Two things live on this page: how to bring Ask Mallard to your organization, and everything a research, compliance, or AI-oversight office needs to review it. Everything here is also visible in the product; this page puts it in one place, in the order a reviewer asks.
Ask Mallard is sold to institutions as an annual, invoiced agreement scoped to your deployment — which programs and groups are covered, governance and oversight needs, onboarding, and support — rather than a per-seat price list. Access for medical students, residents, and fellows is sponsored by the institution; there is no individual trainee tier. Shared workspaces, the plan library, and pooled plan volume are packaged inside the agreement.
The intent is capacity, not substitution. Mallard tightens the front end of research support — intake, triage, first-pass study-design clarification, consultation preparation — so trainees and clinicians arrive at your research-support and biostatistics teams better prepared, and specialist time goes to complex design decisions, analysis, interpretation, and project execution. It extends the reach of those teams; it does not replace them, and it says so wherever it could be mistaken for that.
Institutional AI guidance typically sorts research tasks into acceptable and not-recommended columns. Ask Mallard’s function sits in the acceptable column of every framework we have reviewed: it suggests options for study designs, drafts an initial analysis plan, suggests structures for tables and figures, and identifies potentially relevant references via live PubMed search. The not-recommended activities — selecting a design without discussing it with collaborators, treating AI as the source of regulatory determinations, drafting the interpretation of results — are the ones the product is built to push back toward humans, as §5 details.
| What leaves the browser | The study description the user types (after identifier redaction), plus their selections (funding level, team, data approach, data-collection status, data source, what the plan is for, time horizon, and whether to lead with the simplest or the strongest design). No data files: the tool has no upload path for datasets, only for protocol-style documents whose text is redacted before display. |
| Where it goes | Relayed through an Ask Mallard serverless function to two AI providers: Anthropic (Claude), which drafts the plan and reviews it, and OpenAI, which reviews it again independently. Both receive the same redacted description, on every plan and every design brief — not only on complex studies. The function does not persist the text; it passes it through. Study text never goes to analytics. |
| Why two providers | A senior methodological review by a model from a different company is the check most likely to catch what the drafting model got wrong, because it does not share the drafting model's blind spots. Ask Mallard merges the two reviews deterministically and runs its own statistical checks afterwards; the models do not decide what ships. |
| Model training | Text sent to produce a plan is not used to train models. |
| What is retained | Plans generated while signed in are filed to the account automatically, as versions of the study they belong to, and a saved plan includes the study description it was generated from. They are kept 12 months from last activity, with email warnings before deletion. Signed out, only a plan the user presses Save on is kept, and it stays in that browser. An in-flight server copy of a generating plan is cleaned up within days and never includes the description. Account deletion removes everything immediately. |
| Generation telemetry | A small record of how each plan was generated is kept for 13 months: the model used, which internal checks flagged something, whether the review raised and resolved anything, and per-stage timings. No study text, no account or workspace identifier. A reader can also flag a plan section as wrong, which stores the section and a reason from a fixed list and nothing else; there is no free-text field anywhere in either record. |
| Details | The privacy page carries the full inventory, including the third-party list and the analytics consent gate. |
The rule is stated at the point of entry — describe the study, not the patients — and enforced twice mechanically. Uploaded documents are scrubbed of identifiers (MRNs, names, dates of birth, contact details, SSNs, device serials, and the other HIPAA identifier categories the rules can anchor on) before the text enters the app’s state, so an un-redacted copy never exists in the page. At Generate, the text is checked again: a match blocks the send behind a warning panel until the user removes it or accepts the automatic removal. Warnings report categories and counts only — never the matched values. Automatic detection is a backstop, not a license: users are told to strip identifiers themselves, and a study plan never needs any.
Fabricated references are the most detectable AI failure in scholarly writing, so the product is built not to produce them. Background citations are never written by the model: it emits search queries, and the app resolves each one against PubMed live, showing only real records — a query with no match renders as a labeled gap for the user to fill, not an invented reference. The two or three methodological references the model does write are checked against PubMed before display, and each is labeled with the verdict: verified with its PMID, or “could not verify — check against the original before citing.” Every export repeats the instruction to verify each citation against its primary source, and the literature scan describes itself as a relevance scan, not a systematic search.
Journal and institutional guidance asks authors to disclose AI use and document what it was used for. Every plan ships with both: a paste-ready disclosure sentence for the Methods or Acknowledgements — naming the tool, build, underlying model and vendor, what it generated, the generation and revision dates, and that authors reviewed and are responsible for the content — plus a reference-list entry, links to the ICMJE and APA guidance, and a version history recording every revision. The exports also state which models drafted and reviewed the plan.
| Literature searching | Identifying potentially relevant references: yes, via live PubMed. Reference lists without verification: prevented by construction (§6). Reading the originals remains the researcher’s job, and the product says so beside every list. |
| Project design | Suggesting designs and drafting the initial analysis plan: the core function. Design selection is framed as the team’s decision — plans are “a starting draft” with tailored questions to bring to a statistician, sized to declared funding, team, and data. |
| Regulatory approvals | Orientation only; the IRB decides (§5). Questions are generated for the local regulatory office. |
| Data collection & analysis | The tool neither collects nor analyses data. Code is exported as templates for a human analyst, labeled “not run against your data,” with assumptions to check listed beside it. No PHI enters the tool (§4). |
| Manuscript writing | Structures and planning-stage prose with invented placeholder numbers, quarantined and watermarked as examples. Interpretation of results is excluded; disclosure text is supplied (§7). |
| Peer-review confidentiality | The critique-response feature instructs users to paste only critiques received on their own work — never a manuscript or proposal they are reviewing for someone else. |
The tool cannot know your data, your institution’s determinations, or your field’s standards. Verifying the design and analysis with a qualified biostatistician, obtaining the IRB or QI determination before starting, confirming every citation against its primary source, checking the code’s assumptions against real data, and disclosing AI use on submission are the researcher’s responsibilities — and every export says exactly that, in those words. How the engine itself is tested, including what has and has not been validated, is documented on the methods page, limitations first.