Last updated: 1 September 2026
This policy covers EVIS (the web application at siftwork.co.uk, also served from evis-research.vercel.app) and EVIS Citations (the Word add-in that connects to it). It's operated by Siftwork Labs Ltd, company number 17412359, 128 City Road, London, EC1V 2NX, United Kingdom ("we", "us").
If you're using EVIS through an institution (for example a university), your institution may have its own separate agreement with us governing account provisioning — this policy still describes how we ourselves handle your data.
Account data. When you sign in with GitHub, we receive your email address, display name, and avatar image from GitHub's OAuth API. We create an account record from this. We don't receive your GitHub password — GitHub never shares it with us.
Research content. Search queries, protocols, uploaded documents, scan results, extracted paper metadata, screening decisions, and generated write-ups — whatever you create while using EVIS.
Word add-in token. A separate, random credential (not your GitHub password, not your session) that the add-in uses to talk to EVIS from inside Word. We store only its cryptographic hash, never the raw value, the same way a password would be stored. See section 5.
Usage data. Which endpoints are called, timestamps, and token/cost accounting for the AI features you use — this is what lets us show you your own usage and enforce plan limits, not a general activity log sold or shared onward.
We do not collect payment card details directly — if you're on a paid plan, that goes through Stripe, who handle it under their own privacy policy.
Bibliographic database providers. To find papers, your search terms are sent to the databases you've selected — PubMed, Europe PMC, Semantic Scholar, CrossRef, OpenAlex, CORE, arXiv, and similar. These are the same public/institutional APIs a manual literature search would use; each has its own terms.
AI model providers. Generating analyses, extracting structured data, and screening papers uses large language models: primarily Anthropic's Claude, and also Groq and OpenAI for specific processing pipelines. Web search — including your research question and conversation, used to ground answers and find grey literature — uses Perplexity's API. Requests are processed by these third-party AI providers (currently Anthropic, OpenAI, Groq, and Perplexity) under their commercial API terms. We don't train our own models on your data. Each provider's current data-handling terms are published on their own sites: Anthropic, OpenAI, Groq, Perplexity.
GitHub. Used only to verify your identity at sign-in (OAuth) and, for the Word add-in, to verify the token-issuance request came from a real, currently-valid GitHub session.
Stripe. Payment processing for paid plans, if applicable to your account.
We don't sell personal data, and we don't share your research content with other users or third parties for marketing purposes.
EVIS Citations runs inside Word's own task pane, not inside your browser. A few things work differently there:
ReadWriteDocument, nothing broader like mailbox or calendar access.Authorization header of requests it makes to EVIS's own API, over HTTPS.Research content and account data are kept for as long as your account is active. If you close your account, we retain data for 30 days (in case you change your mind or need an export), then delete it.
Add-in tokens are kept until revoked — see the security notes on the add-in itself for why we're adding expiry to this in a future update.
If you're in the UK or EU, you have rights under UK GDPR / GDPR to access, correct, export, or delete your personal data, and to object to certain processing. Contact us at hello@siftwork.co.uk to exercise any of these — we'll respond within one month.
You can export your own research content at any time from within EVIS. Deleting your account deletes the data described in section 6.
EVIS is a research tool intended for use by researchers, students, and academics. It isn't directed at children, and we don't knowingly collect data from anyone under 16.
Account credentials and add-in tokens are never stored in plain text — see our published security notes on the Word add-in for specifics. All traffic to EVIS, from the web app and from the add-in, is HTTPS-only.
We'll update the date at the top of this page when this policy changes, and email account holders in advance of any change that reduces your rights or meaningfully changes what we do with your data.
Siftwork Labs Ltd
128 City Road, London, EC1V 2NX, United Kingdom