XS News stands for full privacy and security. Those are two different things and both matter: privacy is a question of law and of what a company chooses to store, while security is a question of how your connection is protected while it is open. This page covers both, in detail.
We can be specific about it rather than merely reassuring, because privacy comes down to three checkable facts: where a company is registered, where its servers stand, and which law can be used to reach them. Those decide what is actually possible with your data — no matter what any terms document promises. Every other privacy sentence on the internet, ours included, rests on them.
Why jurisdiction decides everything else
Data protection is not primarily a technical discipline. Encryption protects data while it travels; the law decides what happens to it once it has arrived, and which rules the company holding it has to follow.
That is why the first question worth asking a provider is not “do you encrypt?” — almost everyone does — but “which country’s law applies to you?” A company can only protect your data as far as its own legal environment allows. Beyond that point, good intentions are irrelevant.
XS News is registered in the Netherlands, and the servers you connect to from Europe stand in the Amsterdam region. The party you have a contract with — and the only party a request could be addressed to — is a Dutch company. There is no parent company in another country. Being European has practical consequences beyond the legal ones — latency, euro pricing, support hours: what a European provider means in practice →
The US CLOUD Act does not apply to us
The CLOUD Act is a United States law from 2018. It allows US authorities to compel an American service provider to hand over customer data — and crucially, it applies regardless of the country the data is physically stored in.
This is the detail that catches people out. A US-based provider can rent a data centre in Frankfurt or Amsterdam, advertise “European servers” entirely truthfully, and still fall under that law. The servers are in Europe; the company is not. No clause in their terms of service can override an obligation their own government places on them.
So “EU servers” on its own tells you very little. What matters is where the company itself is registered — and ours is registered in the Netherlands. There is no US entity in our structure for the CLOUD Act to attach to: no American parent company, no US subsidiary, and no American operator running our infrastructure on our behalf.
That is not a policy we could quietly change later. It follows from how the company is built.
What the GDPR actually gives you
The GDPR gets mentioned so often that it has started to sound like a formality. It is not. It gives you concrete, enforceable rights over data a company holds about you:
- Access — you can ask what we hold about you, and we have to tell you.
- Rectification — anything wrong gets corrected.
- Erasure — you can have your data deleted, except where we are legally required to keep it (invoices, for the period Dutch tax law prescribes).
- Portability — you can request your data in a form you can take elsewhere.
- Objection — you can object to processing you did not ask for.
There is also a principle behind those rights that matters more than any single one of them: data minimisation. Under the GDPR we are only allowed to collect what we actually need for the service. Not what might be interesting, not what could be monetised later — what is necessary. Which brings us to the most important section on this page.
What we store, and what we deliberately do not
The strongest privacy guarantee is not a promise to protect data. It is not having the data in the first place. Nothing that was never recorded can be leaked in a breach, requested later, sold to an advertiser, or lost by an employee.
- Your e-mail address — to send login codes, invoices and service notices.
- Your username — it is how the server recognises your connections.
- Your plan and its status — so you get the service you paid for.
- Payment records — invoices we are legally required to keep.
Four items. Remove any one of them and the service stops working or breaks the law.
- What you download. No record of which articles you requested.
- Which groups you read or browsed.
- What you searched for in your newsreader.
- Your download history — there is no list to show you, because there is no list.
- Behavioural profiles — we do not build them, and we sell nothing to anyone.
None of this is needed to deliver Usenet access — so under the GDPR we are not allowed to collect it anyway.
Notice the asymmetry. The left column is short because it has to be. The right column is where a privacy policy is either serious or decorative.
Where your data actually sits
Worth being concrete about, because “European” is easy to say and easy to hedge. Your account data — e-mail address, plan, payment records — is held by XS News on European servers. Not by a partner, not by a processor on another continent.
We do also run servers in the United States, and it is worth saying plainly what they are for: speed, and nothing else. They exist so that customers in North America get a short route to the articles instead of crossing the Atlantic for every request. No customer data lives there. A Usenet article is public data that everybody can fetch; your account is not, and it stays in Europe.
Who can see what
It helps to be precise about which party learns which thing, rather than waving at “privacy” in general:
Encryption: 256-bit SSL/TLS, on by default
Everything above is the privacy half — which law applies, and what we refuse to store. The rest of this page is the security half: what protects the connection itself, every time it opens.
Every connection between your newsreader and our servers is protected with 256-bit SSL/TLS encryption on port 563, the standard secure NNTP port. (You will see both names used for the same thing: TLS is the modern successor to SSL, and most newsreaders still label the setting “SSL”.) It is not a premium feature, an add-on, or a checkbox you have to find in a settings panel — it is how the service is configured out of the box.
What that gets you concretely:
- Your internet provider cannot read your traffic. They see encrypted bytes going to a Dutch address, nothing about the contents.
- Nobody on the network in between can either — not on public Wi-Fi, not at a hotel, not on a shared line.
- The connection is authenticated, so your newsreader can verify it is really talking to our server and not to something impersonating it.
Our newsreader tutorials use the encrypted settings throughout, so following any of them leaves you with SSL/TLS enabled without having to think about it.
Secure authentication and account hygiene
Your account has its own username and password, used to authenticate every single connection. Two practical consequences:
- You can change the password yourself, any time, from the member area. If a device goes missing or you shared credentials with someone you no longer trust, you do not need to contact anybody — rotate it and every connection using the old one stops working.
- Login to your account uses a one-time code sent by e-mail, so gaining access to the account area requires access to your mailbox, not just a guessed password.
No app, so no telemetry
This one is easy to overlook because it is an absence. Usenet works over a standard protocol through a newsreader you choose yourself. There is no XS News application on your computer or phone.
Which means there is no software of ours running on your device that could collect usage statistics, crash reports, device identifiers, advertising IDs or a contact list. We could not build a behavioural profile from your device even if we wanted to, because we have nothing installed there. Just a server, a port, and your credentials.
Try it, then decide
You do not have to take a website’s word for any of this. Our privacy policy is the formal version of this page, and our terms spell out the rest.
When you want to test the service itself, pick a plan you can cancel in a few clicks. Everything on this page applies to every plan we sell, monthly or annual — privacy is not an upgrade.