Data and privacy, in plain language.

Last updated: 4 October 2026

The short version

  • We collect what you type into our forms and your profile, and how you found the site.
  • The assistant is an AI. Your conversations with it are not stored on our servers unless you choose to save them on your account; saved ones are deleted 90 days after you last open one, when you delete them, or when you delete your account. Anthropic, our AI provider, processes them to write the answer and deletes them within 30 days (longer only if flagged for a safety review).
  • The free tools send only what you ask them to check (search terms, references or identifiers) from our server to PubMed, Crossref and ClinicalTrials.gov, so those services never see who you are. The Traffic Light also sends your idea to Anthropic. We do not keep your idea, your list or the results.
  • Five providers handle the data for us: Supabase, Netlify, Anthropic and GitHub (backups) in the United States, and Brevo in the EU. Most of it is stored in the United States.
  • No advertising, no analytics, no tracking cookies, and no fonts or scripts loaded from other companies.
  • You can see, correct, export or delete your data at any time. Write to dimitri@askdimitri.net.

Who is responsible

AskDimitri is a personal platform run by Dr. Dimitrios Magouliotis, an individual based in the United States. He decides how your personal data is used, which makes him the controller under the EU General Data Protection Regulation (GDPR). You can reach him at dimitri@askdimitri.net. Your data is not owned by or shared with any institutional employer.

What we collect

When you fill in a form

The request-access form, the protocol template form and the book list ask for your email address and your name, plus optional answers: your career stage, what you are working on, and how you heard about AskDimitri. We record which form you used, and when you confirmed your email address.

How you found us

With a form we also save the campaign tags in the link you arrived on (utm_source, utm_medium and utm_campaign), the website that sent you (its domain only, never the full address), and the first page you opened here, with every other link parameter removed. Advertising click identifiers such as fbclid and gclid are never saved. Until you submit a form, this stays in your browser (see Browser storage).

If you arrive on one of the letters without campaign tags, we note that instead (for example utm_source=archive, utm_campaign=issue-003). If your browser blocks site storage, these tags are added to the page address instead.

Requests you have not confirmed yet

A form submission is kept as a pending request until you confirm it: open the link we email you and press Confirm on the page it opens. Nothing is added to the mailing list or the member list before you confirm.

Your profile

Inside the dashboard you can add your institution, country, specialty, goals and how you heard about us. All of it is optional.

Using the platform

The questions you send to the mailbag; how many assistant prompts you used this week and when you first used the assistant; how many times you used each member tool this week; whether you have seen the dashboard tour; your place in the queue and when you were given access; whether you joined the book list; and the date you unsubscribed, if you did. Supabase handles sign-in and records your sign-in email address and sign-in times.

Security and abuse prevention

To stop spam and abuse, our server functions count recent requests per IP address and per email address. Both are stored only as one-way hashes, never in plain form, and the counters are deleted after about 2 days. We also keep daily totals of assistant use and cost, which are not linked to any person.

Provider logs

Our hosting and database providers keep short-lived technical logs of requests, such as IP address, browser type and time.

Email

Brevo sends the letters and our other emails. It records whether each email was delivered and may record whether it was opened and which links were clicked.

The assistant and your documents

The assistant is an AI system: its answers are written by Claude, a large language model made by Anthropic, following instructions written by Dr. Magouliotis. He does not read your conversations.

When you ask a question, your message, the earlier messages in that conversation, any document text you attach, and your profile details (career stage, what you are working on, institution, country, specialty and goals, so the answer fits you) go through our server to Anthropic, only to generate the answer. A PDF you attach is turned into text inside your browser; the file itself is never uploaded.

AskDimitri does not store your conversations or documents on its servers, unless you switch on saving on your account (below). Anthropic keeps what it receives through its API for up to 30 days and then deletes it. If Anthropic's safety systems flag a conversation as a possible breach of its usage policy, Anthropic may keep it for up to 2 years. Anthropic does not use this data to train its models.

Chat history on your device. The dashboard can keep your past conversations in this browser's local storage if you choose "This browser only" in its History column. It stays on your device and is never sent to us. You can clear it at any time in the dashboard, or by clearing this site's data in your browser.

