Skip to main content

Privacy and data use

Privacy notice

RSRC collects the minimum information reasonably needed to operate this website, understand whether its research tools are useful, protect the service, and respond to people who choose to contact us. We do not operate victim-case intake and ask that you not send sensitive scam-case, health, financial-account, government-identification, or authentication information.

Effective date
Last reviewed

Who operates RSRC

The Romance Scam Research Center (RSRC) is a program of the Social Technology and Safety Foundation, a South Dakota nonprofit organization. In this notice, “RSRC,” “we,” and “our” refer to the Foundation and its RSRC program. Privacy questions and requests may be sent through the contact form, by email to info@romancescamresearch.org, or by mail to 1100 W Cherry St, Vermillion, SD 57069, USA.

Information we collect and why

Information RSRC collects, the activity that provides it, and why it is used
ActivityInformationPurpose
Contacting RSRCName, email address, topic, message, delivery status, and any information you include voluntarily.Respond, route the message, prevent abuse, and maintain an operational record.
Corrections and resource suggestionsPage, publication, country, or official resource; concern type; description; supporting URL; optional name and email; reference number; status; and editorial decision history.Investigate research-integrity corrections and evaluate proposed official reporting or support resources.
Research submissionsCitation and publication details, relevance statement, relationship to the work, conflict disclosure, name, email, reference number, and screening history.Screen proposed research for possible inclusion and document the curation decision.
NewsletterEmail address, subscription and unsubscribe dates, unsubscribe token, and delivery records.Confirm and honor the requested subscription, send newsletters, prevent duplicate delivery, and process unsubscribe requests.
Accounts and administrationName, email, password hash, role and account status, session state, multifactor-authentication configuration, recovery-code material, and trusted-device records.Authenticate authorized administrators, protect restricted functions, and investigate security or operational events.
Using public pages, the Library, and resource directoryThe limited analytics described below, including public routes, searches, selected filters, result counts, source interactions, resource-directory country or jurisdiction selections, official-resource opens, clicks to selected external websites, broad browser viewport category, approximate location, and privacy-preserving visitor identifiers.Measure research and resource use, understand which responsive layouts visitors receive, evaluate whether official, organizational, and researcher links are useful, improve discovery and presentation, maintain content, classify likely automated traffic, secure the service, and allocate research effort.

Please do not submit confidential research manuscripts, unpublished sensitive data, victim case files, passwords, payment-card details, or other information that RSRC has not specifically requested. Authorized administrators can upload research documents in PDF or Markdown format. RSRC retains the documents, extracted text, file-identification details, and curation history for research analysis and source verification. These internal files are not made public through the Library; public records link to original sources.

Public author profiles are assembled from scholarly metadata, including author names, research identifiers, publication associations, and available affiliation information. They help readers find related research and do not imply an affiliation with or endorsement of RSRC. Authors can use the correction or privacy-request process to raise inaccurate information or concerns about its use.

Analytics, search records, and approximate location

RSRC operates internal, privacy-preserving analytics for public page visits, Library searches, publication detail, original-source, free-full-text, and citation-export actions, Research Insight views, country or jurisdiction selections in the official-resource directory, official-resource opens, and clicks on RSRC links to LDHerrera.com and ExpertApproach.com. Records may include a keyed pseudonymous visitor identifier, a hashed browser signature, traffic classification, dates and counts, the public route and page path without query parameters, page title, a broad responsive-layout category, search text, selected filters, result count, publication identity and action, selected resource country or jurisdiction, official-resource identity, selected external destination, and a normalized referring domain. The layout category reports only whether the browser viewport is mobile-width, tablet or small-window width, desktop width, or wide-desktop width; RSRC does not retain exact screen or viewport dimensions. The full referring URL, query string, fragment, and activity after a visitor leaves RSRC are not stored. This minimization applies to RSRC’s internal public-page analytics.

When you search the Library, RSRC records the words you search for, the filters you select, the number of results returned, and whether you open a publication or follow an original-source link. We use this information to understand which research topics visitors are seeking, identify searches that do not produce useful results, improve the Library, and help determine where additional research organization or content may be valuable. Search records are not used for advertising, sold, shared with advertisers or data brokers, or intended to identify individual visitors.

When you use the official-resource directory, RSRC records the country or jurisdiction you select and whether you open a listed official source. We use this information to understand where visitors seek help, identify the resources they find useful, prioritize verification and coverage, and improve the directory. RSRC does not record activity after you leave for the official source.

To improve traffic-quality reporting, a public page may send a first-party browser confirmation after the page has remained visible briefly. The confirmation uses a short-lived, single-use security token tied to the current session and reports only the broad layout category described above. It helps distinguish ordinary browser use from simple automated requests, but RSRC does not treat it as definitive proof that a person is present. RSRC also evaluates privacy-preserving aggregate patterns, such as unusually distributed bursts, repeated one-page visits, and request rates. Unverified and likely automated activity is retained for auditing but excluded from reported visitor demand.

