Skip to main content

Privacy and data use

Privacy notice

RSRC collects the minimum information reasonably needed to operate this website, understand whether its research tools are useful, protect the service, and respond to people who choose to contact us. We do not operate victim-case intake and ask that you not send sensitive scam-case, health, financial-account, government-identification, or authentication information.

Effective date
Last reviewed

Who operates RSRC

The Romance Scam Research Center (RSRC) is a program of the Social Technology and Safety Foundation, a South Dakota nonprofit organization. In this notice, “RSRC,” “we,” and “our” refer to the Foundation and its RSRC program. Privacy questions and requests may be sent through the contact form, by email to info@romancescamresearch.org, or by mail to 1100 W Cherry St, Vermillion, SD 57069, USA.

Information we collect and why

ActivityInformationPurpose
Contacting RSRCName, email address, topic, message, delivery status, and any information you include voluntarily.Respond, route the message, prevent abuse, and maintain an operational record.
Correction requestsPage or publication, concern type, description, supporting URL, optional name and email, reference number, status, and editorial decision history.Investigate and document research-integrity corrections.
Research submissionsCitation and publication details, relevance statement, relationship to the work, conflict disclosure, name, email, reference number, and screening history.Screen proposed research for possible inclusion and document the curation decision.
NewsletterEmail address, subscription and unsubscribe dates, unsubscribe token, and delivery records.Confirm and honor the requested subscription, send newsletters, prevent duplicate delivery, and process unsubscribe requests.
Accounts and administrationName, email, password hash, role and account status, session state, multifactor-authentication configuration, recovery-code material, and trusted-device records.Authenticate authorized administrators, protect restricted functions, and investigate security or operational events.
Using public pages and the LibraryThe limited analytics described below, including public routes, searches, selected filters, result counts, source interactions, clicks to selected external websites, broad browser viewport category, approximate location, and privacy-preserving visitor identifiers.Measure research use, understand which responsive layouts visitors receive, evaluate whether organizational and researcher links are useful, improve discovery and presentation, maintain content, classify likely automated traffic, secure the service, and allocate research effort.

Please do not submit confidential research manuscripts, unpublished sensitive data, victim case files, passwords, payment-card details, or other information that RSRC has not specifically requested. Research PDFs used internally for curation and analysis are not made public through the Library.

Analytics, search records, and approximate location

RSRC operates internal, privacy-preserving analytics for public page visits, Library searches, publication detail, original-source, free-full-text, and citation-export actions, Research Insight views, and clicks on RSRC links to LDHerrera.com and ExpertApproach.com. Records may include a keyed pseudonymous visitor identifier, a hashed browser signature, traffic classification, dates and counts, the public route and page path without query parameters, page title, a broad responsive-layout category, search text, selected filters, result count, publication identity and action, selected external destination, and a normalized referring domain. The layout category reports only whether the browser viewport is mobile-width, tablet or small-window width, desktop width, or wide-desktop width; RSRC does not retain exact screen or viewport dimensions. The full referring URL, query string, fragment, and activity after a visitor leaves RSRC are not stored. This minimization applies to RSRC’s internal public-page analytics.

When you search the Library, RSRC records the words you search for, the filters you select, the number of results returned, and whether you open a publication or follow an original-source link. We use this information to understand which research topics visitors are seeking, identify searches that do not produce useful results, improve the Library, and help determine where additional research organization or content may be valuable. Search records are not used for advertising, sold, shared with advertisers or data brokers, or intended to identify individual visitors.

To improve traffic-quality reporting, a public page may send a first-party browser confirmation after the page has remained visible briefly. The confirmation uses a short-lived, single-use security token tied to the current session and reports only the broad layout category described above. It helps distinguish ordinary browser use from simple automated requests, but RSRC does not treat it as definitive proof that a person is present. RSRC also evaluates privacy-preserving aggregate patterns, such as unusually distributed bursts, repeated one-page visits, and request rates. Unverified and likely automated activity is retained for auditing but excluded from reported visitor demand.

The web request’s IP address is used transiently in application memory to create the keyed visitor identifier and to derive approximate country, continent, region, and city when reliable geographic data is available. The raw IP address is not stored. Approximate location may be wrong and is used for aggregate reporting and resource planning, not to make decisions about an individual. Network addresses and browser details are not retained with contact or newsletter records. Application-session records likewise do not retain network addresses or browser details.

RSRC does not use Google Analytics, advertising pixels, cross-site tracking, or analytics cookies. Public-use measurements are collected by RSRC’s own application and are not used for targeted advertising or to build advertising profiles.

Cookies and browser storage

The site uses first-party session and security cookies for functions such as request protection, temporary browser confirmation, authentication, and preserving a Library result context. Administrators may choose a trusted-device cookie that allows a registered browser to skip a new multifactor code for up to 90 days; RSRC stores a one-way hash of that token, a general device label, last-use time, and expiration. The device can be revoked from the administrator security page. Application session records do not retain IP addresses or browser user-agent strings.

If a visitor dismisses the Library’s AI-transparency notice, a first-party local-storage preference remembers that choice in that browser. RSRC does not use analytics cookies. Blocking browser storage may affect remembered preferences but should not prevent access to public research content.

AI-assisted processing

RSRC uses OpenAI’s API to assist with research-document analysis, reference discovery, synopsis generation and checking, research mapping, synthesis, and limited text classification or translation. When a Library query appears to use another language, the short query may be sent to OpenAI for language identification and English translation; RSRC does not include the visitor’s IP address or browser details in that request. The original query, detected language, accepted translation, confidence, and search mode may remain in internal search records.

