Accountability
Transparency is not an obligation for us. It's a choice. Here we explain the rules we follow and how you can reach us.
For details on AI transparency, credibility scaffolding, and source quality, see why you can trust this.
Sources and copyright
ovr.news collects news from public RSS feeds. We don't copy articles. Our AI creates original summaries in new words. The original remains the publisher's property. We always link to the source.
We respect paywalls and access restrictions. If a source blocks access, we accept that, and articles where we cannot retrieve sufficient content are excluded. On the EU Copyright Directive's text and data mining opt-out (Article 4): when we consider adding a source, we read its robots.txt for AI crawler directives, and a domain that signals one is flagged and set aside rather than onboarded. Two honest limits — it's a signal a person acts on, not an automatic block, and we don't re-scan sources already on the list. So if you've opted out and we're still carrying you, tell us and we'll remove you.
For publishers: See our dedicated publisher information page for details on attribution, data processing, and how to opt out.
The EU AI Act
Since 2 August 2026, Article 50 of the EU AI Act requires that text generated by AI and published to inform the public be identified as such. That applies to us. Every summary and every headline on this site is written by a language model, not by a person.
The law exempts AI text that a human reviews before publication. We don't claim that exemption. Nobody reads each article before it goes live — selection and writing are automated end to end, which is precisely the case the disclosure rule exists for.
So we label it: on the article page, the homepage and lens pages, both RSS feeds, the email and channel digests, and — since August 2026 — the preview card that apps like Slack and WhatsApp generate when someone pastes a link to us. (We mark the fields those cards read; whether a given app chooses to show them is outside our control.) Not a footer link on any of them: a feed reader, an email or a preview card never shows you this page. What is not AI-generated: the images (see below) and the source links, which always point at the original.
We follow the EU's Code of Practice on Transparency of AI-Generated Content, published in June 2026 and confirmed by the Commission as an adequate way to meet these duties. It deliberately prescribes no single marking technique — no method available today satisfies everything the Act asks of one — so what you see here is our reading of it, not a certification.
The Act also asks that generated text be marked so machines can detect it, not just people. Every article carries a standard tag for that, and so does every item in our feeds.
Article 50's remaining duties don't reach us — we run no chatbot, no emotion recognition, and we generate no synthetic images, audio or video. If you think a summary misrepresents its source, use the report button on the article. That's the correction mechanism, and we read what comes in.
Images
Images on ovr.news come from four sources:
- Source images: The preview image (og:image) from the original article. We don't host these ourselves; your browser loads them directly from the source. If the source blocks this, the image disappears automatically.
- Wikimedia Commons: Freely available images under the CC BY-SA 4.0 license. Attribution is always shown.
- Unsplash: Images under the Unsplash license. Attribution is shown out of respect, although not required.
- Curated library: A collection of CC-licensed images we maintain ourselves, with attribution and license links.
Who owns this, and who pays for it
Knowing who stands behind a news service is part of being able to judge it. The European Media Freedom Act asks media services to publish this, and we would rather publish it than argue about whether we have to.
- Published by: Veen Systems, The Netherlands. ovr.news appears under the Busara.eu name — that is the name of the project, not a separate company; Veen Systems is the practice responsible for publishing it. Reach us through the contact form or at busara.eu@proton.me.
- Ownership: Independently owned. No shareholders, no parent company, no investors. The beneficial owner is Jeroen Veen, who is also the person who builds and runs it.
- State ownership: None. No government or public authority holds any interest, direct or indirect.
- State advertising revenue (2025): €0. We carry no advertising at all, so there is nothing to declare here — from any government, and from any other advertiser.
- Revenue from non-EU public authorities (2025): €0.
- How it is funded: donations, and unpaid work. No ads, no paywall, no sponsored placement, no affiliate links. If that ever changes, this section changes first.
Editorial independence. Nobody outside this project can influence what appears here, and there is no commercial relationship that could create the pressure — no advertiser to please, no investor with a return to earn, no sponsor whose sector we would then be softer on. What gets published is decided by the lens scores and the editorial rules, which are documented in under the hood rather than left to discretion. Where a rule removes a story, that removal is recorded so it can be reviewed later.
Conflicts of interest. The technical work on ovr.news is done by the operator's own freelance practice — the same person builds it, runs it and owns it. That is the one structural conflict worth naming, and naming it is the mitigation available to a project this size. We hold no stake in any organisation we cover. If a story ever concerned a party we are connected to, we would say so on the article.
Privacy
Data controller: Veen Systems, The Netherlands — see who owns this. For privacy questions, use our contact form.
Short version: We collect as little as possible. We set no cookies on the public site, don't track you, and don't show ads. You are not a product here. (Cloudflare's infrastructure may set technical cookies for DDoS protection, outside our control; our operator-only admin area uses strictly-necessary session cookies.)
What we don't do
- No tracking cookies
- No advertisements
- No selling data to third parties
- No Google Analytics or Facebook Pixel
- No automatic personal data collection — the only personal data we hold is what you give us directly (contact form, email signup).
What we do
- Cloudflare hosting: Our site is hosted via Cloudflare Pages. They process technical data (IP address) to secure and deliver the site. See their privacy policy. Cloudflare acts as a data processor under a standard Data Processing Addendum.
