Data and privacy, in plain language.
Last updated: 4 October 2026
The short version
- We collect what you type into our forms and your profile, and how you found the site.
- The assistant is an AI. Your conversations with it are not stored on our servers unless you choose to save them on your account; saved ones are deleted 90 days after you last open one, when you delete them, or when you delete your account. Anthropic, our AI provider, processes them to write the answer and deletes them within 30 days (longer only if flagged for a safety review).
- The free tools send only what you ask them to check (search terms, references or identifiers) from our server to PubMed, Crossref and ClinicalTrials.gov, so those services never see who you are. The Traffic Light also sends your idea to Anthropic. We do not keep your idea, your list or the results.
- Five providers handle the data for us: Supabase, Netlify, Anthropic and GitHub (backups) in the United States, and Brevo in the EU. Most of it is stored in the United States.
- No advertising, no analytics, no tracking cookies, and no fonts or scripts loaded from other companies.
- You can see, correct, export or delete your data at any time. Write to dimitri@askdimitri.net.
Who is responsible
AskDimitri is a personal platform run by Dr. Dimitrios Magouliotis, an individual based in the United States. He decides how your personal data is used, which makes him the controller under the EU General Data Protection Regulation (GDPR). You can reach him at dimitri@askdimitri.net. Your data is not owned by or shared with any institutional employer.
What we collect
When you fill in a form
The request-access form, the protocol template form and the book list ask for your email address and your name, plus optional answers: your career stage, what you are working on, and how you heard about AskDimitri. We record which form you used, and when you confirmed your email address.
How you found us
With a form we also save the campaign tags in the link you arrived on (utm_source, utm_medium and utm_campaign), the website that sent you (its domain only, never the full address), and the first page you opened here, with every other link parameter removed. Advertising click identifiers such as fbclid and gclid are never saved. Until you submit a form, this stays in your browser (see Browser storage).
If you arrive on one of the letters without campaign tags, we note that instead (for example utm_source=archive, utm_campaign=issue-003). If your browser blocks site storage, these tags are added to the page address instead.
Requests you have not confirmed yet
A form submission is kept as a pending request until you confirm it: open the link we email you and press Confirm on the page it opens. Nothing is added to the mailing list or the member list before you confirm.
Your profile
Inside the dashboard you can add your institution, country, specialty, goals and how you heard about us. All of it is optional.
Using the platform
The questions you send to the mailbag; how many assistant prompts you used this week and when you first used the assistant; how many times you used each member tool this week; whether you have seen the dashboard tour; your place in the queue and when you were given access; whether you joined the book list; and the date you unsubscribed, if you did. Supabase handles sign-in and records your sign-in email address and sign-in times.
Security and abuse prevention
To stop spam and abuse, our server functions count recent requests per IP address and per email address. Both are stored only as one-way hashes, never in plain form, and the counters are deleted after about 2 days. We also keep daily totals of assistant use and cost, which are not linked to any person.
Provider logs
Our hosting and database providers keep short-lived technical logs of requests, such as IP address, browser type and time.
Brevo sends the letters and our other emails. It records whether each email was delivered and may record whether it was opened and which links were clicked.
The assistant and your documents
The assistant is an AI system: its answers are written by Claude, a large language model made by Anthropic, following instructions written by Dr. Magouliotis. He does not read your conversations.
When you ask a question, your message, the earlier messages in that conversation, any document text you attach, and your profile details (career stage, what you are working on, institution, country, specialty and goals, so the answer fits you) go through our server to Anthropic, only to generate the answer. A PDF you attach is turned into text inside your browser; the file itself is never uploaded.
AskDimitri does not store your conversations or documents on its servers, unless you switch on saving on your account (below). Anthropic keeps what it receives through its API for up to 30 days and then deletes it. If Anthropic's safety systems flag a conversation as a possible breach of its usage policy, Anthropic may keep it for up to 2 years. Anthropic does not use this data to train its models.
