Governance record · Actual site behavior

Privacy should describe what the site actually does.

This record covers public browsing, Vercel hosting, the protected review, local-only interactions, ordinary email correspondence, external links, and the boundary around future research data.

A privacy page must describe what the site actually does—not what a template assumes a website probably does.

Version
1.0
Effective
August 9, 2026
Last reviewed
August 9, 2026
Correction path
Report an issue

Current public record

Implemented behavior and known incompleteness.

Implemented now

  • No account system, public form, participant enrollment, newsletter signup, session replay, advertising tracker, support-link tracker, or analytics package.
  • No site-set application cookie or local-storage record; the private definition builder uses temporary browser memory and an optional clipboard action.
  • Ordinary email is correspondence and is not automatically research data, a testimonial, a quotation, or permission for publication.

Still incomplete

  • A fixed correspondence-retention schedule has not been established, so none is promised.
  • Email infrastructure and hosting providers process information under their own terms and technical practices.
  • Future studies will require separate participant privacy and data-governance records before collection begins.
01

Scope

This record applies to Neurosexology.org public pages, protected previews, local-only interactions, links, and messages sent to hello@neurosexology.org. It is not a study consent form, clinical privacy notice, or policy for a future dataset.

02

Information received when visiting

The application does not ask a visitor to identify themselves. As with ordinary web hosting, Vercel may process request and usage information such as IP address, requested URL, date and time, browser or device information, referrer, errors, and security or diagnostic data.

03

Hosting and security logs

Vercel hosts the site and may retain infrastructure, access, firewall, performance, and diagnostic records under its own service practices. Neurosexology does not treat ordinary hosting logs as research data or use them to infer sexual interests or experiences.

04

Cookies and local storage

The Neurosexology application source sets no cookie and writes nothing to localStorage or sessionStorage. The protected review uses Vercel Authentication, which sets an access cookie after an authorized login. That review-only cookie is controlled by Vercel rather than the application.

05

Analytics status

No @vercel/analytics package, analytics script, custom analytics event, session replay, advertising pixel, or support-link tracker is installed in the current application. If aggregate analytics are later proposed, this record must be updated before deployment with provider, data, retention, cookie, query-string, and opt-out behavior.

No performative cookie banner is shown because the application currently offers no non-essential cookie choice.

06

Email correspondence

An email may contain the sender's address, name or signature, message, attachments, routing headers, timestamps, and technical metadata. It may be used to understand and answer the note, route a correction, consider a proposal, maintain a correspondence record, or improve public explanation in a non-identifying way.

A message is not automatically research data, a testimonial, a published case, or permission for continuing contact.

07

Sensitive information not requested

Do not send medical records, explicit images, legal documents, passwords, financial information, identifying third-party information, detailed patient or student cases, or intimate histories unnecessary to the question. A conceptual question may be asked without explaining why it matters personally.

08

Research-data boundary

No participant study, research intake, waitlist, pre-screening, or lived-experience submission pathway is active. Correspondence cannot be silently converted into a dataset. Any future research collection requires a separate protocol, consent process, responsible institution or investigator, security design, retention rule, withdrawal rule, and public-return plan.

09

External links

Following an external link sends the visitor to another service with its own logs, cookies, privacy terms, and security. The browser may transmit a limited referrer under the site's strict-origin-when-cross-origin policy; sensitive user-entered state is not appended to external URLs.

10

Service providers

Vercel provides hosting and deployment protection. Email and network providers involved in sending or receiving correspondence process messages and metadata. External resources such as PubMed, RAINN, 911.gov, and NO MORE receive a request only when a visitor chooses to open their links.

11

Retention

No fixed correspondence-retention period is currently promised. Messages may be kept while relevant to the conversation, correction history, project administration, safety, or legal obligations, then removed when no longer needed. Provider backups or legal requirements may limit immediate deletion.

12

Access, correction, and deletion questions

A person may ask what correspondence Neurosexology retains about them, request a correction, or request deletion where applicable. Identity may need to be reasonably verified. The response will state any practical, legal, security, provider, or archival limitation rather than guarantee an outcome in advance.

13

Children and age-related collection

The site provides general public knowledge and does not offer accounts, behavioral advertising, participant recruitment, or a form aimed at collecting information from children. Children should not send intimate or identifying information through ordinary email. Any future age-specific research or service requires separate review, consent, and safeguarding.

14

Security limitations

HTTPS, deployment protection for review builds, restrictive browser permissions, framing protection, content-type protection, and a referrer policy reduce some risks. No website or ordinary email channel can promise absolute security, anonymity, clinical confidentiality, legal privilege, or protection from all provider processing.

15

Policy changes

Material changes to analytics, cookies, forms, accounts, providers, research intake, retention, or reuse must be described here before deployment, versioned, dated, and linked through the Corrections record. A technical rebuild alone does not reset the review date.

16

Contact

Privacy questions may be sent to hello@neurosexology.org with the subject “Neurosexology — privacy question.” This founder-led address is not monitored as a crisis, emergency, clinical, safeguarding, or legal service.

Record details

Record ID
NS-GOV-PRIVACY-001
Record type
Governance record
Canonical URL
https://neurosexology.org/privacy/
Publication status
Published
Evidentiary status
Governing commitment
Version
1.0
Author / architect
Nicholas Julian Madison
Related record IDs
NS-PARTICIPATE-001 · NS-GOV-SAFEGUARDS-001 · NS-GOV-CORRECTIONS-001
Last substantively revised
August 9, 2026