Skip to main content
C CiteSonar
Document status In effect
01Privacy Policy 02Terms of Service 03Data Processing Addendum

CiteSonar legal

Privacy Policy

Last updated: 27 September 2026

This policy explains what information CiteSonar collects, why, how long we keep it, who we share it with, and the choices you have. It is effective from 27 September 2026. If you connect a Google account, see Google user data.

Who we are

CiteSonar (citesonar.com) is a search-visibility tool for website owners. It shows why a site does or does not appear in search results and in AI assistant answers, recommends changes, and measures whether those changes worked. CiteSonar only reads data: it never changes your website, your Google account, or any other account you connect.

CiteSonar is a product of Design with Aya LLC, 6834 S. University Blvd., #101, Centennial, CO 80122, USA, which is the controller of the personal information described here. For anything in this policy, email hello@citesonar.com.

Google user data

You can connect a Google account to a site in CiteSonar. Connecting is optional and is done one site at a time. When you connect, Google shows you a consent screen and we request these permissions, all read-only:

  • openid and userinfo.email (Google shows these as "Associate you with your personal info on Google" and "See your primary Google Account email address"): your Google account ID and email address. We use them to show you which Google account is connected and to reuse the same connection when you connect another site.
  • Search Console, webmasters.readonly ("View Search Console data for your verified sites"): the list of Search Console properties you can access and your permission level on each; and, for the property you choose for a site, its search performance (the search queries, page URLs and countries, with clicks, impressions and average position) and the index status of that site's pages.
  • Google Analytics, analytics.readonly ("See and download your Google Analytics data"): the names and IDs of the Analytics accounts and properties you can access, used only so you can pick one; and, for the property you choose for a site, daily totals of sessions, engaged sessions, key events and, where your property records it, revenue, broken down by date, landing page, traffic source and country. These are aggregate totals. We do not request or receive information about individual visitors to your site.

How we use it. Only to provide features you can see in CiteSonar for the site you connected: search and traffic charts, recommendations (for example, queries where your site almost ranks), checking whether a change you made moved clicks or visits from AI assistants, confirming that you control the site, the reports you send or share, and suggesting keywords to track from your top Search Console queries.

What we never do. We never write to or change anything in your Google accounts. We never use Google user data for advertising, never sell it, and never give it to advertising platforms, data brokers or information resellers. We never use it to decide creditworthiness or for lending. We do not use it to develop, improve or train generalized artificial intelligence or machine-learning models. Our staff do not read it unless you ask us to (for example, in a support request), unless it is necessary for security (such as investigating abuse), unless the law requires it, or where it has been aggregated and anonymized for internal operations.

Who receives it. Google user data is stored on our hosting provider, DigitalOcean. Encrypted backups of our database, which include it, are kept with Backblaze; the backup job runs on GitHub-hosted runners that briefly process the database dump before it is encrypted and uploaded. We do not send Google Analytics data to our AI providers or data vendors; if you connect your own AI agent and ask it for these figures, we return them to your agent, and its provider handles them under your agreement with it. Search Console query text (never the clicks, impressions or positions) leaves CiteSonar only when a feature you use needs it: when a query becomes one of your tracked keywords (including the top queries we suggest from Search Console when you set up a site), it is sent to DataForSEO to look up its search rankings and to run the AI-answer visibility checks built from it, and to our AI model providers when they draft AI prompts from that keyword or you generate a content brief for it. These providers act only on our instructions and only to deliver that feature. Report and alert emails you set up (delivered by Resend) and share links you create can include Search Console and Analytics figures. We may also disclose Google user data where the law requires, or as part of a merger, acquisition or sale of assets, and then only after asking for your explicit consent.

How we protect it. Google access and refresh tokens are encrypted before they are written to our database, with a key kept in a separate secret store, so a copy of the database alone cannot unlock them. Tokens are never written to logs or returned by our API. Data travels over HTTPS, and each workspace's data is separated inside the database itself, not only in application code.

How long we keep it. Daily Search Console and Analytics rows are kept for 18 months and then deleted. Search Console queries you do not track are condensed after 90 days into monthly totals without the query text. Monthly totals are kept while the site exists. A row cited as evidence for an action you took is kept as that action's receipt while your account exists. Tokens are kept until you revoke CiteSonar's access or delete your workspace. Your Google account ID, email and the chosen property IDs are kept while your account exists, so that reconnecting restores your history.

