Privacy Policy

Last Updated: February 2026

Introduction

Citation Rocket ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and safeguard your information when you use our platform.

By using Citation Rocket, you agree to the collection and use of information in accordance with this policy. If you do not agree with our practices, please do not use the service.

1. Information We Collect

We collect several types of information to provide and improve our service:

1.1 Information You Provide Directly

Account Information: When you create an account, we collect:

  • Name

  • Email address

  • Password (encrypted)

  • Company name and industry (optional)

  • OAuth provider information (if you sign up with Google)

Website Data: When you run audits, we collect:

  • URLs you submit for analysis

  • Business descriptions you provide or confirm

  • Competitor URLs you specify

Payment Information: When you subscribe, our payment processor collects:

  • Credit card or payment method details

  • Billing address

  • Payment history

We do not store complete credit card information on our servers. Payment data is handled securely by our third-party payment processor (Dodo Payments).

API Keys: If you provide third-party API keys (such as Perplexity API keys) for enhanced features, we store these encrypted in our database.

Communications: If you contact us for support, we collect the contents of your messages, email address, and any attachments you send.

1.2 Information We Collect Automatically

Audit Results: When you run audits, we collect and store:

  • Detected content signals from analyzed websites

  • Calculated scores and grades

  • Generated playbooks and recommendations

  • Schema markup generated for your site

  • Citation snapshot results

  • Benchmark comparisons

Usage Data: We automatically collect information about how you interact with the service:

  • Pages visited within the platform

  • Features used

  • Time spent on the platform

  • Browser type and version

  • IP address

  • Device information

  • Referring URLs

Cookies and Tracking Technologies: We use cookies and similar technologies to maintain sessions, remember preferences, and analyze usage patterns. See Section 8 for more details.

1.3 Information from Third Parties

OAuth Providers: If you sign up using Google OAuth, we receive basic profile information (name, email) from Google.

Web Scraping Results: When analyzing websites, we collect publicly available data from the URLs you submit. This may include page content, metadata, schema markup, and other publicly accessible information.

Perplexity API: When using the Citation Snapshot feature, we receive responses from Perplexity's API containing citation information.

2. How We Use Your Information

We use collected information for the following purposes:

To Provide the Service:

  • Process and analyze websites you submit

  • Calculate AI readiness scores

  • Generate playbooks, recommendations, and schema markup

  • Provide citation snapshots

  • Display benchmark comparisons

  • Create PDF reports

Account Management:

  • Create and maintain your account

  • Authenticate your identity

  • Process subscription payments

  • Send transactional emails (welcome messages, subscription confirmations, password resets)

Service Improvement:

  • Analyze usage patterns to improve features

  • Develop new functionality

  • Fix bugs and optimize performance

  • Conduct internal research and analytics

Benchmark Development:

  • Aggregate anonymous audit data to create industry benchmarks

  • Identify common content patterns and trends

  • Improve scoring algorithms

Communications:

  • Send important service updates

  • Respond to support requests

  • Send marketing communications (you can opt out at any time)

Legal and Security:

  • Comply with legal obligations

  • Protect against fraud and abuse

  • Enforce our Terms of Service

  • Protect the security and integrity of the platform

3. How We Share Your Information

We do not sell your personal information. We share information only in the following limited circumstances:

Service Providers: We share data with third-party vendors who help us operate the service:

  • Hosting providers (for database and server infrastructure)

  • Payment processors (Dodo Payments for subscription billing)

  • Email service providers (Resend for transactional emails)

  • Authentication providers (Firebase)

  • API providers (Perplexity for citation snapshots)

These providers are contractually obligated to protect your data and use it only for the purposes we specify.

Aggregated Data: We may share aggregated, anonymized data that does not identify you personally. For example, we might share industry benchmark statistics or usage trends.

Legal Requirements: We may disclose information if required by law, legal process, or government request, or if we believe disclosure is necessary to:

  • Comply with legal obligations

  • Protect our rights or property

  • Prevent fraud or abuse

  • Protect the safety of users or the public

Business Transfers: If Citation Rocket is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change and any choices you may have.

With Your Consent: We may share information for other purposes with your explicit consent.

4. Data Security

We implement reasonable technical and organizational measures to protect your data:

Encryption:

  • All data transmitted between your browser and our servers is encrypted using HTTPS/TLS

  • Passwords are hashed using industry-standard algorithms

  • API keys are stored encrypted in our database

Access Controls:

  • Backend systems require authentication

  • Database access is restricted to authorized personnel only

  • We implement role-based access controls

Security Practices:

  • Regular security updates and patches

  • Rate limiting to prevent abuse

  • Webhook signature verification

  • Secure session management

  • CORS protection

Limitations: While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

5. Data Retention

Account Data: We retain your account information as long as your account is active. If you close your account, we will delete your personal data within 90 days, except as required for legal or business purposes.

