Privacy

Privacy Policy

This policy explains how AI Systematic Review, operated from the Netherlands, handles account, research, voice, and billing data in the private-beta SaaS service. It applies to the website, application, and support channels.

Last updated: 4 September 2026.

Information we process

  • Account and access data: name, email address, authentication identifiers, profile settings, private-beta status, and support communications.
  • Review content: research questions, criteria, chat messages, prompts, uploaded PDFs and bibliographic files, study data, screening and extraction decisions, generated outputs, human approvals, and provenance records.
  • Billing data: Stripe customer and subscription identifiers, invoice and payment status, credit grants and usage, and refund or dispute records. Complete card details are collected by Stripe and are not stored by us.
  • Technical data: IP address, request and security logs, device or browser information, service events, error details, performance metrics, sanitized page journeys and interaction outcomes, and cookie or local-storage state used for authentication, abuse prevention, workflow recovery, and consented analytics.
  • Contact and waitlist data: the details you submit through our contact or waitlist forms and your marketing preferences.

How we use information and our legal bases

  • Contract: create and secure your account, run the review workflow, store project history, produce exports, provide support, and administer subscriptions and credits.
  • Legitimate interests: protect the service, prevent abuse and fraud, diagnose failures, maintain reproducibility and provenance, improve reliability, and understand aggregate service use.
  • Legal obligations: keep required accounting and transaction records, respond to lawful requests, and establish or defend legal claims.
  • Consent: use optional Google Analytics measurement, send optional marketing, access your microphone, or retain raw voice audio when an explicit storage choice is offered. You may withdraw consent without affecting earlier lawful processing.

AI processing and research content

The service sends prompts and the project context needed for a task to configured AI providers. That context can include chat text, research questions, study metadata, extracted PDF text, and selected document passages. We minimise the context to what the requested stage needs, but do not promise that every prompt is free of personal data.

OpenAI states that API inputs and outputs are not used to train its models by default. Provider-side retention and abuse monitoring remain governed by our provider contract and the provider policies in force at the time.

This service is designed for scientific literature and de-identified research material. Do not upload identifiable patient records, protected health information, or other special-category personal data unless we have agreed in writing that the required contract and safeguards are in place.

Voice data

  • Microphone audio is sent to OpenAI for transcription and, when enabled, realtime voice processing. Generated speech is also produced by OpenAI.
  • Raw microphone audio is not stored by us by default. If you explicitly choose a feature that persists it, the recording becomes a project artefact and follows the project retention rule.
  • Transcripts and the resulting chat messages are stored with the project for reproducibility. Browser microphone permission can be revoked at any time, and text chat remains available.

Service providers and recipients

These providers process data only for the functions described. Redis is self-hosted inside the selected application hosting environment, not a separate Redis SaaS recipient. The deployment host and region are environment-specific and will be confirmed before external paid access.

ProviderPurposeTypical data
OpenAIAI reasoning, document-context processing, transcription, realtime voice, and speech synthesisPrompts, relevant project excerpts, outputs, voice audio, and pseudonymous usage metadata
GoogleGemini routing, reCAPTCHA abuse prevention, and consented Google Analytics measurement when those configured features are usedPrompt and routing context; form security, device, and network signals; or sanitized website interaction, performance, and pseudonymous analytics-cookie data
SupabaseAuthentication, PostgreSQL database, and project file storageAccount data, project records, uploaded files, artefacts, and access logs
StripeCheckout, subscriptions, credit purchases, invoices, tax configuration, refunds, and fraud controlsIdentity and billing details, payment method data, transaction status, and Stripe identifiers
Application host and self-hosted RedisRun the web and worker services; Redis provides durable queues, event history, and rate limitingEncrypted application traffic, job payloads, short-lived operational state, and service logs
Resend and MailerLiteDeliver contact messages and administer the optional waitlist or newsletterName, email address, message, role, and communication preferences

PubMed/NCBI, MeSH, Crossref, and public full-text sources also receive the search terms or identifiers needed to retrieve public literature. We do not intentionally send them account or billing data.

Retention, export, and deletion

  • Project files, PDFs, messages, decisions, generated artefacts, and provenance are retained for the life of the project; no separate automatic project expiry currently applies.
  • Deleting a project permanently removes its storage prefix and cascading project records. Successful account deletion has no recovery grace period and also cancels the active subscription and removes the Stripe customer.
  • Accounting, payment, credit, fraud-prevention, and dispute records that must be retained are pseudonymised and kept for the Dutch seven-year accounting baseline, subject to the final legal review and any mandatory exception.
  • Before deletion, you can download an account manifest and create the existing publication and reproducibility bundle for each project. Provider copies may remain for their contractual security or legal retention period.

Cookies and browser storage

We use authentication storage, a short-lived private-beta access mirror cookie, and local or session storage needed for preferences and workflow recovery. These controls do not grant backend authority on their own. When configured, Google reCAPTCHA processes device and network signals to protect public forms.

Google Analytics is optional and does not load until you choose “Allow analytics.” If allowed, Google sets first-party analytics identifiers and receives sanitized route names, navigation and form outcomes, coarse feature events, browser or device information, performance metrics, and approximate location derived from network information. We replace project, invitation, and article identifiers before sending page data. Query strings are stripped except an allowlist of campaign keys (utm_source, utm_medium, utm_campaign, utm_content, utm_term, utm_id, gclid, gad_source, gclsrc, dclid, wbraid, and gbraid). We do not send research questions, searches, study content, project identifiers, prompts, transcripts, names, or email addresses to Analytics. Advertising storage, Google Signals, and advertising personalization are disabled.

You can change or withdraw this choice at any time through “Analytics choices” in the site footer or project terminal. Withdrawing consent stops further Analytics events and removes accessible first-party Google Analytics cookies on this site.

Your choices and rights

  • Depending on applicable law, you may request access, correction, deletion, restriction, objection, or portability, and may withdraw consent.
  • You may object to processing based on legitimate interests and may complain to the Dutch Data Protection Authority or the supervisory authority where you live or work.
  • We normally respond within one month. We may ask for information needed to verify your identity and may retain data where law or an overriding legal claim requires it.
  • The service does not make solely automated decisions that produce legal or similarly significant effects about you. Research suggestions and screening outputs remain subject to human review.

Security and international transfers

We use access controls, tenant-isolation policies, encryption provided by our infrastructure, signed storage access, and operational logging. No internet service can guarantee absolute security.

Some providers may process information outside the European Economic Area. Where required, we rely on an adequacy decision, standard contractual clauses, or another lawful transfer mechanism. Contact us for the transfer safeguard relevant to your account.

Controller and contact

Data controller: AI Systematic Review. For privacy requests or questions, email george@systematicreviewtools.app. You can also use the in-product export and deletion controls in Settings.

See the Terms of Use for service and billing conditions.