RPO / PRIVACY
Privacy Policy.
What personal information RPO collects, why, who processes it, and how to access or remove it.
Privacy Policy
1. Scope
This Policy explains how Research Purpose Only ("RPO", "we", "us") handles personal information in connection with:
- the public RPO website;
- the membership application process;
- membership administration, including renewal; and
- email communications RPO sends.
It applies to applicants, members, and visitors to the RPO website. It does not apply to any third-party website RPO links to.
Related documents. Each is a separate document that applies on its own terms; none is incorporated into another:
- Notice at Collection — the short notice presented at or before collection.
- Terms of Use — terms governing use of the website.
- Research Disclaimer — the research-use boundaries that apply to RPO and its members.
- Email Consent Disclosure — how RPO contacts you, and marketing email.
- Membership Agreement — the membership contract, accepted with the application.
2. Who operates RPO
RPO operates from California, United States.
3. What we collect
3.1 Information you provide
| Category | Examples | When |
|---|---|---|
| Identifiers and contact information | First and last name, email address, telephone number (optional) | Application |
| Location and eligibility information | City, state/region, country. RPO accepts applicants in the United States only. | Application |
| Age eligibility | Your certification that you are 21 years of age or older | Application, and again at membership acceptance |
| Professional and affiliation information | Organization or institution name as typed (optional), a professional or institutional web address (optional), a self-selected background category | Application |
| Research interests and free text | The research areas you select, an "other" description where you select it, and your answer to what brings you to RPO | Application |
| Government identification document | A government-issued photo identification document, where RPO requests one. See section 5. | Only where requested |
| Consent and certification records | Which acknowledgements and certifications you gave, the exact on-screen wording shown to you, and the version and content hash of the document in force at that moment | Application |
| Membership records | Membership status, your joining date, membership year start and end dates, and renewal records | Membership |
3.2 Information generated automatically
| Category | What is actually stored |
|---|---|
| Request and security information | A keyed cryptographic hash of your IP address together with the identifier of the key version used, a truncated browser user-agent string (up to 255 characters), a request identifier, and timestamps |
| Email delivery information | Whether a message RPO sent to your address was delivered, bounced, or drew a complaint. This describes a mailbox, not a person. |
| Provider logs | Our hosting, database, email, error-monitoring and security providers keep their own operational logs. See section 7. |
RPO does not store your IP address itself. The raw address is used in memory to compute a keyed hash and is not written to RPO's database.
3.3 What RPO deliberately does not collect
RPO's database has no field for, and RPO does not collect:
- date of birth — age is a certification you make, not a date you supply;
- government identification numbers, or any other data printed on an identification document;
- health, medical, or clinical information;
- financial account or payment information;
- biometric identifiers, facial-recognition templates, or selfie-matching data;
- precise geolocation;
- taxpayer or national identification numbers;
- a profile photograph or avatar of any kind.
RPO does not perform optical character recognition, barcode extraction, identification-number extraction, biometric analysis, or automated identity matching on any document, and uses no automated identity-checking vendor.
4. Why we use personal information
| Purpose | Explanation |
|---|---|
| Reviewing applications | To consider your application and decide whether to approve it. Applications are reviewed by a person. RPO does not make application decisions by automated processing. |
| Eligibility and compliance | To confirm that eligibility requirements — United States location, 21 years of age or older, truthful application information, and the research-use restrictions — are met and continue to be met. |
| Administering membership | To record your acceptance of the Membership Agreement and the required certifications; to begin membership on approval; and to operate the 12-month membership year and handle renewals. |
| Service communications | To contact you about your application or membership. See section 9. |
| Marketing | To send research updates and news, as described in section 9 and in the Email Consent Disclosure. |
| Security and abuse prevention | To protect the website and the application process against automated abuse, and to apply rate limits. |
| Records and evidence | To keep a record of what you agreed to, when, and in what version. |
| Legal and compliance obligations | To comply with applicable law and to establish, exercise, or defend legal claims. |
5. Government identification documents
This section describes exactly what RPO does. It deliberately claims no safeguard that RPO has not implemented.
When. RPO may request, review and retain a government-issued photo identification document in some circumstances where RPO considers it appropriate. It is not a universal requirement of application, approval, membership, or renewal, and the Membership Agreement does not make it a condition of any of those. Where a document is requested, RPO asks for it once; a new document is not automatically required each year.
How it is held. The document file is placed manually, by an RPO administrator, into a private RPO Google Drive location. Access to that location is restricted to the RPO administrators who need it. RPO does not use "anyone with the link" sharing for these files.
What the RPO application stores. The RPO application does not store the document. It stores only:
- a private Google Drive link to the file;
- the document type (government identification);
- which administrator attached it and when; and
- if it is removed, which administrator removed it and when.
What RPO does not do with it. RPO does not extract, transcribe, or index anything printed on the document. There is no identification number, no date of birth, no address, no issuing authority, no expiry date, and no extracted name in RPO's records. RPO does not derive a profile photograph from it.
Encryption. The file is protected by Google's own access controls and by RPO's restriction of access to that Drive location. RPO does not apply an additional RPO-controlled encryption layer or hold a separate RPO encryption key above the provider's controls. This is stated plainly because overstating it would be inaccurate.
