citepath.io
Log inStart free

Privacy Policy

Last updated: 25 May 2026 · Version 1.0

This Privacy Policy describes how citepath.io (ABN 48 595 594 995) (“we”, “us”, or “our”) collects, uses, discloses, and protects personal information about visitors to our website and users of our web application (collectively, the “Service”). By creating an account or otherwise using the Service, you acknowledge that the practices described in this policy will apply to you.

Plain English summary

citepath.io is an AI visibility tool operated from Australia. This policy explains what personal information we collect about you, why we collect it, who we share it with, and how long we keep it. It applies whether you are visiting our marketing site, using the web application, or receiving an email from us.

citepath.io is the entity responsible for your personal information — the “APP entity” under the Privacy Act 1988(Cth) and the “controller” under the General Data Protection Regulation and the UK GDPR.

The Service is designed for use by professionals (SEO freelancers, digital agencies, and similar). If you are using the Service in a personal capacity, the Australian Consumer Law and equivalent consumer-protection laws in your jurisdiction may give you additional rights, and nothing in this policy limits those rights.

1. Introduction

We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) as our primary regulatory framework. Where you are located in the European Union, the European Economic Area, the United Kingdom, or another jurisdiction whose data-protection law applies to the processing described in this policy, we additionally observe the requirements of that law (including the General Data Protection Regulation and the UK GDPR). To the extent of any inconsistency between the protections afforded by your local law and this policy, the protections of your local law prevail.

This policy governs your use of the Service. It does not, by itself, constitute your consent to any processing of your personal information. Where consent is required as the lawful basis for processing under the applicable law, we will obtain it separately and in the form that law requires.

Capitalised terms not defined in this policy have the meaning given to them in our Terms of Service.

2. Information We Collect

2.1 Account information

When you create an account, our authentication provider (Supabase Auth) collects your email address and a salted, hashed copy of your password. We do not have access to your plaintext password.

In your associated profile we store: your first and last name (collected at signup; legacy accounts created before this field was added may not have these recorded); the business name, role, and intended-use category you provide during onboarding; a flag recording your confirmation that the Service is being used for professional or business purposes; your current subscription plan and, for paid plans, the Stripe customer and subscription identifiers and the start and end dates of your current billing period; the version identifiers of the Terms of Service and Privacy Policy you accepted, together with the timestamps of acceptance; and an inactivity-tracking timestamp recording the last date on which you used the Service (used to trigger the warning email described in section 4 and section 7).

2.2 Information you submit to the Service

When you use the Service, we collect and store: the URLs you submit for a citation check; the search queries you run those URLs against; any monitored-query configurations you create (the URL, query, schedule, and label); the entries you save to your query library; and the names of any custom prompt categories you create. Where you initiate the same action from within a workspace, your action is also associated with that workspace and the role under which you acted (see section 2.5).

2.3 Content fetched from URLs you submit

When you submit a URL for a citation check, our server-side fetcher retrieves the publicly accessible content of that URL in two ways: (i) we request the page’s readable text from Jina AI’s content-extraction service, which fetches the URL on our behalf and returns the cleaned-up text; and (ii) we separately fetch the raw HTML of the URL directly in order to parse any embedded JSON-LD structured data. Up to approximately ten kilobytes of the readable text are then forwarded to Anthropic for the purpose of generating Fix Engine recommendations and competitor analysis. No other AI provider receives this page content from us.

The four citation engines (Perplexity, ChatGPT, Gemini, and Claude) each perform their own independent web search when running a citation check, and do not receive your page content from us. Brand sentiment scoring is performed by Anthropic but operates on the citation engines’ answer text rather than on your page content, and likewise does not receive your page content.

When you submit a URL to the buyer-intent query generator (the “suggest queries” feature), our server fetches the page directly, extracts a short summary (the page’s title, its meta description, its first few headings, and a short opening excerpt of the page body), and forwards that summary to Anthropic to produce the suggestions. No other AI provider receives any part of this content.

You are responsible for ensuring that you have the right to submit any URL whose page contains third-party personal information or other content protected by law.

2.4 Information generated by the Service about you

The Service produces and stores the following outputs in connection with your account: per-engine citation verdicts and aggregate citation scores; brand sentiment scores together with a short rationale; ranked Fix Engine recommendations including any ready-to-paste code snippets the Service generates; competitor analysis summaries listing the URLs your submitted page was compared against and short bullets explaining the comparison; and, for monitored queries, one-sentence insight summaries generated when a monitored query’s citation status changes between runs. These outputs are stored on the simulation or monitoring-run record to which they relate.

