Privacy Policy

Data Processing Agreement and Terms and Conditions

Our Data Processing Agreement (DPA) forms part of our Terms of Use, which apply alongside this privacy policy. For every processor we use — hosting, database/auth, AI analysis, payments — we have entered, or will enter, into a DPA as Art. 28 GDPR requires.

1. An overview of data protection

General information

This overview summarizes, in brief, what happens to your personal data when you visit our website or use the Citation Booster app — which analyzes your articles for Google AI Overview visibility. "Personal data" means anything that can identify you, directly or indirectly. The full declaration below this overview covers the details.

Data recording on this website and in the app

Who is responsible for data recording (the "controller")?

Data on this website is processed by the website operator, whose contact details appear under “Information about the responsible party (the ‘controller’ under the GDPR)” in this Privacy Policy.

How do we record your data?

  • Data you give us directly: signing up (email, password), logging in, resetting your password, and the article URLs or text you submit for analysis.
  • Data recorded automatically on each visit: technical details like browser type/version, operating system, referrer URL, hostname, access time, and IP address (server log files, §4). We use only strictly necessary cookies (auth/session, §4).

What do we use your data for?

  • Running the service: performing the article analysis (URL and keyword only, never customer data), storing your reports, sources, gaps and suggestions, and managing your account and credits.
  • Securing the website and app, and keeping them stable and free of errors.
  • Meeting our contractual and legal obligations.

Separation principle: your customer data — account, contact, and payment details — is used only to run your account, and is never used for analyses or reports and never sent to analysis processors. Analyses and reports draw only on freely available, non-customer data: the public article content you submit and the public web data fetched for it (see §4 and §5).

What rights do you have?

At any time and free of charge, you may ask what personal data we hold about you — its source, recipients, and purposes — and you may have it corrected or erased. Where you gave consent, you can withdraw it at any time, with effect going forward. In certain circumstances you may request that processing be restricted, and you may complain to the competent supervisory authority. Reach us any time at the address above.

Analysis tools and third-party tools

The only third-party processing we do is what running the service requires: hosting, database/auth, and payment processing (§2, §5–§6). The declaration below has the details.

2. Hosting

Our website and app are hosted with the following provider:

Hetzner

Provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.

Our legal basis for using Hetzner is Art. 6(1)(f) GDPR — our legitimate interest in providing the website and app as reliably and securely as possible. Where storing cookies or accessing information on your device requires consent (§ 25 TDDDG), Art. 6(1)(a) GDPR applies as well; you may withdraw that consent at any time.

Hetzner's privacy policy: https://www.hetzner.com/legal/privacy-policy/

Data processing: we have entered, or will enter, into a data processing agreement (DPA) with Hetzner as Art. 28 GDPR requires, ensuring visitor personal data is processed only on our instructions and in line with the GDPR.

3. General information and mandatory information

Data protection

We take protecting your personal data seriously, treat it as confidential, and handle it in line with statutory data protection law — in particular the GDPR — and this declaration.

Using this website or app involves collecting various personal data. This declaration explains what we collect, why, and how. Transmitting data over the internet — email, for instance — can have security gaps, so complete protection against third-party access can't be guaranteed.

Storage duration

Unless this policy states a more specific retention period, we keep your personal data until the purpose it was collected for no longer applies. If you make a valid deletion request or withdraw consent, we delete your data unless another legally permitted reason to keep it applies (e.g. tax or commercial retention duties) — in which case we delete it once that reason no longer applies.

In practice: account data persists while your account exists and is deleted once the account is deleted (subject to retention duties); reports and analysis artifacts tied to your account go with it; server logs are kept only as long as security and error analysis require, then deleted or anonymized.

