NonProfit Media is committed to protecting the privacy of our readers, sources, and contributors. This policy explains what data we collect, why we collect it, how long we keep it, and the rights you have over your information.
Our core commitment: We do not sell your data. We do not run advertising. We do not build behavioral profiles. Your privacy is not a product.
NonProfit Media is an independent, nonprofit investigative journalism organization headquartered in Washington, D.C. We conduct original investigations and curate critical reporting from trusted sources including ProPublica, Reuters, the Associated Press, The Guardian, The Marshall Project, The Intercept, InsideClimate News, and other credentialed news organizations.
Data controller: NonProfit Media, Inc.
Contact: [email protected]
Mailing address: NonProfit Media, Washington, D.C. 20001
We collect only what is necessary to operate our platform and serve our public-interest mission.
Information you provide directly:
• Email address (newsletter subscriptions, tip submissions, contact forms)
• Name (optional, for newsletter personalization)
• Message content (contact and tip submissions)
• PGP public key (optional, for encrypted communications)
Information collected automatically:
• IP address (anonymized within 24 hours)
• Browser type and operating system
• Pages visited and time spent (aggregate analytics only)
• Referring URL
Information we do NOT collect:
• Payment information (donations processed by third-party processors)
• Social Security numbers or government IDs
• Precise geolocation
• Biometric data
• Behavioral advertising profiles
We use collected data exclusively for the following purposes:
Newsletter delivery: Sending the edition(s) you subscribed to
Tip processing: Routing secure tips to our editorial team
Platform improvement: Aggregate, anonymized analytics to understand which investigations reach the most readers
AI-assisted journalism: When AI tools assist in research or content creation, user data is never used to train AI models. Our editorial standards require human review of all AI-assisted work before publication.
Legal compliance: Responding to valid legal process (see Section 7)
Security: Detecting and preventing abuse, spam, and unauthorized access
We do not use your data for behavioral advertising, political targeting, or sale to third parties — ever.
For users in the European Economic Area, United Kingdom, and Switzerland, our legal bases for processing personal data are:
Consent** (Article 6(1)(a)): Newsletter subscriptions and optional contact forms:
Legitimate interests** (Article 6(1)(f)): Security monitoring, fraud prevention, and aggregate analytics:
Legal obligation** (Article 6(1)(c)): Compliance with valid court orders or legal process:
You may withdraw consent at any time by unsubscribing or contacting [email protected]. Withdrawal does not affect the lawfulness of processing before withdrawal.
We retain personal data only as long as necessary:
|-----------|-----------------|
Tip submissions are retained for 7 years to support ongoing investigations and legal proceedings. Source identity is stored separately from tip content and is accessible only to the Editor-in-Chief.
| Data Type | Retention Period |
|---|---|
| Newsletter subscriber email | Until unsubscribe + 30 days |
| Tip submission content | 7 years (journalistic record) |
| Contact form messages | 2 years |
| Server access logs (IP) | 90 days, then anonymized |
| Aggregate analytics | Indefinitely (no personal data) |
Protecting confidential sources is a core editorial and legal obligation. Our source protection protocols include:
SecureDrop: Anonymous tip submission via our SecureDrop instance (Tor network)
PGP encryption: End-to-end encrypted email communications
Compartmentalization: Source identity is known only to the receiving editor; it is never stored in shared systems
No metadata logging: We do not log IP addresses or browser fingerprints for tip submissions
Legal defense: We will contest any subpoena or legal demand seeking to identify confidential sources and will notify sources of legal demands where legally permitted
We follow the guidelines of the Reporters Committee for Freedom of the Press and the Society of Professional Journalists Code of Ethics regarding source protection.
We will resist overbroad legal demands for user data. Our policy:
• We require a valid, specific legal process (subpoena, court order, or warrant) before disclosing any user data
• We will notify affected users of legal demands unless prohibited by law or court order
• We will challenge demands we believe are unconstitutional, overbroad, or contrary to press freedom
• We publish an annual transparency report disclosing the number and type of legal demands received
• We do not participate in voluntary data-sharing programs with law enforcement
We have never received a National Security Letter. We will update this statement if that changes (a "warrant canary").
Depending on your jurisdiction, you have the following rights regarding your personal data:
All users:
• Right to unsubscribe from communications at any time
• Right to request deletion of your data (subject to journalistic retention obligations)
EEA/UK/Switzerland (GDPR/UK GDPR):
• Right of access (Article 15)
• Right to rectification (Article 16)
• Right to erasure (Article 17)
• Right to restriction of processing (Article 18)
• Right to data portability (Article 20)
• Right to object (Article 21)
• Right to lodge a complaint with your supervisory authority
California (CCPA/CPRA):
• Right to know what personal information is collected
• Right to delete personal information
• Right to opt-out of sale (we do not sell data)
• Right to non-discrimination for exercising rights
To exercise any right, contact: [email protected]
We use a limited number of third-party services, each selected for their privacy practices:
Email delivery: Transactional email via encrypted SMTP relay (no third-party email marketing platforms)
Donation processing: Stripe (PCI-DSS compliant; we never see or store payment card data)
Hosting: Cloud infrastructure with data stored in the United States
CDN: Content delivery network for static assets only (no user data transmitted)
We do not use social media share buttons that track users, embedded third-party video players with tracking, or any ad networks.
We will notify newsletter subscribers of material changes to this Privacy Policy at least 30 days before they take effect. The date of the most recent revision appears at the top of this page. Continued use of our platform after the effective date constitutes acceptance of the updated policy.
For questions or concerns about this Privacy Policy, contact:
NonProfit Media, Washington, D.C. 20001
To exercise your rights, report a privacy concern, or request data deletion, contact our Privacy Officer:
We respond to all privacy requests within 30 days.