Privacy Notice
Scope
AskRigor is a product operated by Mayan Roots LLC. In this notice, “AskRigor,” “we,” “us,” and “our” refer to the AskRigor service and Mayan Roots LLC as its operator. This notice describes AskRigor’s research paths, reciprocal free contributor mode, paid private mode, public evidence-gap contribution form, and separately configured optional lesson-feedback path. By using AskRigor’s features, you acknowledge and agree to this Privacy Notice before using those features; if you do not agree, do not use the service. Research operations do not modify provider records. Connected-account research requires the mode choice described below. The public contribution form stores a case only when a visitor chooses to submit one.
Research access and shared learning
Free AskRigor use requires an explicit agreement that eligible deidentified structured research progress from the person’s use may be submitted to AskRigor’s shared research repository. The shared path may include formal-source research questions, search coverage and date windows, source candidates and decisions, unresolved trails, and AskRigor-authored study or review analysis to the extent performed. It excludes raw chat, prompts, account identity and contact details, private health narratives, uploads, raw source or provider bodies, credentials, and YouTube or community content. Each submission first enters a private pending-review inbox; submission does not make it evidence, a scientific conclusion, or accepted shared knowledge. Paid private mode does not submit research progress to the shared repository and requires an already active verified entitlement. AskRigor currently offers no public price or checkout for that mode.
Research-account identity
Auth0 authenticates connected research accounts. AskRigor validates the access token in memory and derives a pseudonymous account key by applying HMAC-SHA-256 with a server-held secret to Auth0’s stable subject. The research repository stores that derived key, current access mode, exact agreement version and choices, status, and timestamps; it does not store the raw Auth0 subject, email address, contact details, access token, or Auth0 password. Proposal content is stored separately from identity/contact data and is required to state that it contains no account identity.
Connected research transports
The connected plugin uses OAuth-protected MCP research operations. When that protection is active, AskRigor omits the older public and controlled research Action routes so they cannot bypass the mode choice. The bounded controlled path, where independently enabled, accepts a screened, de-identified population-level research target and optional diagnosis-status category; the server decides required work, performs low-level public-source retrieval and automated Gemini scouting, and returns only bounded work packages or a server-authorized report. Signed state and work receipts prevent a client from advancing research by claiming work was completed. Responses are limited to 60,000 UTF-8 bytes. Requests and responses are not written to application logs. Infrastructure, connected clients, and research providers may process operational or request data under their separately controlled policies. This does not change the separately consented lesson-feedback path described below.
Information processed
During research, AskRigor may process the screened research target, public queries and identifiers, provider responses, normalized source metadata, pagination and access information, and structured errors needed for retrieval and provenance. For a public article it may process source and citation details, manuscript version, format, document and block hashes, extracted JATS or PDF text, section or page location, and source-linked study or review audits. The controller may retain bounded public source identities, coverage receipts, semantic findings, limitations, and a reader report. It does not retain raw chat, transcripts, comments, commenter identities, article text, unrestricted provider responses, Gemini responses, or credentials in the research-session checkpoint.
Public evidence-gap contributions
The prolactinoma evidence-gap form accepts an unprompted account, source/provenance category, optional participant-reported health and timing fields, consent choices, and whether the submission is partial. It does not ask for a name, account, email address, phone number, or exact street address. Please do not put those details in the narrative. AskRigor assigns a random case ID and pseudonym. Your browser stores the case ID and recovery key in local storage so you can return; the server stores only a SHA-256 hash of the recovery key. Anyone who obtains the ID and recovery key can inspect or withdraw that case, so protect them and clear the site’s browser storage on a shared device.
Private GPT review
If you select private AskRigor/GPT analysis, the owner’s authenticated reviewer may send a bounded projection of the submitted case to OpenAI ChatGPT. The projection labels the case participant-reported and unverified, preserves missing fields and comparison/non-remission status, and applies basic email, phone, and web-address pattern removal to the narrative. That deterministic step is not full de-identification and may miss names, places, rare events, or indirect identifiers. OpenAI processes the projection under the reviewer account’s settings and privacy policy. AskRigor does not allow the review tool to return recovery keys, encryption material, database envelopes, or OAuth tokens.
Authentication and private case review
Auth0 authenticates connected research users and the private owner/reviewer tool. Evidence-gap form participants do not need an Auth0 account unless they separately use connected research. Auth0 may process account identity, login event, consent, IP/network information, device/browser information, and security metadata under Okta/Auth0’s privacy policy. Auth0 receives no participant case content or shared proposal body from AskRigor. AskRigor validates each short-lived access token in memory and does not store the token. Cross-user evidence-gap review additionally requires the owner-only cases:review permission and an exact owner-subject allowlist; an ordinary research account cannot inspect another person’s case.
