Evidite, Inc. operates SciPubAudit.org and CitateScreen.com. This policy explains what those services collect, what leaves an uploaded document, and how long files remain.
Your manuscript or paper
An uploaded PDF or Word document is stored in a private per-run directory only while its citations are extracted and checked. The uploaded source file and verbose processing log are deleted as soon as processing stops, whether the audit succeeds or fails.
Derived citation results and downloadable reports remain available for no more than two hours after the run begins so your browser can poll for completion and download them. Choosing Reset deletes them sooner. Expired and orphaned run directories are removed automatically, including after a server restart.
We do not index uploaded document text, use it to train a model, sell it, or show it to another customer.
Verification lookups
To verify a reference, we may send one citation, DOI, PMID, PMC ID or other bibliographic identifier at a time to Evidite's Stacks index and to source services such as Crossref or NCBI. These lookups do not include the whole document, its filename or your account details.
Account and operational records
At registration we collect your email address and, if supplied, your name, institution and role. Passwords are stored only as hashes. We also keep authentication, Terms acceptance, credit and payment records needed to operate the account; those records may include timestamps, IP address and user agent.
Operational logs contain service events, HTTP status, timing and opaque run identifiers for security and troubleshooting. They may also contain limited citation or quotation lookup text for up to 90 days, but not the complete uploaded paper or its filename. The verbose per-run subprocess log is deleted as soon as processing stops.
Your data settings
If Usage statistics is on, we collect session-level aggregate metrics: the product and document type, citation counts by result, and processing time. These records contain no account ID, role, filename, citation text or other document content.
If you separately opt in to Citation research, we may retain de-identified citation-level mismatch data: the submitted citation metadata, the canonical record it resolved to and which fields differed. This does not include the uploaded file, filename, surrounding prose or quoted passages. Turning the setting off stops future contributions.
Service providers
We do not sell personal information or share it for third-party advertising. We use cloud hosting and database providers, Stripe for payment, SendGrid for transactional email, and the source services described above. If you separately opt in to marketing communication, your account contact fields may be sent to our CRM provider.
Retention
Account data is retained while your account is active. Billing, fraud-prevention and legal records are retained as required for those purposes. Uploaded source files are retained only during processing; derived run artifacts have the two-hour maximum described above. Aggregate telemetry stored without an account ID and de-identified, opt-in research records may be retained to measure and improve verification quality because they are not linked to an account.
Cookies and browser storage
Sign-in tokens are kept in your browser's localStorage. We do not use tracking or advertising cookies and do not run third-party analytics.
Security and your rights
All traffic is carried over TLS and access to production systems is restricted. Depending on your jurisdiction, you may request access, correction, export or deletion of personal data, or object to certain processing. Contact info@evidite.com.
Children and policy changes
The services are not directed at children under 13, and we do not knowingly collect their personal information. We may update this policy and will provide notice before material changes take effect.
Questions about your privacy?
Write to info@evidite.com. The button below opens a pre-addressed message.
Email us about privacy