Privacy at Ask Mallard

The short version: we collect as little as the product allows, we don't run ad trackers, and the only copy of your study text we keep is the one inside the plans in your library.

What Ask Mallard is. An app that provides a biostatistics consult and a library of calculators for clinicians, trainees, and health researchers. It helps you plan and interpret research methods. It is not a medical device, does not process patient records, and is not a substitute for a qualified statistician, your IRB, or clinical judgment.

What stays on your device

Your theme preference and tier selection live in your browser's local storage, and clearing your browser data removes them.

Signed out, nothing you generate is saved. A library that lives in one browser is a promise we cannot keep — it does not survive a cleared cache or a second device — so we no longer keep one. If a plan from an earlier version of the app is still in your browser, it is still there and still exportable: the Saved tab shows it, marks it as stored on that device only and not kept, and offers a button to remove it. Nothing new is written.

What is stored on your account

So your work can follow you across devices, when you are signed in the studies you work on are stored on our server (via Netlify) keyed to your account, and synced to the devices where you sign in. Saving is automatic and there is no Save button to forget.

A study is saved from the moment you ask for a design brief, not only when a plan is finished. We write the record at four points: when your description is accepted and the brief starts, when the brief is ready, when the full plan is generated, and again each time you generate a new brief or plan for the same study. That means a brief you never turn into a plan is still yours — it is a decision you made about your study, and it used to exist only in the tab that produced it. Records for one study are grouped together as versions of it.

A saved study includes the study description you typed, and the design brief and plan hold whatever you described. Your library lists studies by their description and uses it to group versions together, so the description is stored with the record and kept for as long as the record is. It is not stored anywhere else, and deleting the study or your account deletes it with them.

How many we keep. A free account keeps one completed plan; a study still at the brief stage is held beside it and only takes that place once its plan is generated, so trying a second study can never remove the plan you already spent a credit on — and when it is about to, the app tells you and asks first. Pro keeps 40 studies, and up to 24 versions of any one of them. If a Pro subscription ends, nothing you have is deleted. Updating, revising or re-exporting anything you already hold removes nothing at all, however far over the new limit you are; the limit applies only to what you add next, and generating a new plan then replaces the least recently used one — named, and only after you say so.

We also keep simple counters of how many plans you have generated and how many design briefs you have run, to enforce plan and brief limits and to show your remaining plan credits. You can remove saved studies from the Saved tab, or delete your account to remove them (see Your choices, below).

How long we keep your plans. Saved studies, briefs included, are kept for 12 months from the last time you generated or revised them, then deleted. We email you before that happens — roughly a month ahead and again about a week ahead — so nothing disappears without notice; revising a plan resets its clock, and any plan you export (Word, code pack, or PDF) is yours to keep regardless. Generation recovery records include your study description, saved inputs and generated output. They let you recover a paid result from credit activity even if you closed the browser or your library was full. These records are retained for up to 12 months from generation and then removed; export results you wish to keep. Account deletion removes these recovery records too. If generation is still running, deletion waits until it finishes; new generation is blocked once deletion begins.

Accounts and sign-in

Signing in is optional; you can use the free tier without an account. If you choose to sign in, authentication is handled by Clerk, our identity provider. Depending on the method you pick (Google or an email link), Clerk receives and stores your email address and basic profile identifiers to create and secure your account. Your subscription status (free or Pro) is stored on your Clerk account so it follows you across devices. We do not receive or store your social-login password. Clerk processes this data under its own privacy terms.

What is processed when you run a consult

The Consult feature sends the study description you type to AI models to generate a plan. Your text is relayed through a Ask Mallard serverless function and the response is returned to you. The function does not persist your text; it passes it through.

Two companies process that text, not one. Anthropic (Claude) drafts the plan and reviews it, and OpenAI reviews it a second time — independently, so that a methodological problem one model misses has a second chance of being caught. Both receive the same redacted study description. This applies to every plan and to every design brief; it is not limited to complex studies, and there is no setting that turns the second review off.

Do not paste identifiable patient information into the consult. Describe your study in de-identified terms — populations and variables, not names or records.

Reliability and error logs

When a plan fails to generate, Ask Mallard records the error — its type and message, the engine involved, the app version, and standard request metadata such as your IP address and browser — so we can find and fix problems. These logs are kept only to keep the service working, are visible only to Ask Mallard, and are not used to profile you or build an advertising picture of you.

How each plan was generated. When a plan is generated we also keep a small record of how it was built, so we can tell whether the checks and reviews described on the methods page are working: which model drafted it, which of our internal checks flagged something, whether the reviewers raised anything and whether the revision fixed it, and how long each stage took. It holds no study text and nothing that identifies you or your account, and it is not linked to your plans, so it cannot be traced back to a study. We keep these for 13 months, which lets us compare a month against the same month a year earlier.

