- Introduction
- Data we collect
- How we use your data
- Legal basis for processing
- Cookies and tracking
- Third parties and sub-processors
- Data retention
- Security
- Your rights
- International transfers
- Children
- Changes to this policy
- Contact us
Introduction
Citex measures how a brand appears in the answers produced by AI assistants and AI search engines. To do that we hold some information about you and about the brands you track. This policy explains what we hold, why we hold it, how long we keep it, and what you can ask us to do with it.
The controller of that data is the team that operates Citex, reachable at hello@usecitex.com. Once the operating company is registered, its legal name, registered office and company number will be published in this section.
This policy covers usecitex.com and the Citex application. It does not cover sites we link to; when you follow a link out of Citex, the policy of that site applies.
Data we collect
Account data. Your name, email address, password (stored only as a hash), preferred language, and the organisation you belong to.
Workspace data. The brand you track, its website domain, the competitors you add, the prompts you configure, and your notification preferences.
Billing data. Your plan, subscription status, invoice history, and the customer identifier held by our payment processor. Card numbers are entered directly with the processor. We never see them and never store them.
Collected answers. The responses that AI platforms return for your tracked prompts, and everything we derive from them — brand mentions, positions, sentiment scores, cited URLs. An answer may name a person, so this can contain personal data that neither you nor we chose to collect.
Technical data. IP address, browser and device type, pages viewed, and timestamps. These appear in server logs and, in aggregated form, in traffic statistics.
Support data. Whatever you send us by email or through the contact form, and our replies.
We do not ask for special categories of data — health, beliefs, political opinions, biometrics. Please do not put them into a prompt, because a prompt is sent to third-party AI platforms.
How we use your data
To run the service: execute your prompts against the AI platforms you selected, store the results, build your dashboards, and send the reports and alerts you asked for.
To manage accounts and keep them secure: authenticate you, apply your plan limits, detect and block abuse, and keep an audit record of significant actions.
To bill you: take payment, issue invoices, and recover failed payments.
To support you: answer your questions and investigate problems you report.
To improve the service: study aggregated usage and diagnose faults. Wherever aggregated data answers the question, we use that instead of individual records.
To send service messages: trial ending, payment failed, a material change to this policy or to the terms. These are not marketing and you cannot unsubscribe from them while you hold an account.
To send marketing email: only if you opted in, and every message carries a working unsubscribe link.
We do not sell personal data, we do not share your workspace data with other customers, and we do not use your prompts, your results or your content to train AI models.
Legal basis for processing
Performance of a contract. Running the service, managing your account, billing you, and sending service messages. Without this data there is no service to provide.
Legitimate interests. Security and abuse prevention, aggregated product improvement, and contacting existing customers about the service they already use. We have weighed these against your interests and consider them proportionate. You may object at any time, and we will stop unless we have compelling grounds that override your objection.
Consent. Marketing email and any optional integration you switch on. You can withdraw consent whenever you like; withdrawal does not affect anything done before it.
Legal obligation. Tax, accounting and company records that we are required to keep for a fixed period.
Cookies and tracking
We set no advertising cookies, run no ad pixels, and do not track you across other websites.
On the public site, two small values are stored by your browser and never sent to us: your language choice, kept in local storage under citex-lang, and a per-session flag that stops the site redirecting you to your language more than once. Both live on your device and you can clear them by clearing site data.
In the application we set one cookie that keeps you signed in. It is strictly necessary — without it the application cannot tell one signed-in user from another — so it does not require consent.
For traffic statistics we use a privacy-focused analytics service that sets no cookies, assigns no persistent identifier, and produces only aggregates: page, referring site, country, device type. It cannot build a profile of you and it does not follow you to other sites.
Because we set no analytics or advertising cookies, we do not show a cookie banner. If that ever changes, we will ask for your consent before any such cookie is set, and refusing will not restrict your use of the site.
Third parties and sub-processors
We rely on a small number of suppliers to deliver the service. Each of them acts on our instructions under a written data processing agreement, and each receives only what it needs.
