How RigorMD handles your data. Plain-English headings, operative policy.
Your account details (name and email, held by our authentication provider), the manuscript package you upload, the free text you type into the Design and Revision tools (your study description and the reviewer comments you are responding to), payment records, and the operational logs needed to run and audit the service — submission status, report access, and error diagnostics. We do not collect more than the service needs.
The processors actually in the stack. The same applies to the free text you type into the Design and Revision tools, which is processed like manuscript content. No others receive your content.
| Processor | Role |
|---|---|
| Clerk | Authentication and organization accounts |
| Stripe | Payment processing — card details never touch our systems |
| Anthropic & OpenAI | The two appraisal engines, via their commercial APIs |
| Crossref, NCBI & the DOI Foundation | Reference verification — cited DOIs and PMIDs are looked up in the public registries by bare identifier only; manuscript text is never sent |
| Cloudflare R2 | Manuscript and report file storage (S3-compatible object store) |
| Resend | Transactional email (report-ready notices) |
| Vercel | Web hosting |
| Northflank | Application workers and database hosting |
| Sentry | Error monitoring |
| Plausible Analytics | Cookieless, aggregate visit measurement on the public marketing pages only — it is never loaded on your dashboard, submissions, or report pages, and never receives manuscript content, titles, or findings |
Manuscript content reaches the model providers through their commercial APIs only, and we do not train models on your files. How uploads are screened and isolated is described on the security page.
Manuscript content is retained for 90 days by default, then expired and purged — files, artifacts, reports, and findings — after a short grace period, with an audit record of the purge. Encrypted backups age out on a fixed schedule after a deletion or purge — up to 14 days for database backups and roughly 35 days for the object-storage replica. Billing and audit records are preserved as required. You can request deletion of a submission at any time by emailing support@abigailmd.com from your account email — it follows the same purge path. An in-product delete control is on the roadmap.
RigorMD is operated by Abigail MD, Inc., the data controller, and processing happens in the United States on the processors listed above (visit analytics is processed by Plausible in the EU). We process your data to deliver the service you purchase (your account, manuscript processing, report delivery), to keep the service secure (screening, audit logs, error monitoring), and to meet legal obligations (billing records).
Why we are allowed to process it. We process your account details and your manuscript to deliver the service you bought — that is, to perform our contract with you. We process operational logs, screening results, and error diagnostics because we have a legitimate interest in keeping the service secure and auditable. We keep billing records because the law requires it.
Sending data across borders. Processing happens in the United States. Where your data is protected by the UK GDPR, the New Zealand Privacy Act, or the Australian Privacy Principles, we rely on contractual safeguards with each processor listed above — standard contractual clauses, or that provider's equivalent data-processing terms — to hold them to the standard your own law requires.
Privacy officer. Ramsey Dallal, support@abigailmd.com. Write to the same address to exercise any of the rights below.
You can request a copy of your data, correction, or deletion at support@abigailmd.com from your account email. If you are in the EU or UK, we honor these requests in line with the GDPR's access, rectification, erasure, and objection rights, and we respond to verified requests within 30 days (one month). You may also lodge a complaint with your supervisory authority.
Cookies: only the ones required for sign-in and payment — our visit measurement sets none. On the public marketing pages we count visits with Plausible, a cookieless analytics tool that stores no personal identifiers and cannot follow you across sites; it is never loaded once you sign in. If you arrive from a campaign link, the campaign labels in the link (utm codes — no personal data) are kept in your browser's local storage for up to 90 days so a later purchase can be credited to the campaign.