Last updated: July 24, 2026
Privacy policy
This page describes what data Citerra stores, why, where it lives, and the controls for exporting or deleting it.
Who is responsible
Citerra operates this website and the Citerra application. For any privacy question or request, write to support@citerra.de.
What is collected
Waitlist: the email address entered on the coming-soon page, stored until early access opens or removal is requested.
Account: email address, name, and organization membership, managed by the authentication provider (Clerk).
Content: the documents, source files, uploaded PDFs, and library data created inside the application. This may include unpublished research; it is treated as confidential, is never used to train models, and is retrievable only inside the organization that owns it.
Diagnostics: error reports with personal data scrubbed. No advertising trackers, no session recordings of editor surfaces.
Why it is processed
To provide the service (contract): storing and compiling documents, searching literature, managing citations.
To run AI features on request (contract): selected text and retrieved library excerpts are sent to the model provider with zero retention where supported, and only when an AI action is used.
To keep the service reliable and secure (legitimate interest): error monitoring, rate limiting, abuse prevention.
Where data lives and who processes it
The application database and generated files are hosted in the EU (Ireland). LaTeX compilation runs in the EU (Frankfurt) on ephemeral machines. These subprocessors handle specific slices of data:
- Convex — application database and generated artifacts (EU West, Ireland)
- Clerk — sign-in identity: email, name, organization membership
- UploadThing — uploaded PDF and image files
- Fly.io — LaTeX sources during compilation (EU, Frankfurt; deleted after each job)
- OpenAI — text excerpts sent for AI assistance and search indexing (zero-retention API)
- Copyleaks — document text submitted for plagiarism scans, only with per-scan consent, never added to their database
- Sentry — error reports with personal data scrubbed
How long data is kept
Organization data is kept for the lifetime of the organization plus 30 days after deletion is requested, then permanently removed — including uploaded files and search indexes. Deletion can be cancelled at any point inside those 30 days.
Export bundles and compiled artifacts prepared for download are removed within 24 hours.
Your rights
Access and portability: an organization admin can export all organization data as a zip from the organization settings page.
Erasure: an organization admin can schedule deletion of all organization data from the same page, with the 30-day grace window described above.
For anything else — rectification, restriction, objection, or a complaint — write to support@citerra.de. EU residents may also contact their local supervisory authority.
Changes
Material changes to this policy are announced on this page with an updated date.