How to revoke access and delete it. You can revoke CiteSonar's access at any time at myaccount.google.com/permissions. Disconnecting a site in CiteSonar (Site settings, "Disconnect this site") stops us using that connection for the site. When you revoke access or delete your workspace, we delete the stored tokens. Data already imported stays in your workspace for the periods above; to have it deleted sooner, delete the site or your workspace, or email hello@citesonar.com and we will delete it within 30 days.

Limited Use. CiteSonar's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

At a glance

Data Why we have it How long we keep it Shared with
Account details: email, hashed password, role, language Signing in, security, service emails Until your workspace is deleted DigitalOcean (hosting); Resend (email delivery)
Google access tokens (encrypted) Reading the properties you connected Until you revoke access or delete your workspace Google, when we refresh or revoke access; stored encrypted on DigitalOcean
Search Console search performance, index status Charts, recommendations, measuring results 18 months daily; monthly totals and action receipts while the site or account exists DigitalOcean; encrypted backups at Backblaze; query text only: DataForSEO and our AI model providers, when a feature needs it
Google Analytics totals Measuring traffic, AI-assistant visits and outcomes 18 months daily; monthly totals while the site exists DigitalOcean; encrypted backups at Backblaze; your own AI agent if you ask it
What you enter: sites, business context, competitors, keywords, markets, prompts, actions, briefs The core service Until you delete the site or workspace DataForSEO (keywords, prompts, domains); our AI model provider (brief and prompt inputs)
Search rankings and AI answers we obtain for your keywords and prompts Search and AI visibility tracking 18 months, then monthly totals Obtained from DataForSEO
Copies of your public web pages Audits and checking that changes went live The latest two per page; pages cited as evidence while your account exists DigitalOcean
Search and AI crawler visits from server logs you send us Showing which bots read your site 90 days, then monthly counts DigitalOcean
Billing and credit records Billing, tax and accounting Permanently; after workspace deletion, only de-identified financial totals Stripe, once paid plans launch
Security records: sessions, hashed API keys, audit logs, hashed IP addresses Keeping accounts safe, preventing abuse Sessions, API keys and audit logs while your workspace exists; hashed IP addresses up to 30 days DigitalOcean
Backups of the whole database Recovering from failures A rolling 7 days at DigitalOcean; up to 90 days for encrypted off-site copies at Backblaze DigitalOcean, Backblaze
Emails you send us Answering you Up to 24 months after the conversation ends, unless needed longer to resolve a dispute or meet a legal obligation Spaceship (mail forwarding); Google (Gmail inbox)

Information we collect

  • Account information: your email address, a password stored only as a one-way hash, your role in the workspace, your language preference, the workspace name, and the country you declare for pricing.
  • Team information: the email addresses of people you invite, and which sites each of them may see.
  • Information you provide about your sites: domains, business description, positioning, voice, competitors, keywords, markets, AI prompts, notes, and the actions and briefs you work on.
  • Connected account data: Google data as described above, only for the sites and properties you choose.
  • Public information about your site: our crawler reads your site's public pages, identifying itself in its user agent, to audit them and to check that changes went live. We also look up public data about your site, such as page-experience data, archived copies, certificate records, and public discussions that mention your business. This is information about websites, not about people.
  • Search and AI answer data: search rankings, competing results and AI assistant answers for your keywords and prompts, obtained from DataForSEO using your credits.
  • Server logs, if you choose to send them: we keep only lines made by known search and AI crawlers, and discard lines made by human visitors when the log is read. For each crawler visit we keep the path, the bot, the response status, the time, and a keyed one-way hash of the crawler's IP address.
  • API and AI agent access: API keys, stored only as hashes; the AI applications you authorize through our MCP connection; and an audit log of settings changes made with each key.
  • Billing information: paid plans are not live yet. When they launch, Stripe will process payments and collect your payment details and billing address; we will store your Stripe customer and subscription identifiers, your plan, invoice amounts and credit balances, and we will never see or store your full card number. Credit balances for free plans are recorded now.
  • Security information: a record of each signed-in session (when it started and was last used; we do not store your IP address or device details with it), and keyed one-way hashes of IP addresses to limit sign-up and free-tool abuse, kept for up to 30 days and then deleted. We never store raw IP addresses of people using the service.
  • Messages you send us, and the emails we send you.

