Privacy Policy
Effective 7 September 2026. Last updated 8 September 2026.
This policy explains what personal information Finnish IRL ("we", "our", "us", "the Site") collects, why we collect it, how long we keep it, who we share it with, and what you can do about it. It is written in plain English, and it is written EEA-first: the Site is aimed at people living in Finland and elsewhere in Europe, so the EU General Data Protection Regulation, the Finnish Data Protection Act and the ePrivacy rules are the baseline. Because the operator is a United States company, the equivalent rights under the UK GDPR and under US state privacy law (California's CCPA as amended by the CPRA, and the Virginia, Colorado, Connecticut, Utah and Texas statutes) are covered as well, and we extend the core rights to everyone regardless of where they live.
Finnish IRL is operated by a United States company and most of our service providers are based there, so personal information is transferred to and processed in the US under the safeguards described in section 6.
The Site is written for adults. It covers real spoken Finnish, including swearing, and it is intended for readers who are at least 18. See section 9.
1. Who we are
Finnish IRL is operated by Data Sauna LLC, a single-member limited liability company formed in the State of Wyoming, United States, with a registered office at 30 N Gould St, Ste R, Sheridan, WY 82801, USA. For the purposes of this policy Data Sauna LLC is the data controller under the GDPR and the UK GDPR, and the business under the CCPA/CPRA. The way to reach us about anything on this page is moi@finnishirl.com.
2. Notice at collection: what we collect and why
We try to collect as little as possible. This is the whole inventory, mapped to the CCPA's categories of personal information.
Newsletter signup
CCPA categories: identifiers (email address, IP address) and internet or network activity (the page you signed up from).
- Email address - stored lowercased, so we can send you the daily word.
- Signup source - which page and which placement you signed up from, for example "word:mid" or "home:grid". It is a short bounded label, never the slug of the word you were reading, and we use it to see which placements actually convert.
- IP address - captured at the moment of signup and used to rate-limit the form and detect abuse. We do not profile you with it and we do not look up your location from it.
- Timestamp - when the record was created, which is our record of consent.
Purpose: sending the newsletter you asked for, and keeping the signup form free of spam. Legal basis for EU and UK visitors: your consent under Art. 6(1)(a) GDPR for the newsletter itself, and our legitimate interest under Art. 6(1)(f) in an abuse-free form for the rate limiting. Retention: section 6.
The list itself lives with Resend, which is both where a subscriber record is stored and the service that delivers the email. We do not keep a second copy of the list anywhere else, we do not sell or rent it, and every email carries a one-click unsubscribe.
Analytics and advertising
CCPA categories: internet or network activity (pages viewed, referrer, device), and online identifiers - the ad-serving cookies Google AdSense may set for every visitor, and, only if you accept cookies, the analytics and advertising cookies set by Google Analytics, Microsoft Clarity and the Meta Pixel. The cookieless tools (Vercel Analytics, Cloudflare Web Analytics, and Google Analytics before you accept) are aggregated and not linked to you.
We use two cookieless, privacy-friendly tools - Vercel Analytics and Cloudflare Web Analytics - that run for every visitor. They record page views, referrer, country, device type and browser, but set no cookies, write no localStorage, and store no personal identifier that can be linked back to you. We use them to understand aggregate traffic. Legal basis for EU and UK visitors: legitimate interest under Art. 6(1)(f) GDPR.
We also use Google Analytics 4. It runs for every visitor, but by default - before you accept cookies - it operates in a cookieless "consent denied" mode under Google Consent Mode v2: no cookies and no persistent identifier, only anonymised aggregated pings. It sets cookies and enables full measurement only after you accept. If you accept, we also load Microsoft Clarity (heatmaps and session replay, with text you type masked) and may load the Meta (Facebook) Pixel for campaign measurement and targeting; neither loads unless you accept. The full breakdown is on the cookie page. Legal basis for EU and UK visitors: your consent under Art. 6(1)(a) GDPR for the cookie-based tools, and legitimate interest under Art. 6(1)(f) for the cookieless GA4 pings. You can withdraw consent at any time.
Advertising (Google AdSense)
Display ads on this site are served by Google AdSense, which is what pays for running it, so its script loads for every visitor, before and regardless of your cookie choice. Until you accept, we ask Google for non-personalized ads - selected from general context such as the page and approximate location rather than a profile of your browsing history - and Google's Consent Mode v2 signals for ad storage, ad user data and ad personalization are set to denied. Non-personalized still involves storage: Google may set cookies on finnishirl.com and on its own domains, and read device storage, for frequency capping, ad measurement and invalid-traffic detection. Accepting cookies upgrades AdSense to personalized ads from your next page view; rejecting keeps them non-personalized.
Google requires AdSense publishers to state the following, so to put it plainly: third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website or to other websites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to this site and other sites on the internet. You can opt out of personalized advertising at Google's My Ad Center, and out of many third-party vendors' use of cookies for personalized advertising at youronlinechoices.eu in Europe or aboutads.info/choices elsewhere. Opting out this way stops the personalization, not the ads themselves.
