Effective date · 2026-04-21 Last updated · 2026-05-24 Related · Terms of Service

Use of the Site and Services is also governed by the Terms of Service. The two documents are intended to be read together; the Terms of Service control on non-privacy matters and incorporate this Privacy Policy by reference (Terms §10).

The short version

  • No tracking cookies. Web Cited sets zero first-party or third-party tracking cookies. A single first-party local-storage key remembers your privacy-notice dismissal; see Local storage below.
  • Cookieless aggregate analytics on the marketing site only. We use Plausible to count aggregate pageviews and a small number of named conversion events on web-cited.com (for example, /start clicks, /snapshot submissions, sample-deliverable downloads). Plausible does not set cookies, does not retain Internet Protocol (IP) addresses, does not enable cross-site or cross-device tracking, and does not share data with advertising networks. No Google Analytics, no Fathom, no behavioral profiling. The intake API at api.web-cited.com and the audit pipeline at audit.web-cited.com are not instrumented with Plausible.
  • No advertising or fingerprinting scripts. The only third-party script that loads on this site is the Plausible analytics beacon (above). No ad networks, no chat widgets, no embedded video, no marketing pixels, no fingerprinting libraries, no retargeting.
  • One use of local storage, only to remember that you dismissed the on-site privacy notice - it never leaves your browser.
  • If you email us or submit the intake form, we have what you sent us - nothing more. See the sections below for exactly where that data goes and for how long.

What we do not collect

Web Cited does not retain your Internet Protocol (IP) address, does not set tracking cookies, and does not profile or fingerprint visitors. The public marketing site loads Plausible for cookieless aggregate analytics (see Third parties below); Plausible derives country-level geographic detail from a daily-rotating hash and does not retain the IP address itself. We make no requests to advertising networks, behavioral-profiling services, or fingerprinting libraries.

Our hosting and content-delivery providers (described in Hosting below) may process IP addresses and request metadata at the network level for security, abuse prevention, and content delivery; that processing is governed by the providers' own privacy policies. Web Cited does not request, retrieve, or use those infrastructure logs.

Local storage

Our privacy notice (the bar that appears at the bottom of the screen on your first visit) needs to remember that you've dismissed it, so we don't show it again on every page. To do that we set a single key in your browser's local storage:

  • wc-notice-dismissed-v1 - value "1", set when you click "Got it".

Local storage is first-party and is never transmitted to any server, including ours. You can clear it any time via your browser's site-data controls. Clearing it will simply make the notice reappear on your next visit.

If you submit the intake form or email us

The intake form at /start sends the fields you fill in - first and last name, work email, company, website, the primary market you serve, whether you have a storefront or service area, a short business description, the buyer questions you want us to test, your competitor list, the audit tier you've selected, and your explicit consent acknowledgment - to our own API at api.web-cited.com. From there, your submission is recorded as a contact and deal in our CRM, a scope-confirmation email is sent to you automatically through our email-delivery service, and an invoice is generated through our payment processor with a hosted-checkout link. If you pay, a kickoff email is sent automatically and we begin the audit. If you don't, the record stays in our CRM and we close it out. "Contact" links elsewhere on the site open a standard mailto: in your email client, which transmits your email address to our inbox directly.

We use anything you send us solely to reply, to scope the engagement, and - if you become a client - to deliver the audit. We do not add you to a marketing list. We do not share, sell, or transfer your information to any third party beyond the service providers listed in the "Third parties" section below. If you ask us to delete your record and any associated data, we will - see "Your rights" for the process and timeline.

Free Snapshot tool

The free single-engine snapshot tool at /snapshot takes two pieces of information: a domain you want measured and your work email. The domain is sent to Anthropic Claude (a large language model service) inside a single buyer-research prompt, and Claude's response is checked for whether your domain or brand name appears. The result (a binary cited / not cited verdict and a 500-character preview of Claude's response) is shown to you on the page and is also stored alongside your email in our customer relationship management (CRM) system. We use a Cloudflare Workers KV namespace to remember which (email, domain) pairs we have already measured in the last 30 days; if you (or anyone) ask for a snapshot on the same domain within that window, we return the cached result rather than running a new Claude call. Snapshot results stored in our CRM are retained on the same indefinite-by-default basis as other CRM records, and can be deleted on request per Your rights.

Your snapshot email is also added to our marketing list. We send at most two emails per month to that list: roughly one research-report announcement and one product-update or fix-of-the-month note. You can unsubscribe with one click from the link at the bottom of any of those emails, and unsubscribing also removes you from our marketing list while preserving the snapshot result in our CRM (so you can take another snapshot later without re-running it). Marketing emails are sent through our email-delivery service (Resend) and unsubscribe events are honored at the shared suppression list described under Hosting.

