Skip to document
MetaPrism
Terms of Use Privacy Policy Acceptable Use Policy Cookie Policy
Back to MetaPrism

Privacy Policy

How we collect, use, and protect personal data when you use MetaPrism.

Last updated: 23 August 2026

This Privacy Policy explains how Source Control IKE (“Source Control”, “MetaPrism”, “we”, “us”, or “our”) processes personal data when you use MetaPrism (the “Service”). It should be read together with our Terms of Use, Acceptable Use Policy, and Cookie Policy.

Controller
Source Control IKE
Argyrakouli 40, 41334 Larissa, Greece
GEMI: 187982940000
VAT / ΑΦΜ: 803039020
Email: support@metaprism.io

For EEA data subjects you may contact us at the above address or email regarding data-protection matters.

1. What we collect

Depending on how you use the Service we may process:

CategoryExamples
AccountEmail, name/display name, password hashes or authentication tokens, role
UsageLogin times, IP address / user-agent, feature usage, error reports and optional bug screenshots
Project & research dataProject membership, bibliographic records, notes, search strategies, comments, tasks
DocumentsPDF full texts and metadata (DOI, PMID, titles, hashes). Files are stored only within the projects/teams you attach them to
CommunicationsPassword-reset and access emails, messages you send to support, author full-text upload emails
AIPrompts, selected excerpts, and model responses when you use AI features; provider/model identifiers
Payments (when enabled)Billing identity, plan, invoices (typically via a payment processor such as Stripe). We do not intend to store full card numbers

We do not require special-category data about identifiable patients. You must not upload identifiable patient records or other special-category data unless you have a lawful basis and appropriate safeguards.

1a. MetaPrism Capture browser extension

If you install the MetaPrism Capture browser extension (Chrome / Firefox):

  • The extension reads visible page metadata on supported literature database hosts and parses citation export files (RIS, BibTeX, CSV) that you select locally. It does not bypass vendor authentication or access content behind paywalls.
  • When you confirm an import, bibliographic metadata is sent to the MetaPrism API using your authenticated session.
  • Access and refresh tokens are stored in browser extension local storage (chrome.storage.local on Chromium-based browsers). They are not placed in URLs.
  • Optional capture diagnostics (last 20 events) store technical metadata only — adapter name, host, counts, and recovery hints. They do not include tokens, titles, abstracts, or full citation bodies.
  • The extension does not send remote analytics or telemetry.

2. Why we process data and lawful bases

We process data to:

  • provide and secure the Service (accounts, projects, document storage within teams);
  • send transactional email;
  • improve reliability (logs, diagnostics, optional bug reports);
  • provide the AI features you request;
  • meet legal obligations and enforce the Terms;
  • process payments when commercial billing is enabled.

Lawful bases (EEA/UK):

  • Performance of a contract
  • Legitimate interests (security, product improvement, preventing abuse, efficient operation of the Service), balanced against your rights
  • Consent (where required, e.g. non-essential cookies or marketing)
  • Legal obligation

3. AI data handling

  • AI features primarily run on infrastructure we control. For most tasks we use our own models.
  • When third-party models are used, customer content is processed under contractual terms that prohibit the provider from using it to train their foundation models.
  • We do not use your prompts, documents, or outputs to train third-party foundation models.
  • We may use anonymised or aggregated technical signals to improve the reliability of our own systems.
  • AI-related data is retained only as long as needed to provide the feature and for security/audit purposes, then deleted or anonymised.

4. Sharing and processors

We share data only as necessary with:

  • service providers acting as processors (hosting, email delivery, payment processing, error monitoring) under written contracts that meet GDPR requirements;
  • project collaborators you invite (within the scope of the project);
  • authorities when required by law or to protect rights and safety.

We do not sell personal data.

A current list of categories of processors (or named subprocessors) can be requested from support@metaprism.io. Enterprise customers may request a Data Processing Agreement (Art. 28 GDPR).

5. International transfers

Data is primarily processed in the European Economic Area. If we transfer data outside the EEA we use appropriate safeguards (Standard Contractual Clauses or adequacy decisions).

6. Retention

We retain personal data only as long as necessary for the purposes described:

  • Account data: while the account is active and for a reasonable period thereafter (normally up to 12 months after closure, unless a longer period is required by law).
  • Project content: follows the project lifecycle and deletion requests, subject to backup retention (normally ≤ 90 days) and any legal hold.
  • Logs and security data: typically 12–24 months.
  • AI interaction data: retained only as needed for the feature and security, then deleted or anonymised.

7. Security

We implement appropriate technical and organisational measures designed to protect personal data. No method of transmission or storage is completely secure.

8. Cookies and similar technologies

We use necessary cookies and similar technologies to operate the Service. Non-essential cookies (if any) will only be set with your consent. Details are provided in our Cookie Policy.

9. Your rights

Depending on your location you may have rights of access, rectification, erasure, restriction, objection, data portability, and withdrawal of consent. You also have the right to lodge a complaint with a supervisory authority (in Greece: the Hellenic Data Protection Authority – www.dpa.gr).

To exercise rights contact support@metaprism.io. We may need to verify your identity. We will respond within the time limits required by law.

10. Children

The Service is not directed at children under 18 (or the higher age of majority required in your jurisdiction). We do not knowingly collect personal data from children.

11. Changes

We may update this Privacy Policy. We will post the updated version and revise the “Last updated” date. Material changes will be communicated by reasonable means.

Contact

Source Control IKE
Argyrakouli 40, 41334 Larissa, Greece
support@metaprism.io

MetaPrism — Meta-analysis for researchers

support@metaprism.io