Last updated: July 24, 2026

Privacy policy

This page describes what data Citerra stores, why, where it lives, and the controls for exporting or deleting it.

Who is responsible

Citerra operates this website and the Citerra application. For any privacy question or request, write to support@citerra.de.

What is collected

Waitlist: the email address entered on the coming-soon page, stored until early access opens or removal is requested.

Account: email address, name, and organization membership, managed by the authentication provider (Clerk).

Content: the documents, source files, uploaded PDFs, and library data created inside the application. This may include unpublished research; it is treated as confidential, is never used to train models, and is retrievable only inside the organization that owns it.

Diagnostics: error reports with personal data scrubbed. No advertising trackers, no session recordings of editor surfaces.

Why it is processed

To provide the service (contract): storing and compiling documents, searching literature, managing citations.

To run AI features on request (contract): selected text and retrieved library excerpts are sent to the model provider with zero retention where supported, and only when an AI action is used.

To keep the service reliable and secure (legitimate interest): error monitoring, rate limiting, abuse prevention.

Where data lives and who processes it

The application database and generated files are hosted in the EU (Ireland). LaTeX compilation runs in the EU (Frankfurt) on ephemeral machines. These subprocessors handle specific slices of data:

  • Convex — application database and generated artifacts (EU West, Ireland)
  • Clerk — sign-in identity: email, name, organization membership
  • UploadThing — uploaded PDF and image files
  • Fly.io — LaTeX sources during compilation (EU, Frankfurt; deleted after each job)
  • OpenAI — text excerpts sent for AI assistance and search indexing (zero-retention API)
  • Copyleaks — document text submitted for plagiarism scans, only with per-scan consent, never added to their database
  • Sentry — error reports with personal data scrubbed

How long data is kept

Organization data is kept for the lifetime of the organization plus 30 days after deletion is requested, then permanently removed — including uploaded files and search indexes. Deletion can be cancelled at any point inside those 30 days.

Export bundles and compiled artifacts prepared for download are removed within 24 hours.

Your rights

Access and portability: an organization admin can export all organization data as a zip from the organization settings page.

Erasure: an organization admin can schedule deletion of all organization data from the same page, with the 30-day grace window described above.

For anything else — rectification, restriction, objection, or a complaint — write to support@citerra.de. EU residents may also contact their local supervisory authority.

Changes

Material changes to this policy are announced on this page with an updated date.

Back to citerra.de