Citation Monitor subscription

If you subscribe to the $49/month Citation Monitor product, additional data is collected and processed on a monthly cycle: the buyer-research prompt you supply, your domain, and up to three named competitor domains, all of which are submitted to the same six large language model services used by the audit (OpenAI, Anthropic, Google Gemini, Perplexity, xAI, DeepSeek) every 30 days. DeepSeek's default API endpoint is hosted in mainland China; customers can opt out of DeepSeek routing at intake or at subscription start, in which case the monthly reading runs against the remaining five engines (subscription price unaffected). The resulting citation share, competitor breakdown, and per-engine numbers are stored in our CRM record for the subscription duration, plus the standard CRM retention window after cancellation, and can be deleted on request per Your rights. Subscription billing is processed by Stripe; payment-card data is never seen or stored by Web Cited. You can cancel the subscription at any time from the Stripe-hosted billing portal accessible from each monthly email; cancellation stops future readings and future charges but does not retroactively delete prior readings unless you separately request deletion.

How long we keep your data

The retention periods below apply by default. You can request deletion at any time (see Your rights); a deletion request shortens the retention window for personal-data records to the timelines described there.

  • Intake-form data and CRM record (your contact details, company, deal record, scope notes): retained while the relationship is active and for as long as we may reasonably need it for follow-up engagements, dispute resolution, and operational records, unless you request deletion. Indefinite by default; deleted within 30 business days of a deletion request, subject to the legal-records carve-out below.
  • Email correspondence (scope, kickoff, follow-up, support, and ad-hoc threads): retained in our email-delivery service's logs and in our mail provider's archive while the relationship is active, unless you request deletion. Indefinite by default; deleted within 30 business days of a deletion request, subject to the legal-records carve-out below.
  • Intake API operational data (the at-rest record on our edge-compute platform): retained for the duration of the audit engagement and for normal operational purposes (debugging, audit-trail integrity, abuse prevention) thereafter. Deleted within 30 business days of a deletion request.
  • Playbook URL content: 12 months hosted at a private URL, plus 12 months in archive, then deleted at 24 months from delivery unless a separate retention agreement applies. Full schedule in Terms of Service §6.1.
  • Paid invoices and tax records: 7 years, retained by our payment processor and by Web Cited as required by tax and accounting law. We can remove your name and company from any draft, unpaid, or voided invoice on request, but cannot delete paid-invoice records during the retention period.
  • Free Snapshot tool result and request cache: snapshot results are retained on the same indefinite-by-default basis as CRM records and deleted within 30 business days of a deletion request. The (email, domain) request cache that prevents repeat snapshots on the same domain expires automatically after 30 days, after which a fresh snapshot may be requested.
  • Citation Monitor subscription data: monthly readings are retained for the duration of an active subscription and for 90 days after cancellation, then deleted unless extended by a separate retention agreement. The CRM contact record itself follows the standard CRM retention schedule above. Deletion requests during an active subscription end the subscription and remove the readings within 30 business days, subject to the legal-records carve-out for any paid invoices.
  • Local-storage notice-dismissed key (wc-notice-dismissed-v1): set in your browser only; never transmitted to Web Cited or any third party. Persists until you clear browser site data.

Legal-records carve-out: Web Cited may retain certain records longer than the periods above where required by law (for example, tax and accounting records under U.S. and California law; records under legal hold or active dispute resolution). The carve-out is narrow and applies only to the specific records covered.

Retention matrix

The table below summarizes how long Web Cited keeps each category of data and what triggers deletion. Where this table conflicts with the section-specific paragraphs above or in the Terms of Service, the more specific paragraph controls. If you have purchased an audit, your engagement-specific retention may differ; consult your Scope Confirmation.

