Privacy Policy
Citations.io is a trading style of CITATIONS IO LTD, a company registered in England and Wales (company number 17311704) with its registered office at 38, Collingwood Buildings Collingwood Street, Newcastle Upon Tyne, United Kingdom, NE1 1JF. Registered with the UK Information Commissioner's Office (ICO registration ZC187049).
1.Who we are
Citations.io is operated by CITATIONS IO LTD, a company registered in England and Wales (company number 17311704), with its registered office at 38, Collingwood Buildings Collingwood Street, Newcastle Upon Tyne, United Kingdom, NE1 1JF ("we", "us", "Citations.io").
We act as the data controller for the personal data described in this policy, except where we process Customer Data on behalf of a business customer, in which case that customer is the controller and we act as their processor under our Data Processing Addendum.
For any privacy question or to exercise your rights, contact privacy@citations.io.
2.Scope of this policy
This policy applies to the citations.io website, the Citations.io application, our APIs, browser extensions, marketing communications, and any other product or service that links to it (collectively, the "Service"). It does not apply to third-party websites or services we do not control, even if they are linked from the Service.
3.Personal data we collect
Information you provide
- Account data: name, work email, password (hashed), organisation, role.
- Billing data: billing address, VAT number, last four digits of payment card (full card data is handled by Stripe, never stored by us).
- Customer Data: brand names, domains, prompts, competitors, reports, integration credentials and any other data you submit to the Service.
- Support data: information you share when contacting us, including emails, chat messages and attachments.
Information collected automatically
- Usage data: pages viewed, features used, clicks, referring URLs, session timestamps.
- Device data: IP address, browser type and version, operating system, device identifiers, time zone, language.
- Log data: API requests, error traces, authentication events for security and abuse prevention.
- Cookies and similar technologies: see our Cookie Policy.
Information from third parties
- Identity providers (e.g. Google) when you sign in via OAuth - we receive your name, email and profile image.
- Integrations you choose to connect, such as Google Search Console, GA4, Slack or Mailgun.
- AI search engines (ChatGPT, Perplexity, Gemini, Claude and others) - we query their public-facing surfaces to measure how your brand is cited; this is publicly available output, not personal data.
- Enrichment providers for company firmographics in connection with sales outreach where lawful.
4.How and why we use personal data
- Provide the Service - create your account, deliver scans, citations, prompts, reports and integrations you request.
- Billing - process subscriptions, prevent fraud, comply with tax obligations.
- Communications - send service emails, security alerts, product updates and (with your consent where required) marketing.
- Improve the Service - measure feature usage, debug issues, develop new features.
- Security and abuse prevention - detect, investigate and respond to threats, misuse and policy violations.
- Legal compliance - respond to lawful requests, enforce our agreements, exercise or defend legal claims.
5.Lawful bases (UK and EU GDPR)
- Contract (Art. 6(1)(b)) - to provide the Service you have signed up for.
- Legitimate interests (Art. 6(1)(f)) - to secure and improve the Service, prevent fraud, conduct limited B2B marketing of our own products, and operate our business. You may object at any time.
- Consent (Art. 6(1)(a)) - for non-essential cookies, marketing emails where required, and any optional processing we describe at the point of collection. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)) - to comply with tax, accounting and law-enforcement requirements.
6.How we share personal data
We share personal data only where necessary and with appropriate safeguards in place:
- Sub-processors who operate the Service on our behalf (hosting, AI inference, email, payments, analytics, support). The current list is at /subprocessors.
- Professional advisers (lawyers, accountants, auditors) under duties of confidentiality.
- Authorities and courts where required by law, regulation, or to protect rights, property or safety.
- Successors in connection with a merger, acquisition, financing or sale of assets, subject to confidentiality protections.
We do not sell personal data. We do not "share" personal data for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA).
7.International data transfers
We are based in the United Kingdom. Some of our sub-processors are located in the United States or other countries outside the UK and European Economic Area (EEA). Where we transfer personal data outside the UK or EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions where available, and supplementary technical and organisational measures such as encryption in transit and at rest.
8.How long we keep personal data
- Account data: for the life of the account, plus up to 90 days after deletion for backups and dispute resolution.
