Live — tracking ChatGPT, Gemini, Claude, Grok, DeepSeek, Google AI Overviews & PerplexityMulti-run sampling — every engine on your plan, every cycleFree first measurement — see how AI sees youEvery metric ships a 95% confidence range
Legal

Privacy Policy

What we collect, why we collect it, who processes it, and the rights you have over it.

This policy explains how E-Nomad LLP (“CitedOS”, “we”, “us”) handles personal data when you use citedos.com and the CitedOS platform. We are the data controller for account data; for the brand data inside your workspace we act on your instructions. Short version: we collect the minimum needed to run an AI-visibility measurement service, our public marketing pages carry analytics and advertising tags that do not run unless you accept them — section 5 — none of which reaches the product you sign in to, and we never sell personal data. We do build aggregated, de-identified industry benchmarks out of platform activity, and we treat those aggregates as ours to publish and commercialize — see section 3, which also covers what differs between the Free plan and paid plans.

1. Data we collect

  • Account data — your email address, display name (optional) and a bcrypt-hashed password. We never store passwords in plain text. If you sign in with Google instead of a password, we also store the URL of your Google profile picture, and there is no password to store — see section 12.
  • Workspace configuration — the brands, competitors, topics and prompts you set up for tracking. This is business data about companies, though names or URLs you enter may incidentally contain personal data.
  • Measurement data — answers and citations collected from the ChatGPT, Gemini and Claude APIs for your prompts, and copies of the publicly available web pages those answers cite. This is content about the public web, not about you.
  • Connected account data — if you link Google Search Console, Google Analytics 4 or Bing Webmaster Tools, we store an encrypted refresh token plus a bounded cache of the metrics you asked us to read (search queries, clicks, impressions, position, AI-referral summaries). We read only the properties you select, you can disconnect at any time, and this data is never used for model improvement or sold in any form — see section 3. Section 12 sets out exactly which Google APIs we call and what we do with what they return.
  • Usage data — server logs (IP address, user agent, timestamps, requested routes) and in-product events, used for security, debugging and capacity planning. When something errors we also record the fault itself — the exception, where it happened, and your IP address — with our monitoring provider, deliberately without request bodies, cookies or query parameters. Separately, and only on our public marketing pages and only if you accept it, website analytics and advertising measurement run in your browser; section 5 says exactly what that is and how to refuse it.
  • Billing data — handled by LemonSqueezy as merchant of record. We receive order metadata (plan, status, order ID, billing email) but never your full card number.
  • Demo booking data — if you book a demo on /demo, whatever you give the scheduler (typically your name, email address and an optional note) plus the time you chose. You need no account to do this, so for many people it is the only personal data of theirs we ever hold. The booking is made inside Google’s scheduler and reaches us as a calendar invitation — it does not pass through the CitedOS database. See section 4 for Google’s role and section 6 for how long we keep it.

2. Why we process it (purposes and legal bases)

  • Providing the service (contract) — running your measurement cycles, storing results, showing dashboards and reports.
  • Billing and account management (contract, legal obligation).
  • Security and abuse prevention (legitimate interest) — protecting accounts, rate-limiting, fraud prevention.
  • Service improvement (legitimate interest) — aggregated, de-identified statistics about how the product is used.
  • Transactional email (contract) — receipts, security notices, service messages. Marketing email only with your consent, with a working unsubscribe.
  • Arranging a demo you asked for (steps taken at your request before any contract — GDPR Art. 6(1)(b)) — holding the slot, sending the invitation and joining the call. The same purpose and the same basis apply if you skip the scheduler and email us for a time instead. Booking does not create a CitedOS account, and marketing email still requires the separate consent described above.

3. Aggregated insights, benchmarks and model training

CitedOS is a benchmarking product: it is only useful because it measures many brands against the same engines. This section states exactly what we derive from that, and where the line sits.

