Site Logo

Where Does Your Research Data Go? Evidano vs NVivo, MAXQDA, ATLAS.ti, Delve & Dedoose

Subprocessor chains, AI model ownership, human review, training use, and encryption — compared side by side, with each claim quoted from the vendor's own terms.

Data security · Provider comparison

Where Your Research Data Actually Goes

ProviderSubprocessorsAI modelsReads your content?Trains on your data?Encryption posture
EvidanoClosed system2 — Microsoft Azure, StripeOwn in-house modelsNoNeverAES-256 · FIPS 140-2 · closed system
NVivo8+ — OpenAI, Anthropic, Azure, AWS, Speechmatics, Sentry, Zendesk, CloudflareThird-party (OpenAI, Anthropic)May human reviewUsed to "improve" AI servicesAccess-controlled, not end-to-end
ATLAS.ti5 — OpenAI, Google Analytics, Mixpanel, speech-to-text, ZohoThird-party (OpenAI)May human reviewContent uploaded to OpenAI serversNot a zero-knowledge system
MAXQDA5 — AWS, Amazon Bedrock, Google Vertex AI, RunPod, SpeechmaticsThird-party (Bedrock, Vertex AI)Reviews flagged promptsProviders receive the dataAccess-controlled, not zero-knowledge
Delve4 — OpenAI (undisclosed), Heroku, AWS, BonsaiThird-party (OpenAI)May human reviewCannot assure non-disclosureData not confined to the user
Dedoose3 — Microsoft Azure, Amazon S3, Google AnalyticsNot disclosedMay send PII to othersNot disclosedKeys stored in Dedoose
Contained / customer-controlledData leaves your control

Provider by provider, in their own words

Our policy explicitly forbids using Customer Data for training, retraining, or improving our AI models.

TLS 1.2 or higher protects data moving between you and our servers.

Your data is secured with industry-standard AES-256 encryption on our servers.

When you delete it, it's gone.

Evidano runs on a deliberately small footprint: Microsoft Azure for hosting and Stripe for payments are the only subprocessors, with no AI vendors, analytics brokers, or support-tool third parties in the chain. Because Evidano uses its own in-house AI models rather than routing prompts to OpenAI, Anthropic, or Google, research content never leaves this closed system to reach an external model provider — the primary exposure that every competitor below carries.

Encryption is applied end to end and to a government-grade standard: TLS 1.2+ in transit, AES-256 at rest, and FIPS 140-2 compliant cryptographic modules. Customer content is explicitly never used to train, retrain, or improve Evidano's AI models, and each tenant is logically segregated by a unique tenant ID to prevent cross-contamination.

Control stays with the customer. Data can be deleted on demand through the interface, and on termination it is purged from production within 30 days and from backups within a further 90 days — not retained indefinitely. Data residency is pinned to the US (Azure US East) or EU (Azure West Europe), with SCCs for any onward transfer, and the service maps to SOC 2 Type 2, GDPR, HIPAA (BAA-ready), and CCPA/CPRA.

Customer authorizes Lumivero and any third-party service providers to process and use Customer Data or other inputs… examine inputs and outputs where necessary… and improve the operation, reliability, and security of A.I. Services.

accessible to a limited number of persons duly authorised by Lumivero

Abuse monitoring logs may contain certain customer content, such as prompts and responses.

we may retain and human review customer content

NVivo's operator, Lumivero, does not run its cloud and AI functions as a system where only the user can technically reach the data. Its DPA lists subprocessors across OpenAI, Anthropic, Microsoft Azure, AWS, Speechmatics, Sentry.io, Zendesk, and Cloudflare, without clearly mapping which of them receive raw research content, prompts, outputs, or audio. The sheer breadth of that chain — eight-plus organizations touching research data — is the core exposure, and it is not offset by end-to-end encryption.

The terms contemplate human access rather than preventing it: data is “accessible to a limited number of persons duly authorised by Lumivero,” the customer authorizes providers to “examine inputs and outputs” and to “improve” the AI services, and transfers are permitted to “any country or territory.” Where OpenAI is used, abuse-monitoring logs may contain prompts and responses. OpenAI's own terms state it “may retain and human review customer content” — a pathway to human eyes on research data that Evidano's closed model simply does not have.

Intentional AI Coding will upload your intent, your questions, chosen category code names, and your document content to ATLAS.ti and OpenAI servers.

[OpenAI] monitoring logs may contain certain customer content, such as prompts and responses

[OpenAI] may retain and human review customer content

We use the analysis service Google Analytics… data is transmitted to Google's servers in the USA.

ATLAS.ti leans on OpenAI, Google Analytics, Mixpanel, a third-party speech-to-text provider, and Zoho's US CRM, so user data may be accessed, logged, or transferred across several companies and jurisdictions. Its own wording confirms that AI coding “will upload your intent, your questions… and your document content to ATLAS.ti and OpenAI servers” — the actual research documents leave the user's control.