Chat history on your device. The dashboard can keep your past conversations in this browser's local storage if you choose "This browser only" in its History column. It stays on your device and is never sent to us. You can clear it at any time in the dashboard, or by clearing this site's data in your browser.
Saved conversations on your account. If you choose "My account" instead, each conversation is saved on our server (the Supabase database, encrypted at rest) under your account: the mode, a short title taken from your first question, and the messages. An attached document is never saved. You can hold up to 50 saved conversations, and open, download or delete any of them, or all of them, in the dashboard. A saved conversation is deleted 90 days after you last opened or added to it, when you delete it, when you switch the setting off, and when you delete your account. Dimitri does not read them; they are used for nothing but showing them back to you.
Do not share patient-identifiable or confidential information. See Data security and HIPAA.
The tools
Traffic Light. Your research idea and the optional details you add (who, what, the comparison, the outcome, the design and your data) go through our server to Anthropic, which builds the search terms and weighs what the searches found, under the same terms as the assistant. The search terms go from our server to PubMed (NCBI) and ClinicalTrials.gov. AskDimitri does not store your idea or the result on its servers.
Reference Check. Reference Check sends the references you paste to PubMed (NCBI) and Crossref from our server, so those services never see who you are. Your list is not saved. The public records they return are kept for up to 7 days to make repeat checks faster.
The lookup cache. What PubMed, Crossref and ClinicalTrials.gov return (public records about papers and trials) is kept for up to 7 days so repeat checks are faster. It is stored by what was asked, not by who asked, and is never linked to you. It also keeps how PubMed read each search (the search terms, not who searched) for the same 7 days.
Authorship Sheet. It runs in your browser. The sheet lives in the part of the page address after the #, which browsers do not send to any server, so we never receive it. Anyone who has the link can read the sheet.
Allowances. For members we count how many times each tool was used this week, to apply the weekly allowance. The free pages count checks per network with the same one-way hashes as our abuse-prevention counters.
Why we use your data (lawful bases)
- Dimitri's Letters and the emails you ask for (the protocol template, book news): your consent, given when you confirm your email address. You can withdraw it at any time with the unsubscribe link in every email. Unsubscribing also pauses your access to the assistant, because access travels with the letters.
- Your account, the assistant, the library and the mailbag: to provide the service you asked for (GDPR Article 6(1)(b)).
- How you found us, abuse prevention, security logs and usage totals: our legitimate interests in knowing which channels bring readers and in keeping the service safe and within budget (Article 6(1)(f)). You can object to this at any time.
- Records of when you consented: our legal obligation to be able to show consent (Articles 6(1)(c) and 7(1)).
We use your email to deliver the letters and to sign you in, and your profile to shape the letters and the assistant's advice. We do not sell your personal data and we do not use it for advertising.
Who processes it for us
We share personal data only with these providers. Each processes it on our instructions under its data processing terms and receives only what its job needs:
- Supabase: database, sign-in and sign-in emails, and file storage. Our project runs in the United States (AWS, Oregon).
- Netlify: hosting and the server functions that run the site, in the United States.
- Brevo (France): the mailing list and our emails, stored in the European Union.
- Anthropic (United States): writing the assistant's answers and the Traffic Light's search terms and verdict, as described above.
- GitHub (Microsoft, United States): keeps a weekly backup copy of our database, which holds the member records, profiles, mailbag questions and pending requests described above, for 90 days, so the service can be restored after a failure.
The site loads no fonts, scripts or images from any other company. Opening a public page sends your IP address only to Netlify, our host. The login page and the dashboard also connect your browser directly to Supabase, in the United States, to sign you in, keep you signed in and download library files. The download links in the protocol template email point at Supabase too.
Transfers outside the EU
Supabase, Netlify, Anthropic and GitHub store and process data in the United States. For people in the EU, the EEA, Switzerland and the UK, these transfers rely on the European Commission's Standard Contractual Clauses included in each provider's data processing terms and, where a provider is certified, on the EU-US Data Privacy Framework. You can ask us for a copy of the safeguards.
