EvidenceHelix • Effective September 18, 2026

Data Retention Policy

EvidenceHelix follows a data-minimization principle: retain information only as long as reasonably necessary for the service, security, dispute resolution, and applicable legal obligations.

Account data

Account identifiers and password hashes may be retained while an account is active and for the time reasonably required to complete account closure and protect the service from abuse or fraud.

Research workspace data

Research-topic workspace content is retained while needed to provide the service. When an account is deleted, associated workspace content should be deleted or de-identified unless a legal, security, or dispute-preservation obligation requires limited retention.

Public protocol uploads

Public protocol files and extracted text are treated as workspace content and follow the same deletion rules. EvidenceHelix v1 does not permit patient or participant records.

Security logs

Security and reliability logs are minimized and rotated according to operational needs. Research content should not be copied into logs unless necessary to investigate a specific incident.

Backups

Deleted information may remain temporarily in protected backups until the normal backup lifecycle expires. Backup copies are not used as active product records.

Legal preservation

Specific records may be preserved when reasonably necessary to comply with law, respond to valid legal process, investigate security incidents, prevent fraud/abuse, or resolve disputes.