2.5 Workspace and collaboration data

Where the Service is used within a workspace, we additionally collect and store: the workspace record (name, owner, the plan tier captured at the workspace’s creation, and any archive timestamp); the membership record for each user invited to the workspace (the inviting account, the invited email address, the role granted, and the timestamps of invitation and acceptance); and any pending workspace invitations (the invited email address, the role to be granted, the unguessable invite token, and an expiry timestamp). Where you act as a Workspace Member rather than as the Workspace Owner, additional rules apply — see section 12.

2.6 Client portal data

Where you create a client portal (a feature available on the Agency tier), we store a record linking your account to the monitored query the portal exposes, together with the unique, unguessable URL through which the portal can be reached, an optional label you provide, and an active/inactive flag. Anyone who holds the URL can view the monitoring data for that query without logging in — see section 11.

2.7 Billing information

Payment processing is handled entirely by Stripe on Stripe’s hosted checkout page. We do not see, collect, or store your payment card details. In your profile we retain the Stripe customer and subscription identifiers associated with your account (the subscription identifier is removed when you cancel) and the start and end dates of your current billing period as reported by Stripe.

2.8 Support communications

Our in-app support chat is answered by an automated assistant powered by Anthropic. We do not retain the content of your in-app chat messages, or the assistant’s replies, on our servers. If you choose to escalate the chat to a human, the conversation transcript is emailed to our support inbox through Resend, where it is retained as set out in section 7.

When you submit a message through our public contact form, the same support inbox receives your name, email address, subject, and the body of your message.

2.9 Waitlist submissions

If you join a feature waitlist, we store the email address you provide until the relevant feature is launched or the waitlist is closed.

2.10 Signup and acceptance audit log

When you complete signup, we create a separate audit record evidencing your acceptance of these documents. The record comprises: the date and time of signup; the version identifiers of the Terms of Service and Privacy Policy in force at that time; the onboarding answers you provided (your business name, role, and intended use of the Service); your confirmation that the Service is being used for professional or business purposes; and, where available from the request, the IP address from which you signed up. This record is retained for evidentiary purposes as set out in section 7.

3. How We Use Your Information

We use the information described in section 2 for the purposes set out below. For users to whom the GDPR or UK GDPR applies, we have identified the lawful basis on which we rely for each purpose. For Australian users, the same purposes are the primary purposes of collection under Australian Privacy Principle 6.

3.1 Service delivery

Lawful basis (EEA/UK): performance of a contract (GDPR Art 6(1)(b)). To provide the Service to you. This includes running citation checks across the supported AI engines on your behalf; generating brand sentiment scores, Fix Engine recommendations, competitor analysis, and monitoring insight summaries; generating buyer-intent query suggestions when you submit a URL for that purpose; operating workspaces and member access; storing and displaying your citation history; and delivering monitoring and progress reports.

3.2 Billing and subscription management

Lawful basis (EEA/UK): performance of a contract (GDPR Art 6(1)(b)) and compliance with legal obligations (GDPR Art 6(1)(c)). To process payments via Stripe, manage your subscription state across billing periods, give effect to cancellations and any applicable refunds, and retain financial records as required by Australian tax and accounting law.

3.3 Safety, abuse prevention, and fair-use enforcement

Lawful basis (EEA/UK):our legitimate interests (GDPR Art 6(1)(f)). To enforce per-plan usage limits, deter abuse of the Service, and ensure fair allocation of paid third-party AI capacity across our user base. After an account is deleted, we retain anonymised counts of past activity solely to prevent quota bypass via re-registration; this retention is necessary because the email address remains in our authentication system for the same reason — see section 8.

3.4 User support

Lawful basis (EEA/UK): our legitimate interests (GDPR Art 6(1)(f)). To answer in-app chat questions using an automated assistant, to handle escalated conversations as described in section 2.8, and to respond to public contact-form submissions.

3.5 Service-related communications

Lawful basis (EEA/UK): our legitimate interests (GDPR Art 6(1)(f)) and, where applicable, compliance with legal obligations (GDPR Art 6(1)(c)). To send transactional and policy-related emails relating to your use of the Service, including workspace invitations addressed to people you invite, notices that an unused account is approaching its automatic-deletion date, and notices that we have materially updated this Privacy Policy or the Terms of Service (see section 14).