Data categoryRetentionTrigger for deletion
Customer Content (audit inputs: URLs, buyer questions, competitors)Through engagement + 30 days post-deliveryCustomer deletion request OR 30-day post-delivery expiry, whichever comes first
Per-engine raw LLM responses (audit + monitoring)Through engagement + 90 days post-delivery90-day post-delivery expiry
Audit deliverables on Web Cited servers (PDF + Playbook + Schema Pack)Playbook hosted at private URL for 12 months from delivery + 12 additional months archived = 24 months total24 months from delivery (per Terms of Service §6.1)
Citation Monitor subscription readings + dashboard dataThrough subscription + 90 days post-cancellationCancellation + 90 days OR customer deletion request
Free Snapshot results + (email, domain) cacheSnapshot results: indefinite by default. Cache: 30-day rolling windowSnapshot: customer deletion request. Cache: 30-day expiry
Customer record in CRM (contact + deal metadata)Indefinite by defaultCustomer deletion request (honored within 30 business days, subject to legal-records carve-out)
Email correspondence in Web Cited's inbox + Resend logsIndefinite by default in our inbox; Resend logs per their retention policy (typically 12 months)Customer deletion request (inbox); Resend retention expiry (logs)
Click-through assent logs (per Terms of Service §19.10)The longer of (i) the duration of the engagement plus 4 years and (ii) any applicable statute of limitations period for claims arising from the engagementEnd of retention window described in §19.10
Paid-invoice and tax records (Stripe + Web Cited)7 years (U.S. + California tax law)7-year post-payment expiry
EMAIL_SUPPRESSION list (bounce + complaint hygiene, shared across Aliso LLC products)Indefinite (compliance requirement)Customer may request removal in writing; honored only if Web Cited determines re-engagement is safe
Aggregated / anonymized analytics (cannot identify any individual customer)IndefiniteNever (anonymized data is no longer personal data)

Why we are allowed to process your data

Under applicable data-protection law (including the EU and UK General Data Protection Regulation, where it applies, and California's Consumer Privacy Act and California Privacy Rights Act), we rely on the following legal bases to process your personal data:

  • Performance of a contract: to provide the audit Services you have engaged us to perform (intake, scope confirmation, payment, audit execution, deliverable delivery, follow-up).
  • Legitimate interests: to respond to inbound inquiries, to operate and secure the Site and intake API, to maintain audit-trail integrity, to prevent abuse, and to develop anonymized and aggregated analytics about the Services in line with Terms of Service §8.4. These interests are balanced against your rights and freedoms; if you object, contact us at the address in Your rights.
  • Legal obligation: to retain tax, accounting, and dispute-resolution records, to respond to lawful requests from public authorities, and to comply with applicable law.
  • Consent: where you provide it explicitly (the acknowledgement checkbox on the intake form covers your assent to processing intake data for the purposes above; consent is not the legal basis on which we rely for performance-of-contract or legal-obligation purposes).

Deliverable retention

Once your audit is delivered, the audit report PDF is sent to you and is yours to keep, and the Schema Pack is delivered to you as a downloadable .zip. The Playbook (Audit and Enterprise tiers) is hosted at a private URL for twelve (12) months from delivery. After 12 months, Web Cited may take the URL offline; we retain a copy of the rendered content in our archives for an additional twelve (12) months and can re-publish on request. After 24 months from delivery, the rendered Playbook content may be deleted from Web Cited's systems unless a separate retention agreement applies. The full retention schedule for deliverables is in Terms of Service §6.1.

Hosting

This site is a static collection of HTML, CSS, JavaScript, and images served by Cloudflare Pages, which delivers content through Cloudflare's global edge network. Cloudflare may retain access logs (including IP addresses and request headers) at the infrastructure level for security and content delivery, as described in Cloudflare's privacy policy. DNS for web-cited.com is also provided by Cloudflare and may process DNS query metadata. The intake API at api.web-cited.com runs on Cloudflare's edge-compute platform (Cloudflare Workers) and may retain its own access logs at the infrastructure level. The audit pipeline at audit.web-cited.com runs on Railway, a managed application hosting platform, which executes the audit and stores intermediate audit state during processing; Railway may retain access logs at the infrastructure level, as described in Railway's privacy policy. Web Cited does not access, request, or retrieve any of these providers' infrastructure logs.

Third parties

When you submit the intake form, your data flows through a short list of service providers we need to actually deliver the audit. The full list mirrors Terms of Service §6.7 and is grouped by what each provider handles.

Personal-data processors (handle your contact details, your company information, and your payment information):

  • Cloudflare: hosts the marketing site (Cloudflare Pages), runs our intake API at api.web-cited.com (Cloudflare Workers), and stores at-rest operational data on Cloudflare's storage backends.
  • HubSpot: customer relationship management (CRM) system holding your contact record and deal record.
  • Resend: email-delivery service for scope, kickoff, and follow-up emails.
  • Stripe: payment processor for invoices and the hosted checkout you are redirected to. Web Cited never sees your card data.

