage data (plan, usage records, and associated contact details) is managed on our behalf by GetLago.
  • Communications: anything you send us through contact forms, email, or chat.

Information collected automatically

  • Log data: IP address, browser type and version, pages visited, referring page, and timestamps (see Log Data below).
  • Cookies and similar technologies (see Cookies below).
  • API usage data: for the News API, CatchAll, and NewsMCP, we record the API keys used, endpoints called, request counts, response times, and error rates, to enforce rate limits and quotas and to bill usage-based plans.

Content processed through the APIs

  • Search queries and Query Data: text submitted to CatchAll, the News API, or NewsMCP (for example, a company name, topic, or natural-language question). These fields are not intended for submitting personal information about third parties, and customers should not submit sensitive personal data (health information, financial account numbers, government IDs, etc.) as query input.
  • News content: articles, headlines, and metadata returned by our APIs are sourced from publicly available news publishers. This content may itself contain personal information about people named in the news (for example, public figures, executives, or parties in reported legal proceedings). We do not control the content of third-party news articles and are not the original source of that personal information.

Information from other sources

  • If you sign in via Google or another identity provider, we receive the name, email, and profile picture that provider is permitted to share.
  • Publicly available business information (e.g., company name and domain) if you request a demo or trial through a form that performs company lookup or enrichment.

Log Data

We collect information that your browser or application sends whenever you visit our website or call our APIs ("Log Data"). This Log Data may include your computer's Internet Protocol ("IP") address, browser type and version, the pages or endpoints you access, the time and date of access, the time spent, and other statistics. This applies equally to log data generated by calls to our APIs (the News API, CatchAll, and NewsMCP), not only to visits to our marketing website.

Cookies

Cookies are small files, which may include an anonymous unique identifier, that a website sends to your browser and stores on your device. We use cookies to collect information about how the Services are used. We categorize cookies as essential, functional, statistics/analytics, and marketing, and only load non-essential cookies after you have made a choice through our cookie consent banner. You can view the full, up-to-date list of individual cookies and services we use, their category, and their purpose at any time via the cookie consent tool on this site.

Where required by law (including in the EEA and UK), we obtain your consent before setting non-essential cookies, and you may withdraw or change that consent at any time using the privacy settings control available on the site. You can also instruct your browser to refuse cookies; if you do, some portions of the Services may not work as intended.

How We Use Information

We use personal information to: provide, operate, and secure the Services; create and manage accounts, API keys, and billing; respond to inquiries and provide customer support; send administrative and, where you've agreed, marketing communications; monitor, analyze, and improve the Services, including through aggregate usage analytics; enforce rate limits, quotas, and our Terms of Service; detect, prevent, and investigate fraud, abuse, and security incidents; and comply with our legal obligations.

Disclosure of Information

We may share personal information with:

  • Sub-processors who support the Services, currently including:
  • Xero (New Zealand / Global) — cloud-based accounting and financial management software.
  • Mercury (USA) — banking and financial services platform.
  • Salesforce (USA / Global) — customer relationship management (CRM) and sales platform.
  • Amazon Web Services (AWS) (Global) — cloud hosting and infrastructure services.
  • GetLago (USA) — SaaS subscription management platform; stores subscription and usage data (customer name, email, plan, and usage records) for billing purposes.
  • Stripe (USA / Global) — payment processing; handles and stores payment card details on our behalf.
  • Pylon (USA) — customer support platform.
  • Our affiliates, for internal administrative purposes.
  • Professional advisors (lawyers, auditors, accountants), where necessary to obtain their advice.
  • A buyer or successor in the event of a merger, acquisition, financing, or sale of assets, subject to standard confidentiality commitments.
  • Law enforcement, regulators, or other parties, where we believe disclosure is required by law, to protect our rights or the safety of others, or to investigate fraud or security incidents.
  • With your consent, or at your direction.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.