Almost everyone reading this site is in scope for Google's own consent message. Google requires a certified consent management platform before any ad personalization in the EEA, the UK and Switzerland, and we use Google's own. Because this site is written for people in Finland, that message - not our banner - is the consent record for most of our readers. It records your choice under the IAB Transparency and Consent Framework (TCF v2.2), our own banner stays hidden so you get one prompt rather than two, and we read that same signal to decide whether to run Google Analytics' cookie-based mode, Microsoft Clarity and the Meta Pixel. An honest note on the limits: the AdSense script still runs before you make a choice, and ad serving involves device storage even in non-personalized mode, so a strict reading of the ePrivacy rules would require consent for that as well. The cookie page says how to block ad-related storage entirely.
Server logs
CCPA categories: identifiers (IP), internet activity (URLs, user-agent).
Like any website, our host (Vercel) generates short-lived server logs containing the request IP, user agent, timestamp and the URL requested. They are used for delivery, performance debugging and abuse prevention, and retained under Vercel's standard log retention. Legal basis for EU and UK visitors: legitimate interest in operating and securing the Site.
Browser storage
Google AdSense aside - it can set ad-serving cookies on this domain for every visitor, as described above - the Site sets no tracking cookies unless you accept non-essential cookies. The only other client-side storage used by default is a small set of first-party values in your browser's localStorage:
- cookie-consent - whether you accepted or rejected non-essential cookies.
- fi_popup_shown_at - a timestamp, so the newsletter signup popup does not show again for 30 days after you have seen it.
- fi_subscribed - set after a successful signup, so we stop showing you the popup on future visits.
None of these contain personal information - they are short strings, timestamps or boolean flags. The two fi_ entries are written whether or not you accept: they are what stops the popup showing again, so they have to work for someone who declined. The popup is our own, sets no cookie, loads nothing from a third party, and never opens over a consent prompt. If you accept, additional third-party cookies from Google Analytics, Microsoft Clarity and the Meta Pixel may be set - see the cookie page for the breakdown, the legal basis, and how to clear them.
Embedded content
There is none. No embedded video, no social embeds, no comment widget, no map, no font CDN. Fonts, illustrations and photographs are all served from this domain.
3. Sale and sharing of personal information
We do not sell personal information for money, and we do not disclose your email address or the content of messages you send us to anyone for their own marketing. Advertising works differently: if you accept cookies, personalized advertising through Google AdSense - and the Meta Pixel, where we run it - involves disclosing online identifiers and browsing activity to those companies, and under the CCPA/CPRA that likely qualifies as a "sale" or "sharing" for cross-context behavioural advertising. You can opt out at any time using the "Cookie settings" link in the footer.
We also treat a Global Privacy Control signal from your browser as a valid opt-out that overrides a stored acceptance: when GPC is present we keep advertising non-personalized and do not load the consent-gated tools, on every page load, without you having to do anything else. Because that decision has already been made in your browser, the cookie banner and the footer control that reopens it are not shown to you at all - there is nothing left for them to ask.
If you do not accept, ads stay non-personalized: Google still receives your IP address, user agent and the page you are viewing in order to serve and measure an ad and detect invalid traffic, but that data is not used to build cross-context advertising profiles with our authorisation, and we do not otherwise sell or share your information. We do not knowingly sell or share the personal information of anyone under 16.
4. How we use your information
- To send you the daily newsletter you signed up for.
- To rate-limit signups and prevent spam and abuse.
- To understand, in aggregate, how the Site is used and improve it.
- To serve and measure the display ads that pay for the Site - non-personalized by default, personalized only if you accept cookies.
- To respond to your requests, including unsubscribe and deletion.
- To comply with applicable law and protect our legal rights.
We do not use your personal information for automated decision-making or profiling that would produce legal or similarly significant effects on you (Art. 22 GDPR), and we do not process "sensitive personal information" as the CPRA uses that term.
5. Who we share information with
We rely on a small set of vendors - "service providers" under the CCPA/CPRA, "processors" under the GDPR - that process information on our behalf, under contract. Each only sees what it needs to do its job.
| Provider | What it does | What it sees |
|---|---|---|
| Vercel Inc. (USA) - privacy policy | Hosting, the serverless function behind the signup form, and Vercel Analytics (cookieless, all visitors). | Requests to the Site, and short-lived server logs. |
| Cloudflare, Inc. (USA) - privacy policy | Cloudflare Web Analytics, cookieless aggregate traffic measurement. Runs for all visitors. | Page, referrer, country, device type. No cookie, no identifier. |
| Google Ireland Ltd. - privacy policy | Google Analytics 4. Runs for all visitors in a cookieless denied mode; sets cookies only if you accept. | Pages viewed, referrer, approximate location, device. |
| Google Ireland Ltd. - advertising | Google AdSense, the display advertising that funds the Site. Runs for all visitors; non-personalized until you accept. | Your IP address, user agent, the page you are viewing, and its own ad-serving cookies. |
| Microsoft Corp. - privacy statement | Microsoft Clarity, aggregate heatmaps and session replay with typed text masked. Loads only if you accept. | Page interactions, device, and its own cookies. |
| Meta Platforms Ireland Ltd. - privacy policy | Meta (Facebook) Pixel, campaign measurement and audience building. Loads only if you accept. | Page views and conversion events, and its own cookies. |
| Resend, Inc. (USA) - privacy policy | Holds the subscriber list and delivers the newsletter. | Your email address, signup source, IP address and timestamp, and the content of the emails sent to you. |
We do not add or change vendors casually. When we do, this list and the "last updated" date at the top change with it.