How long we keep it
- Unconfirmed requests: the confirmation link works for 48 hours, and the request is deleted after 30 days.
- Your member record, profile and mailbag questions: until you delete your account.
- If you unsubscribe: your record stays, marked as unsubscribed, so that we keep respecting your choice. Delete your account to remove it completely.
- Abuse-prevention counters: about 2 days.
- Tool allowance counts: 8 weeks.
- The lookup cache of public records from PubMed, Crossref and ClinicalTrials.gov, and how PubMed read each search: up to 7 days, linked to no one.
- Daily usage totals: kept, because they identify no one.
- Assistant conversations: not kept by us, unless you choose "My account" in the dashboard: then until you delete them or your account, or switch the setting off, and at most 90 days after you last opened one. Up to 30 days at Anthropic, or up to 2 years if flagged by its safety systems.
- Provider logs: the short periods each provider sets.
- Backups: every backup copy of the database is kept for at most 90 days, so data you delete is gone from every backup within 90 days.
Browser storage and cookies
We use no advertising, analytics or tracking cookies. The site keeps only this in your browser:
- Your sign-in session, kept in local storage by the Supabase sign-in library so you stay signed in to the dashboard. The service needs it to work.
- Chat history, only if you choose "This browser only", and the history setting you chose, until you log out (see The assistant).
- How you found us: the campaign tags, the referring website's domain and your first page, held in session storage while the tab is open. It is deleted when you close the tab and is sent to us only if you submit a form.
- Traffic Light: your last check, in session storage while the tab is open; your last 10 checks in local storage, only if you switch that on (you can clear them on the page); and an idea typed on the free page, in local storage for 24 hours, only if you choose to sign in from there (if you dismiss the dashboard's note about that idea, a record that you did, deleted when you log out at the latest). "Discuss in the assistant" passes the text to the dashboard through session storage, once.
- Motion: a note in session storage that the Δ has already drawn itself, so it does so once per visit. It holds nothing about you and is deleted when you close the tab.
Your rights
Under the GDPR you have the right to:
- access your data and get a copy of it;
- correct it;
- delete it;
- restrict how we use it, or object to it, including to anything based on our legitimate interests;
- receive it in a portable, machine-readable format (data portability);
- withdraw your consent at any time, without affecting what happened before.
The dashboard's Profile tab lets you correct your details. The Account tab deletes your account in one step: your member record, profile, mailbag questions, pending requests, your sign-in account and your Brevo contact. For a copy of your data, a portable export, or anything else, email dimitri@askdimitri.net. We answer within one month.
We make no decisions about you based only on automated processing that have legal or similarly significant effects. Access to the assistant is given by hand.
Complaints. You can complain to a data protection supervisory authority, in particular in the EU country where you live or work. In Greece this is the Hellenic Data Protection Authority (www.dpa.gr). We would be grateful for the chance to put things right first, so please write to us too.
Age
AskDimitri is for adults. You must be 18 or older to use it, and we do not knowingly collect data from anyone younger.
Mergers or partnerships
In the event of a merger, acquisition, or institutional partnership, you will be notified by email no less than 30 days in advance and given the option to opt out before any data transfer occurs.
Changes to this policy
We will post any change here with a new date. If a change materially affects how we use your data, we will email members before it takes effect.
Disclaimer
AskDimitri is an AI-powered research and educational tool. It does not provide medical, legal, or investment advice. Content generated by AskDimitri is intended solely for research methodology and career guidance and for educational purposes. It should not be used as a substitute for professional medical judgment, legal counsel, or financial advice. Always consult a qualified professional for clinical, legal, or financial decisions.
Data security and HIPAA
Do not share sensitive personal, confidential, or identifiable patient information through this platform. AskDimitri is not a secure clinical communication tool and is not HIPAA compliant. Everything you send to the assistant is processed by a third-party AI provider, so treat it as non-confidential.