Saved conversations on your account. If you choose "My account" instead, each conversation is saved on our server (the Supabase database, encrypted at rest) under your account: the mode, a short title taken from your first question, and the messages. An attached document is never saved. You can hold up to 50 saved conversations, and open, download or delete any of them, or all of them, in the dashboard. A saved conversation is deleted 90 days after you last opened or added to it, when you delete it, when you switch the setting off, and when you delete your account. Dimitri does not read them; they are used for nothing but showing them back to you.

Do not share patient-identifiable or confidential information. See Data security and HIPAA.

The tools

Traffic Light. Your research idea and the optional details you add (who, what, the comparison, the outcome, the design and your data) go through our server to Anthropic, which builds the search terms and weighs what the searches found, under the same terms as the assistant. The search terms go from our server to PubMed (NCBI) and ClinicalTrials.gov. AskDimitri does not store your idea or the result on its servers.

Reference Check. Reference Check sends the references you paste to PubMed (NCBI) and Crossref from our server, so those services never see who you are. Your list is not saved. The public records they return are kept for up to 7 days to make repeat checks faster.

The lookup cache. What PubMed, Crossref and ClinicalTrials.gov return (public records about papers and trials) is kept for up to 7 days so repeat checks are faster. It is stored by what was asked, not by who asked, and is never linked to you. It also keeps how PubMed read each search (the search terms, not who searched) for the same 7 days.

Authorship Sheet. It runs in your browser. The sheet lives in the part of the page address after the #, which browsers do not send to any server, so we never receive it. Anyone who has the link can read the sheet.

Allowances. For members we count how many times each tool was used this week, to apply the weekly allowance. The free pages count checks per network with the same one-way hashes as our abuse-prevention counters.

Why we use your data (lawful bases)

We use your email to deliver the letters and to sign you in, and your profile to shape the letters and the assistant's advice. We do not sell your personal data and we do not use it for advertising.

Who processes it for us

We share personal data only with these providers. Each processes it on our instructions under its data processing terms and receives only what its job needs:

The site loads no fonts, scripts or images from any other company. Opening a public page sends your IP address only to Netlify, our host. The login page and the dashboard also connect your browser directly to Supabase, in the United States, to sign you in, keep you signed in and download library files. The download links in the protocol template email point at Supabase too.

Transfers outside the EU

Supabase, Netlify, Anthropic and GitHub store and process data in the United States. For people in the EU, the EEA, Switzerland and the UK, these transfers rely on the European Commission's Standard Contractual Clauses included in each provider's data processing terms and, where a provider is certified, on the EU-US Data Privacy Framework. You can ask us for a copy of the safeguards.

How long we keep it

Browser storage and cookies

We use no advertising, analytics or tracking cookies. The site keeps only this in your browser:

Your rights

Under the GDPR you have the right to:

The dashboard's Profile tab lets you correct your details. The Account tab deletes your account in one step: your member record, profile, mailbag questions, pending requests, your sign-in account and your Brevo contact. For a copy of your data, a portable export, or anything else, email dimitri@askdimitri.net. We answer within one month.

We make no decisions about you based only on automated processing that have legal or similarly significant effects. Access to the assistant is given by hand.

Complaints. You can complain to a data protection supervisory authority, in particular in the EU country where you live or work. In Greece this is the Hellenic Data Protection Authority (www.dpa.gr). We would be grateful for the chance to put things right first, so please write to us too.

Age

AskDimitri is for adults. You must be 18 or older to use it, and we do not knowingly collect data from anyone younger.

Mergers or partnerships

In the event of a merger, acquisition, or institutional partnership, you will be notified by email no less than 30 days in advance and given the option to opt out before any data transfer occurs.

Changes to this policy

We will post any change here with a new date. If a change materially affects how we use your data, we will email members before it takes effect.

Disclaimer

AskDimitri is an AI-powered research and educational tool. It does not provide medical, legal, or investment advice. Content generated by AskDimitri is intended solely for research methodology and career guidance and for educational purposes. It should not be used as a substitute for professional medical judgment, legal counsel, or financial advice. Always consult a qualified professional for clinical, legal, or financial decisions.

