Sign in
Topical header

Privacy & Cookies Policy

Effective Date: 15 November 2025 (Updated for Slack)

1. Introduction

Topical (“we”, “us”, “our”) is committed to protecting your privacy and handling personal data in compliance with the UK GDPR and EU GDPR. This Privacy & Cookies Policy explains what information we collect, how we use it, how long we retain it, and your rights.


2. Information We Collect

2.1 Account Information

  • Name
  • Email address
  • Authentication information (managed by our identity provider)

We use AWS Cognito to manage authentication.
If you sign up with email and password, Cognito handles all password storage and verification on our behalf — Topical does not receive or store your password. If you sign in using Google or Slack, no password is created.

2.2 Integration Information

If you connect third-party services (e.g., Slack, Mailchimp, YouTube), we collect:

  • OAuth tokens
  • Workspace/team identifiers
  • Channel IDs (Slack)
  • Integration configuration settings

We only access the scopes you grant during installation.

2.3 Newsletter & Workflow Content

We store the newsletter issues, drafts, sources, and settings you create in Topical.

2.4 Analytics & Tracking Information

We use:

  • Google Analytics
  • Sentry (error monitoring)
  • Facebook/Meta Pixel
  • Twitter/X Pixel
  • Reddit Pixel

These services may collect:

  • IP address
  • Device identifiers
  • Browser information
  • Pages visited
  • Actions taken
  • Referrer URLs

Tracking pixels are used to measure advertising performance and improve our marketing.

2.5 Cookies

We use essential cookies for authentication and session management, and optional analytics/advertising cookies where consented.

2.6 Billing Information

Payments are processed by Stripe. We never store your full card details on our servers.

2.7 AI Processing

When you use Topical’s AI features, newsletter text or metadata may be processed by third-party AI providers (e.g., OpenAI, Anthropic) strictly for the purpose of generating or editing content. We do not allow these providers to train their models on your data.


3. How We Use Your Information

We use your information to:

  • Provide and operate the Topical service
  • Generate newsletters and workflow outputs
  • Connect to integrations such as Slack
  • Send important service notifications
  • Analyse usage to improve the product
  • Diagnose technical issues (via Sentry)
  • Measure advertising performance (via pixels)
  • Comply with legal obligations

4. Legal Basis for Processing (GDPR)

We process personal data under the following legal bases:

  • Performance of a contract: Account operation, service delivery
  • Legitimate interest: Analytics, product improvement, security
  • Consent: Advertising cookies and tracking pixels
  • Legal obligation: Tax and financial recordkeeping

5. Retention of Personal Data

We retain personal data only as long as necessary for the purposes outlined above:

  • Account data: While your account is active and up to 12 months after closure
  • Newsletter content & workflows: Until you delete them, or up to 30 days after account deletion
  • Integration tokens (Slack, Mailchimp, etc.): Deleted within 24 hours of disconnecting
  • Error logs (Sentry): Up to 90 days
  • Analytics data: Up to 26 months
  • Billing records: Minimum 6 years (legal requirement)
  • Backups: Automatically overwritten within 90 days

You may request earlier deletion where legally permitted. To request removal of your data, contact: support@usetopical.com


6. Sharing Your Information

We only share data with trusted sub-processors necessary to operate the service:

  • AWS – hosting and storage
  • Stripe – billing
  • Google Analytics – analytics
  • Sentry (Functional Software Inc.) – error monitoring
  • Facebook/Meta, Twitter/X, Reddit – advertising performance tracking
  • OpenAI / Google (LLM providers) – content generation
  • Slack Technologies LLC – if you connect your Slack workspace

We do not sell your personal data.


7. International Data Transfers

Many of our service providers are located outside the UK/EU, including in the United States. Where data is transferred internationally, we rely on:

  • Standard Contractual Clauses (SCCs)
  • UK Addendum (for UK GDPR)

to ensure an adequate level of protection.


8. Your Rights (GDPR)

You have the right to:

  • Access your data
  • Correct inaccurate data
  • Delete your data
  • Restrict or object to processing
  • Port your data
  • Withdraw cookie/marketing consent at any time

To exercise these rights, contact: support@usetopical.com


9. User Responsibility

Users must not store sensitive categories of data (e.g., health, political, financial details) inside Topical. We are not responsible for sensitive data entered contrary to our guidance.


10. Cookies Policy

We use:

  • Essential cookies – required for login and security
  • Analytics cookies – performance measuring
  • Advertising cookies/pixels – only with consent

You can manage cookie preferences via your browser or our cookie banner.


11. Changes to This Policy

We may update this policy occasionally. Changes will be posted on this page with an updated effective date.


12. Contact Us

For all questions including GDPR requests: support@usetopical.com