Marketing-site analytics (touches only the public marketing site at web-cited.com; never the intake API, the audit pipeline, the Free Snapshot tool's submitted prompts, or Citation Monitor data):

  • Plausible: aggregate website analytics on the public marketing site only (cookieless; no Internet Protocol address retention; country-level geographic detail derived from a daily-rotating hash; no Customer Content; no contact details; no payment information). Plausible Insights OÜ is incorporated in Estonia and processes data on infrastructure operated by European companies within the European Union. Privacy and data processing addendum at plausible.io/data-policy and plausible.io/dpa.

Audit-content backends (process your Customer Content, meaning the buyer questions, brand and competitor list, and URLs you submit on intake; do not directly receive your name, email, or other contact details):

  • Railway: managed application hosting that runs the audit pipeline at audit.web-cited.com and stores intermediate audit state (your submitted URLs, buyer questions, and per-engine LLM responses) during processing.
  • OpenAI, Anthropic, Google (Gemini), Perplexity, xAI (Grok), and DeepSeek: large language model (LLM) backends queried with your buyer questions to test how each engine answers. DeepSeek's default endpoint is hosted in mainland China; customers can opt out of DeepSeek routing at intake (the remaining five engines run as normal, pricing unaffected).
  • DataForSEO: structured search-engine and SERP (search engine results page) data provider.

Each provider acts as a data processor under our instructions and is governed by its own privacy policy and our data-processing agreement with it. We do not share, sell, or transfer your information to any third party beyond this list. For links to each provider's current privacy statement, email hello@web-cited.com.

Outside of the audit pipeline and the cookieless Plausible analytics beacon on the public marketing site, this site uses no advertising networks, chat widgets, embedded video, marketing pixels, or fingerprinting libraries. We use the system font stack rather than a third-party font service. We do not embed YouTube, Vimeo, X/Twitter, Calendly, Intercom, or any other widget. The only outbound network calls a page on this site makes are: (a) the Plausible analytics beacon on the marketing site, (b) any link you click yourself, and (c) form submission to api.web-cited.com on /start and on the Free Snapshot tool.

Publicity

Per Terms of Service §11, Web Cited may identify you as a customer (by name and logo) on the Site, in marketing materials, and in case studies, in factual descriptions of the engagement and without disclosing Confidential Information. To opt out at any time, email hello@web-cited.com with the subject "Publicity opt-out". Following an opt-out, Web Cited will use commercially reasonable efforts to remove or redact references on assets Web Cited controls within thirty (30) days; see Terms §11 for the full mechanism.

Children

This site is intended for an adult business audience. We do not knowingly collect any information from anyone under the age of 18, consistent with Terms of Service §1.

Automated decision-making

When you submit the intake form, it receives a simple scope-fit score before anything else happens. The score gates only one thing: whether a scope-confirmation email and invoice are generated automatically, or whether your intake is held back for a human to review first. Either way, a human sees every intake - the score doesn't accept or reject anyone on its own. Under GDPR Article 22, this does not qualify as "solely automated decision-making with legal or similarly significant effects." We disclose it here in the interest of full transparency. If you'd prefer your intake be reviewed manually rather than scored, reply to the scope email when you receive it, or email hello@web-cited.com before submitting.

Your rights

If you haven't contacted us or submitted the intake form, we don't have any record of you: rights like access, rectification, deletion, and portability have nothing to act on. If you have submitted the intake or emailed us, you can exercise those rights by writing to hello@web-cited.com. We'll acknowledge within 5 business days and complete the action within 30 business days, across each of the systems involved: our CRM, the email-delivery service's message logs, the intake API's operational storage, and our email threads. Invoices already paid are retained by our payment processor for the period required by tax law (generally 7 years); we can remove your name and company from any draft, unpaid, or voided invoice, but cannot delete paid-invoice records.

The rights listed above (access, rectification, deletion, portability, and objection to processing) are intended to satisfy applicable obligations under California law (the California Consumer Privacy Act and California Privacy Rights Act) and EU and UK law (the General Data Protection Regulation and UK GDPR), where each applies. Residents of those jurisdictions have any additional rights granted by local law; we will honor any such rights on the same email-request mechanism. You also have the right to lodge a complaint with your local data-protection authority (in California, the California Privacy Protection Agency; in the EU, your member-state supervisory authority; in the UK, the Information Commissioner's Office).

Changes to this policy

If we materially change how we process personal information on this site - for example, by introducing tracking cookies, behavioral profiling, an advertising network, or a new service provider that processes personal data - we will update this page, change the "Last updated" date at the top, and re-show the privacy notice on your next visit. Material changes will be reflected before - not after - the change goes live.

Contact

Questions about this policy or about Web Cited's data practices generally should go to hello@web-cited.com.