We do not use the information described in section 2 to send you unsolicited marketing communications, and we do not sell, rent, or otherwise make that information available to any third party for marketing purposes.

3.6 Legal, regulatory, and dispute-resolution use

Lawful basis (EEA/UK): compliance with legal obligations (GDPR Art 6(1)(c)) and our legitimate interests (GDPR Art 6(1)(f)). To respond to lawful requests from law-enforcement and regulatory bodies, to establish, exercise, or defend legal claims, and to enforce our Terms of Service.

Where we rely on legitimate interests as the lawful basis under the GDPR or UK GDPR, you have the right to object to the processing — see section 12. We will give effect to your objection unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defence of legal claims.

4. Third-Party Service Providers

We use the following third-party service providers to operate citepath.io. Each provider receives only the information necessary to perform their function.

ProviderPurposeData shared
SupabaseDatabase, authentication, account emailsAccount, profile, workspace, simulation, monitoring, portal, and audit records as described in section 2. Primary database hosted in Sydney, Australia. Signup confirmation emails are delivered through the Supabase authentication mailer.
VercelApplication hostingIP address and request metadata. Server logs are retained for one day.
StripePayment processingYour email address, billing information, and payment card details — collected directly by Stripe on Stripe’s hosted checkout page. We do not see or store card details.
AnthropicAI processingThe URL and query you submit for a citation check; page content fetched from your submitted URL for the purpose of Fix Engine recommendations, competitor analysis, and buyer-intent query suggestions; the other engines’ answer text for the purpose of brand sentiment scoring; and the content of your in-app support-chat messages.
OpenAI, Google, PerplexityAI citation checksThe URL and query you submit. Each provider performs its own independent web search; no page content is sent to these providers from us.
Jina AIPage content extractionThe URL you submit. Jina AI fetches that URL on our behalf and returns its readable text to us; the text is then handled by us as described in section 2.3.
ResendTransactional email deliveryThe recipient email address and the content of: escalated support-conversation transcripts; public contact-form submissions; workspace invitations sent to people you invite; and notices warning of upcoming automatic account deletion.
UpstashRate limitingYour account identifier used to count requests within defined time windows. No other personal data is shared.

5. Overseas Disclosure

Several of the third-party providers listed in section 4 process personal information outside Australia. These include Vercel, Stripe, OpenAI, Google, Anthropic, Perplexity, Resend, Upstash, and Jina AI. Although our primary Supabase database is hosted in Sydney, Australia, certain Supabase services (including the authentication mailer that delivers signup confirmation emails) may be operated from other regions.

Australian users. We rely on the reasonable-steps mechanism under Australian Privacy Principle 8.1 to ensure that overseas recipients handle your personal information in a manner consistent with the Australian Privacy Principles, principally by relying on the data-processing terms each provider publishes. We do not rely on your use of the Service as deemed consent for overseas disclosure under APP 8.2(b).

EEA and UK users. Where personal data is transferred from the European Economic Area or the United Kingdom to a country that the European Commission or the United Kingdom has not recognised as providing an adequate level of data protection, we rely on the relevant standard contractual clauses, the UK International Data Transfer Addendum, or other transfer mechanisms made available by each provider in their published data-processing terms.

6. PDF Report Generation

PDF reports are generated entirely within your browser. No PDF file is uploaded to or stored on our servers.

The information that appears inside a PDF — citation results, monitoring history, and related metadata — is the same data we already hold about your account as described in section 2. When you click download, that data is sent from our database to your browser, where your browser assembles the PDF on your device.

