At Aevum News, data is the foundation of journalism. Every reader interaction, source submission, and editorial draft follows a strictly governed lifecycle. This document outlines how we handle information from the moment it enters our systems to its eventual archival or deletion, ensuring transparency, security, and editorial integrity.
We treat all data with the same rigor we apply to fact-checking. Privacy is not an afterthought—it is embedded into our editorial and technical infrastructure.
1. Collection
Data enters our ecosystem through three primary channels:
- Reader Interactions: Analytics, newsletter sign-ups, comment submissions, and preference settings. All collection is opt-in where possible, with clear consent flows.
- Source Submissions: Tips, documents, and multimedia from whistleblowers or contributors, routed through encrypted drop portals (SecureDrop integration).
- Editorial Workflow: Drafts, research notes, and interview recordings generated internally by our newsroom.
We minimize collection to only what is necessary for journalism and service improvement. No covert tracking or third-party fingerprinting occurs on our platforms.
2. Processing
Raw data is processed through automated and human-reviewed pipelines:
- Anonymization: Personal identifiers are stripped or hashed before entering analytical datasets.
- Verification: Source submissions undergo cryptographic hashing to preserve chain-of-custody while enabling editorial review.
- Categorization: NLP-assisted tagging helps assign stories to beats, but all final classification is human-led.
Processing occurs within isolated environments. Editorial staff only access data relevant to their assignments.
3. Storage
All data is stored using enterprise-grade encryption:
- At Rest: AES-256 encryption across all databases and object storage.
- In Transit: TLS 1.3 enforced for all internal and external communications.
- Geographic Residency: Reader data remains within EU/EEA jurisdictions unless explicit consent is given for cross-border transfer.
Access follows the principle of least privilege. Multi-factor authentication is mandatory for all editorial and technical accounts.
4. Editorial Usage
Data is used exclusively for:
- Informing reporting and investigative journalism
- Improving user experience and content delivery
- Measuring article reach and engagement (aggregated, anonymized)
We never sell reader data. Personal information is never used for targeted advertising. Our revenue model is subscription-driven, aligning our incentives with reader trust, not surveillance capitalism.
5. Dissemination
Published stories undergo a redaction workflow before release. Sensitive data points are reviewed by our legal and ethics boards. When sharing datasets publicly, we:
- Apply differential privacy techniques where applicable
- Remove direct and quasi-identifiers
- Provide clear attribution and usage licenses (CC BY-NC 4.0 for public datasets)
6. Retention
Data is never stored indefinitely without purpose. Retention periods are strictly defined:
- Reader accounts: 7 years after last active interaction
- Analytics data: 24 months (aggregated thereafter)
- Source submissions: Retained for the lifespan of the investigation, then transferred to archival storage or deleted per contributor request
- Editorial drafts: 5 years, unless marked for permanent archival value
7. Deletion & Archival
When retention periods expire, data enters one of two pathways:
Files undergo cryptographic erasure (key destruction) followed by physical media wiping or destruction. Certificates of destruction are logged for audit trails.
Archival data is moved to cold storage, encrypted, and accessible only to authorized historians or regulatory bodies under legal warrant. The Aevum Digital Archive preserves significant journalism while redacting private identifiers.
Compliance & Ethics
Our lifecycle adheres to GDPR, CCPA, and the Society of Professional Journalists Code of Ethics. We conduct annual third-party audits and publish compliance reports publicly. Readers may request data export or deletion at any time via privacy@aevumnews.com.
Transparency is not a feature—it is our operating system.
Visual Overview
Collection
Opt-in reader data, secure source drops, editorial inputs
Processing
Anonymization, verification, ethical tagging
Storage
AES-256 encryption, TLS 1.3, jurisdictional residency
Usage
Editorial workflow, experience optimization, no ad-sales
Dissemination
Redaction review, public dataset licensing, attribution
Retention
Strict time-bound policies, purpose-driven storage
Deletion / Archival
Cryptographic erasure or cold historical storage