  • Aggregated, de-identified data belongs to us. We compute statistics across workspaces — citation rates by source type, engine behaviour, industry visibility baselines — that cannot reasonably be linked back to you, your workspace or any individual. As between you and us, that aggregated data is owned by CitedOS, and we may use, publish and commercialize it for any lawful purpose, including industry benchmarks, research, public reports and product development. It is not personal data, and we do not attempt to re-identify it.
  • Free plan and trials — model and product improvement. On the Free plan and during a trial, we may use your workspace content (prompts, topics and the engine answers we collect for them) to improve our own ranking, extraction and analysis models. You can opt out at any time, on a forward-looking basis, from Settings → Data rights (or by emailing support@citedos.com if you prefer) — opting out does not downgrade your plan or reduce your features.
  • Free plan and trials — OpenAI’s data-sharing programme. On the Free plan and during a trial, the calls we make to OpenAI on your behalf run on an API key enrolled in OpenAI’s data-sharing programme: OpenAI may use the prompts and answers sent through that key to improve their models, and in exchange we get a free daily allowance that is part of how a no-card trial can exist. This covers the measurement prompts we send on your behalf, the answers they return, and the internal analysis steps that read them. It never covers anything read from a connected Google or Bing account, which stays on the private key on every plan. The same opt-out applies: switch it off in Settings → Data rights and your workspace moves to our private key, on which OpenAI does not train.
  • Paid plans are excluded. We do not use paid workspace content for model improvement at all, and paid workspaces always run on our private OpenAI key, which is excluded from OpenAI’s training. Upgrading stops this prospectively; it does not retroactively unwind improvements already made while you were on a free plan.
  • Always carved out, on every plan. We never use for model improvement, and never sell in any form: account credentials, billing data, support conversations, or anything read from a connected Google Search Console, Google Analytics or Bing account — those providers’ API terms forbid it and we honour that.
  • This is still not a sale of personal data. Commercializing de-identified aggregates is not selling personal data, and we do not share personal data for cross-context behavioural advertising. We have not done so in the preceding twelve months.
  • After you leave. Aggregates already computed survive account deletion, because they contain nothing that identifies you. Your identifiable account and workspace data is still deleted or de-identified on the schedule in section 6.

4. Processors and subprocessors

We use a small set of infrastructure providers to run CitedOS. Each processes data only to provide its function to us:

  • Vercel — application hosting and content delivery, plus cookieless product and performance analytics (page views and Web Vitals, recorded against the page template rather than any URL that identifies you).
  • Supabase — managed Postgres database where account and workspace data live.
  • LemonSqueezy — payments, tax and receipts as merchant of record (it is an independent controller for the checkout it operates).
  • OpenAI, Google and Anthropic — we send your configured prompts (buyer-intent queries, not your personal data) to their APIs to measure engine answers. For OpenAI we hold two keys and which one your workspace uses is a data-rights decision, not an operational one: paid and opted-out workspaces use a private key excluded from training, free and trial workspaces use a data-sharing key OpenAI may train on (section 3).
  • ScrapingBee — fetches the public web pages cited in engine answers for source analysis.
  • Google Calendar (appointment scheduling) — the booking form on /demo is hosted and run by Google. It is loaded only if you click to load it. If you do, Google receives whatever you type into its form (typically your name, email address and an optional note), along with your IP address and user agent, and may set its own cookies in that frame. For that booking Google is an independent controller under its own privacy policy, not our processor — we do not control what it collects there. What reaches us is the resulting calendar event: your name, email address and any note you added. If you would rather not involve Google, email support@citedos.com and we will arrange a time by hand — see section 5.
  • Trigger.dev — background job infrastructure that orchestrates collection and analysis pipelines.
  • Sentry — error and performance monitoring for the application. When something breaks, Sentry receives the error and the technical context around it: the exception and its stack trace, the page or API route it happened on, browser and device details, your IP address, and the identifiers of your account and your workspace — so we can tell whether a fault hit one customer or everyone. Those identifiers are opaque IDs; we do not send your name or your email address with them. We have disabled the collection of request bodies, cookies and query parameters, so what you typed into a form, your session cookie and anything our own URLs carry in a query string are not sent. Sentry is our processor and uses this only to help us fix the fault.
  • Consent management platform [vendor to be confirmed before launch] — the banner that asks which cookies you accept and the durable record of your answer. It runs before any analytics or advertising tag, stores your choice on your device so you are not asked again on every page, and keeps a record of which version of the banner you were shown and when, which is how we evidence consent if we are asked to. It is our processor.
  • Google (website analytics) — Google Analytics 4, delivered through Google Tag Manager. This is Google’s third and separate role on this list, and we keep the three apart on purpose because the data, the legal basis and your ability to refuse are different in each: elsewhere in this list Google is an AI-engine API vendor that answers our measurement prompts, and the independent controller of the /demo scheduler. Here it is our processor for analytics. On our public marketing pages only, and only if you accept analytics cookies, it records that a browser viewed a page — the page path, a randomly generated identifier stored on your device, referrer, approximate location derived from your IP address, and device and browser details — so we can see which pages bring people in. The address we send is sanitized before it leaves your browser (section 5). We do not send it your name, your email address or anything from inside your workspace.
  • Meta Platforms (Meta Pixel) — advertising measurement, loaded through the same tag manager, on the same public marketing pages, and only if you accept advertising cookies. It tells Meta that a browser visited a page on citedos.com, together with the IP address and user agent every web request carries, so we can tell whether advertising we pay for reaches the people we intended. For that data Meta is an independent controller under its own privacy policy, not our processor — we neither control nor can enumerate what it does with it, the same distinction as the Google scheduler entry above. If you refuse advertising cookies it is never loaded and no request reaches Meta.