7. Data Retention

Data typeRetention period
Account and profile dataRetained until you delete your account. On deletion, your profile is marked as deleted, your plan reverts to free, and your subscription identifier is cleared — see section 8.
Email address held in our authentication recordRetained indefinitely after account deletion to prevent quota bypass via re-registration with the same address.
Citation history — the URLs you submitted, the queries you ran, per-engine citation verdicts, and the generated sentiment, Fix Engine, and competitor outputs attached to each simulationRetained until you delete your account. On deletion, the URL and query fields are replaced with anonymous placeholders and the generated-output data is removed. Anonymised count records are then retained indefinitely to enforce quota fairness.
Saved query libraryDeleted on account deletion.
Monitored queries and their monitoring history (including generated one-sentence insight summaries)Deleted on account deletion. Monitoring history is also deleted whenever its parent monitored query is removed.
Workspace recordsRetained until you archive the workspace, after which the workspace is permanently deleted following a 30-day restore window. On the owner’s account deletion, retained workspaces are archived and permanently deleted as part of the account-deletion flow — see section 8.
Workspace membershipsRemoved when a member leaves the workspace, when the owner or an admin removes them, when the member’s account is deleted, or when the parent workspace is permanently deleted.
Pending workspace invitationsCreated with a 7-day expiry. Removed on acceptance, on revocation by an inviter, or when a fresh invitation for the same address replaces a pending one.
Client portal records (Agency tier)Retained until you delete the portal. Where the owning workspace is deleted, the portal is deactivated; the record remains in our database in an inactive state until you explicitly delete it.
In-app support-chat messagesNot retained on our servers. Messages exist only during your browser session.
Escalated support-chat transcripts and public contact-form submissionsDelivered to our support inbox and retained for as long as is reasonably necessary to resolve the matter and to maintain a record of the interaction, after which they are destroyed in the ordinary course of our email housekeeping.
Signup and acceptance audit recordRetained indefinitely after account deletion for evidentiary purposes, to demonstrate which version of the Terms of Service and Privacy Policy you accepted at signup.
Waitlist submissionsRetained until the relevant feature is launched or the waitlist is closed.
Financial records5 years, as required by Australian tax and accounting law.
Payment card detailsNot stored by us. Stripe retains payment data in accordance with its own obligations — see Stripe’s Privacy Policy.
Server logsRetained for 1 day, then deleted.

8. Account Deletion

You may delete your account at any time via the account settings page. Deletion takes effect immediately and cannot be undone.

When you delete your account, the following happens:

  • Permanently deleted: your saved query library; your monitored queries and their monitoring history; the workspaces you owned, together with all queries, monitoring history, and other data scoped to them; your memberships in workspaces owned by other accounts (the other workspace owners are not notified of your departure); and any pending workspace invitations addressed to you.
  • Anonymised and retained:your past citation records. The URL and query fields are replaced with anonymous placeholders, and the generated sentiment, Fix Engine, and competitor outputs are removed. The anonymised count records are then retained indefinitely to enforce quota fairness across re-registration with the same email address — see section 3.3.
  • Deactivated but not deleted:client portals you previously created. Where a portal sat inside one of the workspaces you owned, the portal is deactivated as part of that workspace’s cleanup — the public link will no longer load — but the portal record itself remains in our database until you explicitly delete it from the portal management screen. If you wish for no portal record to remain after account deletion, delete each portal first from the in-app portal screen, then delete the account.
  • Retained indefinitely: your email address in our authentication record, retained to prevent quota bypass via re-registration with the same address; your Stripe customer identifier, retained to enable resumption of a subscription if you return; and your signup and acceptance audit record, retained for evidentiary purposes per section 7.
  • Stripe subscription: if you have an active paid subscription at the time of deletion, that subscription is cancelled immediately as part of the deletion. We do not issue refunds for the unused portion of a billing period unless required by applicable law.

Workspace archiving (a separate flow). Outside the account-deletion path described above, the owner of a workspace may archive that workspace at any time from the workspace management screen. An archived workspace enters a 30-day restore window during which the owner can restore it. After that window expires, the workspace and all data scoped to it are permanently deleted following the same anonymise-then-delete pattern described above for owned workspaces at account deletion.

Re-registration with the same email. If you re-register using the email address that was previously associated with a deleted account, you will be linked to the same internal authentication record. None of the data previously deleted or anonymised is recoverable.

9. Security

We implement industry-standard technical and organisational measures to protect your personal information, including encryption in transit and at rest, access controls, and authentication safeguards. While we take reasonable steps to protect your information, no system is completely secure and we cannot guarantee absolute security.

10. Cookies and Local Storage

We use cookies and limited browser local storage only to keep you signed in and to remember your active workspace selection. We do not use cookies or local storage for advertising, behavioural profiling, or cross-site tracking, and we do not load any third-party analytics scripts.

The items we set are:

  • Authentication session cookies — set by our authentication provider (Supabase) and required to keep you signed in. Clearing these cookies will log you out.
  • Active-workspace selection cookie — set by us and remembered for up to one year. Tells the server which workspace you most recently selected so we can show you the right data on your next request.
  • Active-workspace local-storage entry — stored only in your browser as a backup of your active-workspace selection. Not transmitted to our servers.