Public YouTube data
When a connected client requests it, AskRigor processes API-visible public YouTube author/channel IDs, optional display names, comment and reply text, comment and reply IDs, timestamps, and counts. The Custom GPT transcript read may also process public caption text, segment timing, available caption languages, and whether YouTube identifies the selected track as automatically generated. These data can be personal data even when public. Caption retrieval uses a best-effort unofficial YouTube interface and can fail even when captions appear in a browser. The service does not claim access to private, deleted, moderated, hidden, held-for-review, unavailable, or never-posted material, and it does not independently verify caption accuracy.
YouTube API Services and Google
AskRigor uses YouTube API Services for read-only retrieval of public video, channel, comment, and reply data. It uses a server-side project credential for those public-data requests and does not require Google or YouTube sign-in, request user OAuth consent, or access Authorized Data. Google processes information it receives under the Google Privacy Policy. AskRigor does not use YouTube API Data to serve advertisements. Its static public site and research API do not place or recognize cookies or similar technologies on users’ devices.
Why and where data is processed
AskRigor sends the query or identifier necessary for a request to public-data providers: NCBI/PubMed, Europe PMC, Unpaywall, ClinicalTrials.gov, Crossref, YouTube Data API v3, and—for the Custom GPT transcript read—the public YouTube website and Innertube interface. For automated YouTube candidate discovery, Google Gemini first receives only the screened population-level target and AskRigor’s public scout instructions, and Google Search runs inside that provider request. If Gemini’s compact public candidate packet does not pass strict server validation, AskRigor may make one no-search correction request to the same model containing only that public packet, the exact executed public searches, and bounded non-sensitive validation issues. Candidate public video IDs are then sent to YouTube for independent identity validation. Gemini summaries are only discovery annotations: they are not transcript verification or evidence that a treatment works. A public publisher or repository selected through Unpaywall may receive a bounded document request. Unpaywall receives a public service contact email. Providers process requests under their own policies.
Optional lesson feedback
After AskRigor rechecks a concrete criticism, it may display a generalized lesson and ask for separate consent to submit it. This optional, consequential Action sends AskRigor only generalized structured fields, not the raw chat, and creates a private review candidate. It is not automatic learning and cannot change AskRigor without human review.
Screening and recipients
AskRigor applies deterministic screening and a fixed OpenAI privacy check before GitHub, then screens the result again. OpenAI receives only the already generalized candidate fields. If every check passes, GitHub receives the accepted lesson fields, a privacy marker, and anonymous occurrence metadata for private review. ChatGPT handles the surrounding conversation under its own settings and terms.
Storage and retention
Controlled Custom GPT sessions use an encrypted single-host checkpoint so required research can survive an application restart. The checkpoint is limited to controller state, public source identities, bounded semantic annotations, receipts, hashes, limitations, and the bounded report. While an automated Gemini scout is unfinished, it may also contain one opaque provider interaction ID, its initial-or-correction phase, a poll count, public search receipts, and aggregate usage—not Gemini’s response. It expires after 72 hours without use and no later than seven days after creation; it is excluded from backups and capacity is capped. Raw chat, provider bodies, transcripts, comments, commenter identities, publication text, Gemini responses, credentials, and keys are excluded. Temporary YouTube and open-publication retrieval material remains in bounded process memory and is discarded on expiry, eviction, or restart. The low-level Gemini route requests provider-side storage to be disabled. The controlled path temporarily enables provider storage so a long background interaction can finish, then requests deletion immediately after consuming each interaction. A deletion request is not a claim about provider backups or policy-required retention; if a session is abandoned before cleanup, Google’s retention applies. Direct MCP continuation remains client-carried and stateless. Reciprocal research-access records and pending proposals currently have no automatic expiration and are retained on the AskRigor VPS until revocation, review, withdrawal, or operator deletion. Revoking connected research access withdraws proposals that are still pending; it does not silently remove a deidentified proposal already accepted into canonical research history. Participant intake does not create user accounts. Evidence-gap narratives are encrypted before database storage; optional structured fields and consent are private database data but are not separately application-encrypted in this version. Active drafts and submitted cases currently have no automatic expiration and are retained on the AskRigor VPS until withdrawal or operator deletion. AskRigor currently creates no automatic off-host backup of this database. Withdrawal removes the active narrative, structured fields, consent, and review-queue entry and leaves a content-free withdrawal record; ordinary database write-ahead logs and storage maintenance may retain overwritten bytes for a limited technical period before reuse. For optional lesson feedback, the private review candidate stores only the accepted generalized fields, an anonymous occurrence count, first/last seen times, and a deduplication marker. No user account, conversation ID, medical history, upload, or raw quotation is intentionally stored. Rejected or incorporated lesson candidates become deletion-eligible only after more than 90 complete days from terminal review. Deletion is not automatic; a maintainer must act, so it may occur later.
