This policy explains how personal data is processed when you use Cited (joincited.ai, app.joincited.ai). We run the service on a data-minimising footing: no tracking cookies, no ad scripts, and analytics only via a self-hosted, cookieless statistics tool.
Controller
Digital Domination LLC, 523 Jackson Street, Unit #210, Saint Paul, Minnesota 55101, USA
E-mail: hey@joincited.ai · Represented by: Alexander Kirsch-Clayton
EU representative (Art. 27 GDPR)
As the controller is established outside the European Union, the designated representative in the Union is: Sandra Mannigel, citizen and resident of Germany, email address: dsgvo@digitaldomination.xyz.
Hosting and delivery
The service runs on servers of Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) in Falkenstein, Germany, under an Art. 28 GDPR data processing agreement. Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) sits in front of the service as CDN and attack protection. Transfers to the USA rely on the EU-US Data Privacy Framework and, additionally, the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Server log files
Accessing the service automatically creates server log files (IP address, timestamp, page requested, referrer, user agent). They are deleted after 14 days at the latest. Legal basis: Art. 6(1)(f) GDPR (security, stability, abuse prevention).
Account and registration
On registration we process your e-mail address, name, company, password (stored exclusively as a cryptographic hash), plan, and language setting — to provide the service (Art. 6(1)(b) GDPR), until you delete your account. Optionally you can sign in with Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland); we then receive your e-mail address and name from your Google account. Passkeys store only a public key with us — biometric data never leaves your device. With two-factor authentication enabled, we store the TOTP secret and backup codes.
Security and abuse prevention
On signup and login we process your IP address in hashed form for rate limiting and abuse prevention (Art. 6(1)(f) GDPR). Sign-in and form pages use Cloudflare Turnstile, a cookieless bot-protection service by Cloudflare, Inc.; Cloudflare processes the IP address and common browser signals for bot classification, without cookies and without persistent storage. Third-country transfer as described under "Hosting and delivery".
Monitoring queries to AI platforms
The core of the service is sending your configured queries (prompts, brand names) to AI platforms and analysing the answers. Depending on configuration, recipients are: OpenAI, L.L.C. (USA); Anthropic, PBC (548 Market Street, PMB 90375, San Francisco, CA 94104, USA); Google Ireland Limited / Google LLC; Perplexity AI, Inc. (USA); and DataForSEO (dataforseo.com) and SerpApi, LLC (USA) as collection providers. Only the query texts themselves are transmitted — no account data, no e-mail addresses. Legal basis: Art. 6(1)(b) GDPR. Where providers are located in the USA, transfers rely on the EU-US Data Privacy Framework or the EU Standard Contractual Clauses. Under the providers' standard API terms, inputs are not used to train their models.
Free scan
For the free scan we process the brand name, an optional website URL, and your e-mail address, to run the scan and deliver the report link by e-mail (Art. 6(1)(b) GDPR). A few days later we send a single reminder e-mail about your report (Art. 6(1)(f) GDPR); you can object at any time, informally. New scans trigger an internal Slack notification (Slack Technologies Limited, Dublin, Ireland); transfers to the USA rely on the EU-US Data Privacy Framework. To limit abuse we process your IP address in hashed form (Art. 6(1)(f) GDPR). We also record your scan request (e-mail address, brand name, website URL, scan result) in our internal customer-relationship system to follow up on your interest in our services (Art. 6(1)(f) GDPR); you can object at any time. Free-scan data is deleted after 12 months at the latest, or earlier on request.
E-mail delivery (Resend)
Transactional e-mails (verification, login links, password resets, weekly digests, scan reports) are sent via Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) using Resend's EU region (Ireland), under an Art. 28 GDPR data processing agreement; third-country transfers rely on the EU-US Data Privacy Framework and, additionally, the EU Standard Contractual Clauses.
Payments (Stripe)
Payments are handled by Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). Payment data (e.g. name, address, card details) is collected and processed directly by Stripe; we store no card data. Legal basis: Art. 6(1)(b) GDPR and our legitimate interest in a secure payment process (Art. 6(1)(f) GDPR). Third-country transfers rely on the EU-US Data Privacy Framework and, additionally, the EU Standard Contractual Clauses. Details: stripe.com/privacy. Payment-related data is retained as required by statutory commercial and tax law.
Slack alerts (optional)
Pro-plan customers can configure their own Slack webhook; in that case we send the weekly digest to the Slack channel the customer designates. This is set up solely at the customer's initiative (Art. 6(1)(b) GDPR); processing within the customer's Slack workspace is the customer's responsibility.
Cookies and local storage
We set only technically necessary cookies: a session cookie for sign-in (httponly, invalidated on logout or session end) and a language cookie ("cited_locale", 12 months) storing your chosen language. Your theme preference (light/dark) is kept in your browser's localStorage and never leaves your device. We set no tracking, marketing, or analytics cookies.
Analytics
For reach measurement we use GoatCounter, self-hosted on our server in Falkenstein (stats.joincited.ai). It records anonymised, aggregated statistics (page views, referral sources) — without cookies, without storing IP addresses, without transmission to third parties. We use no Google Analytics, Meta Pixel, Tag Manager, or other third-party trackers.
Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21), as well as the right to lodge a complaint with a supervisory authority. Account holders can export their data as a machine-readable archive (at most once every 30 days) and delete their account entirely, self-service, under Settings → Data & privacy. Otherwise an e-mail to hey@joincited.ai suffices.
Retention
Account and monitoring data is stored until you delete your account; deletion takes effect immediately and completely (account, brand configuration, prompts, scan history, sessions, two-factor data). Server logs are deleted after 14 days at the latest. Hashed sign-in attempts (rate limiting) are deleted after 30 days; hashed signup records for abuse prevention and free-scan data after 12 months at the latest. Administrative logs of support interventions are kept separately for accountability. Payment-related data is retained to the extent required by law.
Changes
This policy was last updated on August 19, 2026. We announce material changes on this page.