Skip to content
cite†

Privacy notice

Last updated 27 September 2026.

Who we are

Chalkstream Development runs cite.io and is the data controller for the personal data this page describes. Write to hello@cite.io with any question about this notice or about your data.

Visitors: what we collect

The home page, the blog and this page count page views with Umami, an analytics tool that runs on our own server. The signed-in app pages carry no analytics. Each page view records:

  • the page URL and title, and the page you came from;
  • your browser, operating system, device type, screen size and language;
  • your approximate location: the country, region and city worked out from your IP address;
  • a visitor hash: a code derived from your IP address and browser that changes every month.

Umami uses your IP address to make the hash and to look up the location. It does not store the IP address. Nothing is stored on your device, and nothing is read from it.

The web server keeps standard access logs. Each log line holds the IP address, the page requested, the time and the browser.

Why we collect it

We collect this data to see which pages are read and to keep the site secure. Our lawful basis is legitimate interests. The interest is knowing what visitors read, and spotting abuse in the server logs.

How long we keep it

  • Access logs: 14 days.
  • Analytics records: indefinitely. They identify nobody: the IP address is not stored, and the visitor hash changes every month.

What we do not do on the public pages

  • We set no cookies.
  • We do no cross-site tracking.
  • Visitors are not identified.
  • No third party receives visitor data. The fonts, the scripts and the analytics all come from our own server.
  • Nothing is sold.

If your browser sends the Do Not Track signal, the analytics tool skips your visit to this site.

Where the data lives

All data on this site is held on one server rented from Hetzner Online GmbH in Helsinki, Finland. Three backup copies exist:

  • Hetzner's automatic daily server images, held in Hetzner's own backup storage in the same datacentre. Seven images are kept, and the oldest is deleted first.
  • A nightly copy to a Synology storage device in the United Kingdom, with snapshots up to twelve months deep.
  • A daily copy, encrypted before it leaves our systems, in Synology C2 cloud storage in Frankfurt, Germany, about one month deep.

Your rights

Under UK data protection law you have these rights:

  • Access. You can ask us for copies of your personal information, and for details of where we got it and who we share it with.
  • Rectification. You can ask us to correct or delete personal information you think is inaccurate or incomplete.
  • Erasure. You can ask us to delete your personal information.
  • Restriction of processing. You can ask us to limit how we use your personal information.
  • Objection. You can object to our use of your personal information.
  • Portability. You can ask us to transfer the personal information you gave us to another organisation, or to you.

Some rights depend on the lawful basis. The right to object applies where we rely on legitimate interests, and the right to portability applies where we rely on contract. We never rely on consent, so there is no consent to withdraw. Some exemptions apply, and the ICO's website explains them.

To make a request, email hello@cite.io. We respond without undue delay, and in any event within one month.

How to complain

If you have any concern about our use of your personal information, email hello@cite.io and we will put it right. If you remain unhappy after raising it with us, you can complain to the Information Commissioner's Office (ICO), the UK supervisory authority:

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint

Accounts

An account is the service you asked for, so our lawful basis for holding account data is contract. An account holds:

  • your email address. There is no password: you sign in with a code that we email to you each time;
  • your organization's name and your role in it;
  • the invitations you send, which hold the invitee's email address;
  • your projects, search queries, research notes and reports;
  • the provider API keys your organization enters, stored encrypted;
  • usage records, which include the full prompts sent to the language model;
  • the header images made for your reports.

Cookies. The sign-in pages and the app set a session cookie and a CSRF cookie. Both are necessary to sign you in and to keep you signed in.

Email. We send sign-in codes and invitations from research@cite.io through Brevo, an email provider that processes the messages on our behalf.

Retention. We keep account data for the life of the account. Backup copies hold the data for up to twelve months after deletion: seven nightly database dumps and seven Hetzner server images, then storage snapshots kept on a schedule of seven daily, five weekly and twelve monthly.

Closing an account. There is no self-serve deletion yet. Email hello@cite.io and we delete the account.

Billing and service providers

Payments. Paddle is the merchant of record. Paddle sells the service to you and holds your payment details as an independent controller under Paddle's own privacy policy. Cite receives a customer identifier and the state of the transaction or subscription, never card details. Paddle's checkout sets Paddle's own cookies on the checkout page only.

Research providers. To do the research, Cite sends project topics, search queries, fetched page text and report drafts to three providers:

  • OpenAI, for writing and images;
  • Serper, for web search;
  • Jina, for reading pages.

They see report content, not who you are. Today those calls use your organization's own keys. Once paid signups open, they use Cite's keys.