Data Retention

We retain personal information for as long as necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Account information (held in our databases and in internal tools such as Notion and Salesforce) is retained for as long as your account remains active; contact name and email address may be retained longer to maintain our business records. Closing your account does not automatically delete this information; we retain it as part of our business records unless you specifically request deletion (see Your Privacy Rights above) or as part of periodic internal data-minimization reviews. Billing records are retained for approximately seven years, consistent with applicable U.S. tax and accounting record-keeping practice. Server logs are retained for 7 days and then automatically deleted. API logs are retained in their original form for 90 days, after which they are archived into compressed files; these archives are kept indefinitely, and are deleted only as part of occasional storage-management cleanups or when storage capacity requires it. Rate-limiting counters (for example, NewsMCP's keyless tier) expire automatically within minutes to hours.

International Data Transfers

NewsCatcher is a U.S. company, and personal information we collect is generally processed in the United States. If you are located outside the United States, your information will be transferred to, stored, and processed in the United States and potentially other countries. Where required, we rely on appropriate safeguards for these transfers, such as the European Commission's Standard Contractual Clauses or equivalent mechanisms recognized under UK and Swiss law.

Your Privacy Rights (EEA, UK, and Switzerland)

Subject to applicable law, you have the right to: request access to, and a copy of, the personal information we hold about you; request correction of inaccurate information; request deletion of your information; object to or request that we restrict certain processing; request a portable copy of information you provided to us; and withdraw consent at any time where processing is based on consent. To exercise these rights, contact us at team@newscatcherapi.com. We will not discriminate against you for exercising these rights. If you are in the EEA, UK, or Switzerland, you also have the right to lodge a complaint with your local data protection authority.

California and Other U.S. State Privacy Rights

If you are a California resident, the CCPA (as amended by the CPRA) gives you the right to know the categories and specific pieces of personal information we have collected about you, the right to delete personal information, the right to correct inaccurate personal information, and the right to opt out of the sale or sharing of personal information. As stated above, we do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of in that respect. To exercise your CCPA rights, contact us at team@newscatcherapi.com. We will verify requests using information associated with your account or, if you have no account, by matching the details you provide against what we hold. If you are a resident of Nevada, Virginia, Colorado, Connecticut, Utah, or another state with a comprehensive privacy law, you may have similar rights, and we will honor valid requests consistent with applicable law.

Do Not Track

Our Services do not currently respond to 'Do Not Track' browser signals.

The News API, CatchAll, and NewsMCP use natural language processing, entity resolution, and related machine-learning techniques to enrich, classify, deduplicate, and cluster publicly available news content. We do not use the contents of customer accounts (billing information, account credentials) to train models. Where we use aggregated or de-identified query or usage patterns to improve the accuracy or performance of the Services, we do so only in de-identified or aggregated form, or as otherwise permitted under your customer agreement. We do not make decisions producing legal or similarly significant effects about individuals using solely automated means.

Security

The security of your personal information is important to us, but no method of transmission over the Internet or method of electronic storage is 100% secure. While we use commercially reasonable means to protect personal information, we cannot guarantee its absolute security. We maintain administrative, technical, and physical safeguards designed to protect personal information, consistent with our SOC 2 Type II report and other certifications referenced on our Security & Compliance page, details of which are available under NDA on request. In the event of a security incident affecting your personal information, we will notify affected individuals and/or customers, and relevant authorities, as required by applicable law.

Children's Privacy

Our Services are not directed to children under 13 (or under 16 in the EEA and UK, where GDPR sets a higher default age of consent for information-society services), and we do not knowingly collect personal information from them. If you are a parent or guardian and believe your child has provided us with personal information, please contact us. If we learn we have collected personal information from a child below the applicable age, we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. For material changes — for example, a new category of information collected, a new purpose of use, or a new category of third party we share information with — we will provide additional notice, such as a notice on this page, an email to account holders, or an in-product notice, before the change takes effect. You are advised to review this Policy periodically; changes are effective when posted on this page unless stated otherwise.

Contact

If you have any questions about this Privacy Policy, please contact us at team@newscatcherapi.com. By post: NewsCatcher, Inc., 1321 Upland Drive, PMB 17947 Houston, TX 77043, United States.

Secure strategic advantage with real-world signals for your teams and models

What you don't know can hurt you. Let's change that.

Book a Demo