1. Introduction
This privacy policy explains how Evidora collects and processes personal data when you use the service at https://evidora.se/en. We comply with the EU General Data Protection Regulation (GDPR) and applicable data-protection law.
Evidora is a medical evidence search and synthesis service for licensed healthcare professionals. The service is not intended for patients and does not replace clinical judgement.
2. Controller
Evidora is the controller for the processing described here. Contact us at support@evidora.se for privacy questions.
3. Personal data we process
We process account data, chats and questions, technical data, and feedback you choose to send us. If you explicitly turn on voice-camera analysis, selected camera frames and AI-derived visual descriptions are also processed and may contain health data.
Patient-identifying information
Do not enter or show names, identity numbers, faces, labels, documents, screens, or other information that can identify a patient. Use hypothetical or de-identified clinical scenarios and camera views, obtain everyone’s consent, and use the feature only when you have lawful authority to process the information.
4. Purposes and legal basis
We process data to provide the service and requested AI features, keep you signed in, protect the service from abuse, and improve Evidora through anonymous analytics and feedback. Contract performance and legitimate interests support core service and security processing. Camera processing starts only after your explicit action; you must have consent and any additional lawful basis required for health data.
5. Third-party providers
We use Supabase for authentication and database services, Vercel for hosting and AI Gateway, selected AI providers for inference, and Resend for email delivery. Camera frames and derived descriptions are sent through AI Gateway. We request routing that disallows prompt training where the Gateway credential and provider support it. Zero-data-retention routing is used only when it is explicitly enabled on a supported deployment; otherwise provider-side handling follows the applicable provider terms. Transfers outside the EEA use appropriate safeguards such as Standard Contractual Clauses.
6. Retention
Account data and saved chats are kept while your account is active. Camera frames exist only in temporary app cache for the request and are deleted after the frame is read; if iOS interrupts before deletion completes, Evidora purges its Camera cache before the next voice session. Camera frames and silent visual descriptions are transient request or live-session context and are not stored in the saved chat or Evidora server storage. Voice transcripts and camera-informed assistant replies are saved as normal chat messages and follow saved-chat retention. Upstream AI providers may process or retain transient request data under their applicable terms unless zero-data-retention routing is explicitly enabled on a supported deployment; Evidora requests no-prompt-training routing where supported. Pseudonymous abuse-prevention counters contain no camera content and are normally pruned within 48 hours after their window expires. Feedback is kept only while relevant, up to 24 months. Evidora server and security logs are normally deleted within 30 days and must not contain camera content.
7. Your GDPR rights
You can request access, correction, deletion, restriction, portability, object to certain processing, or withdraw consent. Email us and we will respond within 30 days.
8. Security
We use TLS, access controls, encryption where appropriate, and least-privilege access for service providers.
9. Changes
We may update this policy. Material changes will be communicated in the service or by email.