citelity.Terms
Legal

Privacy Policy

This page describes what citelity collects, why, who else touches it, and how to get it removed. It is written to be read, not to be survived.

Last updated: 28 July 2026

Who we are

citelity is operated by [LEGAL_ENTITY], registered at [REGISTERED_ADDRESS]. For anything on this page, write to [CONTACT_EMAIL].

We are the controller of the data described below. Where we use other companies to process it on our behalf, they are listed by name in “Who else processes your data”.

What we collect

Four categories, and nothing outside them.

An email address, if you give us one
When you join the waitlist, unlock a report from a free tool, or ask us to email you a site report. We store the address, the date, and which page it came from.
Your Google account details, if you sign in
Your email address, name and profile picture, supplied by Google when you authorise the connection. We use them to identify your account and nothing else.
Google Search Console and Google Analytics data, if you connect it
Read-only. Covered in detail in the next section, because this is the part Google requires us to be specific about — and the part you should care most about.
What you type into the product
Site addresses, target keywords, tracked prompts, the pages you ask us to analyse, and the content generated for you. Free tools also receive whatever URL or text you paste into them.

We do not ask for, and have no use for, payment card numbers. Payments run through our payment provider, which handles card data directly; we receive only a customer reference and a subscription status.

How we use Google user data

When you connect your Google account, citelity requests two read-only permissions, and only these two:

webmasters.readonly
Google Search Console, read-only
To read the queries your site already ranks for, along with their impressions, clicks, average position and the pages that earn them. This is what the product starts from: it is how we decide which page to suggest fixing, and how we measure whether the fix changed anything afterwards.
analytics.readonly
Google Analytics 4, read-only
To read sessions arriving from AI assistants — ChatGPT, Perplexity, Gemini and others — so a change to a page can be measured against real traffic rather than against a score we invented.

We cannot change anything in your Google account. Both permissions are read-only. citelity cannot submit URLs, edit properties, alter settings, or write data back to Search Console or Analytics.

What we store. Weekly snapshots of your Search Console query data — the keyword, the page, and its clicks, impressions, CTR and position — so the product can show a trend rather than a single day, and so a page changed today can be compared against how it performed before. Analytics figures are read at the moment a report is generated and stored as the aggregate numbers shown in that report.

What we never do with it.We do not sell it, rent it, or share it with advertisers or data brokers. We do not use it to train machine learning models, ours or anyone else's. We do not use it to build a picture of you across other websites. We do not read it for any purpose other than producing the analysis and measurements you asked for.

citelity's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access. Disconnect at any time from your citelity settings, or directly at your Google Account permissions page. Revoking stops all future access immediately. To have the data we already hold deleted as well, ask us — see “Your rights”.

Why we use it

To run the product you signed up for: finding the queries where AI answers without you, writing or revising the page, and measuring what changed. To send the emails you asked for — reports, weekly digests, alerts. To keep the service working and secure, which includes rate limits and abuse prevention. To bill you, if you are a paying customer.

Where you gave us an email address for a report and we also send occasional product updates, you can stop those in one click from any of them; it does not affect anything else.

Who else processes your data

We use a small number of companies to run the service. Each receives only what its job requires.

Supabase
Database hosting — where your account, sites, keywords and generated content are stored.
Vercel
Application hosting and delivery.
Anthropic
The AI models that analyse pages and write content. Page text and keywords are sent for processing; Anthropic does not train models on API inputs.
DataForSEO
Search result and AI-answer data for the keywords you track. Receives keywords, not your account data.
Beehiiv
Email list — receives your email address and its source.
Resend
Transactional email delivery — receives your address and the message.
Dodo Payments
Payments, as merchant of record. Handles card data directly; we never see it.
Cloudflare Turnstile
Bot protection on free tools, when enabled.

Some of these operate outside your country. Where data leaves the [JURISDICTION], it is transferred under the standard contractual protections those providers offer.

How long we keep it

Account data and connected-site data: for as long as your account exists. Delete the account and it goes with it.

Search Console snapshots: kept while your account is active, because the product's job is comparing today against earlier. Ask us to delete them sooner and we will.

Free tool results: cached for 24 hours, keyed to the URL or text you submitted, so a repeat check is instant and costs nothing. Not linked to your identity.

Email addresses: until you unsubscribe or ask for removal. Server logs: a short operational window, then discarded.

Your rights

Whatever your location, you can ask us to show you what we hold, correct it, delete it, or send it to you in a portable format. You can object to us using it for anything beyond running the service, and withdraw consent for marketing email at any time.

Write to [CONTACT_EMAIL]. We will answer within 30 days, and usually much sooner — this is a small operation and the queue is short. If you are in the EEA or the UK and unhappy with the outcome, you can complain to your national data protection authority.

Cookies

We use a session cookie to keep you signed in, and nothing else on the marketing site. No advertising cookies, no cross-site tracking, no third-party analytics pixels. The free tools store your unlock state in your own browser, which never reaches us.

Security

Data is encrypted in transit and at rest by our hosting providers. Google tokens are stored server-side and never exposed to the browser. Database access is denied by default and mediated entirely by the application, which checks ownership before every query.

No system is perfect. If we ever discover a breach affecting your data, we will tell you and the relevant authority within the timeframes the law requires, and we will tell you what actually happened rather than the minimum we could get away with.

Changes

If we change how we use Google user data, we will update this page and ask you to review the change before it takes effect. For other changes we will update the date at the top; material changes get an email.

Questions about any of this go to [CONTACT_EMAIL]. See also our Terms of Service and how we measure things.