Infrastructure and database: account data, workspace data, collected answers.
Application hosting and content delivery: technical data and server logs.
Payments — Stripe: name, email, billing address, card data entered directly with them, and your subscription record.
Transactional email: your name, your email address, and the contents of the messages we send you.
Traffic statistics: aggregated page views with no personal identifier.
Error monitoring: technical diagnostics, with personal fields stripped before they are sent.
AI platforms — the providers behind ChatGPT, Claude, Gemini, Perplexity, Google AI and Grok: the text of the prompts you configure. They may retain that text under their own policies. Do not put personal or confidential information into a prompt.
We name each supplier on this page as it is engaged, and we will announce any addition before it takes effect, so that you have time to object. Write to hello@usecitex.com for the current list at any moment.
Data retention
Account and workspace data: for as long as your account is active, then for 30 days after you ask us to delete it. The 30 days are a grace period in case the request was a mistake; after that the data is erased.
Collected answers and the metrics derived from them: 24 months on a rolling basis, so that year-on-year comparison works, or until you delete your account if that comes first.
Billing and accounting records: for the period required by the tax law that applies to us, which is typically longer than the life of your account. This is a legal obligation and we cannot shorten it on request.
Server logs: 30 days.
Support correspondence: 24 months from the last message.
Backups: deleted data can survive in encrypted backups for up to 35 days, after which the backups themselves expire. During that window the data is not used for anything.
Security
Data is encrypted in transit with TLS and encrypted at rest by our infrastructure provider. Passwords are stored only as salted hashes and are never recoverable in readable form.
Each customer's data is isolated at the database level, so a query made by one organisation cannot reach another organisation's rows. Access to production systems is limited to the people who need it, requires multi-factor authentication, and is logged.
Credentials for the AI platforms and for our payment processor are held only on our servers. They are never sent to your browser.
Backups run automatically and restores are tested, because an untested backup is not a backup.
No system is perfectly secure. If a breach affects personal data we will notify the competent supervisory authority within 72 hours where the law requires it, and we will tell you without undue delay when the risk to you is high.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, hand it to you or to another provider in a machine-readable format, or stop processing it where we rely on legitimate interests. Where we rely on consent, you can withdraw it at any time.
Write to hello@usecitex.com. We reply within one month; if a request is genuinely complex we may extend that by two months and will tell you why within the first month. There is no charge, unless a request is manifestly unfounded or excessive.
We may ask you to confirm your identity first, so that nobody else can obtain or erase your data by pretending to be you.
If you are unhappy with how we handled your request you can complain to a data protection authority. Every country in the European Economic Area has one, and you may go to the authority of the country where you live, where you work, or where you believe the problem occurred.
International transfers
We prefer suppliers that host data inside the European Economic Area, and our database is hosted in the EU.
Some processing still happens in the United States — our payment processor and several of the AI platforms operate there. Those transfers are covered by the European Commission's Standard Contractual Clauses and, where the supplier is certified, by the EU-US Data Privacy Framework. We also apply additional measures such as encryption in transit and minimising what is sent.
You can ask us for a copy of the safeguards that apply to a specific transfer by writing to hello@usecitex.com.
Children
Citex is a tool for businesses and is not directed at children. You must be at least 16 years old to create an account, or older if the law where you live sets a higher age for consenting to online services.
We do not knowingly collect data about children. If we learn that we hold any, we delete it promptly.
Changes to this policy
When this policy changes we publish the new version on this page and update the date at the top. The previous version stays available on request.
If a change materially affects your rights or how we use your data, we will email every account holder at least 30 days before it takes effect, so that you can object or close your account first.
Contact us
For anything in this policy, including a request about your rights, write to hello@usecitex.com. That address reaches the people who run Citex, and it is the fastest route for a privacy question, a rights request or a security report.
We have not appointed a data protection officer, because our scale does not require one. If that changes, this section will name them.