Privacy
How RigorMD handles your data. Plain-English headings, operative policy.
§01 What we collect
Your account details (name and email, held by our authentication provider), the manuscript package you upload for a review or re-review, the reviewer letter you paste in when you are responding to reviewers, payment records, and the operational logs needed to run and audit the service — submission status, report access, and error diagnostics. When you create an account you accept these notices, and we record the date of that acceptance together with the versions of the Terms and Privacy pages we had published when we recorded it. We do not collect more than the service needs.
§02 Data processing — who touches what
The processors actually in the stack. The same applies to the reviewer letter you paste in, which is processed like manuscript content. No others receive your content.
| Processor | Role |
|---|---|
| Clerk | Authentication and organization accounts |
| Stripe | Payment processing — card details never touch our systems |
| Anthropic & OpenAI | The two appraisal engines, via their commercial APIs |
| Crossref, NCBI & the DOI Foundation | Reference verification — cited DOIs and PMIDs are looked up in the public registries by bare identifier only; manuscript text is never sent |
| Cloudflare R2 | Manuscript and report file storage (S3-compatible object store) |
| Resend | Transactional email (report-ready notices) |
| Vercel | Web hosting |
| Northflank | Application workers and database hosting |
| Sentry | Error monitoring |
| Plausible Analytics | Cookieless, aggregate visit measurement on the public marketing pages only — it is never loaded on your dashboard, submissions, or report pages, and never receives manuscript content, titles, or findings |
Manuscript content reaches the model providers through their commercial APIs only, and we do not train models on your files. How uploads are screened and isolated is described on the security page.
§03 Retention and deletion
Manuscript content is retained for 90 days by default, then expired and purged — files, artifacts, reports, and findings — after a short grace period, with an audit record of the purge. Encrypted backups age out on a fixed schedule after a deletion or purge — up to 14 days for database backups and roughly 35 days for the object-storage replica. Billing and audit records are preserved as required. You can request deletion of a submission at any time by emailing support@abigailmd.com from your account email — it follows the same purge path. An in-product delete control is on the roadmap.
§04 Your rights and contact
RigorMD is operated by Abigail MD, Inc., the data controller, and processing happens in the United States on the processors listed above (visit analytics is processed by Plausible in the EU). We process your data to deliver the service you purchase (your account, manuscript processing, report delivery), to keep the service secure (screening, audit logs, error monitoring), and to meet legal obligations (billing records).
Why we are allowed to process it. We process your account details and your manuscript to deliver the service you bought — that is, to perform our contract with you. We process operational logs, screening results, and error diagnostics because we have a legitimate interest in keeping the service secure and auditable. We keep billing records because the law requires it.
Sending data across borders. Processing happens in the United States. Where your data is protected by the UK GDPR, the New Zealand Privacy Act, or the Australian Privacy Principles, we rely on contractual safeguards with each processor listed above — standard contractual clauses, or that provider's equivalent data-processing terms — to hold them to the standard your own law requires.
Privacy officer. Ramsey Dallal, support@abigailmd.com. Write to the same address to exercise any of the rights below.
You can request a copy of your data, correction, or deletion at support@abigailmd.com from your account email. If you are in the EU or UK, we honor these requests in line with the GDPR's access, rectification, erasure, and objection rights, and we respond to verified requests within 30 days (one month). You may also lodge a complaint with your supervisory authority.
Cookies: only the ones required for sign-in and payment — our visit measurement sets none. On the public marketing pages we count visits with Plausible, a cookieless analytics tool that sets no identifier of its own and cannot follow you across sites. It never runs on your dashboard, on your submission pages, or on your report pages: we exclude those by their address, not by whether you are signed in. Because Plausible counts the page address you arrived at, any campaign parameters in that address are part of what it records.
If you arrive from a campaign link, we keep only short campaign labels from that link — the utm codes, which may contain lowercase letters, numbers, hyphens and underscores and nothing else — in your browser's local storage, so that a later purchase can be credited to the campaign. Our own campaign links carry no personal data. Anything else in the link is discarded before we store, send, or bill against any of it. Stored labels stop counting after 90 days and are deleted from your browser the next time you visit; you can also clear them yourself at any time in your browser's site-data settings.