Privacy & Consumer Health Data Policy
Effective / last updated: August 10, 2026
This policy describes the current Evidentia data flow, including health-related searches that may qualify as consumer health data under some state laws. Evidentia is designed for scientific research and evidence exploration, not for storing identifiable patient records.
Do not enter identifiable health information
Do not submit names, medical-record numbers, dates of birth, addresses, account credentials, or other information that identifies a patient, research subject, or individual. Evidentia is not currently offered as a HIPAA-compliant clinical record system.
A health-related search can still be sensitive even without a name. Use general research questions whenever possible.
Categories of information processed
Quick Check data: the claim you enter, generated search terms, retrieved citation/abstract material, automated study assessments, and the resulting evidence brief.
Research Mode data: research questions, PICO criteria, filters, generated search strategies, retrieved study metadata and abstracts, screening decisions, exclusion reasons, researcher notes, automated evidence-intelligence fields, audit events, and timestamps.
TikTok-check data: the public TikTok URL you paste, public metadata returned for that URL such as caption/title and author, and any claim description you type.
Technical data: hosting, network, and security providers may process standard request information such as IP address, browser/device information, timestamps, requested URLs, and error/security information needed to deliver and protect the service.
Browser-local data: recent Quick Check searches and Research Mode projects are stored in local storage on the browser/device you use.
Sources of information
Information comes directly from you when you enter a claim, research question, criteria, note, screening decision, or TikTok URL; from your browser/device and network when requests are made; from PubMed/NCBI when scientific records are retrieved; and from TikTok when you request analysis of a public TikTok link.
Evidentia does not currently purchase consumer profiles or health-data lists from data brokers.
How Quick Check is processed
Your Quick Check claim is sent to Evidentia's server-side functions. The service sends literature-search terms to the U.S. National Library of Medicine / National Center for Biotechnology Information through PubMed and NCBI E-utilities.
Quick Check currently uses the Lovable AI Gateway for functions such as translating the claim into literature-search queries and analyzing retrieved research. Data sent for this purpose can include your claim and selected PubMed citation/abstract text. The gateway may route requests to the configured model provider.
Provider training/data-use notice: Lovable's current documentation states that customer data may be used for model training and other business purposes under its Terms unless the customer/workspace uses available opt-out controls, and states that raw or identifiable PII is not used for model training. Evidentia does not represent that a Lovable training-data opt-out is active unless the operator has separately confirmed that setting or contractual protection. See Lovable's current data-use documentation ↗.
The Quick Check claim is also included in the Evidentia result-page URL so the result can be revisited or shared. As a result, the claim can appear in your browser history, copied links, bookmarks, and ordinary hosting/request records. Evidentia sends a no-referrer policy so the full Evidentia page URL is not intentionally sent as the HTTP referrer when you follow an external link.
How Research Mode is processed
Research Mode project content is primarily stored in your browser under Evidentia's local-storage project key. When you run Evidence Discovery, the research strategy/question and applicable PICO/date criteria are sent to Evidentia's server-side function and then used to query PubMed/NCBI.
The current Research Mode PICO relevance score, abstract result signal, and evidence-direction label are generated by Evidentia logic from retrieved PubMed metadata and abstract text. They are not currently produced by the Lovable AI Gateway. The resulting records are returned to your browser and stored with the local project.
CSV, RIS, and JSON project exports are assembled in your browser and downloaded to your device. Evidentia does not intentionally upload those generated export files to a separate cloud project store.
TikTok link processing
When you paste a supported TikTok URL, Evidentia sends that public URL from its server to TikTok's official oEmbed service to request public metadata. The returned public caption/title may be sent through the Lovable AI Gateway to identify a checkable claim. If you type your own description of the claim, that text may also be sent through the Lovable AI Gateway to normalize it into a searchable statement.
The TikTok URL appears in the Evidentia /video page URL and therefore may be present in browser history or ordinary hosting/request records. If a TikTok-provided thumbnail is displayed, the browser may contact the third-party image host to load it.
Browser storage and retention
Recent Quick Check searches are currently stored under evidentia.history and Research Mode projects under evidentia.research.projects.v1. These records remain in that browser until you delete them, clear site data, or the browser removes them. They are not encrypted by Evidentia before being placed in browser local storage.
Anyone or any software with access to that browser profile may be able to access browser-stored data. Do not use Research Mode local storage for confidential patient/subject records or as the only copy of important research work.
These controls delete data stored by Evidentia in this browser. They do not delete browser history, hosting/security logs, or data a third-party processor may retain under its own lawful retention rules.
Third parties and categories of sharing
Evidentia currently shares or transmits information only as needed to provide, secure, or operate requested features. Relevant categories are:
- PubMed / NLM / NCBI: scientific search terms, research strategies, and record identifiers needed for literature retrieval.
