# bona — full text

> All public bona.works pages concatenated. For the compact index, see <https://bona.works/llms.txt>. The `/kit/<handle>` route is templated and not inlined here.

---
<!-- https://bona.works/ -->

# bona

> Your live media kit. A sponsor-facing kit and post-send report for newsletter operators. Flat $19 a month. No commission. No marketplace lock-in.

bona is the sponsorship layer for newsletter operators. It pulls live numbers from beehiiv, substack, and ghost, renders a kit URL you share with sponsors, and (on Reports tier and up) writes the post-send report so you don't have to.

The brand-rendered HTML at [bona.works](https://bona.works/) is the human-facing version of this summary. This `.md` exists for LLM consumers — agents indexing the public surface, prospective sponsors pasting the URL into a chat to ask "what is this?", and operators curious about the product without leaving their terminal.

## The problem (three of them)

- Post-send reports take two hours per sponsor. Export from beehiiv. Pivot for opens. Click-through by post. Email it six days late. Repeat.
- Joining a marketplace costs 5–20 percent of revenue. Paved, CKSN, Hecto. They handle the workflow — for a cut of every sponsorship.
- Your media kit is a static screenshot from last quarter. Sponsors notice; some accept it; the ones who don't, you lose without ever knowing why.

## How it works

1. **Connect your newsletter.** Paste an API key from beehiiv, substack, or ghost. About 30 seconds.
2. **Share the kit URL with sponsors.** Live numbers, branded to you. Updates every 30 minutes.
3. **After the slot runs, the report writes itself.** Open rates, click-through, top posts — emailed to the sponsor 24h after. Reports tier and up.

## Pricing

- **Free — $0.** One kit, basic theme, powered-by attribution, beehiiv integration.
- **Pro — $19/mo.** Custom domain, branded theme, attribution removed, MCP server for AI assistants, all three platforms, PDF snapshot.
- **Reports — $29/mo.** Everything in Pro, plus post-send sponsor reports auto-emailed 24h after each slot.
- **Booking — $49/mo.** Everything in Reports, plus book-this-slot calendar, Stripe checkout, and a sponsor CRM.

Annual plans save ~17 percent. Existing customers' rates never change.

## Who it's for

Newsletter operators who own their audience and want to keep the rate they signed. If you write the newsletter, sign the sponsor, and run the slot yourself, bona is the tool that handles the kit and the report so you can focus on the writing.

## Read more

- [FAQ](/faq.md) — platforms, pricing, data safety, credit.
- [Privacy Policy](/legal/privacy.md) — what we collect and why.
- [Terms of Service](/legal/terms.md) — pricing, billing, refunds, liability.
- [Cookie Policy](/legal/cookies.md) — what cookies bona sets.
- [Security Policy](/legal/security.md) — how to report a vulnerability.
- [Accessibility Statement](/legal/accessibility.md) — WCAG 2.1 AA commitments.

---
<!-- https://bona.works/faq -->

# FAQ

> Last updated: 2026-05-19 — Version 3

## Which platforms work?

Beehiiv, Substack, and Ghost are all supported today. Paste the API key from your platform and bona pulls aggregate stats — no commission, no platform lock-in.

## Will it work if I have under 1,000 subscribers?

Yes. There's no minimum. The free tier is for everyone.

## Can I hide my actual numbers?

You can show ranges instead of exact figures. Some sponsors prefer that, some don't.

## What happens if I change platforms?

Re-paste the API key from the new platform. The kit URL stays the same.

## Is my data safe?

We pull what your platform's API exposes. We don't store subscriber emails or send anything to your list. You can disconnect any time.

## Why $19?

It's what a Substack subscription costs for a year of one good newsletter. It's what one fewer coffee a week looks like. It's what a tool that runs while you sleep should cost.

## Who painted the flowers?

The bouquets across bona are watercolour studies by Dutch botanical painter Willem van Leen (1763–1825). The originals live in the [Rijksmuseum](https://www.rijksmuseum.nl) and are public domain — we picked them because van Leen painted quietly, for the next century, and so should you.