Retention. Where RPO holds such a document, it may be retained during the relationship.
6. Where information comes from
RPO collects personal information from you directly, from your use of the RPO website, and from its service providers' operational records (for example, email delivery outcomes). RPO does not purchase personal information, and does not acquire applicant information from data brokers.
7. Service providers
RPO uses the following categories of providers to operate the service. Each processes personal information only as needed to provide its service to RPO.
| Provider role | Used for |
|---|---|
| Application hosting | Serving the website and running application code |
| Database | Storing the records described in this Policy |
| Document storage (Google Drive) | Holding any government identification document RPO has requested, as described in section 5 |
| Bot protection | Distinguishing automated abuse from genuine visitors on public forms |
| Rate limiting | Limiting the frequency of requests to public endpoints |
| Email delivery | Sending operational messages and marketing messages |
| Error monitoring | Recording application errors so faults can be diagnosed |
8. Disclosure of personal information
RPO discloses personal information:
- to the service providers described in section 7, for the purposes described;
- where required by law, legal process, or a governmental request; and
- to establish, exercise, or defend legal claims.
As a matter of fact, RPO does not exchange personal information for money, and RPO does not use personal information for cross-context behavioral advertising or targeted advertising. RPO runs no advertising network integrations.
9. How RPO contacts you, and marketing
RPO does not send automated email. A person at RPO may contact you by email or by telephone about your application or your membership. That contact is part of the relationship and is not marketing.
Marketing communications are the occasional research notes RPO sends by email. You receive them only if you asked for them when you applied.
- The marketing opt-in at application is separate from the required document acknowledgements and certifications, and is never pre-selected.
- You may unsubscribe at any time. Unsubscribing has no effect on eligibility, application review, approval, or membership, and does not cancel your membership.
- Unsubscribing does not stop a person at RPO contacting you about your application or membership where that is necessary.
See the Email Consent Disclosure for the full description.
10. Retention and deletion
RPO keeps personal information for as long as it is needed for the purposes described in this Policy, and afterwards where retention is reasonably necessary for legitimate legal, business, or compliance purposes, subject to applicable law.
Two facts are stated plainly because they affect what RPO can promise:
- RPO's retention schedule is not finalized, and automated enforcement is not enabled. RPO's system holds provisional retention policies that currently run in report-only mode.
- Removing personal information from an RPO record is normally anonymization, not deletion of the whole record. Application, membership, consent, certification, renewal, compliance, and audit records may be retained after a person's details are removed, because they are the evidence of what was agreed and what was decided. Consent records are designed to outlive the personal details they relate to.
11. Your choices and requests
You may:
- opt out of marketing email at any time, without affecting your membership;
- ask what personal information RPO holds about you;
- ask RPO to correct inaccurate personal information;
- ask RPO to delete personal information, subject to the limits in section 10; and
- ask how RPO handled your application information.
To make a request, email info@researchpurposeonly.com or use the contact page
on the RPO website (researchpurposeonly.com/contact).
Before acting on a request, RPO will take reasonable steps to confirm that the request genuinely comes from you or from someone authorized to act for you. RPO may decline a request where it cannot reasonably establish this, or where applicable law permits or requires RPO to retain the information.
12. California privacy rights
RPO operates from California and accepts applicants in the United States only.
To the extent such rights apply, a California resident may have the right to know what personal information is collected and how it is used and disclosed; to request deletion; to request correction; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.
RPO does not discriminate against anyone for exercising a privacy right. Opting out of marketing, or making a privacy request, has no effect on an application or a membership.
13. Minors
RPO membership is limited to individuals 21 years of age or older. The RPO website and application process are not directed to children or to anyone under 21, and RPO does not knowingly collect personal information from anyone under 21. If RPO learns that it has collected personal information from someone under 21, it will delete or anonymize that information.
14. Security
RPO applies, and this list is limited to measures actually implemented:
- encrypted transport (HTTPS) for the website and application;
- administrative access restricted to authorized RPO administrators, protected by a password and mandatory time-based one-time-password multi-factor authentication;
- role-based limits on what each administrator can do;
- database-level row security and database-enforced append-only protection for consent and audit records;
- storage of a keyed hash of an IP address rather than the address itself;
- automated bot protection and rate limiting on public endpoints; and
- access logging for administrative actions.
No system is perfectly secure, and RPO does not guarantee that personal information will never be accessed, disclosed, altered, or destroyed. RPO does not apply its own application-level encryption layer above its providers' controls, and does not claim to.
15. United States only
RPO accepts applicants located in the United States only, and does not offer membership outside the United States. RPO's providers may process information in the United States.
16. Changes to this Policy
Each published version of this Policy is stored as an immutable version with a content hash. A change is always a new version, never an edit in place. The version that applied when you gave a consent or certification remains identifiable from RPO's records.
Material changes will be communicated as required by applicable law.
17. Contact
Questions about this Policy, and privacy requests: info@researchpurposeonly.com
You may also use the contact page at researchpurposeonly.com/contact.
Effective September 2026