Privacy Notice
Updated 2026-09-14
This notice explains how the MetaSyntra service administrator processes information to operate the research workspace. For questions, requests about your information, or operator contact details, use our contact form.
Information we collect and why
We collect the email address, username and authentication information needed to create and protect your account; uploaded workbooks, chosen settings and generated outputs needed to perform analyses; and usage, billing, support and security records needed to provide the service, manage allowances, resolve problems and prevent abuse. Service providers may receive IP addresses and technical request information. We record acceptance of the Terms for new accounts.
Research data and administrator access
Upload study-level data that you are authorised to process. Do not upload patient names, medical-record numbers, contact details or other patient identifiers. Personal workbooks are private. In a review project, accepted collaborators can read and download shared references, full texts, approved data and linked results according to their role. We store project invitations and email addresses, membership, protocols, reviewer decisions and an audit history. Unsubmitted reviewer forms remain private to their author. Site administrators do not automatically become project collaborators; the existing support access described below still applies to personal R analyses. Removing a collaborator cannot recall copies they already downloaded.
Authorised administrators can inspect workbook previews, saved settings and generated files, and download original uploads and results for support and service administration. Each preview or download requires a reason and is recorded with the administrator, time, user, analysis and file reference. This access is not an invitation to use research data for unrelated purposes. Locally downloaded administrator copies must be handled securely and removed when no longer needed.
Cloudflare, AI and payments
Cloudflare hosts application services, databases, file storage, the R engine and transactional email delivery. Optional Workers AI uses IBM Granite. Requesting settings suggestions sends only worksheet names, column names and row counts, not workbook cell values. Opting into a results summary sends bounded R-output excerpts, which may include study labels. Suggestions remain editable, and summaries retain source wording and values. AI content is stored with the analysis; separate token and cost records support spending controls.
Private review projects require owner opt-in before hosted AI can be requested. These requests send the PICOTT protocol, eligibility criteria and selected reference or supplied full-text excerpts to Cloudflare Workers AI. Hosted Granite does not read PDF images. The optional local connector downloads selected project evidence to the reviewer’s computer and calls their chosen local model; its key is restricted to the project and their current permissions. AI proposals do not count as independent human reviews and require verification before inclusion in final data.
Stripe processes payment and subscription information when payments are enabled. MetaSyntra stores relevant Stripe identifiers and transaction status, not complete card numbers. Cloudflare and Stripe may process information in countries other than your own, under their applicable service agreements. This notice does not promise that data stays in a particular country.
Retention and deletion
New uploads and outputs are kept for the retention period displayed when uploading, currently at least 30 days. The expiry shown for an existing analysis remains its assigned expiry. You can download or delete completed analyses and close your account from Account settings. Active analyses must stop before closure. Closing an account removes its workbooks and saved AI content and initiates immediate subscription cancellation.
Review projects and uploaded reference/PDF files remain until the owner deletes the project. Owners must transfer ownership or delete their projects before closing their account. A former collaborator’s submitted decisions and audit history may remain with the project to preserve its research record. Linked personal R analyses retain their own displayed expiry and deletion controls.
De-identified job and AI cost history survives deletion so usage controls cannot be bypassed. Financial and administrator audit records may remain for accounting, security and service administration; audit records can contain administrator and user identifiers and action reasons. Access reasons should not contain research data or unnecessary personal details. Execution logs are retained with the analysis for authorised administrators. They are excluded from ordinary member views, account exports and result downloads; run retention and deletion rules still apply. Support requests are removed after 12 months unless deleted earlier. Privacy requests concerning retained records require review of applicable obligations rather than a promise of immediate deletion.
Your choices and requests
You can export account information, download research outputs, delete analyses, change your password, close your account and choose whether to request AI assistance. Contact us to request access, correction or deletion, or to raise an objection, restriction, portability or privacy complaint where applicable. We may verify identity and authority before disclosing or changing data. We will apply the rights and response periods required in your location; you may also contact the relevant data-protection authority.
Cookies, security and changes
We use essential sign-in and security cookies, described in our Cookie Notice. The application does not use advertising trackers or sell research uploads. Access controls, encrypted transport and private file storage reduce risk, but no online service can guarantee absolute security. Significant changes will be reflected here with an updated date and an in-app notice where appropriate.