EvidenceField

Legal

Privacy Policy

Last updated: July 2026

This policy covers the EvidenceField app at app.evidencefield.com — where you sign up, run research studies, and see the evidence we deliver. It’s an early product, actively changing; this describes what the app actually does today, plainly, and it’ll be updated as that changes. For the public marketing site, see its own privacy policy at evidencefield.com/privacy.

1. Account & organization data

When you sign up, we store your name, email, and job role (if you give one), and a bcrypt hash of your password — never the password itself. If you sign up or sign in with Google, we store your Google account ID, the email and name Google gives us, and your profile picture URL instead of a password. Your account belongs to an organization (your company or team); we store the organization’s name and, optionally, its website.

We keep you signed in with a session cookie (ef_session), valid for 30 days, tied to a session record in our database. The cookie is httpOnly — it can’t be read by page scripts — and is deleted when you sign out.

2. Website enrichment

If you give us your company’s website at signup, we fetch the public pages of that site — the same way a browser would — and use it to pre-fill your organization’s research context (industry, market, product, audience) so the AI research director already has useful background. We only fetch the site you told us is yours; we don’t crawl beyond it or fetch anyone else’s site.

3. AI processing (OpenRouter)

Conversations with the AI research director, brief drafting, synthetic respondent panels, cross-evidence synthesis, and transcript translation are all processed by language models, sent through OpenRouter as a gateway. OpenRouter routes each task to whichever underlying model we’ve configured for it — currently a mix of models from Anthropic, Google, and Moonshot AI, chosen per task for quality and cost. The content of your conversation, your brief, and relevant context facts are sent to these providers to generate a response; we don’t control their retention practices beyond our agreements with OpenRouter, but we don’t use your content to train our own models.

4. What we know about you

EvidenceField keeps a running record of facts about your organization — some you tell us directly, some extracted from your website, some surfaced during a conversation with the research director, some from delivered study findings. Every fact records where it came from, and you can view, add, and remove facts at any time on the About you page. Removed facts are excluded from future use, not necessarily purged immediately from our database.

5. Research studies & participant data

When you commission a study, we store the brief and the intake conversation that produced it. For studies involving real research participants (human fieldwork), we also store the evidence collected — interview transcripts, field notes, translations — and the findings synthesized from it, each citing the specific evidence it’s based on. See how EvidenceField treats research participants for what participants themselves are told.

Study data is visible to your organization’s own signed-in members, and to EvidenceField research directors (the staff who design, run, and deliver studies) — research directors can see studies across every organization on the platform, because they’re the people executing the research and writing the findings. We don’t share your study data with other clients.

6. Transactional email

We send account and study-related email (like research director notifications when a study needs review) through Resend. We don’t send marketing email through this channel.

7. Analytics

We use PostHog (PostHog Cloud, hosted in the United States) for product analytics — understanding how people use the app so we can improve it. PostHog’s autocapture records clicks and input interactions, and we log a pageview event on every route change, using cookies and local storage in your browser. This is product analytics only: no advertising, and we don’t sell this data.

8. Where data is processed

Account, organization, and study data lives in a Postgres database we run on Railway, in the United States. AI processing happens at whichever provider OpenRouter routes a given task to (see above); analytics data is processed by PostHog in the United States; transactional email is sent through Resend.

9. Retention & deletion

We retain your account, organization, and study data for as long as your account exists — there’s no automatic expiry. There isn’t a self-serve way to delete your account or data yet. If you want your data deleted, contact us at [email protected]and we’ll do it by hand; we’ll confirm once it’s done. Some records (like billing or legal correspondence, if any) may need to be kept longer where we’re required to.

10. Your choices

You can review and edit what we know about your organization on the About you page at any time. You can ask us to access or delete any data we hold about you by reaching out at [email protected]. You can also limit analytics collection using your browser’s tracking protections, a tracker or ad blocker, or by disabling cookies — the app will still work, though signing in requires the session cookie.

11. Changes

As the product evolves — new features, new vendors, a self-serve delete flow — this policy will be updated to reflect what’s actually collected. Check the “Last updated” date above.

12. Contact

Questions about this policy or your data? Reach us at [email protected].