Legal · Privacy

Privacy, plainly.

We process the minimum personal data we need to run the agency, no more.

Last updated · 5 September 2026

Who we are

CiteSurge is a product of Brainjuice Labs LDA, a company registered in Portugal. Brainjuice Labs LDA operates citesurge.com and the CiteSurge agency workspace. It is the data controller for site and account information. When we process connected customer-property data on your instructions, we act as processor under our data processing agreement.

What we collect

When you visit the site

Standard request logs (IP, user agent, referrer, timestamps), anonymized analytics via GA4, and (if you accept them) preference cookies for the chromatic signature toggle.

When you contact us or book an audit

Your name, work email, company, website, and anything you write in the message body. We use it to reply to you and to prepare a pitch.

When you become a client

Billing details processed by Stripe, Google/Auth.js sign-in data, and the domain-level analytics we pull for your client sites. If you accept analytics, we also collect product-usage events inside the dashboard (which sections you visit) via Mixpanel, stored in the EU under a pseudonymous identifier. We do not resell, trade, or syndicate any of it.

When you authorize a Google data connection

Where a connection is available, you choose the Google Search Console or Google Analytics 4 property and grant read-only access. We receive property details and aggregated reports, such as search queries, pages, clicks, impressions, visits, acquisition sources, and configured key events. We store the normalized records needed for your service and encrypted connection credentials. We do not request raw event-level personal data or permission to edit your Google property.

We use this data for the services you authorize: your audit, recommendations, dashboard, reports and exports, forecasts, and measurement of agreed changes and outcomes. Additional capabilities require separate authorization. Google sign-in and consent to analytics on CiteSurge's own website do not authorize a customer data connection.

Access is limited to your authorized workspace users and processors needed to deliver the agreed service under our data processing agreement. We do not sell this data, publish it, pool it across customers, use it for advertising targeting or lending decisions, or train general-purpose AI models with it. Any processing or transfer must follow the Google API Services User Data Policy, including its Limited Use requirements where applicable.

You can revoke CiteSurge's access in your Google Account. Revocation prevents further authorized collection; it does not itself erase records already held. To request disconnection, access, export, or deletion of retained data, contact privacy@citesurge.com. Customer-property data follows the agreed service retention and the return or deletion terms in our data processing agreement. The seven-year period for financial records is not a blanket retention period for connected property data.

When the AI Readiness Check is available

Where the AI Readiness Check is offered and someone submits a domain, we collect the normalized public domain and request its public homepage, robots.txt, sitemap documents, public AI and agent discovery files, and a bounded set of public links declared by the site. We collect the scan time, selected technical facts needed to produce the result, the scoring version, content hashes, and limited request evidence. For each request, that evidence can include the public URL, a neutral evidence outcome, byte count, selected response headers, and a redacted, escaped excerpt made from no more than 2,048 decoded source bytes. Sensitive values are removed before an excerpt is stored; if we cannot redact it safely, we store no excerpt. We do not store numeric response status codes, raw response bodies, full page text, full header sets, credentials, authorization headers, or cookies for a public AI readiness result.

If the check generates a result, the AI readiness result, findings, selected facts, and limited evidence are stored and published at a shareable result URL. They may include information that a site has already made public. The result says when the scan ran and warns that an automated assessment can be incomplete, wrong, or out of date.

Where an AI readiness leaderboard is published, the newest eligible result for each host is listed by default. A listing carries only the host, the result, its band, the scan date, its rank, and a link to the result. It carries no findings, evidence, excerpts, headers, requester data, verification material, or sender identity. The person who ran a scan can remove that result from the list, and a domain controller can suppress every listing for an exact host.

We also store a pseudonymous requester hash for abuse prevention. It is an HMAC-SHA-256 of the trusted-edge client network prefix, the UTC calendar month, and a service secret. The prefix is IPv4 /24 or IPv6 /48. The raw address is never copied into a readiness-result row. The hash is never published and follows the result's retention period. The full address remains subject to the 30-day server log period stated below.

Why we can process it

Legitimate interest (running the business, responding to enquiries, and providing a limited technical assessment of public websites), contract performance (delivering services you hired us for), and consent (analytics cookies you actively accept). If CiteSurge publishes an AI readiness result, a domain controller can object to the result or future scanning through the account-free controls linked from that result.

How long we keep it

Enquiries: 18 months from last contact. Client records: the life of the engagement plus seven years for tax compliance. Server logs: 30 days. Analytics: 14 months. A completed public AI readiness result and its limited evidence: 12 months from the scan. A suppressed or robots-disallowed scan that produced no result: 30 days from the scan. These are maximum retention periods, not promises that a result remains current for that long.

A verified takedown hides a public result immediately and erases its stored result data within 30 days. An active no-scan instruction stores only the normalized domain and the minimum audit record needed to enforce the choice. It hides earlier results but does not erase them; those rows remain private until their ordinary 12-month or 30-day limit unless the controller also requests removal. A verified withdrawal ends the block immediately but does not republish an old result.

We retain the action, status, verification method, and submitted and completed times for completed takedown, erasure, no-scan, no-scan withdrawal, and leaderboard suppression actions for 24 months. That audit record contains no score, finding, page text, response body, or sender identity.

An account-free removal, no-scan, or leaderboard suppression request uses a one-time domain-control challenge that expires after 30 minutes. Every challenge hash and its temporary request metadata are deleted within 24 hours after completion, failure, or expiry. We never store the plain challenge token. Where a leaderboard suppression is instead proved by email, we record only that the verification method was authenticated email; we do not retain the message, its headers, or the sender address in the readiness data.

A listing key that lets the person who ran a scan remove that result from the leaderboard is stored only as a one-way digest bound to that result. Removing a listing does not erase the result or change its retention period.

Sub-processors

We use a small set of vendors under GDPR-compliant data processing agreements: Stripe (payments), Google OAuth for sign-in, Postgres-managed hosting, GA4 (analytics), Mixpanel EU (dashboard product analytics), and an AI-engine citation tracker used inside the dashboard. The full list is available on request.

Your rights

Access, correction, deletion, portability, objection, and withdrawal of consent. The standard GDPR set. Write to privacy@citesurge.com. We reply inside 30 days.

Contact

Data-related questions: privacy@citesurge.com. Anything else: /contact.


This page is written to be read. It is not a substitute for the full data processing documentation available to clients on request.