You can clear cookies and local-storage entries at any time through your browser settings. None of the items above is used for any purpose other than the strictly necessary functionality described, and no consent banner is presented because no non-essential cookie is set under the ePrivacy Directive or its United Kingdom equivalent.

11. Client Portal

The Service permits users on the Agency tier to create one or more Client Portals. A Client Portal is a public web page, reachable only by following an unguessable URL link, that displays the citation-monitoring status of a single monitored query without requiring the viewer to sign in or hold an account with citepath.io.

11.1 Controller responsibility

The workspace Owner who creates a Client Portal is the data controller in respect of any personal information made available through that portal, and is solely responsible for any disclosure of the portal link to third parties. citepath.io operates only as the technical operator of the portal page; we do not authenticate viewers, we do not record who has been given the link, and we have no control over to whom the workspace Owner discloses the link.

11.2 Deactivation and deletion

The owner of a Client Portal may deactivate the portal at any time from the portal management screen, which causes the public link to stop loading immediately. The owner may also delete the portal record entirely from the same screen, which removes the portal from our database. The behaviour of Client Portals on account deletion and on workspace deletion is described in section 8.

12. Your Rights

Australian users

Under the Australian Privacy Principles, you have the right to:

  • Request access to the personal information we hold about you
  • Request correction of inaccurate or incomplete information
  • Delete your account and associated data via the account settings page
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you believe we have not handled your information in accordance with the APPs

EU, EEA, and UK users

If you are located in the European Union, European Economic Area, or United Kingdom, you also have the following rights under the General Data Protection Regulation (GDPR) or UK GDPR:

  • Right of access to your personal data
  • Right to rectification of inaccurate data
  • Right to erasure (“right to be forgotten”)
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent where processing is based on consent
  • Right to lodge a complaint with your local data protection supervisory authority

Workspace Members

Where you access the Service as a Workspace Member rather than as the account holder, the workspace Owner is the data controller for the queries, URLs, monitoring data, generated outputs, and other workspace-scoped data created inside that workspace. To exercise the rights described above in respect of workspace-scoped data, please contact the workspace Owner in the first instance. We will assist the Owner with any request the Owner reasonably refers to us.

For data held about you in your own account — for example, your email address, profile, and signup audit record — you may contact us directly using the address below.

To exercise any of these rights, contact us at privacy@citepath.io. We will acknowledge your request promptly and provide a substantive response within 30 days of receipt. To protect your personal information from disclosure to an unauthorised person, we may ask you to verify your identity before we act on a request. We do not charge a fee for handling a request unless the request is manifestly unfounded or excessive (for example, a repetitive request), in which case we will tell you in advance and explain the basis for the fee or for declining the request.

13. Minimum Age

citepath.io is intended for users aged 18 and over. We do not knowingly collect personal information from anyone under the age of 18.

14. Changes to This Policy

14.1 Versioning and acceptance

Each version of this Privacy Policy carries a version identifier shown beneath the page title, and your acceptance of the policy is recorded against that identifier. When a new version of the policy takes effect, your continued use of the Service after the effective date constitutes acceptance of the updated policy.

14.2 Material changes

A “material change” is a change that meaningfully expands the categories of personal information we collect, changes the purposes for which we use that information, introduces a new third-party recipient described in section 4, extends the retention periods described in section 7, or limits the rights described in section 12.

Before a material change takes effect, we will:

  • send an email to the address associated with your account, at least 30 days before the effective date of the new version, describing the change and linking to the updated policy; and
  • when you next sign in to the Service on or after the effective date, present an in-app prompt requiring you to re-accept the updated policy before you continue to use the Service.

14.3 Non-material changes

A “non-material change” is a change that does not affect how we collect, use, disclose, retain, or protect your personal information — for example, clarifications of wording, corrections to typographical errors, or reorganisations of the structure of this document. We may publish a non-material change without prior notice; the version identifier and the “Last updated” date shown beneath the page title will reflect the change.

14.4 If you do not wish to accept a material change

The in-app re-acceptance prompt described in section 14.2 is a contractual gate; it does not replace the email notice required by the same section. If you do not wish to accept a material change, you may delete your account before the effective date in accordance with section 8. In that case the prior version of the policy continues to apply to your use of the Service up to the date of deletion.

15. Contact Us

For privacy-related enquiries or to exercise your rights, contact us at:

Contact

citepath.io

ABN 48 595 594 995

privacy@citepath.io