Some providers process data in the United States and the EU; where transfers out of the EEA/UK occur, they rely on recognized safeguards such as Standard Contractual Clauses or an adequacy framework. We will update this list before adding a subprocessor that handles personal data.

5. Cookies and local storage

There are two kinds of storage on this site: the kind that has to be there for it to work, and the kind you choose. Nothing in the second kind happens until you say yes.

Essential, always on, no consent needed. The authentication cookies set by our sign-in system (a first-party JWT session cookie plus its CSRF companion) — without them you cannot stay signed in. Two things live in your browser’s own storage rather than in a cookie and never leave your device: your light/dark theme choice, in localStorage, and — if you arrived from a campaign link — the campaign tag from that link, under the key citedos_utm_first_touch in sessionStorage, so that if you sign up three pages later we can still tell which link brought you. It is per-tab and is discarded when you close the tab. Our own product analytics (Vercel) stores nothing on your device at all.

Analytics and advertising, only if you accept them. On our public marketing pages we load Google Tag Manager, which is the single place from which Google Analytics 4 and the Meta Pixel can run. A consent banner from our consent management platform runs first, before any of them. Until you make a choice, and unless you choose to accept, no analytics or advertising tag is loaded at all: nothing is written to your device and no request is made to Google Analytics or to Meta. Accepting analytics allows the Google Analytics cookies that count a returning browser; accepting advertising allows the Meta Pixel. You can accept one and refuse the other, and refusing costs you nothing — every page works identically either way.

Where these never run at all. The tag manager is never loaded on the screens where you type a credential — sign-in, sign-up and password reset — and never inside the product once you are signed in. Those pages do not include it, and they send it nothing. One honest caveat: a browser tab that has already loaded a marketing page keeps the container in memory for the life of that tab, so moving from our public site into your dashboard does not unload it. What changes is that we stop telling it anything — the tags are configured to record only the events our own code sends, and our code sends none from inside the product. Your dashboards, prompts, competitors and reports are never transmitted to an analytics or advertising vendor.

What we transmit is trimmed before it leaves your browser. Analytics tools normally record the full address of the page you are on. Ours is sanitized first: we send the page path and the campaign parameters (utm_*) and nothing else. Anything our own flows put in the address bar — an email address, a company domain you typed, a password-reset token — is stripped out before any tag can read it, so it cannot reach Google, Meta, or any analytics dataset.

Changing your mind. The consent banner can be re-opened at any time to change or withdraw your choice, and a change takes effect immediately for anything that has not already been sent. Withdrawing is as easy as giving it. You can also email support@citedos.com and we will action it for you, and your browser’s own settings can block or clear all of this independently of us.

