Privacy Policy
Last updated · CoreCited
This explains what CoreCited collects, who it reaches, and how long it stays. It was written by going through the code, so it describes what actually happens rather than what a template assumes.
What we collect
- Your account. Email address, and a password hash if you set one. If you sign in with Google we receive your email and name, nothing else.
- What you ask us to track. Brand names, website domains, competitor names, and the prompts you configure.
- What we measure. The answers AI engines give to your prompts, the sources they cite, the pages we crawl on your site, and the scores we compute from them.
- Usage. Which features you use and how much of your plan allowance you have consumed — this is how the meters on your dashboard work.
What we do not collect
- Card details. Paddle handles payment as merchant of record. We never see, receive or store a card number.
- Your visitors. We do not place any script on your website, so we see nothing about the people who visit it.
- Anything from Google beyond what you grant. If you connect Search Console or Analytics, access is read-only and limited to the properties you pick. You can revoke it in your Google account at any time.
Who your data reaches
These are the only third parties involved, and this is why each one is:
| Service | What for | What it receives |
|---|---|---|
| Supabase | Database, authentication and file storage | Your email, brands, prompts, stored AI answers, audits and reports |
| Vercel | Hosting and content delivery | Request logs and IP addresses, as any web host receives |
| OpenRouter | Runs the tracking questions against ChatGPT, Claude, Perplexity and Gemini | The prompt text you configure, and your brand and competitor names |
| DataForSEO | Google AI Overviews, AI Mode, keyword volume and backlink counts | The prompt text, and the domains you track |
| Paddle | Payment processing as merchant of record | Billing details, which Paddle collects directly — we never see or store a card |
| Google (optional) | Search Console and Analytics, only if you connect them | Read-only access to the properties you choose; revocable by you at any time |
| Resend (optional) | Alert and report emails, when configured | Your email address and the contents of the alert |
We do not sell your data, and we do not use it to train any model. The prompts you configure are sent to AI engines because measuring their answers is the entire product; they are not shared with anyone else.
How long we keep it
- Your measurements stay while your account is open — the history is the product, and a trend needs its past.
- Old usage counters are pruned once the period they belong to has passed.
- If you delete your account, your brands, prompts, stored answers, audits and reports are deleted with it. Ask us and we will confirm when it is done.
How we keep it safe
- Everything travels over HTTPS, and the database is encrypted at rest by our hosting provider.
- Access to your rows is enforced by the database itself through row-level security, not only by application code — so a bug in a query cannot hand one customer another customer's data.
- Credentials you give us for a third-party system — a WordPress Application Password, for example — are encrypted with AES-256-GCM before being written down, and are decrypted only at the moment we use them on your instruction.
- We never see or store card details. Paddle handles payment end to end.
No system is perfectly secure, and anyone claiming otherwise is selling something. If we ever discover a breach affecting your data, we will tell you and the relevant regulator without delay.
Your rights
Wherever you live, you can ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, or ask for it in a portable format — email corecited@gmail.com. You do not need a reason and we will not ask for one. We answer within 30 days.
If you are in the EU or UK, these are your rights under the GDPR, and you may also complain to your local data protection authority. If you are in California, the CCPA/CPRA gives you the right to know what is collected and to have it deleted. We do not sell personal information, so there is nothing for you to opt out of — and there never will be, because the business model is subscriptions.
Where your data is held
Our database, hosting and the AI providers we route through operate across several countries, so your data will be processed outside the country you are in. Where that involves a transfer out of the EU or UK, it relies on the standard contractual clauses our providers have in place. The full list of who receives what is the table above — there is no separate, longer list held somewhere else.
Children's privacy
CoreCited is a business tool and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has given us personal data, email us and we will delete it.
Cookies
We set one cookie, for your login session. There is no advertising, tracking or analytics cookie on this site, which is why you have not been asked to accept anything. If that ever changes, you will be asked first — not told afterwards.
Links to other sites
The comparison pages link to our competitors' own websites, and reports may link to sources AI engines cited. We do not control those sites and this policy does not cover them.
Changes
If this policy changes in a way that affects you, we will email you before it takes effect rather than quietly updating the date at the top.
Questions about any of this? Contact us — or email corecited@gmail.com.