CiteTide Privacy Policy

Effective date: August 21, 2026

1. Controller

The controller of personal data is Jan Brožíček, Company ID (IČO) 08764832, Rižská 1492/2, 102 00 Prague, Czech Republic, legal@citetide.com.

2. Data we process

We process in particular email address, password stored in secured form through Supabase, account data, selected plan, billing country, payment and subscription data processed through Stripe, project data entered by the user such as brand name, domain, competitors and monitored queries, measurement results, recommendations, technical logs, IP address, user agent and customer communications.

3. Project and AI data

Project data is customer business data. It may include brand names, domains, competitor websites, queries and results of AI-response analysis. This data may be sent to AI API providers to perform measurement and analysis. Users should not enter sensitive data, confidential secrets, third-party personal data or data they are not authorised to use in monitored queries.

4. Purposes and legal bases

We process data to create and manage accounts, provide the service, measure AI visibility, store results, generate recommendations, process payments and billing, provide customer support, ensure security, prevent misuse, comply with legal obligations and protect legal claims. The legal bases are mainly performance of a contract, compliance with legal obligations and legitimate interest in secure operation and improvement of the service.

5. Marketing communications

If you give us your optional consent, we may use your email address to send you product updates, tips, offers, newsletters, and other marketing communications related to CiteTide. You can withdraw your consent at any time in your account settings or by using the unsubscribe link in any marketing email. Withdrawing consent does not affect the lawfulness of processing before withdrawal.

6. Service and operational emails

We may send you non-marketing service emails related to your account and the operation of CiteTide, such as security notices, billing messages, changes to the Terms, price or plan changes, important technical changes, outage information, or account-related notifications. These emails are necessary for the performance of the contract, compliance with legal obligations, or our legitimate interest in operating and securing the service. They are not marketing communications and are sent regardless of your marketing consent settings.

7. Providers and recipients

We use in particular Hetzner for VPS hosting in the EU/Germany, Supabase for database and authentication, Stripe for payments and subscriptions, and AI API providers OpenAI, Anthropic, Google/Gemini and Perplexity to process monitored queries and analyse responses. These providers may act as processors, sub-processors or independent controllers depending on the nature of the service and their contractual terms.

8. Google Analytics 4

We use Google Analytics 4 to understand how visitors use our website and to improve CiteTide. Google Analytics is loaded only after you give consent to analytics cookies in our cookie banner. If you do not give consent, Google Analytics is not loaded. In this context, Google may process online identifiers, cookie identifiers, device and browser information, approximate location, pages visited, events, and usage information. We do not intentionally send names, email addresses, payment details, or the content of your CiteTide projects to Google Analytics. The provider of Google Analytics is Google Ireland Limited.

9. Transfers outside the EEA

Some of our providers, including Google, Stripe and selected AI API providers, may process personal data outside the European Economic Area, including in the United States. Where this happens, we rely on an adequacy decision, the EU-U.S. Data Privacy Framework where applicable, Standard Contractual Clauses, or another valid transfer mechanism under GDPR.

10. Retention

Account data is retained for the duration of the account and then for a reasonable period for legal, tax, security and operational purposes. Accounting and tax records are retained for the period required by law. Project data and measurement results are retained for the duration of the account or according to service settings; after account termination they will be deleted or anonymised within a reasonable period. Technical and security logs are retained for a limited period necessary for security and operation.

11. Security

We use appropriate technical and organisational measures, in particular access controls, encrypted communication, secure authentication, regular updates, restricted access to production data, operational monitoring and system backups. No service can guarantee absolute security.

12. User rights

You have the right to access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interest and the right to lodge a complaint with the Office for Personal Data Protection. Requests can be sent to legal@citetide.com.

13. Cookies and localStorage

We use necessary cookies for sign-in and service operation and localStorage for preferences such as language or appearance. We do not use marketing or advertising cookies unless expressly stated otherwise. See the Cookie Policy for details on analytics cookies (Google Analytics 4).

14. Changes to this policy

We may update this policy. We will inform users of material changes by a reasonable means, such as email or an in-service notice.

15. Contact

Jan Brožíček, Company ID (IČO) 08764832, Rižská 1492/2, 102 00 Prague, Czech Republic, legal@citetide.com.