The demo scheduler on /demo. That page is built click-to-load: until you press the button that says it will load Google’s scheduler, the page makes no request to Google at all, and no Google cookie is set on your device as a result of your visit. Your click is the consent — that is why the button exists. If you press it, the booking form runs inside a frame served by Google, which may set and read its own cookies there under its own privacy policy; we neither control nor can enumerate them, and we receive none of them. Not clicking costs you nothing: the page stays fully usable and gives you an email address to book through instead.

6. Retention

  • Account and workspace data — kept while your account is active, and deleted or de-identified within 90 days of account deletion, except where law requires longer (e.g. billing records).
  • Measurement history — kept while the workspace exists, because trends over time are the product; deleted with the workspace.
  • Server logs — retained for a short rolling window, typically 30–90 days.
  • Connected-account tokens — deleted when you disconnect the integration, and with the workspace if that goes first. The cached metrics they populated go at the same moment: they are stored on the connection record itself, so disconnecting removes both together. The one thing that outlives a disconnect is a prompt you chose to create from a search query: it is your prompt from then on, and it keeps the query it came from so we can show you where it came from. Delete the prompt to remove it. See section 12, and section 7 for erasure requests.
  • Demo bookings — kept where they are made, not in our database. A booking never reaches the CitedOS servers, so there is no record of it to delete there: the meeting lives in our Google Calendar, and, if you asked for a time by email instead, in the support mailbox. We keep both for up to 24 months as a record of who we spoke to and about what, and delete either sooner if you ask us to — email support@citedos.com. Deleting a CitedOS account does not touch them, because they were never linked to one.
  • Aggregated, de-identified statistics — retained indefinitely and not deleted on account closure, because they no longer identify you or your workspace. See section 3.

7. Your rights

If you are in the EEA, UK or another jurisdiction with similar law, you have the right to access your personal data, rectify inaccuracies, request erasure, receive a portable copy, object to or restrict certain processing, and withdraw consent where processing is based on consent. Email support@citedos.com and we will respond within 30 days. You also have the right to complain to your local supervisory authority.

8. What we do not do

  • We do not sell or rent personal data. Ever.
  • We do not put advertising on this site, and no ad network sees anything from inside your workspace. We do advertise elsewhere, and to measure whether that works our public marketing pages can load the Meta Pixel — but only on the pages that sell the product, only after you accept advertising cookies, and never on a signed-in screen (sections 4 and 5). What it learns is that a browser visited a marketing page. We do not upload customer lists to ad platforms and we do not share personal data for cross-context behavioural advertising.
  • On paid plans, and on any workspace that has opted out, we do not send your content to OpenAI, Google or Anthropic in a form they may train their foundation models on — those workspaces run on private API keys excluded from training. We will not claim a blanket no, because on the Free plan and during a trial it would not be true: those workspaces run on OpenAI’s data-sharing key, which is stated plainly in section 3 along with the switch that turns it off. Either way, the measurement prompts contain your market queries, not your personal data — and connector data never takes that route on any plan.
  • We do not sell, or use for model improvement, anything read from your connected Google or Bing accounts.

9. Security

Data is encrypted in transit (TLS) and at rest by our database provider; passwords are bcrypt-hashed; access to production is restricted and authenticated; API keys are shown once and stored hashed. No system is perfectly secure — if we learn of a breach affecting your data we will notify you without undue delay.

10. Children

CitedOS is a business tool and is not directed at children under 16. We do not knowingly collect their data.

11. Changes and contact

We will post updates here and, for material changes, notify you by email or in-product notice; the “Last updated” date above reflects the current version. Contact: support@citedos.com · E-Nomad LLP. See also our Terms of Service and Refund Policy.

12. Google user data

This section is the detail behind the “Connected account data” bullet in section 1. It states exactly which Google APIs CitedOS calls on your behalf, what we do with what they return, and how you take the access back. Connecting a Google account is always optional — every feature it powers has a manual fallback, and nothing here happens unless you complete the consent screen yourself.

