This Privacy Policy describes how Citerank ("we," "us," or "our"), an independently operated, self-funded product owned and operated by Michael Cortez, an individual doing business as Citerank, collects, uses, and shares information when you use Citerank ("Service"). By using the Service you agree to this policy.
Account information: Email address and password (hashed) when you register. If you sign in with Google, we receive your email and name from Google.
Audit data: URLs, domains, and queries you submit for analysis. Scan results including AI visibility scores, schema findings, and citation data.
API keys: Third-party API keys you optionally add (Perplexity, OpenAI, Anthropic, DataForSEO) are encrypted server-side and never exposed in plaintext after saving.
Usage data: IP address (hashed for rate limiting), browser type, pages visited, features used, and audit counts.
Payment data: We do not store payment card data. Billing for direct subscriptions is handled by LemonSqueezy (see their privacy policy); lifetime-deal purchases made through AppSumo are billed and processed by AppSumo directly (see their privacy policy). We receive a license key and purchase/tier status from AppSumo, not your card details.
We do not sell your personal information to third parties.
Citerank is an AI-powered platform. When you run a scan, your submitted URL and domain are sent to one or more third-party AI providers to generate scores, citation analysis, and recommendations. This section explains which providers are involved, what data they receive, and how they handle it.
Data sent to AI providers: The URL or domain you submit, plus any text content fetched from that URL during analysis (page title, meta description, on-page content). We do not send your account email, payment data, or API keys to these providers.
AI providers used and their data policies:
Your data is not used to train AI models. None of the above providers use data submitted via their API for model training without explicit opt-in. Citerank does not opt in to any such programs.
Lawful basis (GDPR): Processing of personal data through AI providers is carried out under the lawful basis of legitimate interest (Article 6(1)(f) GDPR), specifically, to provide the AI-powered analysis service you requested. Where required by applicable law, we rely on your consent (expressed through acceptance of this policy and use of the Service).
Data Processing Agreements: Enterprise and agency customers who require a formal DPA may request one through our contact form. A full, standing list of our subprocessors is published on our Subprocessors page.
We share data with:
We may disclose data if required by law or to protect the rights, safety, or property of Citerank, its operator, or others.
Audit data is retained for 12 months from the scan date, then automatically deleted. Account data is retained until you delete your account. API key credentials are deleted immediately upon removal. You can request deletion at any time (see Section 8).
We use an httpOnly session cookie (sb_token) to keep you signed in; it cannot be read by JavaScript and is not used for tracking. We also use localStorage to store non-sensitive UI preferences (such as your theme and last-viewed domain), never your session token itself. We do not use cross-site tracking cookies or behavioral advertising networks. See our Cookie Policy for the full list of cookies we and our analytics providers set.
We use Google Analytics to measure aggregate site traffic (pages viewed, referral sources, general usage patterns), processed under Google's Privacy Policy.
We use Microsoft Clarity to understand how visitors navigate the site, this includes session recordings and heatmaps of on-page behavior (clicks, scrolling, mouse movement). Clarity does not collect the contents of password fields and we do not use it to identify individual users personally. Data is processed under Microsoft's Privacy Statement. You can opt out of Clarity tracking via your browser's Do Not Track setting or standard tracker-blocking extensions.
API keys are encrypted using AES-256 before storage. Passwords are hashed using bcrypt via Supabase Auth. All data is transmitted over HTTPS. Row-level security ensures users can only access their own data.
No system is perfectly secure. We recommend using a strong, unique password for your Citerank account.
Depending on your jurisdiction (including GDPR, CCPA, and similar laws), you may have rights to:
EU/UK users may also lodge a complaint with their local supervisory authority. To exercise any of these rights, use our contact form. We will respond within 30 days.
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, contact us immediately.
Citerank is operated from the United States. If you access the Service from outside the US, your data may be transferred to and processed in the US and other jurisdictions where our AI providers operate. By using the Service, you consent to these transfers. EU/UK users: transfers are conducted under appropriate safeguards (Standard Contractual Clauses where applicable).
We may update this policy from time to time. We will notify you of material changes by email or by a prominent notice in the Service. The "Last updated" date at the top of this page reflects the most recent revision. Your continued use after changes are posted constitutes acceptance.
Privacy questions, data requests, or DPA inquiries: use our contact form.
Citerank is operated by Michael Cortez, an individual doing business as Citerank, United States.
© 2026 Citerank · Privacy Policy · Terms of Service · Refund Policy · Cookie Policy · Subprocessors