6. International transfers and retention
Our service providers are based in the United States, so personal information is transferred out of the EEA. For those transfers we rely on the safeguards under Art. 46 GDPR - typically the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the EU-US Data Privacy Framework where the provider is certified. Each provider's privacy page, linked above, sets out the mechanism it offers.
How long we keep things:
- Newsletter record (email, source, IP, timestamp) - kept while you are subscribed. If you unsubscribe we keep a minimal suppression record so we do not accidentally add you back. If you ask for full deletion, the record goes entirely.
- Cookieless analytics aggregates (Vercel Analytics, Cloudflare Web Analytics) - retained under each provider's standard retention, anonymised at collection and not linked to you.
- Consent-based analytics and advertising cookies (Google Analytics, Microsoft Clarity, Meta Pixel, set only if you accept) - retained for the individual cookie lifetimes listed on the cookie page.
- Ad-serving cookies (Google AdSense, set for every visitor including in non-personalized mode) - retained for the lifetimes Google sets, typically up to about 13 months for the first-party ones. Listed on the cookie page.
- Server logs - short-lived, under Vercel's standard log retention.
7. Your rights
We honour these for everyone, whatever jurisdiction you are in.
- Access - ask for a copy of, or details about, what we hold about you.
- Rectification - ask us to correct something that is wrong.
- Erasure - ask us to delete it. Deletion means deletion.
- Portability - ask for it in a structured, machine-readable format.
- Restriction and objection - ask us to pause a use, or object to processing based on legitimate interest.
- Withdraw consent - at any time, with no effect on processing that already happened. The newsletter has a one-click unsubscribe in every email, and the "Cookie settings" link in the footer reopens whichever consent prompt applies to you.
- Opt out of sale or sharing - we do not sell for money. If you accept cookies, personalized advertising through Google AdSense and our use of the Meta Pixel may qualify as a "sale" or "sharing" for cross-context behavioural advertising; you can opt out at any time via the footer link, or by sending a Global Privacy Control signal, which we honour and which overrides a stored acceptance.
- Limit use of sensitive personal information - non-applicable; we do not process any.
- Non-discrimination - nothing on this site is withheld from you for exercising a privacy right.
To exercise any of these, email moi@finnishirl.com from the subscribed address, or otherwise identify yourself reasonably. We aim to respond within 30 days (GDPR and UK GDPR) or 45 days (CCPA/CPRA). You may appoint an authorised agent where the law allows it.
8. Complaints
We would rather hear from you first, but you are under no obligation to come to us before contacting a regulator.
- Finland - the Office of the Data Protection Ombudsman.
- Elsewhere in the EEA - your national data protection authority. The European Data Protection Board keeps the list.
- United Kingdom - the Information Commissioner's Office.
- California - the California Privacy Protection Agency or the California Attorney General. Other US states: your state Attorney General.
9. Children
The Site is written for adults, not children. It explains how Finnish is really spoken, which includes swearing and words that are not safe in every room, and it is intended for readers who are at least 18. We do not knowingly collect personal information from anyone under 18, the newsletter is not directed at children, and we comply with the Children's Online Privacy Protection Act by not knowingly collecting personal information from children under 13 in the United States, and with the applicable digital-consent age elsewhere. If you believe a minor has given us personal information, tell us and we will delete it.
This applies to advertising too. Because the Site is a general-audience site for adults, it is not tagged as child-directed in Google AdSense, and Google's ad serving here is not subject to the restricted, child-directed treatment. We do not knowingly serve personalized ads to anyone we know to be under 16, and we do not knowingly sell or share their personal information for advertising.
10. Security
Everything is served over HTTPS. Subscriber records are held by our email provider under its own security controls, and the key that can write to them is read at runtime rather than compiled into the site. No system is perfectly secure, but the amount we hold is deliberately tiny. If there is ever an incident affecting your personal information, we will tell you and the relevant authority where the law requires it.
11. AI-assisted content
We use AI tools to research and draft the words and articles. Everything is then rewritten and checked by a human against real usage and against sources such as Kotus, and every word page lists what it was checked against. AI is not used to make decisions about you, to profile you, or to process your personal information - it helps write the content you read. Corrections from native speakers are the most useful mail this site gets and they go straight into the pages.
12. Changes
We may update this policy. Material changes show up in the "effective" and "last updated" dates at the top, and anything significant gets flagged in the newsletter. If a tool is added or removed, this page is updated in the same change as the tool - not afterwards.
13. Contact
Questions, requests or complaints: moi@finnishirl.com, reply to any newsletter email, or use the contact page.