Σύνοψη στα ελληνικά
Μια σύντομη περίληψη της πολιτικής απορρήτου. Αν υπάρχει διαφορά, ισχύει το πλήρες αγγλικό κείμενο παραπάνω.
- Υπεύθυνος επεξεργασίας: ο Dr. Dimitrios Magouliotis, ιδιώτης με έδρα στις Ηνωμένες Πολιτείες. Επικοινωνία: dimitri@askdimitri.net.
- Τι συλλέγουμε: το όνομα, το email και όσες προαιρετικές απαντήσεις δίνετε στις φόρμες και στο προφίλ σας· πώς φτάσατε στον ιστότοπο (ετικέτες καμπάνιας, τον ιστότοπο που σας παρέπεμψε και την πρώτη σελίδα που ανοίξατε)· τις ερωτήσεις σας στο mailbag· και στοιχεία χρήσης, όπως πόσες ερωτήσεις κάνατε στον βοηθό αυτή την εβδομάδα.
- Ο βοηθός είναι τεχνητή νοημοσύνη. Τις απαντήσεις τις γράφει το Claude της Anthropic. Ό,τι στέλνετε στον βοηθό δεν αποθηκεύεται από το AskDimitri. Πηγαίνει στην Anthropic μόνο για να γραφτεί η απάντηση. Η Anthropic το διαγράφει μέσα σε 30 ημέρες (έως 2 χρόνια μόνο αν επισημανθεί για έλεγχο ασφαλείας) και δεν το χρησιμοποιεί για την εκπαίδευση των μοντέλων της. Μη μοιράζεστε στοιχεία ασθενών.
- Εργαλεία: το Traffic Light στέλνει την ιδέα σας στην Anthropic και όρους αναζήτησης στο PubMed και στο ClinicalTrials.gov. Το Reference Check στέλνει τις βιβλιογραφικές αναφορές σας στο PubMed και στο Crossref από τον διακομιστή μας, ώστε να μη βλέπουν ποιος είστε. Δεν αποθηκεύουμε ούτε την ιδέα, ούτε τη λίστα, ούτε τα αποτελέσματα. Το Authorship Sheet λειτουργεί μόνο στον browser σας.
- Πάροχοι: Supabase, Netlify, Anthropic και GitHub (αντίγραφα ασφαλείας) στις ΗΠΑ, και Brevo στη Γαλλία. Τα περισσότερα δεδομένα αποθηκεύονται στις ΗΠΑ, με τις Τυποποιημένες Συμβατικές Ρήτρες της Ευρωπαϊκής Επιτροπής ή το Πλαίσιο Προστασίας Δεδομένων ΕΕ-ΗΠΑ.
- Νομική βάση: η συγκατάθεσή σας για τα Dimitri's Letters (την ανακαλείτε οποτεδήποτε με τον σύνδεσμο διαγραφής σε κάθε email), η παροχή της υπηρεσίας για τον λογαριασμό και τον βοηθό, και το έννομο συμφέρον μας για την προέλευση των επισκεπτών και την πρόληψη καταχρήσεων.
- Διατήρηση: τα αιτήματα που δεν επιβεβαιώθηκαν διαγράφονται μετά από 30 ημέρες. Ο λογαριασμός σας διατηρείται μέχρι να τον διαγράψετε. Τα αντίγραφα ασφαλείας της βάσης δεδομένων διατηρούνται έως 90 ημέρες.
- Τα δικαιώματά σας: πρόσβαση, διόρθωση, διαγραφή, περιορισμός, εναντίωση, φορητότητα και ανάκληση της συγκατάθεσης. Γράψτε στο dimitri@askdimitri.net ή διαγράψτε τον λογαριασμό σας από την καρτέλα Account. Μπορείτε επίσης να υποβάλετε καταγγελία στην Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (www.dpa.gr).
- Ηλικία: το AskDimitri απευθύνεται σε ενήλικες, 18 ετών και άνω.