Privacy Policy
Controller: CiteLyra Data protection contact: support@citelyra.com Version: 2026-09-27 · Effective: September 27, 2026
1. Scope
This policy explains what personal data we process when you use CiteLyra, why, on what legal basis, who we share it with, and your rights.
2. Data we collect
- Account data: email address, hashed password, email-verification status, account timestamps.
- Generation data: the topics, research questions, and metadata you submit; generated drafts and intermediate artifacts; discovered sources and citation verification results.
- Billing data: credit balance and ledger. Card/payment details are handled by Lemon Squeezy, not by us — we receive purchase/credit events, not card numbers.
- Operational data: request and job logs with correlation IDs, error reports, and basic usage/cost metrics. We avoid placing draft content in analytics or error-monitoring payloads and redact secrets.
- Analytics data: pages you visit, the referring page and campaign tags in the
link you arrived by (for example
utm_source), device and browser type, and events such as signing up or starting a checkout. Collected with PostHog. - Advertising measurement data: if you visit our site, the Meta Pixel may record the visit in your browser. When you sign up or buy credits, we send Meta a one-way hashed (SHA-256) copy of your email address and account ID, your IP address and browser type, and, for purchases, the amount. Meta uses this to tell us which of our ads led to a signup or purchase. We never send draft content, topics, or passwords.
3. Why we process it (purposes and legal bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide the service (accounts, generation, downloads) | Contract (6(1)(b)) |
| Billing and credit accounting | Contract (6(1)(b)) |
| Security, abuse prevention, cost control | Legitimate interests (6(1)(f)) |
| Service emails (verification, password reset, transactional) | Contract (6(1)(b)) |
| Legal/accounting obligations | Legal obligation (6(1)(c)) |
| Product analytics (understanding how the site is used) | Legitimate interests (6(1)(f)) |
| Measuring whether our advertising works | Legitimate interests (6(1)(f)) |
4. AI and search providers (what content leaves us)
To generate a draft, your topic and related content are sent to the configured AI provider and to search/citation providers, and artifacts are stored with our object-storage provider. The current providers, what they receive, and whether they may retain content are listed in Subprocessors. You should not submit sensitive personal data of others in your topics.
5. Sharing
We share data only with the subprocessors needed to run the service (AI, search, hosting, storage, email, payments, analytics, error monitoring), with Meta for advertising measurement as described in section 2, and where required by law. We do not sell personal data.
5a. Cookies and similar technologies
- Essential: a secure session cookie that keeps you signed in.
- Analytics: PostHog stores an identifier in your browser to count visits and understand how the site is used.
- Advertising measurement: the Meta Pixel may set cookies (such as
_fbp) to connect a visit to an ad you saw on Facebook or Instagram.
You can block or delete these in your browser settings, and ad blockers typically stop the analytics and advertising scripts entirely. You can control how Meta uses your data in your Facebook or Instagram ad preferences. To object to analytics or advertising measurement for your account, contact support@citelyra.com.
6. International transfers
Some providers process data outside the EEA. Where they do, transfers rely on appropriate safeguards (e.g. EU Standard Contractual Clauses). See Subprocessors.
7. Retention
- Account data: kept while your account exists.
- Generations and artifacts: retained per the configured retention schedule and deleted on request or on account deletion.
- Logs/metrics: kept for a limited operational period, then deleted or aggregated.
8. Your rights
Subject to applicable law, you can request access, rectification, erasure, restriction, portability, and object to certain processing. You can delete your account and its generations from within the app (Account → Delete), and contact support@citelyra.com for other requests. You may lodge a complaint with your supervisory authority.
9. Security
Passwords are hashed (PBKDF2). Sessions use secure, HTTP-only cookies. Transport is encrypted (TLS). Provider keys are server-side secrets, never exposed to the browser. Report security issues to support@citelyra.com.
10. Children
CiteLyra is not directed to children under 16, and we do not knowingly process their data.
11. Changes
We will update the version above and notify you of material changes.
12. Contact
support@citelyra.com · CiteLyra.