This is not a zero-knowledge design. OpenAI's monitoring logs may contain prompts and responses and it “may retain and human review customer content,” Google Analytics transmits data to US servers, Mixpanel and the speech-to-text provider may move personal data outside the EU/EEA, and Zoho's US CRM stores customer data. Sensitive documents, voice recordings, and prompts flow into provider-controlled systems abroad — the opposite of Evidano's single-region, single-vendor posture.

processor shall grant access to the personal data undergoing processing to members of its personnel

your personal data may be transferred to recipients in so-called third countries… and may be accessible to foreign governments, courts, law enforcement agencies, and supervisory authorities.

Authorized Google employees may assess the flagged prompts

[AWS] may store and review the flagged input or output

Activating AI Assist, Tailwind, Transcription, or TeamCloud sends research content off the device into MAXQDA's providers — AWS, Amazon Bedrock, Google Vertex AI, RunPod, and Speechmatics. MAXQDA describes an access-controlled cloud, not an architecture where it and its providers are technically unable to view the data, and each added processor widens the surface for support access, legal demands, and cross-border processing.

The contracts state that personnel are granted “access to the personal data undergoing processing,” and that data sent to third countries “may be accessible to foreign governments, courts, law enforcement agencies.” Providers also reserve review rights: Google says “authorized Google employees may assess the flagged prompts” and AWS “may store and review the flagged input or output.” Human review by upstream AI vendors is an explicit, documented possibility — a risk Evidano removes by owning its models.

Delve describes itself as one of the platforms "using OpenAI," yet OpenAI is absent from its subprocessor register.

Last Updated February 8, 2022

we may retain and human review customer content

cannot assure you [that information] will not be disclosed

Delve routes sensitive research through Heroku, AWS, and Bonsai and states that it is “using OpenAI” — yet OpenAI is missing from a subprocessor register last updated January 14, 2025, and the privacy policy itself dates to February 8, 2022, before Delve's current AI chat and automated coding existed. Users cannot reliably tell what data reaches the AI provider, where it goes, or how long it is kept, because the disclosures do not describe the current AI data flow.

OpenAI's terms allow customer content — including prompts and responses — to be retained and, in defined safety circumstances, human-reviewed. Delve additionally warns that data may be processed in jurisdictions with weaker protection and that it “cannot assure you” information “will not be disclosed.” Delve's own words stop short of guaranteeing confidentiality, whereas Evidano's closed system and never-train commitment are stated outright.

encryption keys are stored in Dedoose

send PII about You to other companies or people

keeps a backup of all data for restoration purposes for a period of 2 years

Dedoose hosts on Microsoft Azure, mirrors project files to Amazon S3, and may process account and usage data through Google Analytics. Because “encryption keys are stored in Dedoose,” the company retains the technical ability to decrypt standard project data — this is not a zero-knowledge or end-to-end encrypted service.

Its privacy wording also states it may “send PII about You to other companies or people,” and it “keeps a backup of all data for restoration purposes for a period of 2 years,” so content may remain recoverable long after use ends. Company-held keys, third-party PII transfers, and two-year retention leave several paths for Dedoose, its subprocessors, or authorities to reach user data — none of which apply under Evidano's customer-controlled deletion and closed encryption.

Comparison compiled from each provider's published privacy terms, data processing agreements, and subprocessor disclosures. Quotes reproduce provider wording; elaborations summarize the documented data flows. Subprocessor counts reflect the providers named in the source material.

Frequently asked questions

Does Evidano train AI models on my research data?
No — never. Evidano runs its own in-house models in a closed system, so your documents are not sent to third-party AI providers, are not human-reviewed, and are never used for training. Data is encrypted with AES-256 using FIPS 140-2 validated modules, and the subprocessor list is two entries: Microsoft Azure for hosting and Stripe for payments.
Do other QDA tools send my data to third-party AI providers?
Yes, per their own documentation quoted on this page: NVivo's AI features run on OpenAI and Anthropic among 8+ subprocessors, ATLAS.ti uploads content to OpenAI servers, MAXQDA routes data through Amazon Bedrock and Google Vertex AI, and Delve uses OpenAI. Dedoose does not disclose its AI arrangements.
Can humans at these companies read my research data?
It depends on the tool. Evidano's terms rule out human review. NVivo, ATLAS.ti, and Delve's AI providers may human-review submitted content, MAXQDA's providers review flagged prompts, and Dedoose's terms allow PII to be shared with other parties. The exact wording from each vendor's terms is quoted in the table below.
Is Evidano compliant with GDPR, SOC 2, and HIPAA?
Yes: Evidano is SOC 2 Type 2 audited, GDPR compliant, HIPAA-ready, and covered for CCPA/CPRA. Encryption is AES-256 at rest and TLS 1.2+ in transit. Details are on the data security page.