Skip to main content

Legal

Privacy Policy

This policy explains what Hikma Research (“the platform”, operated by [Operator legal name and address]) collects, why, who can see it and how you stay in control. It is written for researchers, not lawyers; where the two disagree, the precise wording in each section applies.

Version updated 2026-09-12

What we collect

We collect only what the service needs to work.

  • Account data: name, e-mail address, password hash or passkey public key, linked sign-in providers (Google, ORCID, your institution), sessions with IP address and browser.
  • Profile data you enter: position, institution, interests, links, publications you claim and metrics fetched from OpenAlex for them.
  • Project content: everything members put into a project — references, files, evidence, screening decisions, analyses, manuscripts, messages and comments — together with an activity log of who changed what.
  • AI records: where you connect your own agent, the calls it makes to the platform and their results, recorded in the project so the work can be audited; where the operator has switched the platform's own AI on, also the prompts, results and cost of each run, so budgets can be enforced. What you type into your own AI client is processed by that client's provider and does not reach us.
  • Support and moderation: tickets you send us and reports you file or that are filed about you.
  • Technical data: server logs (request path, status, timing, IP address) kept for security and reliability. We run no advertising or third-party analytics trackers.

Why we use it

To provide the service you signed up for; to keep accounts secure (rate limits, session management, two-factor); to notify you as you configured; to answer support requests; to meter and bill usage where plans apply; to investigate abuse; and to improve the platform using aggregate, non-identifying statistics.

Legal bases

Performance of the contract with you (providing the service), our legitimate interests (security, abuse prevention, improvement), your consent where we ask for it (optional e-mails, linking third-party accounts), and legal obligations.

Who else sees your data

Members of your projects see project content according to their role. Administrators of this installation see account and usage metadata for support and billing, and can access project content only when you ask for help or when a report requires it; such access is logged.

  • Your own AI provider: where you connect an agent of your own (Claude Code, Codex, Cursor, Claude Desktop, ChatGPT or another MCP client), that agent reads what it asks for from your projects and sends it to its provider under the terms and the plan you hold with that provider, who bills you directly. We are not a party to that processing and do not see your prompts; what the agent did in your project is recorded here.
  • Model providers, where the operator has enabled the platform's own AI: passages of sources, evidence and manuscripts needed for a task are then sent by the platform to the language-model provider configured by the administrator. Those providers are contractually barred from training on this data, and each run shows which provider and model were used.
  • Bibliographic sources: search queries and identifiers are sent to OpenAlex, Crossref, PubMed, Europe PMC, arXiv, Semantic Scholar, ClinicalTrials.gov, Unpaywall and OpenCitations.
  • E-mail delivery and hosting: the SMTP provider and hosting infrastructure chosen by the operator process data on our behalf under data-processing agreements.
  • We do not sell personal data.

How long we keep it

Account and profile data for as long as your account exists; project content until the project or your membership is deleted; records of AI conversations and runs for 24 months for auditability; server logs for 90 days; support tickets for 24 months after closure. Backups roll over within 35 days.

Your rights and controls

You can view and edit your profile, export your publications and CV, change visibility and contact preferences, review and clear assistant memory, revoke sessions and API keys, and delete your account from Settings → Security. Deleting removes your profile, memberships, messages and keys; content you contributed to shared projects remains with those projects attributed to a former member, as co-authors depend on it. You may also ask us to access, rectify, restrict or port your data, or object to processing, by contacting support. If you are in the EU/EEA or UK you can complain to your supervisory authority.

Security

Passwords are hashed with a modern algorithm and checked against common-password lists; two-factor authentication, passkeys and institution single sign-on are available; provider keys are encrypted at rest; files are served only to project members with a valid session; every administrative action is logged.

Children

The platform is for researchers and students aged 16 or over.

Changes

We will announce material changes in the app and by e-mail at least 14 days before they take effect. The current version names the legal entity, its data-protection contact and the hosting regions in square brackets until the operator fills them in.

Contact

Questions and requests: [privacy contact e-mail], or the support form. Operator: [Operator legal name and address].