Privacy Policy
Our Core Privacy Commitment: CiteAura never trains AI models on your private data, prompt matrices, or customer audits. All API keys are encrypted with hardware-grade AES-256-GCM and stored exclusively within your isolated tenant workspace.
1. Overview & Scope
CiteAura ("we", "our", or "us") provides a Generative Engine Optimization (GEO) platform that diagnoses, tracks, and verifies brand visibility across artificial intelligence search engines and large language models. This Privacy Policy describes how we collect, use, process, and protect your information when you visit citeaura.com, access the CiteAura web application at citeaura.com/app, or interact with our APIs.
2. Information We Collect
2.1 Account & Workspace Information
When you register for a CiteAura workspace, we collect your email address, organization or team name, role, and hashed password. For single sign-on (SSO) users, we process authentication tokens provided by your OpenID Connect (OIDC) identity provider.
2.2 Usage & Approximate Location Information
We use a first-party random visitor identifier to measure visits, registrations, activation, and subscription conversion. When traffic passes through our trusted edge network, we retain the two-letter country code associated with registration or a visit for aggregate geographic reporting. We do not require you to provide a country during registration, and we do not retain a precise location for this purpose.
2.3 Project & Brand Measurement Data
To perform GEO audits and generate engineering tickets, you provide website URLs, target domains, competitor names, and target keyword question sets. This data is stored in tenant-isolated filesystems (Open SSOT) to generate diagnostic reports and deployment assets.
2.4 Bring Your Own Key (BYOK) Model Credentials
If you configure model API keys (e.g. OpenAI, Anthropic, DeepSeek, Google Gemini, Zhipu AI, Moonshot AI, xAI, Perplexity), your credentials are immediately encrypted at rest using AES-256-GCM. Plaintext API keys are never written to logs, never exposed in client-side responses, and only injected temporarily into isolated worker processes during live sampling executions.
3. How We Use Your Information
We use the collected information strictly for the following purposes:
- Delivering GEO audit diagnostics, perception gap analyses, and 13 standardized engineering tickets;
- Executing AI visibility sampling and verification runs across model matrices;
- Compiling white-label client delivery decks and deployment asset packages (JSON-LD, /llms.txt);
- Managing billing subscriptions, team role permissions, and usage counters;
- Providing technical customer support and critical platform notifications.
4. Zero Model Training Guarantee
We believe in absolute data sovereignty for brand teams and marketing consultants. CiteAura will never sell, license, share, or use your proprietary content, prompt archives, audit findings, or custom strategies to train, fine-tune, or evaluate public machine learning models.
5. Data Isolation & Security Architecture
CiteAura enforces strict multi-tenant isolation:
- Tenant Boundaries: All audit reports, tickets, metrics, and delivery archives are segregated per tenant ID on disk with strict directory traversal prevention.
- Cryptographic Security: Sensitive credentials are encrypted with AES-256-GCM using isolated tenant keys. Communications are encrypted in transit via TLS 1.3.
- Role-Based Access Control (RBAC): Tenant workspaces support Owner, Editor, and Viewer permission tiers to prevent unauthorized access.
- Audit Logging: All security-sensitive operations (key updates, role changes, exports) are recorded in tamper-evident audit event logs.
6. Cookies & Tracking Technologies
We use strictly necessary HTTP-only session cookies to maintain your authenticated login state and CSRF defense headers. We also use a first-party HTTP-only random visitor cookie and short browser storage containing only page paths, source hosts, and campaign labels for aggregate registration and conversion measurement. We do not use third-party behavioral tracking cookies or advertising pixels.
7. Data Retention & Deletion Rights
Under GDPR, CCPA, and global data privacy standards, you have the right to:
- Access & Export: Export all audit records, JSON snapshots, and delivery packs at any time in open standard formats (JSON/Markdown);
- Rectification: Update your profile, organization, or project configurations;
- Permanent Deletion: Request the complete purge of your tenant workspace, encrypted keys, and associated file storage by contacting our privacy team.
8. Contact Us
If you have any questions, privacy concerns, or data subject requests regarding this policy, please contact our Data Protection Team at:
Email: [email protected]
Official Website: https://citeaura.com