Legal

Privacy Policy

Effective date: July 25, 2026

This Privacy Policy explains what data Citenix ("we", "us") collects, why, and your choices. It covers two roles we play:

  • As a controller — for data about you, our account holder, and visitors of citenix.com.
  • As a processor — for visitor analytics that our customers collect on their own websites using the Citenix tracking snippet. For that data, the site owner is the controller and this policy describes how we process it on their behalf.

1. Data we collect from account holders

  • Account: email address, name, and a password we store only as a salted scrypt hash (never in plain text). Optional two-factor secrets if you enable 2FA.
  • Billing: handled by Stripe. We store your Stripe customer and subscription identifiers, plan, and billing status — never card numbers.
  • Site data you connect: crawl results, keyword and ranking data, content analyses, and AI-visibility measurements for the sites you add.
  • Google integrations (optional): if you connect Google Search Console or Google Analytics, we access that data via Google OAuth to power the related features. Citenix's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide your requested features, never for advertising, and we do not sell it. You can disconnect Google at any time in Settings, which deletes the stored tokens.
  • Service usage: feature usage events, credit consumption, and technical logs (IP address, user agent) for security, quotas, and product improvement.

2. Visitor analytics on customers' sites (we are the processor)

Customers can install the Citenix tracking snippet on their own websites. On the customer's instruction it collects:

  • page views, referrer, UTM parameters, approximate location derived from IP, device/browser type;
  • engagement signals (time on page, scroll depth, click positions used for heatmaps);
  • events the customer defines (goals, e-commerce events).

How it works, honestly stated:

  • The snippet is cookieless — it sets no cookies. It stores a random first-party identifier in the browser's localStorage of the visited site so return visits to that same site can be recognized.
  • There is no cross-site tracking: the identifier is scoped to one site and is never linked across different customers' sites.
  • We do not sell this data, use it for advertising, or build profiles of individuals. Each customer's analytics are isolated to their account.
  • Visitors who want data about them removed should contact the owner of the website they visited (the controller); we assist customers with such requests.

3. Visitors to citenix.com and marketing contacts

This is data we hold as the controller — about people interested in Citenix, not about our customers' visitors.

  • Which channel brought you here: a first-party cookie (ctx_ft, 180 days) stores a random id plus the referrer or campaign tag of your first visit, so we can tell which of our own marketing efforts work. It holds no name, email, or profile. If your browser sends Global Privacy Control or Do Not Track, we set nothing at all. See the Cookie Policy.
  • If you request a free AI-visibility scan: we store the email address you gave us and the website you asked about, so we can send you that report — that request is the basis on which we hold it.
  • Contact record: the above, plus any notes our own team writes, is kept in Citenix's internal CRM. It is never shared with other customers, never sold, and never used to build a profile beyond "who asked about what, and how they found us".
  • Email from us: every marketing email carries a one-click unsubscribe. Unsubscribing is permanent and absolute — the address is added to a suppression list that overrides every future list, segment, and sequence. To be removed entirely rather than suppressed, email support@citenix.com.

4. How we use data

  • To provide and operate the Service (crawls, analyses, analytics, AI-visibility runs).
  • To bill subscriptions and prevent abuse (quotas, rate limits, fraud and security monitoring).
  • To improve the Service, using aggregated or de-identified data (e.g. cross-customer benchmarks are computed only over anonymized aggregates with minimum group sizes).
  • To communicate service messages (billing, security, major changes). We don't send marketing email without consent.

5. AI processing

Some features send text to third-party AI model providers (such as Anthropic, OpenAI, Google, or Perplexity) — for example generating the queries used to test your AI visibility, or producing content briefs. We send only what the feature needs (e.g. your site's public content and brand context), not your account credentials or billing data.

6. Subprocessors

ProviderPurposeLocation
Amazon Web ServicesCloud hosting, database, storageUnited States (us-east-2)
StripePayment processingUnited States / global
Anthropic, OpenAI, Google, PerplexityAI model processingUnited States
DataForSEOSearch results and keyword dataUnited States / global
Google (APIs)Search Console / Analytics integration you connectUnited States / global

7. Retention and deletion

  • Account and site data are kept while your account is active.
  • If you delete your account, we delete your tenant data (crawls, analyses, analytics, tokens); backups age out on a rolling basis.
  • Billing records are retained as required by tax and accounting law.

8. Security

Data is encrypted in transit (TLS). Passwords are stored as salted scrypt hashes; session tokens are random 256-bit values; optional TOTP two-factor authentication is available. Each customer's data is isolated per account. Production access is restricted to the operator. No system is perfectly secure — report suspected vulnerabilities to support@citenix.com.

9. International transfers

The Service is hosted in the United States. If you use it from elsewhere (including the EU/UK or GCC), your data is transferred to and processed in the US under this policy.

10. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, or object to certain processing. You can exercise most of these directly (edit your account, disconnect integrations, delete your account) or by emailing support@citenix.com. We respond within 30 days.

11. Children

The Service is not directed at children under 16 and we do not knowingly collect their data.

12. Changes

We may update this policy; material changes are announced by email or in-app at least 14 days in advance. The effective date above always reflects the current version.

13. Contact

Privacy questions and requests: support@citenix.com.