Privacy Policy

Last updated: June 10, 2026  ·  Effective: June 10, 2026

EvidX — Academic Research Tool

1. Who We Are

EvidX ("we", "our", "us") is an academic, educational, and informational application that uses artificial intelligence to help users study, comprehend, and summarize scientific and academic PDF documents. EvidX is not a medical application and does not provide medical advice, diagnoses, or clinical recommendations of any kind. We are committed to protecting your privacy and handling your data transparently.

For questions about this policy, contact us at: privacy@evidx.app

2. What Data We Collect

Category Data points Why we collect it
Account data Email address, encrypted password (hashed), account creation date Authentication and account management
Subscription data Subscription plan, billing cycle, in-app purchase transaction IDs, platform (iOS/Android) Payment validation and quota management
Uploaded documents PDF files you upload for analysis AI analysis service delivery
Usage data Number of documents analyzed, feature interactions, app events (anonymized) Service improvement, quota enforcement
Device data & identifiers Device type, OS version, app version, crash reports, and app-specific device identifiers (e.g. install/instance IDs used by RevenueCat for subscription management and by Firebase Cloud Messaging for push notifications) Bug detection, performance monitoring, subscription management, and push notifications

We do not collect: real names, phone numbers, location data, health records of patients, or payment card numbers (payments are processed by Apple/Google directly).

3. How We Use Your Data

We do not sell your data to third parties. We do not use your data for advertising.

4. AI Processing of Your Documents

When you upload a PDF, it is transmitted securely to our AI processing pipeline. Document content is processed by Anthropic's Claude API to generate analysis and summaries for academic and informational purposes only. AI-generated outputs are not medical advice and should not be used for clinical decision-making. Document processing is transient — document content sent to the AI is not stored or used by Anthropic to train their models under our API agreement.

Uploaded PDF files are stored in your account on our Supabase-powered infrastructure and are accessible only to you. You may delete your documents at any time from within the app.

5. Third-Party Services

Service Purpose Data shared
Supabase Database, authentication, file storage Account data, documents, subscription records
Anthropic (Claude API) AI document analysis PDF content (transient, not retained)
Sentry Crash reporting and error monitoring Device info and identifiers, stack traces (no document content)
RevenueCat Subscription management and in-app purchase validation App-specific device identifier, subscription and transaction status
Firebase Cloud Messaging (Google) Push notifications Device push token / installation identifier
PostHog Product analytics Anonymized usage events (with your consent)
Apple / Google In-app payment processing Transaction IDs only (payment data stays with Apple/Google)

6. Data Retention

7. Your Rights

Depending on your location, you may have the following rights:

To exercise any of these rights, email privacy@evidx.app. We will respond within 30 days (GDPR) / 45 days (CCPA).

8. Analytics and Consent (GDPR / CCPA)

We use PostHog to collect anonymized usage analytics. This is optional. You will be asked for your consent when you first launch the app. You can change your preference at any time in Settings → Privacy → Analytics.

If you are located in the European Economic Area (EEA), United Kingdom, or California, we process your data under the following legal bases:

9. Security

We implement industry-standard security measures:

10. Children

EvidX is not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@evidx.app.

11. International Transfers

Your data is stored on Supabase infrastructure (AWS us-east-1). By using EvidX, you consent to your data being transferred to and processed in the United States. Where required by applicable law (e.g., GDPR), such transfers are covered by appropriate safeguards.

12. Changes to This Policy

We may update this policy to reflect changes in our practices or applicable law. We will notify you of material changes via email or an in-app notification. The "Last updated" date at the top of this page reflects the most recent revision.

13. Contact

For privacy-related questions or to exercise your rights:
📧 privacy@evidx.app