Legal

Privacy Policy

Last updated: July 2026

Self-hosted by design

EvidenceFlow is open-source, self-hosted software. Each deployment is run independently by the organization or individual operating it — there is no central EvidenceFlow server collecting data across installations. This policy describes how a typical deployment handles data; the operator of your specific instance is the actual data controller.

What is stored

Account details (name, email, a hashed password), and any project, study, screening, extraction, and meta-analysis data you enter are stored in the PostgreSQL database of the deployment you use. Uploaded PDFs are stored on that deployment's server. None of this is transmitted to any third party by EvidenceFlow itself.

AI processing

AI-assisted screening, scoring, and extraction run locally via Ollama on the deployment's own infrastructure. Study titles, abstracts, and full text used for AI suggestions are processed locally and are not sent to any external AI API.

Third-party lookups

To retrieve full-text PDFs and bibliographic metadata, EvidenceFlow queries public scholarly APIs — PubMed Central, Unpaywall, Europe PMC, Semantic Scholar, OpenAlex, Crossref, bioRxiv/medRxiv, and CORE. Only identifiers such as titles, DOIs, and PMIDs are sent to these services to locate open-access content.

Session storage

Authentication tokens are stored in your browser's local storage to keep you signed in. Clearing your browser storage or logging out removes them.

Your data

You own the data you enter. To request export or deletion of your account or project data, contact the administrator of the EvidenceFlow deployment you use.

Changes to this policy

This policy may be updated as the platform evolves. Check this page for the current version.