We do not use advertising or analytics trackers on our site or in the product.

How we use information

  • To provide the service you signed up for: collecting and showing your data, making recommendations, generating the briefs you request, measuring results, and sending the alerts, digests and reports you set up.
  • To run your account: sign-in, email verification and password resets, team access, and billing.
  • To keep the service secure and prevent fraud and abuse.
  • To answer your questions and support requests.
  • To meet legal, tax and accounting obligations.

We do not sell personal information, do not share it for advertising, and do not combine your workspace's data with other customers' data. We do not make automated decisions about you that have legal or similarly significant effects.

If you are in the European Economic Area or the United Kingdom, our legal bases are: performing our contract with you (providing the service and billing); your consent (connecting Google, which you can withdraw at any time); our legitimate interests (security, abuse prevention and answering you); and legal obligations (keeping financial records).

AI providers and data vendors

Some features call outside services. Here is exactly what each one receives:

  • Our AI model providers, which we select based on cost and use case (currently Anthropic; we may also use OpenAI), receive the keyword, your business description, positioning and voice, and short excerpts of public web pages when you generate a content brief; and a keyword when drafting AI prompts for you to track. They do not receive your Google Analytics data or any search metrics.
  • DataForSEO receives your tracked keywords, AI prompts, your domain and your competitors' domains, and returns search rankings and the answers AI assistants give to those prompts. To produce those answers it sends your prompts to the AI assistants being checked.
  • TypeSafe, when the answer-checking feature is enabled: receives an AI assistant's answer text, your brand terms, your competitors' names, and the URLs (and, where fetched, short excerpts) the answer cites, and processes them to return an assessment of the answer. TypeSafe keeps this data under its own terms, which set no fixed retention period; deletion is at TypeSafe's discretion. This feature is off unless enabled, and TypeSafe never receives Google user data.

We use our AI model providers' and DataForSEO's business API services, under terms that do not allow them to train their models on what we send. Content we collect from search results, web pages and AI answers is treated as data only; it never controls what CiteSonar does.

Public services we query

To find public information about your site, we query public services:

  • The Internet Archive's Wayback Machine receives public page URLs of your site, to find archived copies.
  • crt.sh, a public certificate search, receives your domain, to find its subdomains.
  • Stack Exchange, and Hacker News search (run by Algolia), receive your business name, taken from the first line of your business description or from your domain, to find public discussions that mention it.
  • Google's Chrome UX Report and PageSpeed Insights receive public page URLs of your site, to measure page experience.
  • Google Public DNS (dns.google): when you verify site ownership, we look up a verification record for your domain (_citesonar.your-domain) through it.

None of these services receive your Search Console or Analytics data.

Sharing you direct

  • Team members and agency clients: people you invite see the sites you allow. An agency client seat is read-only and sees only the sites you grant it.
  • Your own AI agents: CiteSonar has an API and an MCP (Model Context Protocol) connection so you, or an AI assistant you authorize, can use the product. Whatever that assistant requests, including Search Console and Analytics figures, is delivered to it, and its provider handles it under its own terms. Settings-changing abilities are off for each key until you turn them on from a signed-in browser. You can revoke keys and authorized apps at any time in your Account settings.
  • Share links: a report you share can be opened by anyone who has the link until it expires or you revoke it.
  • Slack and webhooks: if you connect Slack or a webhook destination, we send the event notifications you choose (such as alerts) to that destination. Its handling is governed by your agreement with that service.

Service providers

We use these providers to run CiteSonar. Each may use your information only to provide its service to us. Destinations you choose yourself, such as your own AI agent, Slack or a webhook, are not our providers; they are described under Sharing you direct.