- Customer Data: for the life of the account; you can delete specific records at any time. We will delete or return Customer Data within 30 days of termination, except where retention is required by law.
- Billing records: 7 years to meet UK accounting and tax requirements.
- Log and security data: typically 90 days, longer if needed for an active investigation.
- Marketing data: until you unsubscribe, plus a suppression record to honour your opt-out.
9.Your privacy rights
UK and EEA residents (UK GDPR / EU GDPR)
- Access a copy of your personal data.
- Rectification of inaccurate or incomplete data.
- Erasure ("right to be forgotten") where applicable.
- Restriction of processing in certain circumstances.
- Portability of data you have provided to us.
- Object to processing based on legitimate interests, including profiling and direct marketing.
- Withdraw consent at any time where processing relies on consent.
- Lodge a complaint with the UK Information Commissioner's Office (ico.org.uk; we are registered with the ICO under registration number ZC187049) or your local EU supervisory authority.
California residents (CCPA/CPRA)
- Right to know what personal information we collect, use, disclose and (if applicable) sell or share.
- Right to delete personal information we hold about you.
- Right to correct inaccurate personal information.
- Right to opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information, and we honour Global Privacy Control (GPC) signals where applicable.
- Right to limit use of sensitive personal information.
- Right to non-discrimination for exercising your rights.
- Shine the Light (Cal. Civ. Code §1798.83) - we do not disclose personal information to third parties for their own direct marketing.
Other US state residents
If you live in a US state with a comprehensive privacy law - including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky or Rhode Island - you have broadly equivalent rights to confirm whether we process your personal data, obtain a copy of it, correct it, delete it and opt out of targeted advertising, sale and profiling with legal or similarly significant effects.
- We do not sell personal data, use it for targeted advertising, or process it for profiling that produces legal or similarly significant effects about you.
- We honour universal opt-out signals such as Global Privacy Control in states that require it.
- We do not use sensitive personal data for any purpose beyond delivering the Service, and we do not knowingly process the data of anyone under 18.
- If we decline a request, you may appeal by replying to our decision email; we will respond to appeals within 45 days and, where your state provides one, tell you how to contact your Attorney General.
Nevada residents may submit a verified request not to have covered information sold; we do not sell such information.
How to exercise your rights
Email privacy@citations.io from the address associated with your account. We will verify your identity and respond within the time required by applicable law (typically 30 days for GDPR, 45 days for CCPA). Authorised agents may submit requests on your behalf with documented authority. There is no charge for exercising your rights.
10.Automated decisions and AI features
Citations.io uses machine learning and large language models to score visibility, classify citations, generate prompts and suggest content packs. These outputs are decision-support tools, not legally significant automated decisions about you. AI-generated content may be inaccurate; you remain responsible for reviewing it before relying on it. We do not use your Customer Data to train foundation models, and we contractually require our AI sub-processors not to use your inputs to train their models on a default-off basis.
11.Security
We implement administrative, technical and physical safeguards designed to protect personal data, including TLS 1.2+ in transit, AES-256 at rest, role-based access control, least-privilege access, audit logging, vulnerability scanning, and incident response procedures. See our Security page for details. No system is perfectly secure; please use a strong, unique password and enable multi-factor authentication where available.
12.Children's data
The Service is intended for business users aged 18 or over. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact privacy@citations.io and we will delete it.
14.Changes to this policy
We will update this policy from time to time. Material changes will be notified by email or in-product notice at least 30 days before they take effect. The "Last updated" date at the top of this page indicates the current version.
15.Contact, DPO, EU and UK representatives
Controller: CITATIONS IO LTD (trading as Citations.io), 38, Collingwood Buildings Collingwood Street, Newcastle Upon Tyne, United Kingdom, NE1 1JF. US office: Citations IO, 5504 13th Ave, Unit #238, Brooklyn, NY 11219, United States.
Privacy contact: privacy@citations.io.
We are not required to appoint a statutory Data Protection Officer, but our privacy contact handles all DPO-equivalent matters. Where required by Article 27 GDPR, we will appoint EU and UK representatives and publish their contact details here.
Write to privacy@citations.io and we will respond within 30 days, or sooner where required by law.