---
<!-- https://bona.works/legal/privacy -->

# Privacy Policy

> Last updated: 2026-05-28 — Version 3

bona is a tool for newsletter operators to share live media kits and send post-send sponsor reports. This page explains what data we collect, why, and what we do with it.

## What we collect

### From operators (you)

- Email address (when you sign up).
- API keys (encrypted at rest, never logged, decrypted only at use).
- Newsletter metadata pulled from your platform (publication name, post titles, post performance metrics).
- Usage data (what pages you visit in the dashboard, what features you use, errors you hit). Tracked in PostHog.
- Billing information, processed by Stripe. We never see or store full credit card numbers.
- Any information you put in support emails.

### From kit page viewers (sponsors who view your shared URLs) and any other public page

bona uses PostHog (a product-analytics service) on every page of `bona.works`, loaded first-party through `k.bona.works`. On kit pages and elsewhere on the public site, PostHog records:

- Page-view events (which page, when, the referrer).
- A session replay — a recording of the page’s DOM events, scrolls, hovers, and clicks. Input values are masked at the recording layer; any element marked `data-private` is also masked. Mouse movements and click positions are recorded. Canvas content is not.
- Web vitals (LCP, CLS, INP, FID, TTFB) for performance monitoring.
- Browser type, language, and viewport size.
- An opaque PostHog distinct-id, device-id, and session-id stored in browser cookies/localStorage (see the [Cookie Policy](/legal/cookies) for the exact storage keys and how to opt out).
- On `/kit/…` pages: bona’s server also sets `bona_sid_anon`, an HMAC-signed anonymous identifier (no IP, no user-agent, no PII). The in-page PostHog script bootstraps with the same identifier so a returning sponsor is not counted twice across the server-side capture and the client-side script.

We do NOT collect, store, or transmit sponsor email addresses, IP addresses (server-side capture is processed by PostHog with the standard first-party defaults; the address is not stored in our database), or names from kit-page views.

Sponsors can opt out by enabling Do Not Track in their browser (we honor the DNT signal — no PostHog cookies are set and no events are sent), by blocking `ph_*` and `bona_sid_anon` cookies, or by using a tracker-blocking browser extension. The kit page renders and functions identically when analytics is blocked.

### From sponsors (when you schedule a slot for them)

- Sponsor name and email (entered by you).
- Their email is used only to send the post-send report.

## What we don’t collect

- Subscriber email addresses from your newsletter platform. We pull aggregate stats only.
- Subscriber names, demographics, or any per-person data.
- Phone numbers.
- Physical addresses (unless you opt to share for invoicing).
- Any data we don’t need to provide the service.

## What we do with it

- **Provide the service:** show you your dashboard, render your kit pages, send post-send reports.
- **Improve the product:** look at usage patterns to find friction.
- **Communicate:** send transactional emails (login links, billing receipts, error alerts), and (if you opt in) occasional product updates.
- **Bill you:** through Stripe.

## What we don’t do with it

- We never sell your data.
- We never use your data to train AI models.
- We never share your data with third parties except service providers (PostHog, Stripe, Resend, Fly.io) who process it on our behalf.
- We never use subscriber email addresses for any purpose. We don’t have access to them.

## Where it lives

- Hosted on Fly.io (US regions primarily, multi-region as we scale).
- Postgres database (Fly.io managed).
- File storage (Cloudflare R2).
- Analytics (PostHog Cloud, US region).
- Payments (Stripe).
- Email delivery (Resend).

All providers are vetted for their privacy practices and (when applicable) sign Data Processing Agreements with us.

## Your rights

You can:

- **See your data:** every piece we have on you is exportable as CSV/JSON from your account.
- **Delete your data:** account deletion removes all your data within 30 days, except where we’re legally required to retain (e.g., billing records for 7 years).
- **Stop us using your data:** opt out of analytics tracking via account settings; we’ll respect Do Not Track headers.
- **Ask us anything:** email [privacy@bona.works](mailto:privacy@bona.works) and you’ll get a real human reply.

## Children

This service is not directed at users under 16. We do not knowingly collect data from children.

