Privacy
What we collect, why we collect it, who else touches it, and how to have it deleted.
Version 1.0 · effective 30 July 2026
1. Who we are
CitedProof is operated by KIRA Holdings. Contact for any privacy question, request or complaint: hello@citedproof.com. A human answers; there is no ticket portal.
2. What we collect
Three categories, and nothing outside them.
- Account data
- Email address, a hash of your password (never the password), your name and company name if you supply them, your plan, and timestamps for creation, last login and email verification. Sessions store a hash of the session token, the IP address and the browser user-agent string, so that you can see and revoke your own sessions.
- Measurement data
- The domains and brand details you enter, the prompts in your set, and everything the engines returned for those prompts: answer text, cited source URLs, and the raw payload. This is data about your brand, and it is generated by us, it does not come from your customers and it contains no personal data about them unless an engine's answer happens to name a person publicly associated with the brand.
- Commerce and operational data
- Orders, payment records (see §4), and an append-only event log of actions taken in the product: who changed what, when, from which IP. The event log exists so that a disputed change has an answer, and it is the one thing we cannot let you edit.
3. Tracking, stated exactly
- Nothing tracks you inside the product. No advertising tag, no analytics tag and no session recorder runs on any signed-in screen. Your measurement data, your prompts and your findings never reach an advertising network.
- The marketing pages carry two advertising tags. Google Analytics 4 and the Meta pixel run on
the eight public pages of citedproof.com, including this one, so that we can tell which advertising brought
someone here. They set their own cookies (Google's
_ga, Meta's_fbp). We name them here rather than let you find them in the page source. - Do Not Track and Global Privacy Control switch off all three. If your browser sends either signal, neither vendor tag is even downloaded and our own counter records nothing. That is enforced before any request is made, not asked of the vendors afterwards.
- No cross-site identifier of ours, no fingerprint, no data broker enrichment. We do not buy data about you and we do not sell data about you. There is no circumstance in which we would.
- No card numbers. See §4.
Our own counter is first-party and deliberately thin: an event name, the page path, a coarse viewport size, the
referring host (not the full URL), and any utm_ parameters you arrived with. It sets no cookie
of ours and generates no persistent identifier, so on its own it cannot reconstruct a person across visits. The one
cookie CitedProof itself sets is the session cookie you get after logging in, and it exists solely to keep you
logged in.
4. Payments
We never see your card. Payment is processed by TAP Payments. You enter card details on TAP's own hosted page. We store the charge identifier, the amount, the currency and the status. If TAP returns a card token with a payment we store that too, but nothing in CitedProof ever charges it: the monthly renewal is a payment link you pay yourself, not a charge we initiate. The token is useless to anyone else, cannot be turned back into a card number, is never included in your data export, and is destroyed when you delete your account.
5. Who else touches the data
The complete list of processors, and exactly what each one receives. Adding one is a dated change in §12.
| Processor | Purpose | What it receives |
|---|---|---|
| OpenAI | Scores each answer against a strict schema | The engine's answer text and your brand name and aliases. No account or payment data. |
| TAP Payments | Card processing | Your card details, directly from you; your email and the amount. We receive back a charge ID and a token. |
| Google (Analytics 4) | Advertising measurement on the public marketing pages only | A page view and the events in §3 from the public pages, with Google's own cookie. Never any account, measurement or payment data. Nothing at all if you send Do Not Track or Global Privacy Control. |
| Meta (pixel and Conversions API) | Advertising measurement on the public marketing pages only | The same public-page events, with Meta's own cookie; for a purchase, the order reference and amount so the same sale is not counted twice. Never any account, measurement or prompt data. Nothing at all if you send Do Not Track or Global Privacy Control. |
| Cloudflare | Turnstile anti-abuse on the signup form, if enabled | A challenge interaction. If no site key is configured, the script is never loaded and Cloudflare receives nothing. |
| Our host | Servers and database | Everything, because it is the machine the software runs on. The database is not shared with other products. |
We do not use your data to train any model. We do not send your measurement data to any party not listed above.
