Legal
Privacy Policy
Last updated: July 2026
Self-hosted by design
EvidenceFlow is open-source, self-hosted software. Each deployment is run independently by the organization or individual operating it — there is no central EvidenceFlow server collecting data across installations. This policy describes how a typical deployment handles data; the operator of your specific instance is the actual data controller.
What is stored
Account details (name, email, a hashed password), and any project, study, screening, extraction, and meta-analysis data you enter are stored in the PostgreSQL database of the deployment you use. Uploaded PDFs are stored on that deployment's server. None of this is transmitted to any third party by EvidenceFlow itself.
AI processing
AI-assisted screening, scoring, and extraction run locally via Ollama on the deployment's own infrastructure. Study titles, abstracts, and full text used for AI suggestions are processed locally and are not sent to any external AI API.
Third-party lookups
To retrieve full-text PDFs and bibliographic metadata, EvidenceFlow queries public scholarly APIs — PubMed Central, Unpaywall, Europe PMC, Semantic Scholar, OpenAlex, Crossref, bioRxiv/medRxiv, and CORE. Only identifiers such as titles, DOIs, and PMIDs are sent to these services to locate open-access content.
Session storage
Authentication tokens are stored in your browser's local storage to keep you signed in. Clearing your browser storage or logging out removes them.
Your data
You own the data you enter. To request export or deletion of your account or project data, contact the administrator of the EvidenceFlow deployment you use.
Changes to this policy
This policy may be updated as the platform evolves. Check this page for the current version.