Legal
Privacy Policy
This policy explains what Hikma Research (“the platform”, operated by [Operator legal name and address]) collects, why, who can see it and how you stay in control. It is written for researchers, not lawyers; where the two disagree, the precise wording in each section applies.
Version updated 2026-09-12
What we collect
We collect only what the service needs to work.
- Account data: name, e-mail address, password hash or passkey public key, linked sign-in providers (Google, ORCID, your institution), sessions with IP address and browser.
- Profile data you enter: position, institution, interests, links, publications you claim and metrics fetched from OpenAlex for them.
- Project content: everything members put into a project — references, files, evidence, screening decisions, analyses, manuscripts, messages and comments — together with an activity log of who changed what.
- AI records: where you connect your own agent, the calls it makes to the platform and their results, recorded in the project so the work can be audited; where the operator has switched the platform's own AI on, also the prompts, results and cost of each run, so budgets can be enforced. What you type into your own AI client is processed by that client's provider and does not reach us.
- Support and moderation: tickets you send us and reports you file or that are filed about you.
- Technical data: server logs (request path, status, timing, IP address) kept for security and reliability. We run no advertising or third-party analytics trackers.
Why we use it
To provide the service you signed up for; to keep accounts secure (rate limits, session management, two-factor); to notify you as you configured; to answer support requests; to meter and bill usage where plans apply; to investigate abuse; and to improve the platform using aggregate, non-identifying statistics.
Legal bases
Performance of the contract with you (providing the service), our legitimate interests (security, abuse prevention, improvement), your consent where we ask for it (optional e-mails, linking third-party accounts), and legal obligations.
How long we keep it
Account and profile data for as long as your account exists; project content until the project or your membership is deleted; records of AI conversations and runs for 24 months for auditability; server logs for 90 days; support tickets for 24 months after closure. Backups roll over within 35 days.
Your rights and controls
You can view and edit your profile, export your publications and CV, change visibility and contact preferences, review and clear assistant memory, revoke sessions and API keys, and delete your account from Settings → Security. Deleting removes your profile, memberships, messages and keys; content you contributed to shared projects remains with those projects attributed to a former member, as co-authors depend on it. You may also ask us to access, rectify, restrict or port your data, or object to processing, by contacting support. If you are in the EU/EEA or UK you can complain to your supervisory authority.
Security
Passwords are hashed with a modern algorithm and checked against common-password lists; two-factor authentication, passkeys and institution single sign-on are available; provider keys are encrypted at rest; files are served only to project members with a valid session; every administrative action is logged.
Children
The platform is for researchers and students aged 16 or over.
Changes
We will announce material changes in the app and by e-mail at least 14 days before they take effect. The current version names the legal entity, its data-protection contact and the hosting regions in square brackets until the operator fills them in.
Contact
Questions and requests: [privacy contact e-mail], or the support form. Operator: [Operator legal name and address].