Privacy
What we collect, why we collect it, who else touches it, and how to have it deleted.
Version 1.0 · effective 30 July 2026
1. Who we are
CitedProof is operated by KIRA Holdings. Contact for any privacy question, request or complaint: hello@citedproof.com. A human answers; there is no ticket portal.
2. What we collect
Three categories, and nothing outside them.
- Account data
- Email address, a hash of your password (never the password), your name and company name if you supply them, your plan, and timestamps for creation, last login and email verification. Sessions store a hash of the session token, the IP address and the browser user-agent string, so that you can see and revoke your own sessions.
- Measurement data
- The domains and brand details you enter, the prompts in your set, and everything the engines returned for those prompts: answer text, cited source URLs, and the raw payload. This is data about your brand, and it is generated by us — it does not come from your customers and it contains no personal data about them unless an engine's answer happens to name a person publicly associated with the brand.
- Commerce and operational data
- Orders, payment records (see §4), and an append-only event log of actions taken in the product: who changed what, when, from which IP. The event log exists so that a disputed change has an answer, and it is the one thing we cannot let you edit.
3. What we do not collect
- No advertising or analytics pixels. There is no Google Analytics tag, no Meta pixel, no Segment, no session recorder, on any page of this site or in the product.
- No tracking cookies. The only cookie we ever set is the session cookie you get after logging in, and it exists solely to keep you logged in.
- No cross-site identifier, no fingerprint, no data broker enrichment. We do not buy data about you and we do not sell data about you. There is no circumstance in which we would.
- No card numbers. See §4.
Our own product analytics is a first-party event counter: an event name, the page path, a coarse viewport size, the
referring host (not the full URL), and any utm_ parameters you arrived with. It sets no cookie and
generates no identifier, so it cannot reconstruct a person across visits. If your browser sends Do Not Track or Global
Privacy Control, it records nothing at all. The full event list is documented in the source file that implements it.
4. Payments
We never see your card. Payment is processed by TAP Payments. You enter card details on TAP's own hosted page. We store the charge identifier, the amount, the currency, the status and — for the monthly plan — a token that lets TAP charge the same card again. The token is useless to anyone else and cannot be turned back into a card number.
5. Who else touches the data
The complete list of processors, and exactly what each one receives. Adding one is a dated change in §12.
| Processor | Purpose | What it receives |
|---|---|---|
| Apify | Runs the engine queries | Your prompt text and target domain. No account or personal data. Their stated data retention on our tier is 31 days. |
| OpenAI | Scores each answer against a strict schema | The engine's answer text and your brand name and aliases. No account or payment data. |
| TAP Payments | Card processing | Your card details, directly from you; your email and the amount. We receive back a charge ID and a token. |
| Cloudflare | Turnstile anti-abuse on the signup form, if enabled | A challenge interaction. If no site key is configured, the script is never loaded and Cloudflare receives nothing. |
| Our host | Servers and database | Everything, because it is the machine the software runs on. The database is not shared with other products. |
We do not use your data to train any model. We do not send your measurement data to any party not listed above.
6. Aggregate effect sizes
We learn across customers, and here is the exact boundary. When an action is marked shipped and later re-measured, the pair “action type → measured effect” goes into an aggregate table. That table contains the action type, the outcome and the sample size. It does not contain your domain, your brand, your prompts, your text, or anything that identifies you, and no customer-identifying field is ever written to it.
This is how the recommendations get better over time, and it is disclosed rather than buried. If you would rather your results were excluded entirely, email us and we exclude your account — there is no penalty and no feature is withheld.
7. How long we keep it
- Account data — for as long as the account exists, then 30 days after deletion is requested, then it is gone.
- Measurement data — for the life of the account, because the longitudinal series is the product. You can delete a workspace and its runs at any time, and deletion is immediate rather than a flag.
- Payment records — kept for as long as tax and accounting rules require, which is longer than the account. This is the one category we cannot delete on request.
- Event log — 24 months.
- Raw provider payloads — our copy follows the measurement data above; Apify's own copy expires on their 31-day retention.
8. Your rights
Export, correct or delete, by email, without a reason. Send the request from the address on the account to hello@citedproof.com. We answer within 30 days and normally within two business days.
- Export — every raw run, as CSV and JSON, including after you cancel. This is also a button in the product.
- Deletion — the account and its measurement data are deleted within 30 days, except payment records as noted above.
- Correction — anything you can see, you can edit; anything you cannot, we correct on request.
- Objection to the aggregate panel — see §6.
If you are in a jurisdiction that grants additional statutory rights, those rights apply and we do not require you to cite them. If you believe we have handled your data badly, tell us first — but you are entitled to complain to your local authority without doing so.
9. Security
- Passwords are stored as hashes. We cannot read your password and cannot email it to you.
- Session tokens are stored hashed, so a database copy does not hand over live sessions.
- Every database query is parameterised. Every table carrying customer data is scoped to the owning account.
- Traffic is served over HTTPS only.
- If we suffer a breach affecting your data, we email you what we know within 72 hours of establishing it — including when the answer is still “we do not yet know the scope”.
10. Where the data lives
Our servers are in Europe. Our processors operate internationally; sending a prompt to a US-based engine provider is inherent to the product, since that is where the engines are. If you cannot accept that transfer, this product cannot work for you, and we would rather say so on this page than after you have paid.
11. Children
This is a business tool. It is not directed at anyone under 16 and we do not knowingly hold their data.
12. Changes
- Version 1.0 — 30 July 2026
- First published.
Material changes are emailed to account holders before they take effect. Every version is dated here; we do not silently swap the document and leave the date.