Search Console — what we request and why

When you connect Google Search Console we ask for three OAuth scopes: openid and email, used for nothing except showing you which Google account a connection belongs to (“Connected as …”), and https://www.googleapis.com/auth/webmasters. We do not request your contacts, Gmail, Drive or calendar.

Signing in with Google is a separate grant. If you use the “Continue with Google” button instead of a password, that request asks for openid, email and profile — the standard sign-in set. From it we keep your email address, your display name and the URL of your Google profile picture, and we use them only to create and label your account. Our sign-in library also records the OAuth tokens Google returns for that grant on the linked-account row; we do not read them or call any Google API with them (your session is a signed cookie, not a Google token), and they are deleted with your account.

Sign-in and the Search Console connector are the same Google Cloud application, so your Google account lists them as one entry. Removing CitedOS there revokes both at once. Disconnecting inside CitedOS is narrower on purpose: it revokes and deletes only the Search Console connection and leaves your ability to sign in intact.

We ask for the read/write webmasters scope rather than webmasters.readonly for one reason: one feature writes. Sitemap submission is a write, and Google offers no narrower Search Console scope that permits it. Everything else we do with the scope is a read.

  • Reads. The list of properties you can choose from (sites.list); the property’s sitemaps (sitemaps.list); search analytics — queries, clicks, impressions and average position (searchAnalytics.query); and index status for individual URLs (urlInspection.index.inspect).
  • The one write. Submitting a sitemap you asked us to submit (sitemaps.submit), as a step in the guided roadmap. We never submit one without you triggering that step.

What we use it for: replacing our estimated indexation figure with Google’s authoritative answer, seeding AI-visibility prompts from the questions people actually search for, and automatically verifying that a sitemap you submitted was picked up. We read only the single property you select for a brand — never every property on the account.

Google Analytics 4

The GA4 connector works the other way round: there is no OAuth consent screen. You grant our service account read-only Viewer access to the specific GA4 property you choose, from inside your own Analytics admin. We read aggregate reporting data to show which AI assistants are already sending you traffic, and you revoke it by removing that Viewer access.

How we store and protect it

  • The Search Console refresh token is encrypted at rest (AES-256-GCM) with a key held outside the database. We never receive or store your Google password.
  • What we cache is bounded, not a mirror — a capped snapshot of top queries and a capped time series, sized for the charts that display them. We do not bulk-export your Search Console account.
  • Access to that data in production is restricted and authenticated, as described in section 9.

What we never do with it

  • We never sell it, in any form, aggregated or not.
  • We never use it to train or improve any model — ours or anyone else’s. This carve-out holds on every plan, including Free and trial, and it is not something you have to opt out of (section 3).
  • We never use it for advertising, and never transfer it to third parties except the infrastructure processors listed in section 4 that are required to operate the service. There is one place where that transfer is something you do on purpose, and we would rather name it than let you find it: the prompt wizard can show your Search Console queries as suggestions, and a query you choose to promote becomes one of your tracked prompts — which we then send to the AI engines to measure, like any other prompt. Nothing is promoted unless you pick it, and queries you do not pick never leave our infrastructure.
  • We never let humans read it except with your explicit permission — to resolve a support issue you raised, for security investigations, or where law requires it.

CitedOS’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Taking it back

Disconnect from Settings → Integrations at any time. That asks Google to revoke the token and then deletes the whole connection record — the token, the cached queries, the search-performance series and the verification state all live on that one row, so they go together, at once, not on a later schedule.

One thing deliberately survives, and you control it. If you promoted a search query into a tracked prompt, that prompt is yours from then on: it stays after a disconnect, and it keeps a note of the query it was written from so the page can tell you where it came from. It is not a copy of your Search Console data — it is one row you created on purpose, and deleting the prompt removes it. Everything you did not promote is gone with the connection record. You can also revoke CitedOS independently from your Google account permissions page— but note that removes access for the whole CitedOS application, sign-in included, because both grants share one entry there. Either way, revoking does not delete your CitedOS account: the affected features fall back to their manual equivalents, and you can still sign in with an email and password.