If you flag a section. Each plan carries a control for telling us that a section is wrong — that it does not describe the study you are running, or asks for something you could not do. We store only which section you picked and which of the listed reasons, alongside the same anonymous record above. There is deliberately no comment box, because a note would carry your study into a store that is otherwise anonymous; if you have more to say, email support@askmallard.com instead. Flagging is optional, it changes nothing about your plan, and it is not linked to your account.

Third parties we rely on

AnthropicProcesses consult text to draft study plans and to review them. Governed by Anthropic's own privacy and data-use terms.
OpenAIProcesses consult text to review study plans a second time, independently of the model that drafted them. Runs on every plan and every design brief. Governed by OpenAI's own privacy and data-use terms.
ClerkHandles sign-in and stores your account identity and subscription status. Only used if you create an account.
StripeProcesses Pro subscription payments. Ask Mallard never sees or stores your card number — Stripe handles it directly.
NetlifyHosts the site and serverless functions, and stores (via Netlify Blobs) the plans you save when signed in, your plan-usage counters, and error logs used to fix problems. May log standard request metadata (e.g. IP address) for security and rate-limiting.
CloudflareProvides DNS for our domains and runs the email routing behind the addresses on this page. Mail you send to hello@, privacy@ or support@ passes through Cloudflare on its way to us, so your address and what you write are handled by them in transit. The site itself is not proxied through Cloudflare: they do not see your visits, your study text, or anything you type into the app.
PostHogPrivacy-first product analytics, used only if you accept analytics. Receives anonymous usage events (for example, that a plan was generated) and coarse, non-identifying properties — never your study text. Autocapture and session recording are disabled. Separately, if you subscribe to Pro, your Stripe subscription record is copied to PostHog so we can see revenue alongside usage; see Analytics.

Payments

If you subscribe to Pro, Stripe collects and processes your payment details under its own privacy policy. Ask Mallard receives confirmation that a payment succeeded; when you're signed in, your Pro status is recorded on your account (via Clerk) so it applies across your devices. We never see or store your card details — Stripe handles them directly. Your Stripe subscription record is also copied into our analytics tool (PostHog) so subscriptions can be looked at alongside product usage — see Analytics for exactly what that includes.

Analytics and advertising

We use privacy-first product analytics (PostHog) to understand how the app is used — for example, how many plans are generated or which features are used — so we can improve it. We record only anonymous usage events and coarse, non-identifying properties. Your study text is never sent to analytics, the events themselves carry no name or email, and autocapture and session recording are turned off. Analytics runs only if you accept it in the notice shown on your first visit; you can decline. To count repeat visits without knowing who you are, analytics uses a cookie or local storage to hold an anonymous device identifier; declining prevents this. We show no ads, use no advertising trackers, and do not sell your data. If a launch-list email form is present, the address you submit is used only to notify you about Ask Mallard and is not shared.

Subscription data in analytics. If — and only if — you subscribe to Pro, we import your Stripe subscription record into PostHog's data warehouse so we can see how many subscriptions there are and how they relate to product usage. That record is the billing information Stripe already holds for you: the name and email address you gave Stripe, your billing country, and the amount and status of the subscription. It never includes your card number, which Stripe does not share with us, and it never includes your study text or any plan you have generated. Two things worth being plain about: this copy comes from Stripe to PostHog directly rather than from your browser, so declining analytics does not prevent it — the analytics choice governs the usage events the app sends, not this billing record; and it applies to paying subscribers only, so if you have never subscribed, nothing about you reaches PostHog beyond the anonymous events described above. If you would rather it did not, tell us at privacy@askmallard.com and we will remove your record.

Your choices

Children

Ask Mallard is intended for clinicians, trainees, and health researchers, and is not directed to children under 13. We do not knowingly collect information from children.

Changes

If this notice changes materially, we will post the updated notice here. Continued use after a change means you accept the revised notice.

Contact

Questions about privacy? Email privacy@askmallard.com. That address is routed by Cloudflare (see Third parties), so your message passes through them on the way to us — if you would rather it did not, say so and we will give you another route.

Common questions

Do you sell my data or show ads?

No. Ask Mallard shows no ads, uses no advertising trackers, and does not sell your data.

Can I paste patient records?

No. Describe your study in de-identified terms only — no names, MRNs, dates of birth, or other identifiers. Strip identifiers before entering anything.

Where do my saved plans live?

Signed out, nowhere: nothing you generate is saved. If you’re signed in, your studies are stored on our server (via Netlify) and synced to your account so they follow you across devices. You can delete them from the Saved tab.

What happens to the study text I enter?

It is relayed through our function to the AI provider to generate your plan and is not stored afterward.

Do you use cookies or analytics?

Only privacy-first analytics (PostHog), and only if you accept it on your first visit. It records anonymous usage events — never your study text — and sets a cookie or local-storage value to hold an anonymous device ID. Decline the notice, or clear your browser storage, to keep it off. If you subscribe to Pro, your Stripe subscription record (name, email, country, amount) is also copied to PostHog from Stripe; that is separate from the events your browser sends and is not affected by declining. See Analytics.