- Web analytics: A server-side counter records each HTML page render in Cloudflare Analytics Engine. For every page view we store the URL path, a 2-letter country code derived by Cloudflare at the edge, and a coarse human-or-bot label derived in transit from the request's network type and standard browser headers (the headers themselves are discarded, never stored). No IP, no cookie, no user identifier, no User-Agent, no session, no fingerprint — the data is non-personal under GDPR.
- Article images: Thumbnail images are loaded directly from publisher servers. Your browser connects to those servers when displaying images. We do not proxy or cache these requests.
- Local storage: Your theme preference (light/dark) is stored in your browser (localStorage). If you tap "was this worth your time?" on an article, a flag is stored locally so we don't ask you again for that article. If you sign up for our digest, a flag is also stored locally so we don't show the in-feed signup card to you again. If you dismiss that card without signing up, a 30-day cool-off timestamp is stored so we don't keep nagging you in the short term — after 30 days the card may surface again. None of these values leave your device.
- Article flagging: If you report a problem with an article, we store the article ID, a timestamp, and whatever you type in the message box. To prevent abuse, your IP address is temporarily used for rate limiting (max 10 flags per hour) and automatically deleted after 1 hour; it is never linked to your report. Reports are automatically deleted after 90 days. We ask you not to include personal details, but because the message is free text we cannot guarantee it contains none — please don't put anything in it you wouldn't want stored. Our legal basis for keeping the message is legitimate interest (Art. 6(1)(f) GDPR): reader reports are how we find out when the pipeline has published something it shouldn't have. Reports are readable only by the operator.
- Links out to publishers: If you click through to the original article or to one of the corroborating outlets, we record which of our pages you left from, which link you used, the publisher's domain, a timestamp and your country — no IP, no cookie, no identifier. We record the publisher's domain so we can tell publishers how many readers we send them; we never record anything about you beyond your country. We cannot see whether the page you went to loaded, or what you did there. Your IP is used only for rate limiting (max 60 per hour) and deleted after 1 hour.
- Sharing: If you use the share button, we record which page you shared, which method you picked (copy link, WhatsApp, Signal, email, Mastodon, or your device's own share sheet), a timestamp and your country — no IP, no cookie, no identifier, and nothing about who you shared it with. We cannot see whether you actually sent anything: for every method except your device's share sheet, all we know is that you opened it. Your IP is used only for rate limiting (max 30 per hour) and deleted after 1 hour. We count this because we have no other way to tell whether anyone finds a story worth passing on.
- "Was this worth your time?": If you tap this on an article, we record the article ID, a timestamp, your country, and whether our edge classified the request as a browser or an automated client — no IP, no cookie, no identifier. If you also choose to write a line about why, we store whatever you type, with the article ID and a timestamp. Your IP address is used only for rate limiting (max 20 requests per hour; a tap plus a written why costs two of them) and deleted after 1 hour; it is never stored alongside what you wrote. Notes are deleted after 90 days. We ask you not to include personal details, but because the box is free text we cannot guarantee it contains none — please don't put anything in it you wouldn't want stored. Our legal basis for keeping the note is legitimate interest (Art. 6(1)(f) GDPR): we have no way to tell whether the stories we select are worth reading except by asking. Notes are readable only by the operator, and the tap count is never shown publicly.
- Contact form: When you use our contact form, we store your name, subject, and message for 90 days. Your IP address is used for rate limiting (max 5 messages per hour) and deleted after 1 hour. Messages may be forwarded to our inbox via Resend, an email delivery service. Resend processes data in the United States under Standard Contractual Clauses. See Resend's privacy policy.
- Email signup: If you sign up to be notified about a future digest, we store your email address along with a timestamp and the consent text you agreed to. We do not currently send any emails — addresses sit inert until we either launch a digest or write to ask whether you still want to be on the list. You can remove your address at any time at /unsubscribe. Storage is in Cloudflare D1 with EU jurisdiction restriction — your address never leaves EU data centres. Rate limit: max 5 sign-ups per hour per IP, deleted after 1 hour.
Legal basis
Under GDPR Article 6, we process data on the following legal bases:
- Legitimate interest (Art. 6(1)(f)): IP-based rate limiting to prevent abuse. (Web analytics data is non-personal and falls outside GDPR's material scope — listed for completeness.)
- Contract performance (Art. 6(1)(b)): Processing contact form messages to respond to your inquiry.
- Consent (Art. 6(1)(a)): Storing your email address for digest sign-up, recorded with the exact consent text shown to you. Withdrawable at any time via /unsubscribe.
Data retention
- Rate-limiting IP addresses: 1 hour, then automatically deleted.
- Article flags: 90 days, then automatically deleted.
- "Was this worth your time?" notes: 90 days from the most recent note on that article, then automatically deleted.
- Contact form messages: 90 days, then automatically deleted.
- Email signups: until you unsubscribe. We will also write to ask whether you still want to be on the list at least once if no digest has launched within 12 months of your sign-up.
- Web analytics: aggregate data only, no personal data retained.
Your rights
Under GDPR, you have the right to access, correct, or delete any personal data we hold, as well as the right to restrict processing, data portability, and to object. Since we collect almost no data, these rights rarely apply in practice. But they are yours.
To exercise any of these rights, use our contact form or email busara.eu@proton.me. We will respond within 30 days. You may also file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Open source
The scoring filters and training pipeline that power our lenses are public. The site and pipeline code are not yet open source but may be in the future.
Contact
For publishers, privacy questions, feedback, or suggestions: use our contact form.
Last updated: August 2026