  • DigitalOcean (United States, New York region): application hosting, managed database, its automatic backups, and DNS. Stored data is encrypted at rest.
  • Backblaze (United States): off-site database backups, encrypted with our own key before upload.
  • GitHub: runs our scheduled backup job on GitHub-hosted runners, which briefly process the database dump before it is encrypted and uploaded.
  • Stripe: will process payments, invoicing and tax calculation when paid plans launch.
  • Resend: delivery of sign-in, alert, digest and report emails.
  • DataForSEO: search ranking and AI answer data.
  • TypeSafe: checking AI assistant answers, when that feature is enabled.
  • Public services we query about your site, listed below.
  • AI model providers, selected based on cost and use case (currently Anthropic; we may also use OpenAI): content briefs and AI prompt drafting.
  • Spaceship (our domain registrar and DNS host): forwards email sent to our citesonar.com addresses.
  • Google (Gmail): the support inbox that forwarded email is delivered to.

When you connect Google, we also exchange data with Google to read your Search Console and Analytics data.

How we protect information

  • All traffic to CiteSonar uses HTTPS. Sign-in cookies are secure and cannot be read by page scripts.
  • Passwords are stored with a slow one-way hash (Argon2). API keys and invitation links are stored only as hashes.
  • Access tokens for connected accounts are encrypted with a key kept outside the database.
  • The database enforces that each workspace can see only its own rows. Team members can be limited to specific sites.
  • Off-site backups are encrypted with our own key before upload.
  • Administrative access is limited to named operators, and administrative changes are logged.

No system is perfectly secure. If a breach affects your personal information, we will tell you and the relevant authorities as the law requires.

How long we keep information

We keep only what the product uses. The table above gives each period. In addition:

  • Deleting a site freezes it at once: nothing more is collected for it. The site's data is then deleted in a background process, normally within two days. The actions you took on it are archived, and the observations cited as evidence for them are kept as receipts in your workspace until you delete the workspace.
  • Deleting your workspace freezes it at once and signs everyone out. All of its data, including connected Google data, is then deleted, normally within two days. We keep only a record that the deletion happened, and de-identified financial totals we need for accounting and tax, which no longer identify your workspace.
  • If a paid subscription ends, your workspace moves to the free plan with its data kept. It is deleted only if the workspace owner deletes it.
  • Deleted data can remain in encrypted backups until they expire: 7 days for DigitalOcean's automatic backups and up to 90 days for our off-site copies. Our restore procedure re-applies every deletion made after a backup was taken, so restoring a backup does not bring deleted data back.
  • Once paid plans launch, Stripe keeps its own payment records under its own legal obligations.

Your choices and rights

  • Export: download a site's records and evidence as JSON or CSV from that site's settings.
  • Correct: change your details in the product where it allows, or ask us.
  • Delete: the workspace owner can delete the whole workspace from Account settings. Sites can be deleted through our API, or by asking us.
  • Disconnect: disconnect a site's Google connection in its settings, or revoke CiteSonar's access in your Google Account at any time.

Depending on where you live, you may also have the right to access, correct, delete, restrict or object to our use of your personal information, to receive a copy in a portable format, and to withdraw consent. To make a request, email hello@citesonar.com. We may need to confirm your identity, and we will reply within one month. If your account belongs to a workspace run by your employer or an agency, we may refer your request to that workspace's owner. You can also complain to your local data protection authority.

We do not sell or share personal information for cross-context behavioral advertising, as those terms are used in California law, and we do not use sensitive personal information to infer characteristics about you.

International transfers

CiteSonar is operated from the United States, and your information is processed in the United States. Where the law requires, we rely on appropriate safeguards for international transfers, such as the EU Standard Contractual Clauses or our vendors' Data Privacy Framework certifications.

Cookies and local storage

We use only what is needed for the service to work, so there is no cookie banner:

  • A session cookie that keeps you signed in. It lasts at most 30 days, and the session ends after 7 days without use.
  • A short-lived sign-in state cookie that protects the Google connection step and expires after 10 minutes.
  • A language preference cookie, if you choose a language.
  • A light or dark display preference kept in your browser's local storage. It stays in your browser and is never sent to us.

We do not use analytics, advertising or third-party tracking cookies. When paid plans launch, Stripe's checkout pages will set their own cookies under Stripe's privacy policy.

Children

CiteSonar is a business tool and is not directed at anyone under 16. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.

Changes to this policy

When this policy changes we will post the new version here with a new date. If a change is material, especially one that affects how we use Google user data, we will email workspace owners before it takes effect and, where required, ask for your consent again.

Contact

Contact information for questions about this document or your data: hello@citesonar.com