The web request’s IP address is used transiently in application memory to create the keyed visitor identifier and to derive approximate country, continent, region, and city when reliable geographic data is available. Raw IP addresses are not stored in RSRC’s application analytics tables. Hosting, web-server, or security logs may separately contain IP addresses and request details. Approximate location may be wrong and is used for aggregate reporting and resource planning, not to make decisions about an individual. Network addresses and browser details are not retained with contact or newsletter records. Application-session records likewise do not retain network addresses or browser details.

RSRC does not use Google Analytics, advertising pixels, cross-site tracking, or analytics cookies. Public-use measurements are collected by RSRC’s own application and are not used for targeted advertising or to build advertising profiles.

Cookies and browser storage

The optional reading list stores up to 100 public publication numbers in this browser’s local storage until you clear the list or browser storage. RSRC receives those numbers when you view the list or request a citation export, but does not create an account or a stored reading-list collection on the server. A share link includes the selected numbers in its fragment (after the #). Anyone you give that link to can view the selection, which may reveal your research interests. Opening a shared list does not replace your saved list. Clearing your browser’s list does not revoke links you already shared.

Session cookies and preferences

The site uses first-party session and security cookies for functions such as request protection, temporary browser confirmation, authentication, and preserving a Library result context. Administrators may choose a trusted-device cookie that allows a registered browser to skip a new multifactor code for up to 90 days; RSRC stores a one-way hash of that token, a general device label, last-use time, and expiration. The device can be revoked from the administrator security page. Application session records do not retain IP addresses or browser user-agent strings.

If a visitor dismisses the Library’s AI-transparency notice, a first-party local-storage preference remembers that choice in that browser. RSRC does not use analytics cookies. Blocking browser storage may affect remembered preferences but should not prevent access to public research content.

AI-assisted processing

RSRC uses OpenAI’s API to assist with research-document analysis, reference discovery, synopsis generation and checking, research mapping, synthesis, and editorial revision and validation. These requests may include publication metadata, text extracted from PDF or Markdown documents, preserved evidence excerpts, existing explanations, draft revisions, and review feedback. RSRC retains drafts, source-check results, editorial assessments, and processing records to document how published explanations were produced. Authorized maintainers also use AI-assisted tools for editorial review and site maintenance.

Limited classification and translation also use OpenAI’s API. When a Library query appears to use another language, the short query may be sent to OpenAI for language identification and English translation; RSRC does not include the visitor’s IP address or browser details in that request. The original query, detected language, accepted translation, confidence, and search mode may remain in internal search records.

Contact-message screening is local by default. If AI-assisted screening is specifically enabled, only the topic and message text, not the sender’s name or email address, is sent for spam classification. Do not place sensitive personal information in free-text fields. OpenAI processes API data under its own applicable terms and privacy documentation; RSRC does not intentionally use visitor submissions to train a public model.

Service providers and other disclosures

RSRC does not sell personal information or share it with advertisers or data brokers. Limited information may be processed by service providers only when reasonably necessary to operate the website, deliver a service a person requested, protect the organization, or meet a legal obligation, as described below.

  • operate website hosting, database, backup, email-delivery, security, and maintenance services;
  • preserve research PDF and Markdown files and their earlier versions in a private GitHub repository, separately from database backups;
  • use OpenAI’s API for the limited functions described above;
  • load website fonts from Bunny Fonts; your browser contacts that provider when loading the fonts, exposing the network information needed to deliver them, including your IP address;
  • process a donation initiated through PayPal, which receives payment and account information directly under PayPal’s own privacy practices;
  • retrieve or validate scholarly metadata through services such as Crossref, DataCite, DOI.org, OpenAlex, Semantic Scholar, and Unpaywall, generally using publication identifiers and bibliographic data rather than visitor identity;
  • comply with applicable law, legal process, or a valid governmental request; protect the rights, safety, and security of RSRC or others; investigate abuse; or establish, exercise, or defend legal claims; or
  • support an organizational reorganization or transfer, subject to appropriate confidentiality and notice where required.

Providers may process information in the United States or other countries where they operate. A link to a publisher, repository, DOI resolver, government resource, PayPal, or another third party takes you to a service governed by that party’s notice, not this one.

Retention and security

Retention depends on the record’s purpose, operational continuity, research-integrity history, security, dispute resolution, and legal obligations. Active session data follows the configured session lifetime; trusted-device records expire automatically and can be revoked sooner; Telescope diagnostic records are scheduled for deletion after approximately 48 hours; rotating application logs follow the configured operational schedule; and newsletter records remain until unsubscribe and may retain a limited suppression or delivery history.

