CitApp Home

Privacy Policy

This Privacy Policy describes how CitApp collects, uses, stores, and shares your personal information when you use citapp.org and all related services (the "Services").

Last updated: August 16, 2026

Introduction

CitApp is a web-based tool that helps students create citations, manage sources, and generate reference lists. The Services let you save URLs and DOIs, automatically fetch bibliographic metadata, organise sources into projects, and export formatted citations in multiple styles.

By using the Services, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree, please do not use the Services.

Questions or concerns? Contact us at contact@citapp.org.

Summary of key points

  • What personal information do we collect? We collect information you provide (name, email, authentication data) and information collected automatically (IP address, device data, usage data).
  • Do we process sensitive personal information? No.
  • Do we collect information from third parties? We may receive information from Google OAuth when you connect your account.
  • How do we process your information? To provide and improve the Services, communicate with you, prevent fraud, and comply with legal obligations.
  • Who do we share information with? Service providers that help us operate the platform (cloud hosting, AI services, analytics).
  • How do we keep your information safe? Through organisational and technical security measures, though no system is 100% secure.
  • What are your rights? Depending on your location, you may have rights to access, correct, delete, or port your personal information.
  • How do you exercise your rights? Email us at contact@citapp.org.

1. What information do we collect?

Information you provide to us

We collect personal information that you voluntarily provide when you register, use the Services, or contact us. This may include:

  • Email address
  • Authentication credentials (password, or OAuth tokens when you sign in with Google)
  • Sources, citations, projects, and categories you create within the app
  • URLs and DOIs you submit for metadata lookup
  • Excerpts you save from a source, and any notes you add to it
  • Text of your own that you submit to the Academic Shield for checking
  • A copy of the text of pages and PDFs you save, kept so the citation can be checked against what you actually read
  • If you subscribe to Pro: your subscription status and the identifiers that tie it to your Stripe customer record. We never receive or store your card details — those are handled entirely by Stripe

We do not process sensitive personal information.

Social media login data

If you register using Google OAuth, we receive certain profile information from Google, such as your name, email address, and profile picture. See Section 6 for more details.

Information collected automatically

When you use the Services, we automatically collect certain technical information, including:

  • Log and usage data: IP address, browser type, device information, pages viewed, features used, date/time stamps, and other activity data.
  • Device data: Hardware model, operating system, device identifiers, and system configuration.
  • Location data: Approximate location based on your IP address. We do not collect precise GPS-based location data.

2. How do we process your information?

We process your personal information for the following purposes:

  • Account management: To create and maintain your account, authenticate your identity, and keep your account in working order.
  • Service delivery: To generate citations, fetch bibliographic metadata, manage your sources and projects, and provide all other features.
  • Communication: To respond to your inquiries, send service-related messages, and notify you of changes to our terms or policies.
  • Security: To monitor for and prevent fraud, unauthorised access, and other harmful activity.
  • Legal compliance: To comply with applicable laws and regulations.

3. Legal bases for processing (EU/UK users)

If you are located in the EU or UK, we rely on the following legal bases under the GDPR:

  • Consent: When you have given us permission to process your information for a specific purpose. You can withdraw consent at any time by contacting us.
  • Performance of a contract: When processing is necessary to fulfil our obligations to you, including providing the Services.
  • Legitimate interests: When processing is reasonably necessary to achieve our business interests (such as improving the Services and preventing fraud) and those interests do not outweigh your rights and freedoms.
  • Legal obligations: When processing is necessary for compliance with the law.

4. When and with whom do we share your information?

We may share your personal information with the following categories of third-party service providers who perform services on our behalf:

  • Cloud computing services — Supabase (authentication and database) and Vercel (hosting)
  • Payment processing — Stripe, if you subscribe to CitApp Pro. Your card details are entered on Stripe's own checkout page and are never sent to or stored by us; we receive only your subscription status and the identifiers needed to keep it in sync
  • AI platforms — Google Cloud (Gemini models, processed on a European endpoint) for AI-assisted metadata extraction, summaries, reference list generation and the Academic Shield
  • Authentication services — Google OAuth via Supabase

We do not use Google Analytics or any other analytics or tracking service.

These third parties are contractually obligated to protect your data and may only process it as instructed by us.

We may also share your information in connection with a business transfer (merger, sale, acquisition, or similar transaction).

We do not sell your personal information. We do not share your personal information with third parties for their direct marketing purposes.

5. Artificial intelligence

We use AI-powered features as part of the Services: automatic metadata extraction from URLs, DOIs and PDFs, AI-generated summaries of sources, full reference list generation, and the Academic Shield. These features are powered by Google's Gemini models, accessed through Google Cloud. These requests are sent to a European endpoint, so the AI processing takes place within the EU, like the rest of the Services — see section 7.

When you use these features, what you submit is sent to Google's systems to produce the result. That is the URL or DOI for a lookup, the text of the page or PDF for metadata extraction and summaries, and — for the Academic Shield — a paragraph you wrote yourself, together with the saved text of the source you cited, because checking one against the other is what the feature does.

We do not store the paragraph you submit to the Academic Shield. It is sent with the request, used to produce the result you are shown, and not written to our database. What we keep is a count of how many checks you have run this week, which is what the free weekly allowance is measured against. The same applies to text submitted for summaries and metadata extraction: we store the resulting citation details, not a copy of the request.

