Privacy Policy

Last updated: August 3, 2026

1. Who We Are

Aqrab ("we," "our," "us") is an AI-powered research methodology critique platform operated by Coefficients Health Analytics. Our website is aqrab.ai.

2. What Data We Collect

We collect the following types of information:

  • Account data: Email address, name (when you sign up via email, Google, or GitHub).
  • Study data: Research abstracts, study designs, and methodology descriptions you submit for critique.
  • Usage data: API call counts, critique history, timestamps, and plan/subscription status.
  • Payment data: Processed by Stripe. We store only your email, subscription status, and Stripe customer ID — never your card number.
  • Technical data: IP address, browser type, and device information for security and analytics.

Aqrab is not intended to receive protected health information (PHI), patient identifiers, or identifiable patient-level data. Please submit de-identified methodology text only.

3. How We Use Your Data

  • To provide methodology critiques and scoring
  • To manage your account, credits, and subscription
  • To improve our methodology critique framework and scoring accuracy
  • To send transactional emails (magic link login, billing receipts)
  • To detect and prevent abuse of our API

4. AI Processing

We do not intentionally use your submitted study text to train or fine-tune Aqrab. Submissions are sent to the model infrastructure identified below to generate a critique and, for signed-in users, are stored for account history. Third-party processors operate under their own data-processing and retention terms.

5. Data Security

  • Transport security: Production traffic is served over HTTPS.
  • Infrastructure: Authentication and data storage use Supabase; application hosting uses Vercel.
  • Access controls: Saved critique history is retrieved through authenticated account requests.
  • Current boundary: Aqrab does not claim HIPAA, SOC 2, or institutional compliance certification.

6. Data Retention

We retain your data as follows:

  • Critique history: Retained while your account is active or until you request deletion.
  • Usage records: Retained as needed for credit accounting, security, and abuse prevention.
  • Billing records: Retained by Stripe and by us as required for payment, accounting, and legal obligations.

You can request full data deletion by contacting us at anas@coef.health.

7. Third-Party Services

  • Stripe — Payment processing
  • Supabase — Authentication and database
  • OpenRouter / Google Gemini — AI model inference (for generating critiques)
  • Vercel — Hosting and deployment

These services have their own privacy policies. We only share the minimum data necessary for each to function.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data
  • Export your data in a portable format
  • Object to processing
  • Withdraw consent at any time

9. Cookies

We use storage required for authentication and preferences. We do not use advertising cookies. Limited product analytics may be used to understand feature usage and failures.

10. Contact

For privacy-related questions or data deletion requests, contact us at anas@coef.health.