Privacy Notice

What RAPPORT collects, why, who processes it, and how long it is kept
← Back to start
This notice describes the platform as it runs today. The IRB-approved participant consent form, when it is issued, governs the research study; if the two differ, the consent form applies. This notice is updated whenever the platform changes what it collects (see the date at the end).

Who runs RAPPORT

RAPPORT is operated by MindImmerse LLC (Texas) for a research pilot led at the University of Texas at Arlington School of Social Work. The study lead is Donna Schuman, PhD, LCSW, LPC. The study lead is a co-founder of MindImmerse LLC; this interest is disclosed and managed under a UTA conflict-of-interest plan.

What we collect

InformationWhere it comes fromWhy we collect it
Your study ID (for example 2026-01)You enter it at sign-in. Only IDs issued by the study team are accepted.Links your work across sessions and to your study record. Your name is not stored with the research data; the study team holds the key that links ID to person.
The display name you chooseYou enter it at sign-in. It can be any name.Daniel and Dr. Hayes say it aloud. It is sent to the avatar and AI services for that purpose only.
Transcripts of what you and the simulated client (Daniel) and coach (Dr. Hayes) sayYour speech is converted to text by the avatar service; the avatars' replies are generated text.The study analyzes how the skill is practiced. The coach and the rubric scorer read the transcript to give you feedback.
Your written work: the crisis response plan card, your reflection, the transcript of record, the rubric result and its feedback, the three-beats rehearsal responsesYou write them in the modules; the rubric scorer produces the result.Study outcomes and your feedback.
Activity events: which step you were on and when, one-minute activity signals while you are working, how much of each video you played, self-check scores, when a live session started and ended, whether demo mode was usedRecorded by the page as you work.Time on task and completion; the study needs to know how long the training takes.
Technical details: browser type (user agent string), window size, the time of each eventRecorded by the page.To understand and fix problems with the platform.
Avatar session records: the vendor's session identifier and the receipt showing its recording was deletedCreated when a live session starts and ends.Proof that the vendor copy of your session was removed.

What we do not collect

Who processes the information

OrganizationWhat it receivesHow long it keeps it
MindImmerse LLC (on Amazon Web Services, United States; storage in the Ohio region, model calls in US regions)Everything in the table above, stored in the research database.Until the study team confirms the record has been transferred to UTA, then as the IRB protocol requires. Backups are kept for up to one year in a locked archive that no one can delete early.
Anam AI (avatar service)Your live microphone audio and camera video during the session; your chosen display name; the text the avatar speaks.RAPPORT deletes the session and its recording from Anam by automatic request when your session ends and stores the receipt. Anam keeps technical session records (identifiers and timestamps, no content).
Amazon Bedrock (Claude AI models, run by Amazon Web Services inside MindImmerse's account)The transcript text so that Daniel and Dr. Hayes can reply, and so the rubric scorer can score your work; your chosen display name.Processed in the United States and not stored after the reply is returned. Amazon Web Services states that content sent to Bedrock is not used to improve the models and is not shared with the model provider (Anthropic). Anthropic receives nothing.

No one else receives your information. It is not sold or used for advertising.

Who can see it

How we protect it

Only study IDs on the participant list can sign in, and each ID has an access code that is required with it; both come to you privately from the study team. Every request from your browser carries a signed sign-in token that expires after 12 hours. Data travels over HTTPS. The research database is on a private server that only the platform's own services can reach; it is encrypted at rest, backed up every six hours in three separate places, and its records cannot be deleted by software in this phase. Staff accounts are created by an administrator only. The full control set is documented in the platform's security manual, which is available to institutional reviewers.

Your choices

Contact

Donna Schuman, PhD, LCSW, LPC
Study lead; Co-Founder, MindImmerse LLC
Contact details are on the participant consent form.

Questions about your rights as a research participant go to the UTA Office of Research Compliance / Institutional Review Board, as listed on the consent form.

Version 3, 14 September 2026 (version 3 adds the access code to the sign-in description); version 2, 14 September 2026 (version 1 earlier the same day named Anthropic as a processor; the model calls now run inside Amazon Web Services). Source: docs/security-manual.md, section 2 (data inventory). This page is updated in the same change as any change to what the platform stores.