Nothing is sent to an AI service unless you ask for it: saving a source, organising projects, exporting, and every deterministic citation style work without any AI step. All AI processing is governed by this Privacy Policy and our agreements with third-party providers.

To opt out of AI processing, contact us at contact@citapp.org.

6. Social logins

If you register or log in using Google OAuth, we receive certain profile information from Google, which may include your name, email address, and profile picture.

We use this information only for the purposes described in this Privacy Policy. We do not control how Google uses your information — please review Google's privacy policy for details.

7. International data transfers

The Services run inside the European Union. Being specific rather than general, because "we care about your privacy" is not a location:

  • Your data at rest — European Union. Your account, sources, projects and saved page text are stored in our database (Supabase) in the EU.
  • Application servers — European Union (Frankfurt). The Services are hosted on Vercel, and the servers that handle each request run in the EU.
  • AI processing — European Union. Requests to the Gemini models go to a European Google Cloud endpoint, as described in section 5.
  • Payments — Stripe. If you subscribe, Stripe processes the payment and may transfer data outside the EU under its own safeguards. This applies only to subscribers, and only to payment data — never to your sources or your written work.

If you access the Services from outside the EU, your information is still transferred to and processed in it.

We protect international transfers of personal information using appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) where applicable. Copies of these clauses can be provided upon request.

8. How long do we keep your information?

We retain your personal information for as long as you maintain an account with us, or as long as necessary to fulfil the purposes described in this Privacy Policy.

When we no longer have a legitimate business need to process your information, we will either delete or anonymise it. If deletion is not immediately possible (for example, because data is stored in backup archives), we will securely isolate your information from further processing until deletion is possible.

9. How do we keep your information safe?

We implement appropriate technical and organisational security measures to protect your personal information. However, no electronic transmission or storage system is 100% secure. We cannot guarantee that hackers or other unauthorised third parties will not be able to access your information.

You should only access the Services within a secure environment.

10. Children's privacy

The Services are not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13.

If we learn that we have collected personal information from a user under 13, we will deactivate the account and delete the data. If you believe we may have collected data from a child under 13, please contact us at contact@citapp.org.

11. Your privacy rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request that we correct inaccurate or incomplete personal information.
  • Deletion: Request that we delete your personal information.
  • Restriction: Request that we restrict the processing of your personal information.
  • Portability: Request a copy of your data in a structured, machine-readable format.
  • Objection: Object to our processing of your personal information.
  • Withdraw consent: If processing is based on consent, you may withdraw it at any time.

To exercise your rights, email us at contact@citapp.org. We will respond to your request in accordance with applicable data protection laws.

EU/UK users: If you believe we are unlawfully processing your information, you have the right to complain to your local data protection authority.

Account deletion: You can request account deletion by contacting us. Upon deletion, we will remove your information from our active databases. We may retain some information to prevent fraud, enforce our terms, or comply with legal requirements.

12. Cookies

We use one cookie: an essential session cookie that keeps you signed in. We do not use analytics cookies, advertising cookies, or any other tracking technology.

13. Do-Not-Track signals

We do not track visitors across the Services or across other sites, so there is nothing for a Do-Not-Track (DNT) browser signal to disable. The only cookie we set is the essential session cookie described above (see section 12).

14. Updates to this policy

We may update this Privacy Policy from time to time. The updated version will be indicated by a revised "Last updated" date at the top of this page. If we make material changes, we may notify you by posting a prominent notice or sending you a notification.

We encourage you to review this Privacy Policy regularly.

15. Google Docs add-on

The CitApp add-on for Google Docs lets you insert citations and build a reference list without leaving the document you are writing. It requests the following Google OAuth scopes:

  • documents.currentonly: The add-on can only read and edit the single document you have it open in. It cannot access, list, or modify any other file in your Google Drive.
  • script.external_request: The add-on sends requests to citapp.org to fetch your saved sources and generate reference text. Inserting citations and building the reference list send no document content at all — only the identifiers of the sources you chose. The one exception is the Academic Shield: when you select a paragraph and ask for a check, that paragraph and the nearest heading above it are sent to citapp.org, and on to Google Gemini, together with the saved text of the source you cited — comparing the two is what the check is. The paragraph is not stored: it is used to produce the result and not written to our database. Nothing is sent unless you ask for a check, and the rest of the document is never read.
  • script.container.ui: Lets the add-on show its sidebar inside Google Docs.

To connect the add-on, you generate a short-lived, single-use pairing code on citapp.org while signed in, then enter it in the sidebar. This exchanges the code for your CitApp session tokens, which are stored only in your Google account's script properties (not accessible to other users or add-ons) and used solely to authenticate requests to citapp.org on your behalf. You can disconnect at any time from the sidebar, which removes the stored tokens from your account.

Limited Use disclosure. CitApp's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we only use data obtained through Google Workspace APIs to provide and improve the add-on's user-facing citation features; we do not transfer this data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with prior notice; we do not use it for advertising; humans do not read it except with your explicit consent, for security purposes, to comply with applicable law, or when the data is aggregated and anonymized for internal operations. We do not use any data obtained through Google Workspace APIs to develop, improve, or train generalized (non-personalized) AI and/or machine learning models.

16. Contact us

If you have questions or comments about this Privacy Policy, you may contact us at: