Worse on Purpose is published by Patina Media LLC, a Colorado limited liability company. In this policy, "we" and "us" mean Patina Media LLC. We decide how your information is used, so we are responsible for it.
This policy covers:
the Worse on Purpose newsletter and the emails we send
worseonpurpose.com, including the Community at worseonpurpose.com/community
the Brand Ledger at ledger.worseonpurpose.com
We collect what we need to send the newsletter, run memberships and the Community, and read your tips.
When you subscribe. Your email address. The signup form asks for nothing else. We do record when you signed up and which page or form you used.
When you become a member. Your membership plan, payment status and billing history. Stripe processes the payment and holds your card details. We never see or store your full card number.
When you join the Community. Your profile name and optional photo. Everything you post, comment and react to. Who you follow.
When you send a tip or email us. Whatever you choose to send. The tip form on the Brand Ledger asks for the tip, and optionally your email and the brands involved. Emails to any of our addresses reach our inbox with your address and message.
When you answer a poll or survey. Your answer, linked to your subscription.
When you open our emails. Whether you opened each email and which links you clicked. The section on email tracking explains how.
When you visit our sites. Standard technical data: IP address, browser, device, pages viewed and the site that sent you. Our hosts and Google Analytics collect this.
We use your information to:
send the newsletter and any member emails you signed up for
run memberships: billing, access, receipts and refunds
run the Community and keep it free of spam and abuse
read tips and email, reply, and follow up on leads
see which essays and pages get read, so we know what to work on next
spot readers who have stopped opening emails, so we can stop sending to them
keep our sites and accounts secure
meet our legal and tax obligations
What we don't do:
We don't sell or rent our subscriber list.
We don't sell advertising, so no advertiser receives your data.
We don't give your details to any brand we write about.
A small number of companies run parts of Worse on Purpose for us. They handle your data only to provide their service to us.
| Company | What they do for us | What they handle |
|---|---|---|
| Beehiiv | Newsletter, website, Community, email delivery | Subscriber, member and Community data; site visits |
| Stripe | Membership payments | Payment and billing details |
| Our email inbox, the spreadsheet that stores Ledger tips, and Google Analytics on both sites | Emails you send us, tips, site visit data | |
| Vercel | Hosts the Brand Ledger | Site visit data and server logs |
We also use AI tools to help sort and organize tips sent through the Ledger form.
Beehiiv uses its own providers for security, login and error tracking on worseonpurpose.com. These include Cloudflare, HUMAN Security, Stytch and Sentry.
Newsletters you choose to follow. After you subscribe, we suggest a few other newsletters. If you click Subscribe on one, or Subscribe to all, Beehiiv shares your email with those newsletters so they can sign you up. Some of these recommendations are paid: that newsletter pays us a fee for each new subscriber. Nothing is shared if you click Skip. We only recommend newsletters that we read and find valuable ourselves.
When the law requires it. We may disclose information to comply with a valid legal order, or to protect someone's safety. Where the law allows, we will tell you first.
In our emails. Each email carries a tiny image and tracked links. They tell Beehiiv whether you opened the email and which links you clicked. We use this to see what gets read and to stop emailing people who no longer open. To avoid it, turn off images in your email app. Some apps, like Apple Mail, can hide whether you opened an email.
On worseonpurpose.com. Beehiiv sets cookies to keep you logged in, remember your settings, count visits and block bots. Stripe sets cookies on pages with checkout, to prevent fraud. Google Analytics measures which pages are read. Embedded posts from X or Bluesky load code from those services.
On the Brand Ledger. Google Analytics is the only tracking, and it may set its own cookies. The Ledger has no login.
Tracking across other sites. Google, X and Bluesky may recognize your browser across other websites that use their services. We don't control that. You can block it with your browser's privacy settings or Google's opt-out.
Do Not Track. Our sites don't currently respond to Do Not Track browser signals.
The Community. Other members can see your profile name, photo, posts and comments. Only members can see inside the Community. We moderate it, so we can see everything posted there.
Field reports in the Community help build the Brand Ledger, and we may use what you report there. We will always ask before quoting you directly.
Tips. Tips from the Ledger form go to a private spreadsheet that only we can open. The form does not ask for your name, and your email is optional. Leave it out if you want to stay anonymous. Our host still keeps short-lived server logs, which include IP addresses.
We never publish a source's identity without their permission.
If your tip is sensitive, send it from a personal device and a personal email address, not a work one.
| Data | How long |
|---|---|
| Subscriber details | While you're subscribed. After you unsubscribe, we keep your email on a do-not-send list so you don't hear from us again. |
| Membership and payment records | As long as tax and accounting law requires. |
| Community posts and comments | Until you delete them or ask us to. |
| Tips and emails | As long as they're useful to our reporting, or until you ask us to delete them. |
| Website analytics | Google Analytics keeps detailed visit data for 2 months, and data tied to your browser for 14 months after your last visit. Summary reports that don't identify you are kept longer. |
| Server logs | A few days to a few weeks, set by our hosts. |
Ask us to delete your data at any time. We'll delete it unless the law requires us to keep it, and tell you if that's the case.
These rights apply to every reader, wherever you live.
Unsubscribe with the link at the bottom of any email. It takes effect immediately.
Change your preferences or cancel a membership from My Account on worseonpurpose.com.
See your data. Ask for a copy of what we hold about you.
Correct it. Tell us what's wrong and we'll fix it.
Delete it. Ask us to delete your data, including your Community posts and any tips you sent with your email.
Take it with you. Ask for your data in a file you can use elsewhere.
To ask, email [email protected] with "Privacy request" in the subject line. Send it from the address we have on file, so we know it's you. We'll reply within 30 days.
Using these rights won't change how we treat you. Your membership price and access stay the same.
California readers. We don't share personal information with other companies for their own marketing. The one exception is a newsletter you choose to subscribe to through our recommendations.
We are based in the US, and our providers store data mainly in the US. If you read from the UK or the EU, your data is transferred there. Beehiiv covers these transfers with Standard Contractual Clauses and the UK Addendum in its data processing terms.
UK and EU law asks us to name the legal basis for each use of your data:
| What we do | Legal basis |
|---|---|
| Send the newsletter | Your consent, given when you subscribe |
| Run your membership | Our contract with you |
| Run the Community, read tips, measure readership, keep things secure | Our legitimate interest in running an independent publication |
| Keep payment and tax records | Legal obligation |
You can withdraw consent, object to how we use your data, or ask us to restrict it. You can also complain to your local data protection authority. In the UK, that's the ICO.
Children. Worse on Purpose is not meant for anyone under 16. We don't knowingly collect data from children. If you think a child has signed up, tell us and we'll delete their data.
Security. Only the people who run Worse on Purpose can access subscriber data. Our providers encrypt data in transit. No system is perfectly secure. If a breach affects your data, we'll tell you as the law requires.
Every version of this policy carries a number and a date. Each change is logged below, so you can see what changed and when. If a change affects how we use your data, we'll email subscribers before it takes effect.
| Version | Date | Change |
|---|---|---|
| 1.0 | 9/25/26 | First version |
Email [email protected] with "Privacy" in the subject line.