Privacy Policy
Effective Date: June 23, 2026 · Last Updated: June 23, 2026
1. Introduction
This Privacy Policy explains how Citefi ("Citefi," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the Citefi platform, websites, and related services (collectively, the "Services"). Citefi provides an AI-assisted content generation, optimization, and publishing platform for businesses and marketing agencies.
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Services.
This Policy works alongside our Terms of Use and, for business customers, any Data Processing Addendum ("DPA") we enter into with you.
2. Who This Policy Covers and Our Roles
The Services are designed for business use. We interact with two main categories of individuals, and our role differs for each:
- Customers and their personnel — the businesses and agencies that subscribe to the Services, and the individual users who access an account ("Customers" and "Authorized Users"). For information about these individuals and accounts (registration, billing, usage), Citefi acts as a controller (or, under U.S. state laws, a "business").
- Data subjects within Customer Content — individuals whose personal information appears in the content, reviews, datasets, or connected accounts that a Customer uploads, connects, or instructs us to process ("End Data Subjects"). For this information, Citefi acts as a processor / "service provider," processing it only on the Customer's behalf and under the Customer's instructions. The Customer is the controller of that information. If you are an End Data Subject and wish to exercise rights over your personal information, please contact the relevant Customer directly. See Section 11.
For agency Customers using the Services on behalf of their own clients, the agency (or its client) is the controller, and Citefi acts as a processor or sub-processor accordingly.
3. Information We Collect
a) Account and Profile Information. Name, business name, email address, username, password (hashed), role, and similar details you provide when registering or managing an account.
b) Payment Information. Subscription and billing details. Payments are processed by Stripe, Inc. We do not store full payment card numbers on our systems; Stripe collects and processes card data under its own privacy policy. We may receive limited billing metadata (e.g., plan, transaction status, last four digits, billing contact).
c) Customer Content and Connected Data. The materials you provide to or connect with the Services, including:
- Content you upload (e.g., review files via CSV/JSON, documents, datasets, brand guidelines);
- Data we retrieve on your instruction through connected third-party accounts and APIs;
- Generated drafts, briefs, and other outputs created through the Services.
Customer Content may contain personal information about End Data Subjects. We process this information as a service provider/processor on your behalf, solely to provide and improve the Services as instructed.
d) Connected-Account Credentials and Tokens. When you connect a third-party service for publishing or data retrieval, we collect and store the credentials, access tokens, or API keys needed to perform the actions you authorize. These are stored in encrypted form, used only to perform the Services you direct, and never sold or used for unrelated purposes. You can disconnect an integration or revoke access at any time.
e) Usage, Device, and Log Information. Information about how you interact with the Services, including IP address, browser and device type, pages and features used, actions taken, timestamps, and diagnostic/error logs.
f) Publicly Available Monitoring Data. In providing research features, the Services access publicly available web pages and APIs that you configure. We process only publicly accessible information and do not access login-protected or paywalled sources.
g) Communications and Support. Information you provide when you contact us, request support, respond to surveys, or sign up for communications.
h) Cookies and Similar Technologies. See Section 14.
4. How We Use Information
We use information to:
- Provide, operate, maintain, and secure the Services;
- Create and manage accounts and authenticate users;
- Process subscriptions, payments, usage metering, and billing;
- Generate, optimize, schedule, and publish content as you direct;
- Provide customer support and respond to inquiries;
- Monitor, troubleshoot, improve, and develop the Services;
- Detect, prevent, and address fraud, abuse, and security incidents;
- Send service-related communications and, where permitted, marketing communications (which you can opt out of); and
- Comply with legal obligations and enforce our agreements.
We use Customer Content only to provide the Services to the relevant Customer. We do not use one Customer's Customer Content to benefit another Customer.
5. Artificial Intelligence and Automated Content Generation
The Services use artificial intelligence and machine-learning models — including third-party large language models (LLMs) — to generate, analyze, and optimize content. As part of providing the Services:
- Customer Content and prompts may be transmitted to and processed by third-party AI providers acting as our sub-processors (see Section 6);
- We seek to use AI providers and configurations that do not train their models on Customer Content;
- AI-generated output may be inaccurate, incomplete, or unsuitable. Outputs should be reviewed by a human before use or publication. Citefi does not warrant the accuracy of AI-generated content.
6. How We Share and Disclose Information
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising. We disclose information only as follows:
a) Service Providers and Sub-Processors. We use trusted third parties to help operate the Services, bound by contractual confidentiality and data-protection obligations. Current categories include:
- Payment processing: Stripe, Inc.
- Cloud infrastructure and storage: Replit, Inc.; Neon Inc.
- AI / large language model providers: Leading AI model providers supplying large language models, image generation, and text-to-speech services. We automatically use the latest available model versions from these providers.
b) At Your Direction. When you connect or instruct us to publish to or retrieve from a third-party service, we share information with that service as needed to perform the action you authorized.
c) Legal and Safety. To comply with applicable law, regulation, or governmental request; to enforce our Terms; and to protect the rights, property, or safety of Citefi, our Customers, or others.
d) Business Transfers. In connection with a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
e) With Consent. For any other purpose disclosed to you with your consent.
7. Data Retention and Deletion
We retain personal information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Upon account termination, or upon a Customer's verified request, we will delete or de-identify Customer Content within a commercially reasonable period, except where retention is required by law.
8. Security
We implement administrative, technical, and physical safeguards designed to protect information, including:
- Encryption of data in transit (TLS) and at rest;
- Storage of connected-account credentials and tokens in encrypted form, scoped per Customer;
- Logical tenant isolation and access controls to separate Customers' data;
- Role-based access, least-privilege principles, and audit logging.
No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security.
9. International Data Transfers
Citefi is based in the United States and we currently operate and process data in the United States. The Services are presently intended for users in the United States. If you access the Services from outside the United States, you understand that your information will be processed in the United States, where data-protection laws may differ from those of your jurisdiction.
10. Your U.S. Privacy Rights
Depending on your state of residence (including California, Virginia, Colorado, Connecticut, Utah, Texas, and other states with comprehensive privacy laws), you may have rights regarding personal information that we process as a controller/business, including the right to:
- Know or access the personal information we hold about you;
- Correct inaccurate personal information;
- Delete personal information;
- Obtain a portable copy of your information;
- Opt out of the "sale" or "sharing" of personal information (note: we do not sell or share personal information); and
- Not receive discriminatory treatment for exercising your rights.
To exercise these rights, contact us at info@citefi.co. We will verify your request as required by law.
11. Customer Content and Customer Responsibilities
Where Citefi processes personal information on behalf of a Customer, the Customer is responsible for having a valid legal basis and any required consents to provide that information to us. If you are an End Data Subject seeking to access, correct, or delete personal information contained in a Customer's content, please contact the relevant Customer directly.
12. Children's Privacy
The Services are not directed to individuals under the age of 18, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us at info@citefi.co and we will take appropriate steps to delete it.
13. Third-Party Services and Links
The Services integrate with and may link to third-party services. Those services are governed by their own privacy policies, and we are not responsible for their practices. We encourage you to review them.
14. Cookies and Similar Technologies
We and our providers use cookies and similar technologies to operate and secure the Services, remember preferences, authenticate users, and analyze usage. You can control cookies through your browser settings; disabling some cookies may affect functionality.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version with a revised "Last Updated" date and, for material changes, provide additional notice (such as by email or in-product notice). Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
16. Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact us at: