Legal

Privacy Policy

Last updated: 31 August 2026

What applies right now

Citeon is in private beta, so most of what is described below is not happening yet. Today we hold exactly two things: the email address and website you give us when you join the early-access list, and the name, email, company and message you send through the contact form. There are no accounts, no scans and no customer data in the product, because the product is not open. The rest of this policy covers how your information will be handled once it is, and is published now so you can read it before deciding.

1. Who we are

Citeon ("Citeon", "we", "us", "our") provides a generative search visibility platform accessible at citeon.dev. For the purposes of the EU GDPR and UK GDPR we act as a data controller for account data and as a data processor for content you submit into the service. You can reach us at support@citeon.dev.

2. Information we collect

Waitlist data: if you join the waitlist, your email address, the website address you optionally give us, and how you reached us (the referring page or campaign). We use it to tell you when Citeon opens and to prepare something relevant to your site. You can ask us to remove you at any time by emailing support@citeon.dev.

Messages you send us: if you use the contact form, your name, email address, company name if given, the topic and the message itself. We use it to answer you, and we send you an automatic confirmation that your message arrived. We keep the correspondence so we have a record of what was asked and answered.

Account data: name, email, password hash, company name, billing details processed by our payment provider.

Workspace content: the domains, competitors, prompts, schema and other configuration you submit.

Usage data: IP address, browser, device, pages viewed, feature interactions, error logs, approximate location derived from IP.

Cookies and similar technologies: strictly necessary cookies for authentication and session management, plus optional analytics cookies you can decline through the cookie banner.

AI traffic tracking (optional): if you choose to add our AI traffic snippet to your own website, we receive, on your behalf, the AI assistant a visitor arrived from, the page they landed on, and the referring address. We process this data as your data processor under a Data Processing Agreement. You remain responsible for disclosing this collection in your own website's privacy and cookie notices.

3. Legal bases for processing (EEA/UK users)

We rely on (a) performance of a contract to operate the service you subscribed to, (b) legitimate interests to secure, improve and market the service in a proportionate way, (c) consent for non-essential cookies and marketing emails, and (d) compliance with legal obligations such as tax, accounting and responding to lawful requests.

4. How we use your information

To create and operate your account, run scans against AI engines on your behalf, deliver insights, send transactional and (with consent) marketing email, prevent fraud and abuse, comply with law, and improve the product. We do not sell your personal data, and we do not use your workspace content to train any model of our own. Running a scan necessarily sends your configured prompts to the third-party AI providers listed in our Data Processing Agreement, where they are handled under that provider's own terms. Those terms differ between providers, and some may use API inputs to improve their services. We do not send your customers' personal data to any AI provider.

5. Sub-processors and third parties

We rely on vetted sub-processors for hosting, database, email delivery, analytics, error monitoring and payments (including Paddle, which acts as Merchant of Record). When you run a scan, the prompts you configure are transmitted to the relevant AI providers (such as OpenAI, Anthropic, Google, Perplexity and DeepSeek) under their terms. A current list of sub-processors is available on request at support@citeon.dev.

6. International transfers

Your data may be processed in the United States and other jurisdictions outside the EEA or UK. Where required, we rely on Standard Contractual Clauses, the UK Addendum and other lawful transfer mechanisms.

7. Retention

We retain account and workspace data for as long as your account is active and for a limited period afterwards to meet legal, tax and dispute-resolution obligations. You can request deletion at any time as described below.

8. Your rights

Depending on your location you may have the right to access, rectify, delete, restrict or object to processing, withdraw consent, port your data, and lodge a complaint with a supervisory authority. California residents have rights under the CCPA/CPRA including the right to know, delete and opt out of sale or sharing of personal information; we do not sell or share personal information as defined by the CCPA. To exercise any right, email support@citeon.dev.

9. Australian Privacy Principles

For Australian users, we handle personal data in line with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth), and we apply them as our standard whether or not the Act applies to a business of our size. If you are an Australian resident and believe we have breached your privacy, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

10. Security

We use industry-standard administrative, technical and physical safeguards including encryption in transit and at rest. No internet service is perfectly secure and we cannot guarantee absolute security.

11. Children

Citeon is not intended for and is not directed at anyone under 16. We do not knowingly collect personal data from children.

12. Changes

We may update this policy from time to time. Material changes will be communicated by email or in-product notice. Continued use of the service after the effective date constitutes acceptance.

13. Contact

Privacy questions and requests: support@citeon.dev.