General information on the legal bases

Where you've given consent, we rely on Art. 6(1)(a) GDPR (and, for special categories we don't ask for, Art. 9(2)(a) GDPR). Where your data is needed to perform a contract or take pre-contractual steps, Art. 6(1)(b) GDPR applies; where a legal obligation requires it, Art. 6(1)(c) GDPR; otherwise, we rely on our legitimate interests under Art. 6(1)(f) GDPR. Where storing cookies or accessing device information needs consent, § 25(1) TDDDG applies too, and that consent is revocable at any time. Each section below names its basis. Third-country transfers based on explicit consent additionally rely on Art. 49(1)(a) GDPR.

Recipients of personal data

We work with external processors to run the service — hosting, database/auth, payments (AI service providers do not) (§2, §5–§6) — and only disclose personal data to them under a valid DPA, and only as needed. Otherwise, we disclose personal data only to fulfill a contract, meet a legal obligation (e.g. to tax authorities), rely on a legitimate interest under Art. 6(1)(f) GDPR, or where another legal basis allows it. We do not sell personal data or share it for third-party advertising.

Revocation of your consent

Several processing activities need your express consent. You can withdraw any consent you've given at any time; doing so does not affect the lawfulness of processing carried out before the withdrawal.

Right to object (Art. 21 GDPR)

Where data is processed on the basis of art. 6(1)(e) or (f) gdpr, you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data — including profiling based on those provisions. If you object, we will no longer process the data unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims (art. 21(1) GDPR).

Where personal data is processed for direct marketing, you have the right to object at any time to processing for such marketing, including profiling related to it. If you object, the data will no longer be used for direct marketing (art. 21(2) gdpr). We currently don't send direct marketing; if that ever changes, every message will include a way to opt out.

Right to lodge a complaint

If you believe the GDPR has been violated, you may complain to a supervisory authority — typically in your member state of habitual residence, place of work, or where the alleged violation occurred — regardless of other administrative or judicial remedies available to you.

Right to data portability

You may request the data we process automatically under your consent or a contract in a common, machine-readable format, and have it sent to you or to a third party. We transfer it directly to another controller only where that's technically feasible.

Information, rectification, erasure

Subject to statutory conditions, you may ask about the personal data we hold, its source and recipients, and why we process it, and request correction or erasure where applicable. Contact the controller address in §1 at any time.

Right to restriction of processing

You may request that we restrict processing: while we check disputed accuracy; where processing is unlawful and you'd rather we restrict than erase; where we no longer need the data but you need it to assert, exercise, or defend legal claims; or while we're weighing an Art. 21(1) objection. Once restricted, data — beyond simply storing it — is processed only with your consent, to assert, exercise or defend legal claims, to protect someone else's rights, or for important EU or member-state public interests.

SSL/TLS encryption

To keep confidential content secure — registrations, logins, orders, inquiries — this site and the app use SSL/TLS encryption. You can spot an encrypted connection by https:// and the lock icon in your browser. Data encrypted this way can't be read by third parties in transit.

4. Recording of data on this website and in the app

Cookies

Our website and app use cookies — small data packages that don't harm your device. Session cookies disappear when your visit ends; persistent cookies stay until you or your browser deletes them. Some cookies are ours (first-party, e.g. auth/session); others come from third parties.

We use strictly necessary cookies only — covering login/session via our auth provider, security, and load balancing. Cookies needed for electronic communication, for a function you've requested (like staying logged in), or to run the service reliably and efficiently are stored under Art. 6(1)(f) GDPR; where consent is required instead (Art. 6(1)(a) GDPR, § 25(1) TDDDG), we ask for it first, and you can withdraw it at any time.

You can configure your browser to warn you about cookies, allow them only in specific cases, block them entirely, or delete them automatically when you close it. Turning cookies off may limit functionality, such as staying logged in or viewing report history.

Server log files

Our pages' provider automatically collects and stores information your browser sends, in server log files:

  • browser type and version
  • operating system
  • referrer URL
  • hostname of the accessing computer
  • time of the server request
  • IP address

We don't merge this data with other sources. Basis: Art. 6(1)(f) GDPR — our legitimate interest in presenting the site correctly and optimizing it, for which log files are necessary.

