CiteAura
Product
OverviewHow It WorksFeaturesAI visibility audit
Solutions
For brandsFor agencies
Resources
DocsGuidesMethodologySample report
Pricing
Sign In Get Started

Privacy Policy

Effective Date: August 15, 2026 · Version 1.4

Our Core Privacy Commitment: CiteAura never trains AI models on your private data, prompt matrices, or customer audits. All API keys are encrypted with hardware-grade AES-256-GCM and stored exclusively within your isolated tenant workspace.

1. Overview & Scope

CiteAura ("we", "our", or "us") provides a Generative Engine Optimization (GEO) platform that diagnoses, tracks, and verifies brand visibility across artificial intelligence search engines and large language models. This Privacy Policy describes how we collect, use, process, and protect your information when you visit citeaura.com, access the CiteAura web application at citeaura.com/app, or interact with our APIs.

2. Information We Collect

2.1 Account & Workspace Information

When you register for a CiteAura workspace, we collect your email address, organization or team name, role, and hashed password. For single sign-on (SSO) users, we process authentication tokens provided by your OpenID Connect (OIDC) identity provider.

2.2 Usage & Approximate Location Information

We use a first-party random visitor identifier to measure visits, registrations, activation, and subscription conversion. When traffic passes through our trusted edge network, we retain the two-letter country code associated with registration or a visit for aggregate geographic reporting. We do not require you to provide a country during registration, and we do not retain a precise location for this purpose.

2.3 Project & Brand Measurement Data

To perform GEO audits and generate engineering tickets, you provide website URLs, target domains, competitor names, and target keyword question sets. This data is stored in tenant-isolated filesystems (Open SSOT) to generate diagnostic reports and deployment assets.

2.4 Bring Your Own Key (BYOK) Model Credentials

If you configure model API keys (e.g. OpenAI, Anthropic, DeepSeek, Google Gemini, Zhipu AI, Moonshot AI, xAI, Perplexity), your credentials are immediately encrypted at rest using AES-256-GCM. Plaintext API keys are never written to logs, never exposed in client-side responses, and only injected temporarily into isolated worker processes during live sampling executions.

3. How We Use Your Information

We use the collected information strictly for the following purposes:

  • Delivering GEO audit diagnostics, perception gap analyses, and 13 standardized engineering tickets;
  • Executing AI visibility sampling and verification runs across model matrices;
  • Compiling white-label client delivery decks and deployment asset packages (JSON-LD, /llms.txt);
  • Managing billing subscriptions, team role permissions, and usage counters;
  • Providing technical customer support and critical platform notifications.

4. Zero Model Training Guarantee

We believe in absolute data sovereignty for brand teams and marketing consultants. CiteAura will never sell, license, share, or use your proprietary content, prompt archives, audit findings, or custom strategies to train, fine-tune, or evaluate public machine learning models.

5. Data Isolation & Security Architecture

CiteAura enforces strict multi-tenant isolation:

  • Tenant Boundaries: All audit reports, tickets, metrics, and delivery archives are segregated per tenant ID on disk with strict directory traversal prevention.
  • Cryptographic Security: Sensitive credentials are encrypted with AES-256-GCM using isolated tenant keys. Communications are encrypted in transit via TLS 1.3.
  • Role-Based Access Control (RBAC): Tenant workspaces support Owner, Editor, and Viewer permission tiers to prevent unauthorized access.
  • Audit Logging: All security-sensitive operations (key updates, role changes, exports) are recorded in tamper-evident audit event logs.

6. Cookies & Tracking Technologies

We use strictly necessary HTTP-only session cookies to maintain your authenticated login state and CSRF defense headers. We also use a first-party HTTP-only random visitor cookie and short browser storage containing only page paths, source hosts, and campaign labels for aggregate registration and conversion measurement. We do not use third-party behavioral tracking cookies or advertising pixels.

7. Data Retention & Deletion Rights

Under GDPR, CCPA, and global data privacy standards, you have the right to:

  • Access & Export: Export all audit records, JSON snapshots, and delivery packs at any time in open standard formats (JSON/Markdown);
  • Rectification: Update your profile, organization, or project configurations;
  • Permanent Deletion: Request the complete purge of your tenant workspace, encrypted keys, and associated file storage by contacting our privacy team.

8. Contact Us

If you have any questions, privacy concerns, or data subject requests regarding this policy, please contact our Data Protection Team at:

Email: [email protected]
Official Website: https://citeaura.com

CiteAura

Next-gen Generative Engine Optimization (GEO) diagnosis, execution, and delivery.

© 2026 CiteAura
Docs Guides About Contact Sign In Privacy Policy Terms of Service