Detailed Library searches, daily visits, page views, outbound clicks, and resource-directory activity are scheduled for daily pruning. We keep the current week and the previous 26 complete weeks (about six months). Publication and blog interaction records combine repeat activity; these records expire after their last interaction falls outside that same window. Until deletion, pseudonymous visitor identifiers remain personal activity records, not anonymous statistics. Older search text, filters, translations, visitor hashes, and detailed location records are removed from the live analytics tables.

Weekly search and topic totals, and aggregate activity counts without visitor identifiers or search text, may be retained without a fixed period. These totals do not retain visitor identifiers or individual activity histories and are not lifetime unique visitor counts. You can contact RSRC about retention or request deletion as described below.

Backups and server logs follow separate retention arrangements; this automated pruning does not erase those copies.

Correction, publication-submission, editorial, curation, and source records preserve the history of the scholarly collection. Private document version history and database backups can retain earlier copies after a live record changes or is removed. A deletion request therefore requires consideration of retained copies as well as the live website; removal from a public page does not by itself erase those copies. RSRC has not established a single fixed retention period for these archives.

RSRC uses safeguards designed for the nature of the information, including encrypted transport, access controls, multifactor authentication for administrators, hashed passwords and analytics identifiers, restricted diagnostics, security headers, input validation, rate limiting, backups, and monitoring. No online system can be guaranteed completely secure. If RSRC determines that a legally reportable breach occurred, it will provide notice as required by applicable law.

Your choices and privacy requests

  • Use the unsubscribe link in any RSRC newsletter to stop future newsletter delivery.
  • Use browser controls to clear first-party cookies or local-storage preferences.
  • Contact RSRC to request access to, correction of, or deletion of personal information you submitted, or to object to or ask about its use.
  • Authorized administrators can revoke trusted devices, disable multifactor authentication, and manage their account information from the restricted interface.

To protect against unauthorized disclosure, RSRC may ask for information reasonably needed to verify a request. We will evaluate requests under applicable law and may retain information when necessary for research-integrity records, security, legal obligations, or the rights of others. RSRC does not currently use personal information to make decisions that produce legal or similarly significant effects. RSRC does not sell personal information or use it for targeted advertising.

This website and its submission tools are intended for adults and are not directed to children under 13. If you believe a child provided personal information, contact RSRC so the issue can be reviewed. This notice may be updated when practices or legal requirements materially change; the effective and review dates above show the current version.

Regional privacy rights

Privacy rights vary by residence and by whether a law applies to RSRC. RSRC will consider a verified request even when a particular law does not require the requested action. Depending on applicable law, rights may include confirming processing; accessing, correcting, or deleting personal information; receiving a portable copy; restricting or objecting to processing; withdrawing consent; opting out of sale, targeted advertising, or qualifying profiling; and appealing a denied request. RSRC does not discriminate against a person for exercising an applicable privacy right.

United States

The categories RSRC may collect include identifiers and contact information; internet or electronic activity; approximate geolocation; professional, education, or research-submission information; correspondence and other user-provided content; account and security information; and limited inferences such as likely traffic type, research-topic mapping, or language interpretation. These categories come from the person, the person’s browser or device, scholarly and public sources, and service providers. They are used and disclosed for the operational purposes described in this notice. RSRC does not sell personal information and does not use it for targeted advertising or legally significant profiling. A resident of a state that provides an appeal right may appeal a denied request by replying to RSRC’s decision or contacting RSRC with “Privacy appeal” in the subject line.

European Economic Area, United Kingdom, and Switzerland

Where the GDPR, UK GDPR, or a comparable Swiss requirement applies, RSRC acts as controller for the processing described here. Rights may include access, rectification, erasure, restriction, portability, objection to legitimate-interest processing, withdrawal of consent, and a complaint to the data-protection authority where the person lives or works or where an alleged violation occurred. Information is primarily administered in the United States and may be processed in other countries by the providers described above. Where a restricted transfer rule applies, RSRC will use an available lawful transfer mechanism or another permitted basis appropriate to the provider and transfer.

Canada and other jurisdictions

Residents of Canada and other jurisdictions may have rights to access or correct personal information, withdraw consent subject to legal limits, challenge compliance, or complain to an applicable privacy regulator. Residents of jurisdictions including Australia, New Zealand, Brazil, and other countries may have additional rights under local law. Contact RSRC to invoke a right or ask how a local requirement applies to a particular processing activity.

Submitting a request

Submit a request through the contact form or email info@romancescamresearch.org with “Privacy request” in the subject line. Describe the right and the RSRC interaction involved. An authorized agent may submit a request where permitted, but RSRC may require proof of authority and direct identity confirmation. RSRC will acknowledge and respond within the period required by applicable law, subject to a permitted extension, and will explain a denial or limitation. Requests are generally free, although a reasonable fee or refusal may be permitted for manifestly unfounded, excessive, or repetitive requests.