Contact-message screening is local by default. If AI-assisted screening is specifically enabled, only the topic and message text, not the sender’s name or email address, is sent for spam classification. Do not place sensitive personal information in free-text fields. OpenAI processes API data under its own applicable terms and privacy documentation; RSRC does not intentionally use visitor submissions to train a public model.

Service providers and other disclosures

RSRC does not sell personal information or share it with advertisers or data brokers. Limited information may be processed by service providers only when reasonably necessary to operate the website, deliver a service a person requested, protect the organization, or meet a legal obligation, as described below.

  • operate website hosting, database, backup, email-delivery, security, and maintenance services;
  • use OpenAI’s API for the limited functions described above;
  • process a donation initiated through PayPal, which receives payment and account information directly under PayPal’s own privacy practices;
  • retrieve or validate scholarly metadata through services such as Crossref, DataCite, DOI.org, OpenAlex, Semantic Scholar, and Unpaywall, generally using publication identifiers and bibliographic data rather than visitor identity;
  • comply with applicable law, legal process, or a valid governmental request; protect the rights, safety, and security of RSRC or others; investigate abuse; or establish, exercise, or defend legal claims; or
  • support an organizational reorganization or transfer, subject to appropriate confidentiality and notice where required.

Providers may process information in the United States or other countries where they operate. A link to a publisher, repository, DOI resolver, government resource, PayPal, or another third party takes you to a service governed by that party’s notice, not this one.

Retention and security

RSRC retains information only for as long as reasonably necessary for the purpose collected, operational continuity, research-integrity history, security, dispute resolution, and legal obligations. Retention is category-specific: active session data follows the configured session lifetime; trusted-device records expire automatically and can be revoked sooner; Telescope diagnostic records are scheduled for deletion after approximately 48 hours; rotating application logs follow the configured operational schedule; newsletter records remain until unsubscribe and may retain a limited suppression or delivery history; and correction, publication-submission, editorial, curation, and research-provenance records may be retained longer because they document the integrity and history of the scholarly collection. Aggregated or deidentified statistics may be retained without a fixed period.

RSRC uses safeguards designed for the nature of the information, including encrypted transport, access controls, multifactor authentication for administrators, hashed passwords and analytics identifiers, restricted diagnostics, security headers, input validation, rate limiting, backups, and monitoring. No online system can be guaranteed completely secure. If RSRC determines that a legally reportable breach occurred, it will provide notice as required by applicable law.

Your choices and privacy requests

  • Use the unsubscribe link in any RSRC newsletter to stop future newsletter delivery.
  • Use browser controls to clear first-party cookies or local-storage preferences.
  • Contact RSRC to request access to, correction of, or deletion of personal information you submitted, or to object to or ask about its use.
  • Authorized administrators can revoke trusted devices, disable multifactor authentication, and manage their account information from the restricted interface.

To protect against unauthorized disclosure, RSRC may ask for information reasonably needed to verify a request. We will evaluate requests under applicable law and may retain information when necessary for research-integrity records, security, legal obligations, or the rights of others. RSRC does not currently use personal information to make decisions that produce legal or similarly significant effects. RSRC does not sell personal information or use it for targeted advertising.

This website and its submission tools are intended for adults and are not directed to children under 13. If you believe a child provided personal information, contact RSRC so the issue can be reviewed. This notice may be updated when practices or legal requirements materially change; the effective and review dates above show the current version.

Regional privacy rights

Privacy rights vary by residence and by whether a law applies to RSRC. RSRC will consider a verified request even when a particular law does not require the requested action. Depending on applicable law, rights may include confirming processing; accessing, correcting, or deleting personal information; receiving a portable copy; restricting or objecting to processing; withdrawing consent; opting out of sale, targeted advertising, or qualifying profiling; and appealing a denied request. RSRC does not discriminate against a person for exercising an applicable privacy right.

United States

The categories RSRC may collect include identifiers and contact information; internet or electronic activity; approximate geolocation; professional, education, or research-submission information; correspondence and other user-provided content; account and security information; and limited inferences such as likely traffic type, research-topic mapping, or language interpretation. These categories come from the person, the person’s browser or device, scholarly and public sources, and service providers. They are used and disclosed for the operational purposes described in this notice. RSRC does not sell personal information and does not use it for targeted advertising or legally significant profiling. A resident of a state that provides an appeal right may appeal a denied request by replying to RSRC’s decision or contacting RSRC with “Privacy appeal” in the subject line.

European Economic Area, United Kingdom, and Switzerland

Where the GDPR, UK GDPR, or a comparable Swiss requirement applies, RSRC acts as controller for the processing described here. Rights may include access, rectification, erasure, restriction, portability, objection to legitimate-interest processing, withdrawal of consent, and a complaint to the data-protection authority where the person lives or works or where an alleged violation occurred. Information is primarily administered in the United States and may be processed in other countries by the providers described above. Where a restricted transfer rule applies, RSRC will use an available lawful transfer mechanism or another permitted basis appropriate to the provider and transfer.

Canada and other jurisdictions

Residents of Canada and other jurisdictions may have rights to access or correct personal information, withdraw consent subject to legal limits, challenge compliance, or complain to an applicable privacy regulator. Residents of jurisdictions including Australia, New Zealand, Brazil, and other countries may have additional rights under local law. Contact RSRC to invoke a right or ask how a local requirement applies to a particular processing activity.

Submitting a request

Submit a request through the contact form or email info@romancescamresearch.org with “Privacy request” in the subject line. Describe the right and the RSRC interaction involved. An authorized agent may submit a request where permitted, but RSRC may require proof of authority and direct identity confirmation. RSRC will acknowledge and respond within the period required by applicable law, subject to a permitted extension, and will explain a denial or limitation. Requests are generally free, although a reasonable fee or refusal may be permitted for manifestly unfounded, excessive, or repetitive requests.