Data policy.
A technical explanation of publication records, host logs, third-party services and information-security responsibilities.
Actual processing locations, security controls and retention periods depend on deployment settings that still require a publisher audit.
1. Scope
This operational policy supplements the Privacy Policy. It explains how the reviewed Next.js, Convex and optional Clerk application is designed to handle data. It is not an independently audited security or privacy certification.
2. Publishing records
The content database contains article titles, bodies, author labels, source URLs, tags, images, timestamps and publishing states. News ingestion functions also store candidate source records and activity logs used to diagnose feed processing. Original public source references remain attributed to their respective publishers.
3. Visitor and editorial data
Public reading does not currently require registration. Hosting infrastructure may generate access and diagnostic logs. If Clerk sign-in is activated, authorized editorial accounts can generate session and authentication records. The site does not include a public reader portfolio, payment-card checkout or brokerage account integration.
4. Access and vendors
Vercel hosts the site; Convex provides article records, schedules and file storage; Clerk may authenticate editors. Appropriate access control depends on the actual deployment configuration, identities and maintained secrets. Provider contracts, processing locations, optional analytics features and subprocessor practices require operator review.
5. Retention, archival and deletion
Historical reporting is maintained for archive and citation purposes. Logs, candidates, drafts, backups and authentication events can follow different retention schedules established by provider settings and legal requirements. We do not assert that all backups or service logs disappear immediately after a deletion request. Any rights request is evaluated under applicable law.
6. Protection and incident response
Administrative article mutations are intended to require server-side permission checks. Security still depends on account hygiene, key rotation, provider infrastructure and operational incident handling. No published third-party audit or guaranteed breach-response timing is claimed here.
7. AI and content automation
RSS-based collection may assist editorial discovery and AI tools may support draft preparation or illustrations where configured. Such processes relate to reporting; they are not designed to make automated personal financial decisions about site readers. AI output requires verification and can contain mistakes.
8. Requests and changes
Contact the publisher at aromal@recouprev.com for data questions. Do not transmit credentials, government identifiers or sensitive financial records before a secure transfer method is agreed. See the editorial standards for content-correction issues.
Related documents: Privacy policy · Terms · Data handling · Cookies · Editorial standards · Contact.