- Lovable AI Gateway and configured model-processing infrastructure: Quick Check claims, selected scientific text, TikTok captions, and manually entered TikTok-claim descriptions when those AI-assisted features are used. Provider terms/settings may permit uses beyond transient inference, as described above.
- TikTok: a public TikTok URL when the user requests TikTok inspection through oEmbed.
- Hosting/network/security providers: request and technical metadata necessary to serve, protect, troubleshoot, and operate Evidentia.
- Google-hosted web-font infrastructure: standard browser request metadata can be sent when the site loads its externally hosted font resources.
Evidentia has no disclosed corporate affiliates receiving consumer health data at this time. Evidentia does not currently sell consumer health data, use it for behavioral advertising, or intentionally send health searches to advertising pixels/data brokers.
Consumer health data purposes
Health-related search/research information is processed to perform the evidence search or research function you requested; retrieve and rank scientific literature; generate the requested evidence output; maintain browser-local project/history functionality; prevent abuse; troubleshoot failures; and protect service security.
Evidentia itself does not intentionally repurpose health-related user input for advertising, sale, or unrelated profiling. Third-party service providers may have separate data-use rights under their terms/settings, including the Lovable training-data policy described above. Before Evidentia introduces a materially new first-party purpose—such as advertising, unrelated profiling, training an Evidentia model on user content, or sale—it should update disclosures and complete any consent/legal steps required by applicable law.
Your privacy and consumer-health-data rights
Depending on applicable law, you may have rights to confirm whether Evidentia is collecting, sharing, or selling consumer health data; access data; obtain information about recipients; withdraw consent where consent is the legal basis; request deletion; and appeal certain denied requests.
For browser-local data, the controls above provide immediate deletion from the current browser. You may also delete individual Research Mode projects from the Projects page. Browser history must be removed using your browser's own controls.
For data that may be controlled by Evidentia outside your browser, send a request to contact.evidentia@gmail.com. Include enough information to authenticate and locate the request without sending unnecessary health information. Where applicable law requires it, Evidentia will also communicate a valid deletion request to relevant processors/recipients that Evidentia can identify and direct.
Applicable law may permit or require retention of limited security, legal, fraud-prevention, or compliance records even after a deletion request.
Service logs and data minimization
Evidentia application logging is designed not to intentionally write the text of Quick Check claims or PubMed search-query URLs to its own diagnostic logs. Hosting and infrastructure platforms may still create operational, request, abuse-prevention, or security logs according to their configuration and policies.
Evidentia cannot promise that every third-party provider immediately deletes transient request data or operational logs. Provider retention and contractual settings should be reviewed before paid, institutional, or identifiable-health-data use.
Security
Evidentia uses reasonable measures appropriate to its current architecture, including restrictive referrer behavior and baseline browser security headers, and limits intentional application logging of health-query text. No internet service, local-storage mechanism, AI processor, or hosting platform can be guaranteed completely secure.
Before Evidentia stores identifiable health data or handles PHI for a covered entity, it must undergo a separate security, vendor-contract, access-control, retention, incident-response, and HIPAA/state-law review.
HIPAA and other health privacy laws
HIPAA does not apply to every health-related application. If Evidentia later creates, receives, maintains, or transmits protected health information on behalf of a HIPAA covered entity or business associate, Evidentia may itself become a business associate and require a Business Associate Agreement and HIPAA controls.
Separate state consumer-health-data laws can apply outside HIPAA. Evidentia therefore treats the disclosures and rights in this policy as a consumer-health-data baseline rather than assuming that avoiding HIPAA ends the privacy analysis.
Cookies, analytics, and external assets
Evidentia does not currently include a disclosed advertising pixel, behavioral-advertising SDK, or dedicated product-analytics tracker in the application code reviewed for this policy. Browser local storage is used for recent-search and Research Mode project functionality.
The site currently loads some externally hosted assets, including Google-hosted fonts. Those hosts can receive ordinary network metadata when the asset is requested. If Evidentia later adds analytics, advertising, session replay, cross-site tracking, or other non-essential tracking technology, the privacy policy and any required consent controls must be reassessed before launch.
Children
Evidentia is not directed to children under 13 and is not designed to knowingly collect personal information from children under 13. If you believe a child has submitted personal information, contact us.
External sources and links
Evidentia links to PubMed, TikTok, and other third-party resources. Their privacy, security, and content practices are governed by their own policies. See the PubMed / NCBI Notice for source-specific information.
Changes and contact
We may update this policy as the service changes. Material changes should be reflected by a new effective date and, where legally required or appropriate, an in-product notice or consent request.
Privacy and consumer-health-data requests: contact.evidentia@gmail.com.