Registration and accounts

You sign up in the app to use the analysis features. We use what you enter only for the service you signed up for. Required fields must all be filled in, or the sign-up is rejected.

For registered users, we store:

  • account credentials and session data, via our auth/database processor Supabase (email address, password hash — never the plain password — and session tokens); your email, used for account notices such as password resets or significant changes to the service;
  • your account profile and credits (plan, remaining allowance);
  • your analysis artifacts — the article URLs or text you submit, the page content we fetch and parse, reports, detected gaps, suggestions, and their status (e.g. implemented).

Legal bases: consent (Art. 6(1)(a) GDPR) and contract or pre-contractual steps (Art. 6(1)(b) GDPR). Data recorded at sign-up is kept for as long as you're registered and deleted once your account is, subject to statutory retention duties.

Content you submit and page fetching on your behalf

At the core of the service: when you submit an article URL or text, we fetch the public page on your behalf, parse it, check robots rules, run an analysis (§5), and save the resulting report to your account. Basis: Art. 6(1)(b) GDPR, performance of the contract. The analysis works only from freely available, non-customer data — the public article content; your customer data (account, contact, payment details) never goes into an analysis or report, and is never sent to analysis processors. We process submitted content solely to produce the requested analysis, not to train public models. Please only submit content you're entitled to have processed, and don't submit third parties' personal data without a legal basis for doing so.

5. Processors and service APIs

Citation Booster runs on the following processors and service APIs. We have entered, or will enter, into a DPA (Art. 28 GDPR) with each one before it's used in production.

Supabase — auth and database

Provider: Supabase Inc. We use Supabase for user authentication — sign-up, login, password reset, sessions — and as our database, holding accounts, credits, reports, sources, gaps, and suggestions.

Data processed: email address, password hash, session tokens, account profile and credits, and the analysis artifacts described in §4. Bases: Art. 6(1)(a) and (b) GDPR.

6. Payments

We use a third-party payment service to process purchases of plans and credits. When you buy from us, the payment provider processes your payment data — name, payment amount, bank or card details — to carry out the transaction. Its own contractual and data-protection terms apply as well. Basis: contract performance (Art. 6(1)(b) GDPR) and our interest in smooth, convenient, secure payment (Art. 6(1)(f) GDPR); where we ask for consent for a specific action, Art. 6(1)(a) GDPR applies, and that consent is revocable going forward.

Stripe

The provider is Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA. For customers in the EU/EEA, the contracting party is Stripe Payments Europe, Limited, The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland (together "Stripe").

When you buy from us, Stripe processes your payment data — name, email address, payment amount, billing address, card number, bank details — to carry out the payment. Card and bank data goes straight to Stripe over encrypted connections (e.g. Stripe Checkout / Stripe.js) and never reaches our servers in full; at most, we store non-sensitive references like payment status, the card's last four digits, or a subscription ID, to manage your plan and credits. Stripe's own contractual and data-protection terms apply as well:

We use Stripe on the basis of Art. 6(1)(b) GDPR (contract processing) and our interest in smooth, convenient, secure payment (Art. 6(1)(f) GDPR). Where we ask for your consent for a particular action, Art. 6(1)(a) GDPR is the basis, and you may withdraw that consent at any time going forward.

Data processing and third-country transfer: we have a data processing agreement (DPA) with Stripe, as required by Art. 28 GDPR. Where personal data moves to Stripe in the USA, that transfer is safeguarded by Stripe's certification under the EU-US Data Privacy Framework and by the Standard Contractual Clauses in Stripe's DPA (Art. 44 GDPR and following).

Payment transactions are encrypted: wherever we collect payment details, they travel only over encrypted SSL/TLS connections, recognizable by https:// and the lock icon; third parties can't read payment information while it's in transit.

Citation Booster complies with the EU General Data Protection Regulation (GDPR). We use only strictly necessary cookies, and keep data on infrastructure we have under contract, hosted in Germany. We never sell personal data — it isn't our business model.

Effective date: 09-09-2026