Last updated: July 5, 2026
This policy explains what data Citeya collects, why we collect it, who we share it with, and the choices you have — including the cookies and advertising disclosures required under GDPR, the UK/EU ePrivacy rules, and Google's advertising policies.
Account information. When you sign in with Google, we receive your name, email address, and profile picture from your Google account. We do not receive your Google password.
Content you create. Article briefs, generated drafts, titles, keywords, uploaded reference images, and any edits you make are stored in your Citeya workspace so you can retrieve them later.
Usage data. We log basic technical data — IP address, browser type, device type, pages visited, and timestamps — to keep the service secure and to understand how it's used.
Payment data. If you upgrade to Pro, billing is handled entirely by Razorpay. Citeya never receives or stores your card, UPI, or bank details — only a subscription status and ID.
We do not sell your personal data, and we do not use your account information to serve you ads.
Citeya uses a small number of cookies and browser storage items:
You can block or delete cookies in your browser settings at any time. Doing so may sign you out or prevent the theme toggle from persisting, but the rest of the marketing site will continue to work.
Citeya's blog (citeya.com/blog and individual articles) displays advertising served through Google AdSense. This section exists to meet Google's disclosure requirements for publishers who use AdSense.
We may also display a publisher-verification file (ads.txt) that lists Google as an authorized seller of our ad inventory. This is standard practice and does not itself involve collecting personal data.
We share the minimum data necessary with the following processors to operate Citeya:
Each provider processes data under its own privacy policy and only for the purpose we've engaged them for.
We retain your account and content data for as long as your account is active. If you delete your account, we remove your personal data and generated content from our production database within 30 days, except where we're required to retain records for legal or billing purposes.
Data is stored in an access-controlled database, transmitted over HTTPS, and session tokens are signed and time-limited. No method of transmission or storage is 100% secure, but we take reasonable technical and organizational measures to protect your data.
Depending on where you live, you may have the right to:
To exercise any of these rights, contact us at support@citeya.com or via our Contact page. We respond to verified requests within 30 days.
Citeya is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
Citeya's infrastructure and service providers may process data outside your country of residence. Where required, we rely on standard contractual clauses or equivalent safeguards for cross-border transfers.
We may update this policy as our product or legal obligations change. Material changes will be reflected by updating the "Last updated" date above. Continued use of Citeya after changes take effect constitutes acceptance of the revised policy.
Questions about this policy or your data? Reach us at support@citeya.com or through our Contact page.