Skip to content
Research RatsRESEARCH RATS

Privacy Notice

Last updated: 7 July 2026

Controller: Research Rats
Legal form: Sole trader
Website: https://researchrats.co.uk

Business correspondence address:
Research Rats
Office 19734
182-184 High Street North
East Ham
London
E6 2JA
United Kingdom

Privacy contact: privacy@researchrats.co.uk
Legal notices: legal@researchrats.co.uk
Content corrections and safety concerns: content@researchrats.co.uk

Research Rats is an evidence-led educational publishing and digital research platform. We help readers understand the current evidence, uncertainty, safety considerations and regulatory context surrounding peptides and related compounds.

This Privacy Notice explains how we collect, use, share and retain personal data when you use the website, create an account, contact us, receive emails, access member-only content if available, or buy and manage a paid membership.

1. Important health-data warning

Research Rats does not intend to collect personal medical information, health records, diagnoses, treatment history, medication lists, blood results, body images, progress photos, adverse-event reports linked to an identifiable individual, or other special-category health data.

You must not submit personal medical information through comments, contact forms, support emails, community tools or content-correction routes.

If you choose to send sensitive or health-related information despite this warning, Research Rats may process it only where necessary to respond, manage safety or legal risk, comply with legal obligations, protect legitimate interests, or handle your request.

The optional My Protocols tool is the single, deliberate exception. If you choose to use it, you can store a private record of protocols you have independently selected, your own schedule entries, occurrence marks, structured observations and — only if you turn it on — weight entries. This information may include health-related data. It is stored only because you enter it, after you give your explicit consent; it is visible only to your account, is never published, sold or used for advertising, and you can export it or permanently delete it at any time from Privacy & data in your account.

2. Personal data we may collect

We may collect:

  • email address;
  • name;
  • password/authentication credentials handled by Supabase;
  • authentication user ID;
  • 18+ confirmation status;
  • account status;
  • subscription status;
  • payment/customer ID through Stripe;
  • payment history and accounting records;
  • IP address;
  • device, browser and technical data;
  • authentication/session cookie data;
  • cookie or localStorage preference records;
  • Vercel Speed Insights performance telemetry;
  • analytics data if optional analytics are enabled later;
  • email marketing preferences;
  • unsubscribe records;
  • consent records;
  • optional My Protocols records you choose to store (protocols, compounds, schedules, occurrence marks, observations, optional weight entries and your consent record), which may include health-related data;
  • support messages;
  • legal/privacy/content correction emails;
  • system logs;
  • security and abuse-prevention records;
  • error reports if error monitoring is added later.

3. How we collect data

We collect data:

  • directly from you when you create an account, contact us or manage preferences;
  • automatically through website hosting, authentication, security and performance tools;
  • from payment processors when you buy or manage a paid membership;
  • from email providers when sending transactional or marketing emails;
  • from technical service providers that support hosting, authentication, email, payments or site reliability.

4. Purposes and lawful bases

We use personal data for the following purposes:

  • Account creation and login. Email, name, authentication ID, password handled by Supabase. Lawful basis: contract / steps before contract.
  • Age confirmation. 18+ confirmation status. Lawful basis: contract / legitimate interests / legal risk management.
  • Member access. Account status, authentication/session data. Lawful basis: contract.
  • Transactional emails. Email, account status. Lawful basis: contract / legitimate interests.
  • Password reset and verification. Email, authentication records. Lawful basis: contract / security legitimate interests.
  • Website security. IP address, technical logs, account activity. Lawful basis: legitimate interests.
  • Abuse prevention. IP address, account activity, moderation records. Lawful basis: legitimate interests.
  • Performance monitoring. Device/browser data, performance telemetry. Lawful basis: legitimate interests, subject to PECR review.
  • Cookie/site preference record. rr-cookie-consent localStorage key. Lawful basis: legitimate interests / consent record management.
  • Marketing emails. Email, preference status. Lawful basis: consent.
  • Paid membership. Stripe customer ID, subscription status, payment history. Lawful basis: contract / legal obligation.
  • Accounting and tax. Payment and invoice records. Lawful basis: legal obligation.
  • Legal/privacy/content correspondence. Contact details, message content. Lawful basis: legitimate interests / legal obligation.
  • Content corrections. Name/email if supplied, correction details. Lawful basis: legitimate interests.
  • Future comments, if enabled. Account details, comment content. Lawful basis: contract / legitimate interests.
  • My Protocols (optional member tool).The protocol, schedule, occurrence, observation and optional weight records you choose to store, with your consent record. While My Protocols access is active, our lawful basis is UK GDPR Article 6(1)(b): processing necessary to provide the premium My Protocols service requested by the member. If membership becomes inactive, our lawful basis for retaining the member’s My Protocols records is UK GDPR Article 6(1)(a): the member’s consent to retention so that the records can be restored if membership is renewed. The member can withdraw this consent and permanently delete the records at any time through Privacy & data. Our special-category condition throughout is UK GDPR Article 9(2)(a): the member’s explicit consent to processing the health-related information they choose to enter for the specified My Protocols purposes. Withdrawal does not affect processing carried out before consent was withdrawn.