Data security and HIPAA

Do not share sensitive personal, confidential, or identifiable patient information through this platform. AskDimitri is not a secure clinical communication tool and is not HIPAA compliant. Everything you send to the assistant is processed by a third-party AI provider, so treat it as non-confidential.

Σύνοψη στα ελληνικά

Μια σύντομη περίληψη της πολιτικής απορρήτου. Αν υπάρχει διαφορά, ισχύει το πλήρες αγγλικό κείμενο παραπάνω.

  • Υπεύθυνος επεξεργασίας: ο Dr. Dimitrios Magouliotis, ιδιώτης με έδρα στις Ηνωμένες Πολιτείες. Επικοινωνία: dimitri@askdimitri.net.
  • Τι συλλέγουμε: το όνομα, το email και όσες προαιρετικές απαντήσεις δίνετε στις φόρμες και στο προφίλ σας· πώς φτάσατε στον ιστότοπο (ετικέτες καμπάνιας, τον ιστότοπο που σας παρέπεμψε και την πρώτη σελίδα που ανοίξατε)· τις ερωτήσεις σας στο mailbag· και στοιχεία χρήσης, όπως πόσες ερωτήσεις κάνατε στον βοηθό αυτή την εβδομάδα.
  • Ο βοηθός είναι τεχνητή νοημοσύνη. Τις απαντήσεις τις γράφει το Claude της Anthropic. Ό,τι στέλνετε στον βοηθό δεν αποθηκεύεται από το AskDimitri. Πηγαίνει στην Anthropic μόνο για να γραφτεί η απάντηση. Η Anthropic το διαγράφει μέσα σε 30 ημέρες (έως 2 χρόνια μόνο αν επισημανθεί για έλεγχο ασφαλείας) και δεν το χρησιμοποιεί για την εκπαίδευση των μοντέλων της. Μη μοιράζεστε στοιχεία ασθενών.
  • Εργαλεία: το Traffic Light στέλνει την ιδέα σας στην Anthropic και όρους αναζήτησης στο PubMed και στο ClinicalTrials.gov. Το Reference Check στέλνει τις βιβλιογραφικές αναφορές σας στο PubMed και στο Crossref από τον διακομιστή μας, ώστε να μη βλέπουν ποιος είστε. Δεν αποθηκεύουμε ούτε την ιδέα, ούτε τη λίστα, ούτε τα αποτελέσματα. Το Authorship Sheet λειτουργεί μόνο στον browser σας.
  • Πάροχοι: Supabase, Netlify, Anthropic και GitHub (αντίγραφα ασφαλείας) στις ΗΠΑ, και Brevo στη Γαλλία. Τα περισσότερα δεδομένα αποθηκεύονται στις ΗΠΑ, με τις Τυποποιημένες Συμβατικές Ρήτρες της Ευρωπαϊκής Επιτροπής ή το Πλαίσιο Προστασίας Δεδομένων ΕΕ-ΗΠΑ.
  • Νομική βάση: η συγκατάθεσή σας για τα Dimitri's Letters (την ανακαλείτε οποτεδήποτε με τον σύνδεσμο διαγραφής σε κάθε email), η παροχή της υπηρεσίας για τον λογαριασμό και τον βοηθό, και το έννομο συμφέρον μας για την προέλευση των επισκεπτών και την πρόληψη καταχρήσεων.
  • Διατήρηση: τα αιτήματα που δεν επιβεβαιώθηκαν διαγράφονται μετά από 30 ημέρες. Ο λογαριασμός σας διατηρείται μέχρι να τον διαγράψετε. Τα αντίγραφα ασφαλείας της βάσης δεδομένων διατηρούνται έως 90 ημέρες.
  • Τα δικαιώματά σας: πρόσβαση, διόρθωση, διαγραφή, περιορισμός, εναντίωση, φορητότητα και ανάκληση της συγκατάθεσης. Γράψτε στο dimitri@askdimitri.net ή διαγράψτε τον λογαριασμό σας από την καρτέλα Account. Μπορείτε επίσης να υποβάλετε καταγγελία στην Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (www.dpa.gr).
  • Ηλικία: το AskDimitri απευθύνεται σε ενήλικες, 18 ετών και άνω.