6. Aggregate effect sizes
We learn across customers, and here is the exact boundary. When an action is marked shipped and later re-measured, the pair “action type → measured effect” goes into an aggregate table. That table contains the action type, the outcome and the sample size. It does not contain your domain, your brand, your prompts, your text, or anything that identifies you, and no customer-identifying field is ever written to it.
This is how the recommendations get better over time, and it is disclosed rather than buried. If you would rather your results were excluded entirely, email us and we exclude your account, there is no penalty and no feature is withheld.
7. How long we keep it
- Account data, for as long as the account exists. You delete the account yourself, from the settings screen, and it happens at once rather than after a waiting period and rather than behind a flag. If you have never paid us, the account row itself is removed and the email log with it. If you have paid, see payment records below, that case is different and we say how.
- Measurement data, for the life of the account, because the longitudinal series is the product. You can delete a workspace and its runs yourself, from the workspaces screen, and it is a real delete rather than a hidden flag: the runs, snapshots, findings and reports under it go with it. The screen counts what will be destroyed before it offers to do it, and asks you to type the domain. Deleting the whole account destroys every workspace under it in the same way.
- Payment records, kept for as long as tax and accounting rules require, which is longer than the account. This is the one category we cannot delete on request, and it changes what deleting your account does. Rather than claim otherwise, we destroy everything else and anonymise the account those records hang off: the email address, name and company are removed and the password is destroyed, so the account cannot be signed into and nothing left in it identifies you. The deletion screen tells you which of the two outcomes applies to you before you confirm.
- Event log, 24 months.
- Raw provider payloads, our copy follows the measurement data above.
8. Your rights
Export and delete yourself, from the settings screen, without asking and without a reason. Neither is gated on your plan being paid. For anything else, a correction, or a question about the two, write from the address on the account to hello@citedproof.com and we answer within 30 days, normally within two business days.
- Export, one JSON file, from a button in the product, including after you cancel and while an account is read-only; it is not gated on your plan being paid. It carries your account and brand-kit records, every workspace and brand profile, every competitor, every prompt, every measurement snapshot with its denominators and sufficiency reason, every finding, every report record, your orders, payments and subscription history, and your event log. Two things are deliberately not in it: secrets (password hash, session tokens, any card token or provider customer id) are never exported, and the per-run rows behind a snapshot are not in the file today, ask us and we will send them, and they are covered by the deletion right below either way.
- Deletion, a button in the product, not a request to a human: the settings screen counts exactly what will be destroyed, asks you to type your email address, and then does it immediately. Payment records are the single exception, and §7 says precisely what happens to the account they are attached to.
- Correction, some of what you can see is editable in the product today (a workspace name, for one) and the rest is not yet. Anything you cannot edit yourself, we correct on request, from the address on the account.
- Objection to the aggregate panel, see §6.
If you are in a jurisdiction that grants additional statutory rights, those rights apply and we do not require you to cite them. If you believe we have handled your data badly, tell us first, but you are entitled to complain to your local authority without doing so.
9. Security
- Passwords are stored as hashes. We cannot read your password and cannot email it to you.
- Session tokens are stored hashed, so a database copy does not hand over live sessions.
- Every database query is parameterised. Every table carrying customer data is scoped to the owning account.
- Traffic is served over HTTPS only.
- If we suffer a breach affecting your data, we email you what we know within 72 hours of establishing it, including when the answer is still “we do not yet know the scope”.
10. Where the data lives
Our servers are in Europe. Our processors operate internationally; sending a prompt to a US-based engine provider is inherent to the product, since that is where the engines are. If you cannot accept that transfer, this product cannot work for you, and we would rather say so on this page than after you have paid.
11. Children
This is a business tool. It is not directed at anyone under 16 and we do not knowingly hold their data.
12. Changes
- Version 1.0, 30 July 2026
- First published.
Material changes are emailed to account holders before they take effect. Every version is dated here; we do not silently swap the document and leave the date.