Privacy Policy
Last updated October 2026. The CiteProof operator (“we”) runs CiteProof at getciteproof.com.
In short
| Your brief | Free checks: processed in memory to check it. Not stored. Citation strings only leave the server (next row). No AI model reads it. Paid checks keep findings for 90 days (below) — never silently, always stated here. |
|---|---|
| What we send out | Only citation strings, such as 410 U.S. 113, go to CourtListener. Looking up a case in full also reveals that case's identity to CourtListener. After a paid check, the Verification Record is emailed to you via Resend as your durable copy. |
| What we store | Counts, timestamps, a session ID and a source tag. For paid users, also your email and your order and credit records. |
| Paid checks | Their findings (citation outcomes, quoted passages, counts) are kept 90 days so you can retrieve them and chain revisions, then deleted automatically. Free checks are never kept. |
| Rate limits | A hashed IP address and a cookie, held up to 24 hours, never linked to content. |
| Payments | Handled by Paddle. We never receive your card number. |
1. Who we are
The operator of CiteProof, based in Nairobi, Kenya, is responsible for the personal data described here. Contact: [email protected].
2. What we collect, why and how long we keep it
| Data | What and why | Retention |
|---|---|---|
| Your documents | The text of pasted or uploaded briefs, including quotes, is processed in memory to extract and check citations. Uploads are not persisted and are limited to 25 MB. We do not log request bodies. | Not retained after processing |
| Extracted citation strings | Sent to CourtListener to resolve them. Any link between a session and its citations is deleted within 24 hours. We do not keep citation lists tied to your identity. | Up to 24 hours |
| Usage data | Counts of citations and quotes found, timestamps, session ID. Used to run the Service, prevent abuse and measure usage. Not linked to content. | 24 hours, then deleted automatically |
| Source tag | From a link parameter (for example, ?src=linkedin). Stored as a tag only, alongside the usage data above. | 24 hours, then deleted automatically |
| Rate-limit data | A hashed IP address and a cookie, used only to enforce usage limits. Never linked to content. | Up to 24 hours |
| Account data (paid users) | Your email address, a one-way record that consumed sign-in links cannot be reused (a digest, never the link itself), and order and credit records, to run your account and provide support. | While your account is active, then as needed for tax and accounting |
| Paid verification records | The findings of checks you paid for (citation outcomes, quoted passages, counts), kept so you can retrieve them, chain brief revisions, and audit your account. Free checks are never kept. Programmatic (API) use implies the same retention. | 90 days, then deleted automatically |
| Account activity | Sign-ins, completed checks and record downloads: timestamps, counts and statuses only. Never brief text or quoted passages. | 90 days, then deleted automatically |
| Payment data | Collected by Paddle as merchant of record. We receive limited order information (order ID, email, country, plan, amount and status), not your card number. | As required for accounting |
| Support emails | Messages you send us. Please do not include brief text or client information. | 24 months |
| Bounce records | Email addresses that bounced or drew complaints, kept so we stop mailing dead addresses and protect deliverability for everyone else. Address and reason only. | 24 months, then deleted automatically |
| Technical logs | Metadata only, such as citation count, duration, status and error codes. No request bodies. Held in our hosting provider's logs, never in our database. | Up to 30 days (provider log retention) |
| Cookies | Strictly necessary cookies for your session, usage limits and sign-in. We do not use advertising or tracking cookies, and we do not fingerprint browsers. | Session cookie up to 7 days; rate-limit cookies up to 24 hours |
3. Who receives data
| Recipient | Role | Data |
|---|---|---|
| CourtListener (Free Law Project) | Source of case data | Citation strings. Full-opinion lookups reveal which cases were looked up. |
| Paddle.com Market Limited | Merchant of record: payment, invoicing, tax, refunds | Details you give at checkout. Paddle processes them under its own privacy notice. Paddle never receives your brief. |
| Railway | Application hosting; encrypted connections end here | Traffic to and from the Service, processed in memory |
| PostgreSQL, hosted with the application on Railway | Database | Case metadata, and account and order records. No brief text. |
| Cloudflare R2 (only when configured) | Cached public court opinions | Public opinion text only. No user data. |
| Resend | Sends sign-in, welcome, receipt and record emails | Your email address and the links. Sign-in, welcome and receipt mail carries no brief content; the record email carries the Verification Record you paid for, as your durable copy. |
| Google (only if you choose "Continue with Google") | Confirms your email address for sign-in | That you signed into CiteProof and when. Google never receives your brief; scopes are limited to sign-in identity. |
| CiteProof (own servers) | Error logs | Technical error data, with request content removed. We use no third-party error-tracking service. |
| Microsoft (Word add-in only) | Hosts the Office.js library the add-in task pane loads to talk to Word | Standard browser request data when the add-in loads. The main website never loads this or any third-party script. |
We do not sell personal information and we do not share it for advertising. We may disclose data where the law requires, to protect rights and safety, or in a business transfer, and we will tell you unless the law forbids it.
4. How we use data
To provide and secure the Service, enforce usage limits, support you, process orders with Paddle, meet legal and accounting duties, and understand aggregate usage. We do not use your documents to train any model, and no AI model reads your brief.
5. Legal bases
Where laws such as the GDPR, the UK GDPR or the Kenya Data Protection Act apply, we rely on performing our contract with you, our legitimate interests in running and securing the Service and preventing abuse, legal obligations, and consent where it is required.
6. Security
We use encrypted connections, do not log request bodies, limit and cap uploads, and restrict access to our systems. No system is perfectly secure. If a breach affects you, we will notify you as the law requires.
7. International processing
We operate from Kenya and run the Service on Railway's cloud infrastructure. Data also goes to providers in other countries, such as CourtListener and Paddle. By using the Service you understand that your data may be processed outside your country.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, restrict or object to our use of your personal data, and to receive a copy of it. Email [email protected]; we may verify your identity and will reply within 30 days. California residents: we do not sell or share personal information. Because we do not store your brief, we cannot retrieve or delete it. That is deliberate. You may complain to your data-protection authority, including the Office of the Data Protection Commissioner in Kenya.
9. Confidentiality and your professional duties
We are not your lawyer, and you decide what to submit. We need only the citations and the quoted passages to do our check, so in most cases you can remove client names and unrelated facts before you submit. We do not guarantee that any particular submission satisfies your professional obligations.
10. Children
The Service is for adults and professionals and is not directed to anyone under 18.
11. Changes
We will post changes here with a new effective date, and email account holders about material changes.
12. Contact
CiteProof operator, Nairobi, Kenya. Email [email protected].