5. Third-party processors

Research Rats may use:

  • Vercel, for hosting/deployment and Speed Insights;
  • Supabase, for database, authentication and session management;
  • Resend, for transactional and marketing email;
  • Stripe, for payment and subscription processing;
  • Google Workspace, for business email and administration;
  • GitHub, for code repository and deployment workflow;
  • Plausible, if enabled later, for cookieless analytics.

We do not currently use advertising trackers, marketing pixels, Google Analytics, Google Tag Manager, Hotjar, Microsoft Clarity, PostHog, Segment, Fathom, Mixpanel, Amplitude, FullStory, Heap, Datadog, Sentry, session replay or behavioural advertising tools, based on the current technical audit supplied for drafting.

6. International transfers

Some providers may process data outside the UK or EEA depending on infrastructure, support access, sub-processors and account configuration.

Where international transfers occur, Research Rats will seek to rely on appropriate safeguards such as UK International Data Transfer Agreements, UK Addendum to EU Standard Contractual Clauses, adequacy regulations, processor terms or other lawful transfer mechanisms.

7. Retention

We retain personal data only for as long as necessary.

  • Account data. While account exists, then as long as needed for legal, security or business purposes.
  • Authentication/session data. As required for login/security, subject to provider settings.
  • 18+ confirmation. While account exists and as needed to evidence compliance.
  • Marketing consent records. As long as needed to evidence consent/unsubscribe.
  • Support/legal/privacy emails. As long as needed to handle the request and evidence compliance.
  • Content correction records. Usually up to 30 days after closure, unless legal/safety risk requires longer.
  • Payment/accounting records. As long as legally required.
  • Security logs. Limited period appropriate to security and troubleshooting.
  • Comments, if enabled. While published, then deleted/anonymised where practicable unless retention is necessary.
  • My Protocols records.Retained until you delete them from Privacy & data, or until you withdraw consent — in both cases deletion is immediate and permanent. They are also deleted when a whole-account deletion request is completed. Records are kept while your membership is inactive only so they can be restored if you renew; they are never reused for analytics, advertising, research, product training or any unrelated purpose.

8. Your rights

Depending on the lawful basis and circumstances, you may have rights to:

  • access your personal data;
  • correct inaccurate data;
  • request deletion;
  • restrict processing;
  • object to processing;
  • data portability;
  • withdraw consent;
  • complain about how your data is handled.

Requests should be sent to privacy@researchrats.co.uk.

Deleting your whole account. There is no self-service control for this on the website yet. Email privacy@researchrats.co.uk from the address your account uses and we will delete the account and the data held with it. These requests are handled manually at present, so they are not instant. This is separate from deleting your My Protocols data, which you can do yourself at any time from Privacy & data, and separate again from cancelling a paid membership, which is managed through the billing portal on your account page. Cancelling a membership does not delete your data, and deleting data does not cancel a membership.

9. Marketing emails

Marketing emails, newsletters, paid membership promotions and research alerts will be sent only where permitted and, where required, only with opt-in consent. Every marketing email will include an unsubscribe route.

Transactional emails, such as account verification, password reset, legal notices and service messages, are not marketing emails.

10. Complaints

If you have a data-protection complaint, contact privacy@researchrats.co.uk.

You may also complain to the Information Commissioner’s Office if you are dissatisfied with the outcome.

11. Changes to this notice

We may update this Privacy Notice when our services, technology, legal obligations or processing activities change. Material changes will be brought to users’ attention where appropriate.

We use essential site technologies for login, security and preferences, plus cookieless performance measurement. No advertising cookies, marketing pixels or session replay are currently used.

Learn more