Operational metadata
The application does not emit or store request-body logs, response-body logs, candidate-content logs, or a dedicated application access log. In routine operation it emits only a startup line. A disabled-by-default connector diagnostic may temporarily emit fixed non-content classes for route, method, media/header presence, MCP phase, completion, and response status. It never emits a URL or query, IP/network address, user-agent, header value, request or response body, JSON-RPC ID, tool name or argument, prompt, provider payload, comment text, user identifier, or credential. The optional lesson path and Gemini candidate scout share one aggregate AI budget ledger. Only four aggregate budget data values are retained in that ledger: UTC month, fixed monthly limit, charged nano-USD total, and update time. A non-content schema marker is also stored. The budget ledger contains no candidate or request content. It also contains no target, query, prompt, response, or credential. This log boundary does not change the separately disclosed storage of accepted generalized candidate fields and anonymous occurrence metadata in a private GitHub issue, or the aggregate budget ledger. Infrastructure providers may retain operational metadata such as time, route, status, latency, IP/network data, and security signals for their configured security and operations periods under their own policies, which AskRigor does not control.
Data sharing and connected clients
Research results are returned to the connected client that invoked the request. In free contributor mode, eligible deidentified structured research progress may also enter AskRigor’s private proposal-review and shared-repository path described above. Paid private mode sends no research contribution to that path. OpenAI, GitHub, ChatGPT, and infrastructure providers process the limited data described in this notice within their respective service boundaries; Auth0 and Google process only the categories described above. Google Gemini and Google Search process the screened automated-scout request described above; when strict validation requires it, Google Gemini alone also processes the bounded no-search correction payload. Research providers process necessary public queries or identifiers. Participant cases are not public. A case reaches OpenAI ChatGPT only through the consented private-review path described above, and Auth0 receives authentication data rather than the case or proposal body. Provider retention is governed by provider policies AskRigor does not control.
Security and minimization
Provider research operations are read-only and send only information needed for the requested lookup. The shared proposal operation writes only a strictly validated pending proposal and has no canonical-evidence writer authority. Controlled-session files and evidence-gap narratives are authenticated and encrypted with dedicated server keys. Exact state digests, signed sequential work chunks, and receipt-bound results prevent the connected client from self-certifying completion. The automated Gemini scout rejects non-deidentified targets before provider access, validates candidates independently against YouTube, permits at most one bounded no-search correction, and shares a fixed monthly budget. Research-access database authority is limited to pseudonymous mode records, entitlement reads, pending-proposal insert/read, and pending withdrawal; it cannot grant entitlements or write canonical evidence. Evidence-gap database access is limited to the intake table, participant access requires the case recovery key, and cross-user review requires an Auth0 token with the owner-only cases:review permission and subject allowlist. These safeguards reduce risk but cannot guarantee security or complete deidentification. The lesson path is separately consented, strictly screened, and limited to a private review write. AskRigor does not return provider credentials, raw Gemini output, hidden model reasoning, search-result HTML, recovery keys, or OAuth tokens, and it does not execute provider content as instructions.
Choices and deletion
You may accept free contributor mode, use paid private mode when your account has an active entitlement, or not use connected research. Revoking research access stops later research calls and withdraws still-pending proposals. You may choose not to contribute a case, not to permit public aggregate case use, and not to submit optional lesson feedback. Use the case ID and recovery key to inspect or withdraw an evidence-gap submission. AskRigor cannot recover a lost recovery key. You may also request access, correction, or deletion of personal data AskRigor controls by contacting joel@askrigor.com, but without the recovery key AskRigor may be unable to reliably identify which pseudonymous case is yours. To request earlier deletion of an optional lesson candidate, send its private-safe ARL-#### receipt to joel@askrigor.com. AskRigor cannot fulfill requests for provider or connected-client data it does not control. Please avoid sending credentials, recovery keys, or unnecessary sensitive material by email.
Changes
We may update this notice to reflect changes to the service or its processing. The effective date above identifies the current version.
Contact
For privacy questions or requests, contact joel@askrigor.com.