Legal
Privacy Policy
Last updated: August 29, 2026 · CiteSafe
1. Scope
This Privacy Policy describes how we collect, use, store, and share information when you visit citesafe.co, create an account or profile, use verification or related features (including beta), pay for a plan, or contact us. Related documents: Terms, Security, Subprocessors, DPA.
2. Categories of information
- Identifiers & contact: name, email, profile fields you enter, account or gift codes on-device.
- Commercial: plan tier, purchase history metadata via Stripe (we do not store full card numbers).
- Internet / technical: IP address, user agent, approximate location from IP, referrer, host and edge logs.
- Usage: pages viewed, verify runs, feature interactions, error events (no document body in analytics).
- Customer content:
- Cite-only (default): public citation strings extracted in your browser and sent for existence/risk checks.
- Full document (opt-in only): full paste/upload text if you explicitly arm Full document mode with double confirmation.
- Device-local beta: scan history, profile, plan flags often stay in your browser unless a cloud account feature is enabled.
3. How we use information
- Provide citation verification and product features you request.
- Secure the service, prevent abuse, debug failures (without logging full document bodies).
- Bill, prevent fraud, and provide support.
- Comply with law and enforce Terms.
- Communicate product, beta, and billing notices.
We do not sell personal information or document contents. We do not train public generative models on customer content (false). Default: no internal model training on full documents.
4. Cookies and browser storage
Necessary browser storage keeps beta preferences and device-local workspace data. If you choose “Allow analytics cookies,” CiteSafe also stores a random session identifier (cs_sid) and first-touch campaign attribution (cs_utm_ft) for up to 90 days. These analytics records exclude document bodies, pasted text, and citation text. Vercel Web Analytics provides separate aggregated, cookieless page metrics.
You can withdraw permission at any time. Withdrawing deletes the CiteSafe analytics cookies and persistent attribution data on this browser. .
5. Retention (operational)
- Verify request body: not stored in a CiteSafe database (false). Processed in request lifetime only.
- Host / function logs: metadata oriented; target purge within 14 days (provider-dependent).
- Account & billing records: up to 7 years or as required for tax/dispute.
- Support email: up to 3 years.
- Security logs: up to 2 years.
- Browser local data: under your control; clear in Settings or by clearing site data.
- Payments: retained by Stripe under Stripe’s policies.
6. Confidentiality, privilege & professional duties
Uploading or pasting content to CiteSafe does not create an attorney-client relationship or privilege with us. Cite-only mode reduces disclosure surface; it does not create privilege. Only submit content you are authorized to process. Prefer cite-only for client work product. See Security & privilege architecture.
7. Sharing & subprocessors
We share data only as needed to run CiteSafe: infrastructure, payments, and public law index queries. Full list: Subprocessors. Current vendors include: Vercel Inc.; Stripe, Inc.; Free Law Project (CourtListener); Caselaw Access Project (Harvard); U.S. Government Publishing Office (GovInfo).
We may disclose information if required by law, legal process, or to protect rights and safety. Where lawful, we attempt to notify the affected customer before producing customer content (except where notice is prohibited).
8. Security & breach notice
We use HTTPS/TLS and reasonable administrative and technical safeguards for a hosted SaaS beta. No method is perfectly secure. If we confirm a breach of personal information in our control, we aim to notify affected customers within 72 hours of confirmation where required or appropriate, via security@citesafe.co / account email. Report issues to security@citesafe.co.
9. Your rights & choices
Depending on your location (including CCPA/CPRA, Virginia CDPA, and similar laws), you may request access, correction, deletion, or export of personal information we hold, and appeal a denial. Email privacy@citesafe.co with subject “Privacy request.” We aim to respond within 30 days (plus up to 15 if complex). We will not discriminate for exercising privacy rights.
Do not sell / share: We do not sell personal information and do not share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics for advertising.
Device beta data: Settings → Clear beta data, or clear site storage in your browser.
10. International users
Processing is primarily in the United States. If you access CiteSafe from outside the U.S., you understand information may be transferred to and processed in the U.S., which may have different data protection laws. Enterprise transfer terms can be covered in a signed Data Processing Addendum.
11. Children
CiteSafe is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided data, contact privacy@citesafe.co for deletion. Users 13-17 should use CiteSafe only with appropriate authority (e.g. school or parent/guardian policy).
12. Sensitive content
Legal documents may contain sensitive data (health, criminal, financial, minors). Prefer cite-only mode. Do not use Full document mode for sealed, highly sensitive, or unauthorized content. We do not require such data to verify public citations.
13. Automated decisions
Citation status labels (Verified / Needs Review / Could Not Verify) are automated risk signals for human review. They are not legal determinations and are not used for consumer credit or employment eligibility decisions by CiteSafe.
14. Changes
We may update this Policy. The “Last updated” date will change. Material changes may also be noticed in-product or by email where appropriate. Continued use after the effective date means you accept the updated Policy for future use.
15. Contact
- Privacy: privacy@citesafe.co
- Security: security@citesafe.co
- General: hello@citesafe.co
- Legal: legal@citesafe.co