Trust Center

What happens to your data when you use the screening tool, who else touches it, what we will sign, and what we do not yet have. Written for the person in procurement or research IT who has to sign this off.

Screening is local-first

When you import a search export and screen it, the records are parsed, de-duplicated, ranked, and decided in your browser. Nothing is uploaded and no account is required. Close the tab and the data is gone unless you saved it. This is the default, not a mode you have to select.

Data reaches our servers only when you deliberately do one of these things: cloud-save a review so it syncs across devices, invite a collaborator, upload a PDF for full-text screening, or run one of the AI features. Each of those is an explicit action with a visible control.

Where cloud data lives

Cloud-saved reviews sit in a Postgres database with row-level security enabled and a deny-by-default policy, so a row is reachable only through a query that proves the caller owns it or was invited to it. Uploaded PDFs go to a private storage bucket that is not publicly addressable. Traffic is encrypted in transit.

AI features send only the text needed for the specific operation you ran, at the moment you run it. Your corpus is not used to train models and is not retained by us for training.

Subprocessors

The third parties that can process your data, and what each one sees.

ProviderPurposeData involved
SupabasePostgres database, authentication, and private file storage for cloud-saved reviewsAccount details, review metadata, records you cloud-save, uploaded PDFs
VercelApplication hosting and content deliveryRequest logs, IP address at the edge
AnthropicAI screening, AI extraction, AI translation, and Ask your recordsOnly the titles, abstracts, or full texts you send to an AI feature, at the moment you run it
ResendTransactional email (sign-in links, invitations, notifications)Email address and message content
PayPalSubscription billing for self-serve plansBilling identifiers. Card details never reach our servers

Your data, your call

  • Export any review to CSV, RIS, or Excel at any time, on any plan, including the free one. There is no export paywall and no lock-in.
  • Delete a cloud review and its records and uploaded PDFs are removed. Ask us to delete your account and we remove the account and everything attached to it.
  • Cancelling a paid plan does not delete your data or your exports.

What we will provide and sign

  • A formal written quote, on request, for any plan.
  • Purchase orders accepted; we invoice in US dollars by bank transfer.
  • W-9 or the equivalent tax form for your jurisdiction.
  • Completed security questionnaires.
  • A data processing agreement. A business associate agreement is available on the Enterprise plan.
  • Vendor registration in your procurement portal, where you require it.

What we do not have yet

We would rather you learn this here than three weeks into a procurement review.

  • No SOC 2 report and no ISO 27001 certificate. Neither audit has been completed. Some competitors hold these; if your institution requires one as a condition of purchase, we are not a fit today and we will tell you so rather than run you through a process that cannot close.
  • No HIPAA certification. HIPAA has no certifying body, so nobody can hold one, but the meaningful question is whether we will sign a business associate agreement and operate to it. We will, on the Enterprise plan. Screening bibliographic records does not normally involve protected health information in the first place.
  • No formal VPAT. The tool ships keyboard navigation, adjustable font size, and a colour-blind-safe palette, but no accessibility conformance report has been published.

Something here that procurement needs answered?

Send the questionnaire and we will complete it, or tell us the blocker and we will tell you straight whether we clear it.

Talk to our team