Back to AutoEvidence

Privacy Policy

Introduction

Last updated: July 30, 2026

This Privacy Policy explains how AutoEvidence ("we") collects, uses, and protects personal data when you visit autoevidence.com or use the AutoEvidence platform. AutoEvidence is a research-support tool that uses AI to accelerate systematic reviews and meta-analyses — the AI handles volume and consistency, and you handle the scientific judgment.

This policy covers the website and the platform. Our use of cookies is covered separately in our Cookie Policy.

The data we collect

Account data

Your email address and password (never stored in plain text — only a cryptographic hash is kept), plus any settings or profile details you choose to add.

Review content

The research material you create or import on the platform: review protocols (research question, PICO, eligibility criteria), study records (titles, abstracts, and bibliographic metadata), screening decisions, extracted data, analyses, and generated reports.

Usage and server logs

Technical data generated when you use the platform: IP address, browser and device information, pages and actions, and timestamps. We use these logs for security, troubleshooting, and abuse prevention.

Payment metadata

If you purchase a paid plan or review, we keep records of what you bought, invoice details, and payment status.

We never see your card number. Card details are entered directly with Stripe, our payment processor, and are never received or stored by AutoEvidence.

How we use your data

  • ·To provide the service — running searches, screening, extraction, and synthesis on your review content, and showing you the results.
  • ·To keep your account secure — authenticating you, maintaining your session, and detecting suspicious activity.
  • ·To process payments — managing purchases, subscriptions, and receipts through Stripe.
  • ·To communicate with you — sending transactional emails about your account, reviews, and payments (we do not send marketing email without your consent).
  • ·To operate and improve the platform — monitoring performance, fixing errors, and preventing abuse.
  • ·To meet legal obligations — for example keeping required payment and accounting records.

We do not sell your personal data, and we do not use your research content for advertising.

AI processing of your research content

AutoEvidence's core function is AI-assisted evidence review. To deliver it, your review content — study titles, abstracts, and bibliographic metadata, the protocol text you provide (such as your PICO and eligibility criteria), and data extracted from included studies during your review — is sent to third-party AI providers — Anthropic (Claude), OpenAI, and Google (Gemini) — which perform the screening, extraction, and synthesis steps.

This is how the product works, stated plainly: your research content is processed by the named AI providers to return results to you. AutoEvidence never uses your research content to train AI models, and we send it to these providers solely so they can return results to the platform — not for training purposes.

Systematic review work is normally based on published literature. Please do not upload directly identifiable personal data about study participants — the platform is not designed or intended for identifiable patient-level data.

Legal bases (GDPR)

Where the GDPR applies, we rely on the following legal bases:

PurposeLegal basis
Providing the platform, including AI processing of your review contentContract (Art. 6(1)(b))
Security, server logs, abuse prevention, and service improvementLegitimate interest (Art. 6(1)(f))
Optional cookies (analytics or marketing, if ever introduced)Consent (Art. 6(1)(a))
Keeping payment and accounting recordsLegal obligation (Art. 6(1)(c))

Who we share data with

We share data only with the service providers (processors) we need to run AutoEvidence, and only for the purposes described in this policy:

ProviderWhat they do for us
SupabaseDatabase and authentication (PostgreSQL), hosted in the EU (eu-central-1, Frankfurt)
VercelApplication hosting and content delivery
InngestWorkflow orchestration for the review pipeline (queues and step state)
Anthropic, OpenAI, GoogleAI processing of research content (screening, extraction, synthesis)
StripePayment processing — card data is handled entirely by Stripe
ResendDelivery of transactional emails

We may also disclose data where the law requires it — for example in response to a valid legal request.

International transfers

Your account data and review content are stored in the EU: our database and authentication run on Supabase in the eu-central-1 region (Frankfurt, Germany).

Some of our processors — in particular the AI providers — may process data outside the EU/EEA, for example in the United States. Where that happens, transfers are protected by recognised safeguards such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision.

How long we keep your data

  • ·Account data and review content — kept for as long as your account exists. When you delete your account, or ask us to, we delete your data.
  • ·Server logs — kept for a limited period for security and troubleshooting, then deleted.
  • ·Payment records — kept for as long as applicable accounting and tax law requires, even after account deletion.

To request deletion, email support@autoevidence.com and we will act on it without undue delay.

Your rights

Under the GDPR you have the right to:

  • ·Access the personal data we hold about you.
  • ·Rectify data that is inaccurate or incomplete.
  • ·Erase your data ("right to be forgotten").
  • ·Receive your data in a portable format.
  • ·Object to processing based on legitimate interest, and restrict processing in certain cases.
  • ·Withdraw consent at any time, where processing is based on consent.

To exercise any of these rights, email support@autoevidence.com. We respond within one month, as the GDPR requires. You also have the right to lodge a complaint with a supervisory authority — for example the Danish Data Protection Agency (Datatilsynet).

Security

  • ·All traffic is encrypted in transit (TLS), and data in our database is encrypted at rest.
  • ·Passwords are stored only in hashed form.
  • ·Access to production systems is restricted to what is strictly needed to operate the service.
  • ·Card data never touches our systems — it is handled entirely by Stripe.

No system is completely secure, but if a breach affects your personal data we will notify you and the relevant authorities as the law requires.

Cookies

By default we set only strictly necessary cookies: your Supabase authentication session and the ae_consent cookie that remembers your choices for 180 days. We do not currently load any third-party analytics or marketing cookies. Full details, and the option to change your choices, are in our Cookie Policy.

Children, changes, and contact

Children

AutoEvidence is a professional research tool and is not directed at children under 16. We do not knowingly collect data from children; if you believe we have, contact us and we will delete it.

Changes to this policy

We may update this policy as the platform evolves. The date at the top always shows the latest version, and we will highlight material changes on the site or by email.

Contact

Questions about this policy or your data? Email us at support@autoevidence.com.