## How long we keep data

- Active operator data: as long as your account is active.
- Cancelled accounts: 30 days for restoration, then deleted.
- Billing records: 7 years (US tax requirement).
- Aggregated analytics: indefinitely (cannot be linked back to individuals).

## Changes to this policy

We’ll email all current operators 30 days before any material change. Minor wording fixes don’t get an email.

## Contact

Privacy questions: [privacy@bona.works](mailto:privacy@bona.works).
General support: [support@bona.works](mailto:support@bona.works).

---
<!-- https://bona.works/legal/terms -->

# Terms of Service

> Last updated: 2026-05-17 — Version 3

By using bona, you agree to these terms. Plain language.

## What we provide

A tool to:

- Generate a public URL (“kit”) showing your newsletter’s stats.
- Connect to your newsletter platform via API key.
- Send post-send performance reports to your sponsors (Reports tier and up).
- Manage sponsorship inventory and bookings (Booking tier).

## What we charge

- Free tier: $0.
- Pro: $19/month or $190/year.
- Reports: $29/month or $290/year.
- Booking: $49/month or $490/year.

Annual plans are billed up front. All prices in USD.

**Existing customers’ rates never change.** If we raise prices, only new customers pay new prices. This is a real commitment, in writing.

We notify you 60 days before any pricing change for new customers.

## How billing works

- Stripe processes all payments. They handle your card data, not us.
- Subscriptions auto-renew until you cancel.
- Cancel anytime from billing settings. Cancellation takes effect at the end of your current period.
- We don’t auto-charge you for a new period if you cancel before it starts.

## Refunds

- Within 14 days of a charge: refund without questions.
- 14–60 days, with reasonable cause: usually refunded; we ask why.
- Past 60 days: case by case.

## What you agree to

- You’re 16 or older.
- The data you connect is yours (you own the newsletter, you have rights to its API).
- You won’t use the service to send spam, deceive sponsors, or violate the law.
- You won’t try to break the service, scrape it, or use it to harm others.
- You’ll keep your API keys and login secure.

## What we agree to

- We’ll provide the service as described.
- We’ll keep your data secure and private (per our Privacy Policy).
- We’ll publish status, incidents, and changes honestly.
- We won’t take your data and run.

## When things break

We try hard to keep the service up, but we can’t promise 100% uptime. Our target is 99.5%; major incidents get postmortems.

## Liability

We’re a small team with limited resources. Our total liability for anything is capped at the amount you’ve paid us in the past 12 months. This is standard for SaaS.

## Termination

- You can cancel anytime.
- We can terminate your account if you violate these terms (with notice except for serious cases like fraud).
- Export your data from your dashboard at any time.
- Email [privacy@bona.works](mailto:privacy@bona.works) to delete your account; we’ll delete it within 30 days.

## Changes

- We can update these terms with 30 days notice via email.
- Material changes (especially around pricing or data handling) trigger explicit notice.
- If you don’t agree to a change, you can cancel and we’ll prorate.

## Disputes

- We try to resolve any dispute by email first.
- If that fails, disputes go to to be filled in before launch by counsel arbitration.
- No class actions.

## Contact

Email [support@bona.works](mailto:support@bona.works).

---
<!-- https://bona.works/legal/cookies -->

# Cookie Policy

> Last updated: 2026-05-23 — Version 3

We use cookies (and similar technologies) sparingly. Here’s what.

## Session

- `bona_session` — the authentication session cookie. Set when you sign in by clicking a magic link sent to your email, cleared when you log out. HttpOnly, SameSite=Lax. Required for the site to remember you between page loads.

## Analytics

bona uses PostHog (a product-analytics service) on every page of `bona.works`. PostHog is loaded as a first-party script through `k.bona.works`, our reverse proxy — no third-party origins are contacted directly. The cookies below are set by PostHog when its in-browser script runs.

