Skip to content

News. Insight. Updates. Impact.

Editorial Standards

Data Retention

What we keep, and for how long

We collect as little as the product needs, keep it only as long as it is useful, and delete it on request.


We do not collect PHI

ABA Command Center does not solicit, accept, or store protected health information. If a document sent to us contains PHI, we destroy it rather than retain it, and we tell the sender.

Accounts

Account records hold your email address, display name, optional organization and role, and your beat and state preferences. They are kept while the account exists and deleted when you ask us to close it.

Newsletter subscribers

We store your email, the beats and states you chose, the timestamp of your confirmed opt-in, and delivery outcomes for the digests we sent you. Consent timestamps are retained while you are subscribed and for a limited period afterward as proof that consent existed.

Unsubscribing stops all sends immediately. Send logs are kept in summary form for operational troubleshooting and then aged out.

Contact and correction submissions

Contact messages and correction requests are retained while they are open and for a reasonable period after resolution, so we can show why an entry was changed. Correction attachments are stored in a private bucket and are only reachable through short-lived signed links issued to editorial staff.

The editorial record

Article revisions, correction histories, and the audit log of who approved what are retained permanently. That permanence is the point: it is what makes the published record accountable. These records concern editorial actions, not readers.

Research evidence

Agent runs, source checks, content hashes, and submissions are retained so that any published entry can be traced back to the document it came from and the moment it was retrieved.

Resource download logs

When a signed-in user downloads a gated resource we record the account, the file, and the timestamp. These entries are kept while the account exists and are aged out on a rolling basis afterward.

Security, audit, and rate-limit metadata

Authentication events and rate-limit counters — keyed to an account or a coarse request fingerprint such as an IP-derived value — are short-lived and expire automatically once they are no longer useful for abuse prevention.

Editorial audit entries showing who created, approved, or corrected content are part of the permanent published record described above.

Cookies, sessions, and OAuth data

Session tokens and the strictly necessary cookies and browser storage that keep you signed in expire on their own schedule and are cleared when you sign out. Profile identifiers returned by Sign in with Google are stored with your account, not separately.

Requesting deletion

Write to us through the contact form at /contact to access, correct, export, or delete your personal data. We will confirm the request and act on it, except where a record must be kept to document a published correction or to meet a legal obligation.

Our privacy notice explains what each category contains and why we collect it.

ABA Command Center publishes general educational information about the Applied Behavior Analysis industry. It is not legal, compliance, billing, or clinical advice. We do not collect protected health information.