Audit Results: We retain audit results associated with your account for the duration of your subscription to allow you to access historical data. After account closure, audit results are deleted within 90 days.

Aggregated Data: Anonymized, aggregated data used for benchmarks may be retained indefinitely as it cannot be used to identify you.

Legal Retention: Some data may be retained longer if required by law or to resolve disputes.

Backups: Deleted data may persist in backups for up to 30 days before permanent deletion.

6. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal data:

Access: You can request a copy of the personal data we hold about you.

Correction: You can update inaccurate or incomplete information through your account settings or by contacting us.

Deletion: You can request deletion of your account and associated data. Note that some data may be retained as described in Section 5.

Portability: You can request your data in a machine-readable format.

Objection: You can object to certain processing activities, such as marketing communications.

Restriction: You can request that we limit how we use your data in certain circumstances.

Withdraw Consent: Where processing is based on consent, you can withdraw consent at any time.

Do Not Sell: We do not sell personal information. If you are a California resident, you have the right to opt out of the sale of personal information under CCPA, though we do not engage in such sales.

To exercise these rights, contact us at privacy@citationrocket.com. We will respond to requests within 30 days.

Marketing Opt-Out: You can unsubscribe from marketing emails by clicking the "unsubscribe" link in any marketing message or by updating your email preferences in your account settings.

7. International Data Transfers

Citation Rocket operates globally. Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws.

When we transfer data internationally, we ensure appropriate safeguards are in place, such as:

  • Standard contractual clauses approved by relevant authorities

  • Service providers committed to protecting your data

  • Compliance with applicable data protection frameworks

8. Cookies and Tracking Technologies

We use cookies and similar technologies for the following purposes:

Essential Cookies: Required for the platform to function properly. These include session cookies that keep you logged in and remember your preferences.

Analytics Cookies: Help us understand how you use the platform so we can improve it. We may use services like Google Analytics.

Cookie Management: Most browsers allow you to control cookies through settings. Note that disabling essential cookies may affect platform functionality.

Do Not Track: Our platform does not currently respond to Do Not Track signals, as there is no industry standard for compliance.

9. Third-Party Services

Our platform integrates with third-party services that have their own privacy policies:

Firebase Authentication: Handles user authentication. Review Google's privacy policy at https://policies.google.com/privacy

Dodo Payments: Processes subscription payments. Review their privacy policy at their website.

Perplexity API: Powers citation snapshot features. Review Perplexity's privacy policy at their website.

Resend: Sends transactional emails. Review their privacy policy at their website.

We are not responsible for the privacy practices of these third parties. We encourage you to review their policies.

10. Children's Privacy

Citation Rocket is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete it promptly.

If you believe we have collected information from a child, please contact us at privacy@citationrocket.com.

11. California Privacy Rights

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):

Right to Know: You can request details about the personal information we have collected about you in the past 12 months, including categories of data, sources, purposes, and third parties we share with.

Right to Delete: You can request deletion of your personal information, subject to certain exceptions.

Right to Opt Out: You have the right to opt out of the "sale" of personal information. We do not sell personal information.

Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To exercise these rights, contact us at privacy@citationrocket.com or through your account settings. We will verify your identity before processing requests.

12. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):

Legal Basis for Processing: We process personal data based on:

  • Contract performance (providing the service you signed up for)

  • Legitimate interests (improving our service, preventing fraud)

  • Consent (marketing communications)

  • Legal obligations (compliance with laws)

Your GDPR Rights: As outlined in Section 6, you have the right to access, correct, delete, port, restrict, and object to processing of your data.

Data Protection Officer: For GDPR-related inquiries, contact our data protection representative at privacy@citationrocket.com.

Supervisory Authority: You have the right to lodge a complaint with your local data protection authority if you believe we have violated your rights.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy

  • Notify you by email

  • Display a notice on the platform

Your continued use of Citation Rocket after changes take effect constitutes acceptance of the revised policy.

We encourage you to review this policy periodically to stay informed about how we protect your data.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: privacy@citationrocket.com
Support Email: support@citationrocket.com
Website: citationrocket.com

For specific data rights requests (access, deletion, portability), please use the subject line "Privacy Rights Request" to expedite processing.

We will respond to all inquiries within 30 days.

© All rights reserved

© All rights reserved