At the About ME/CFS Research Archive (accessible from https://aboutmecfs.org), we hold user privacy and health information confidentiality as foundational ethical commitments. We recognize the profound sensitivity surrounding chronic, stigmatized, and post-viral medical conditions.

1. Zero Protected Health Information (PHI) Collection

We do not require user accounts, logins, or registration. We do not collect, process, solicit, or store personal health records (PHR), genetic test files, diagnostic records, or any form of Individually Identifiable Health Information under the standards of the Health Insurance Portability and Accountability Act (HIPAA).

2. Zero Commercial Tracking & Data Monetization

We maintain an absolute prohibition against monetizing visitor data:

  • We do not sell, rent, or trade visitor browsing patterns or email addresses to third-party data brokers, pharmaceutical advertisers, or insurance underwriting aggregators.
  • We do not utilize cross-site behavioral tracking pixels, third-party marketing beacons, or invasive biometric fingerprinting scripts.

3. Server Logs & Cloudflare CDN Edge Processing

To maintain security, mitigate distributed denial-of-service (DDoS) attacks, and ensure rapid global performance for cognitively impaired users, this site is deployed via Cloudflare Pages. Cloudflare edge servers may record standard technical connection metadata:

  • Client IP address (anonymized/truncated where feasible)
  • Browser user agent string and operating system
  • Timestamp, HTTP request status code, and bytes transferred

These server logs are retained solely for short-term diagnostic stability, anti-abuse monitoring, and aggregate traffic metrics.

4. Interactive Tools & Local Client-Side Execution

Our interactive health utilities—such as the Aerobic Threshold (AT) Pacing Screener—execute 100% locally within your web browser using vanilla JavaScript. No numeric inputs (age, resting heart rate, severity) are transmitted to or stored on any remote server.

5. Direct Inquiries & Communications

If you voluntarily contact us via email, your email address and message contents are utilized solely to respond directly to your correspondence. Email communications are archived in secure, encrypted mailboxes and never added to marketing lists.

6. Inquiries & Data Rights

Under GDPR, CCPA, and international data protection laws, you retain the right to query what information (if any) is held regarding your correspondence. Inquiries may be directed to our privacy compliance desk at [email protected].