- `ph_<project>_posthog` — PostHog’s distinct-id, device-id, and session-id storage. Set by the in-page script (not by the server), so it is NOT HttpOnly. SameSite=Lax. Secure on HTTPS. Max-Age: 1 year. Contains opaque identifiers only — no email, no IP, no user-agent.
- `ph_<project>_posthog` (`localStorage`, not a cookie) — same payload as the cookie plus the active session-replay metadata. Local to your browser; not sent on every request.
- `ph_<project>_posthog_session_replay` (`localStorage`, not a cookie) — present only while a session replay is being recorded. Holds the replay-buffer pointers, cleared when the session ends.
- `bona_sid_anon` — bona’s server-side anonymous identifier for kit pages (`bona.works/kit/…`). A random 128-bit token HMAC-signed with a server secret; no personal data, no IP, no user-agent. Used by bona’s server to count unique kit views and CTA clicks. When this cookie is present on a `/kit/…` page, the in-page PostHog script bootstraps with the same identifier so the same person isn’t counted twice across the two paths. Scoped to `Path=/kit`, HttpOnly, SameSite=Lax. Max-Age: 1 year.

## How to opt out

- All analytics: clear or block `ph_*` cookies (and the `bona_sid_anon` cookie on `/kit/…` pages) via your browser’s site-settings. Blocking either does not affect your ability to view any kit page or use any bona feature.
- Do Not Track: we honor the DNT signal — when DNT is on, no `ph_*` cookies are set and no PostHog events are sent.
- Operator analytics: you can toggle "analytics tracking" off in your account settings. (Coming soon.)
- Browser cookie blocking: the site will work, but you’ll have to log in more often.

---
<!-- https://bona.works/legal/security -->

# Security Policy

> Last updated: 2026-05-17 — Version 2

We take security seriously. If you find a vulnerability, please tell us.

## Scope

- The marketing site at bona.works
- The application at bona.works
- Public kit pages at bona.works/kit/
- Our API endpoints
- Our infrastructure (within reason — please don’t DDoS us to “test”)

## What’s NOT in scope

- Third-party services (Stripe, PostHog, Fly.io) — report to them directly.
- Social engineering of our team.
- Physical attacks on our infrastructure.
- Disclosed vulnerabilities in dependencies (those are tracked elsewhere).

## How to report

Email: [security@bona.works](mailto:security@bona.works).
PGP key: PGP key not yet published.

In the report, include:

- Description of the vulnerability.
- Steps to reproduce.
- Potential impact.
- Whether you’ve contacted anyone else.

## What we’ll do

- Acknowledge and investigate your report within 7 days.
- Fix valid issues within timelines based on severity: Critical 7 days; High 30 days; Medium 90 days; Low when reasonable.
- Credit you (with permission) in our security disclosures unless you prefer anonymity.

## Bug bounty

We can’t pay cash bounties at our scale (yet). For valid critical and high reports, we’ll send merch / a year of Pro tier on us / a thank-you on a public security page. As we grow, we’ll formalize a cash bounty program.

## What we won’t do

- Sue you for finding a vulnerability we didn’t know about.
- Threaten or harass researchers.
- Hide vulnerabilities to avoid reputational damage.

If we mess up, please tell us — privately first, publicly if we don’t respond.

---
<!-- https://bona.works/legal/accessibility -->

# Accessibility Statement

> Last updated: 2026-05-16 — Version 1

We try to make bona usable by everyone.

## Standard

We target **WCAG 2.1 Level AA** as our minimum.

## What this means

- Screen readers can navigate the dashboard and kit pages.
- Every action is reachable via keyboard navigation.
- Color contrast meets AA standards.
- Touch targets are at least 44px.
- We provide alt text on every meaningful image.
- We use semantic HTML (proper headings, landmarks, ARIA where needed).

## What we don’t yet have

- Full WCAG AAA conformance (it’s a stretch goal).
- Audio descriptions on video content (we don’t currently have video; if we add it, we will).
- Captions on screencasts (we’ll add when we ship them).

## Known issues

We test against axe + WAVE before each release. Known limitations get filed as issues + tracked publicly.

## Ask us

If you hit an accessibility barrier, email [support@bona.works](mailto:support@bona.works). We’ll fix it within 30 days for serious issues, sooner if it blocks core use.

---
<!-- https://bona.works/waitlist/thanks -->

# Thanks for joining the waitlist

We'll email you when bona opens — no marketing list, no drip sequence, just a single message.

[More about bona](/index.md).
