Skip to main content
CCiteUp
FeaturesPricingGuideDocs
中文Log inStart preview→
Menu
FeaturesPricingGuideDocs中文Log in
  1. Home
  2. Privacy Policy

Legal

Privacy Policy

This policy explains what information CiteUp handles, why we use it, when it reaches service providers, and the choices available to you.

Effective
July 13, 2026
Version
1.0
On this page
  1. Scope and who is responsible
  2. Information we collect
  3. How and why we use information
  4. AI, search, and infrastructure providers
  5. Cookies and local storage
  6. When we disclose information
  7. International transfers
  8. Retention and deletion
  9. Security
  10. Your privacy rights
  11. Information about other people
  12. Children
  13. Changes to this policy
  14. Contact

1. Scope and who is responsible

This Privacy Policy applies to CiteUp's public website, development-preview workspace, support interactions, and related services (collectively, the "Service").

The data controller is the entity or individual identified as the CiteUp operator in your preview invitation, order form, or other commercial agreement (the "Operator", "we", "us", or "our"). If your organization gives you access, it may separately control account and workspace information and we may process that information on its behalf.

Please note: The Service is intended for organizations and professional use. It is not designed for personal or household use.

2. Information we collect

We collect information you provide, information created through your use of the Service, and limited technical information needed to operate and protect it.

  • Account and identity data, such as your name, work email, profile image, authentication provider, invitation status, and account identifiers.
  • Workspace and company data, including business profiles, product facts, audiences, brand guidance, source material, prompts, uploaded images and documents, publication status, and other content you submit.
  • Generated and monitoring data, including draft packages, model outputs, raw answer-engine responses, citations, source URLs, extracted brand mentions, metrics, warnings, and associated usage metadata.
  • Support and communications data, including messages, feedback, requests, and records of our response.
  • Technical and usage data, such as IP address, device and browser information, request timestamps, route and error logs, session events, and security signals.
  • Local browser data used for authentication cooldowns, language preferences, session continuity, and interface state.

3. How and why we use information

Where applicable law requires a legal basis, we rely on performance of a contract, our legitimate interests in operating and securing a B2B service, compliance with legal obligations, and consent where we specifically request it. We do not use workspace content to train a general-purpose model of our own unless we first give affected customers separate notice and, where required, obtain consent.

  • Provide, authenticate, maintain, and secure the Service and its workspaces.
  • Generate requested content, run answer-engine monitoring, calculate metrics, and return results to your workspace.
  • Process uploads, preserve source traceability, troubleshoot failures, and improve reliability and usability.
  • Communicate about access, security, support, material service changes, and preview participation.
  • Detect misuse, enforce our terms, comply with law, and establish, exercise, or defend legal claims.

4. AI, search, and infrastructure providers

The Service depends on specialized providers. Depending on the feature and configuration, relevant prompts, profile fields, source excerpts, URLs, files, or instructions may be sent to providers such as OpenAI, Anthropic, OpenRouter and models routed through it, and Doubao Search. Authentication, database, file storage, hosting, delivery, and operational logging may use Supabase, Cloudflare, Google, and Axiom.

These providers process information under their own service terms and our applicable vendor arrangements. Their locations, retention settings, and model-training controls can vary by provider and plan. We limit disclosures to what is reasonably needed for the requested feature, but you should not submit regulated, highly sensitive, export-controlled, or confidential personal data unless your organization has approved that use and appropriate contractual controls are in place.

5. Cookies and local storage

We use essential cookies and similar browser storage for authentication, security, language selection, one-time-code request limits, and saved interface state. These technologies are necessary to provide the features you request. The current preview does not use this data to sell personal information or deliver cross-context behavioral advertising.

If we later add non-essential analytics or advertising technologies, we will update this policy and provide any notice or consent control required by applicable law before using them.

6. When we disclose information

We do not sell personal information. We do not share personal information for cross-context behavioral advertising as those terms are defined under California law.

  • To service providers and subprocessors that host, authenticate, store, monitor, search, generate, or support the Service.
  • To your organization and its workspace administrators, consistent with their account permissions.
  • To professional advisers, auditors, insurers, and financing or transaction counterparties under appropriate confidentiality obligations.
  • To authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or respond to valid legal process.
  • In connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to customary safeguards.

7. International transfers

The Operator and our providers may process information in countries other than where you live. Where required, we use recognized transfer mechanisms and contractual safeguards, such as adequacy decisions or standard contractual clauses. Your organization may contact us for information about safeguards relevant to its deployment.

8. Retention and deletion

We retain account and workspace information while the Service is provided and as reasonably needed for the purposes described above. Retention varies by data type, workspace configuration, provider settings, legal requirements, security needs, and active disputes. Deleted records may remain in protected backups or audit logs for a limited period before being overwritten.

When an account or preview ends, we may delete or de-identify information unless continued retention is required by law, necessary to protect the Service, or directed by the customer that controls the workspace. Model or search providers may apply their own documented retention periods to requests they process.

9. Security

We use reasonable administrative, technical, and organizational measures designed to protect information, including access controls, authenticated requests, tenant-level database controls, and protected service credentials. No online service is completely secure. You are responsible for protecting access to your email account, devices, authentication sessions, and workspace.

10. Your privacy rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent without affecting earlier lawful processing. You may also have the right to complain to your local data-protection authority.

We may need to verify your identity and authority before acting. If your account is managed by an organization, submit the request to that organization first; we will assist it where required. Rights can be limited by law, security, the rights of others, or information we must retain. We will not discriminate against you for exercising an applicable privacy right.

11. Information about other people

If you upload or submit information about another person, you represent that you have the authority and a valid legal basis to do so and have provided any required notice. Do not use the Service to build profiles of individuals, make solely automated decisions with legal or similarly significant effects, or process sensitive personal data without appropriate review and authorization.

12. Children

The Service is not directed to children, and we do not knowingly collect personal information from anyone under 18. Contact us if you believe a child has provided personal information to the Service.

13. Changes to this policy

We may update this policy as the Service, providers, or legal requirements change. We will post the revised version with a new effective date and provide additional notice when a change materially affects your rights or our use of information.

14. Contact

For privacy questions or requests, use the legal contact below and identify the workspace and email address involved. The Operator's full legal name and address are also available in the applicable preview invitation, order form, or commercial agreement.

Legal and privacy contactprivacy@citeup.ai

Related documentRead the Terms of Service→
CCiteUp

Improve AI visibility with verifiable facts.

ProductFeaturesPricingCompare with SEO
LearnGEO strategy guideWhat is GEO?Documentation
LegalPrivacy PolicyTerms of Service
© 2026 CiteUpCiteUp is in development preview. AI answers can vary by engine and over time.