Skip to main content
Citation Safe

Privacy Policy

Version v2026.07.17 · Effective July 17, 2026. Prior version: v1.0, effective July 14, 2026.

This Privacy Policy explains how Digital Empire Holdings LLC (“Citation Safe™,” “we”) handles information when you use citationsafe.com and related APIs, connectors, and add-ins (the “Service”). We are the data controller. Contact: support@citationsafe.com, 30 N Gould St Ste N, Sheridan, WY 82801, USA.

1. Document content — hash-only by default

When you submit a brief or text for verification, we extract citations and, by default, store only a cryptographic SHA-256 hash of the submitted document together with the individual citations found and their verification results. We do not retain the full text of your document by default. This design exists specifically because submissions may contain privileged or confidential legal work product.

1a. Browser extension

The Citation Safe browser extension sends only the text you explicitly select and choose to verify to our API; it is processed under this policy’s hash-only default and is not used for any other purpose.

1b. Word add-in (Microsoft 365 / Office)

When you install and open the Citation Safe Word add-in and click Verify citations in this document, the add-in reads the text of the document you are actively editing (via the Office JavaScript API’s document-body accessor) and transmits it to our verification endpoint at https://citationsafe.com/api/verify. The transmitted text is processed under the same hash-only default described in Section 1: we retain only a SHA-256 hash of the transmitted text plus the extracted citations and their verdicts, not the raw document text.

The add-in does not read documents you are not actively editing, does not access your Microsoft account beyond the identity Microsoft passes to Office add-ins in order to load them, and does not transmit any data to a third party other than Citation Safe’s own verification API. The task pane loads Microsoft’s required Office JavaScript runtime from https://appsforoffice.microsoft.com; it loads no third-party analytics, ad networks, or telemetry beacons. Uninstall the add-in via Word’s Insert → Add-ins → My Add-ins panel; that permanently stops the add-in from reading any further document text.

2. Account and billing data

If you create an account we store your email address and authentication metadata, along with a clickwrap record of your acceptance of these Terms (timestamp, ToS/Privacy version, IP address, and browser user-agent) — see Terms of Service. Paid plans are processed by Stripe, which handles your payment card directly; we do not store full card numbers. We receive limited billing metadata (plan, status, last four digits, billing country) from Stripe to manage your subscription.

3. Usage and technical data

We log operational data needed to run the Service and enforce plan limits — for example verification counts, timestamps, coarse request metadata, and IP-derived rate-limit signals. We use this to prevent abuse, meter usage, and improve reliability.

4. How we use information

We do not sell your personal information, and we do not use submitted document content to train machine-learning models.

5. Third parties (sub-processors)

We share data only with service providers that help us operate: hosting and database infrastructure (e.g. Vercel, Supabase), payment processing (Stripe), transactional email (Resend), and public citation sources used to perform checks (e.g. CourtListener / Free Law Project). Each processes data under its own terms and only as needed to provide its function. The full, current list is published at /subprocessors. Our technical and organizational security measures are described at /security.

5a. Data Processing Addendum (DPA)

A reviewable DPA template, including the EU Standard Contractual Clauses (Module Two, controller-to-processor) and the UK International Data Transfer Addendum as applicable, is published at /dpa. Customers subject to GDPR or UK GDPR may request a signed copy bound to their account at support@citationsafe.com.

6. Data retention

Hashes and citation results are retained to power your verification history and share links until you delete them or close your account. Account and billing records are retained as required for legal and accounting purposes. The full, per-data-type retention schedule (including exact deletion windows for verification history, disputes, subscriber records, and payment records) is published at /retention. You may request deletion as described below.

Our platform runs on Vercel and Supabase. Vercel retains HTTP request logs for a rolling window (up to 30 days by default) that may include HTTP headers, error messages, and IP addresses. We do not persist submitted document text on our platform — only cryptographic hashes of citations. However, if you submit sensitive text (including PHI, PII, or confidential material) that triggers a server error, portions of the request body may briefly appear in Vercel’s error logs before rotating out. For this reason, Medical, Tax, and Legal customers should avoid submitting Protected Health Information (PHI), Social Security Numbers, or other sensitive identifiers; our server-side gates block obvious PHI patterns before processing, but no automated gate is perfect. See our full data handling practices in the AI Disclosure.

7. Your rights

Depending on your location (including under GDPR and CCPA/CPRA), you may have the right to access, correct, delete, or port your personal data, and to object to or restrict certain processing. Submit a self-serve request at /dsr, or email support@citationsafe.com. We confirm receipt of every request by email and respond within thirty (30) days (forty-five (45) days under CCPA). We do not sell personal information or share it for cross-context behavioral advertising.

8. Cookies

We use only cookies strictly necessary to operate the Service (such as authentication/session cookies). We do not run non-essential advertising or cross-site tracking cookies. If that changes, we will add a consent mechanism before any such cookies are set.

9. Security

We use industry-standard measures including encryption in transit (HTTPS/HSTS), scoped access controls, and the hash-only document design above. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

10. International users

The Service is operated from the United States. If you use it from elsewhere, you consent to processing in the U.S. under this Policy.

11. Changes

We may update this Policy; material changes will be posted here with a new effective date and version number, and reflected in the clickwrap acceptance flow at next sign-in.

11a. Breach response

In the event of a personal-data breach, our published response protocol is at /legal/breach-response: 72-hour internal assessment, 30-day notification to affected users and the relevant state Attorney(s) General for confirmed high-risk breaches, and a public post-mortem summary on /security after remediation.

12. Contact

Privacy questions or requests: support@citationsafe.com, /dsr (self-serve data request form), Digital Empire Holdings LLC, 30 N Gould St Ste N, Sheridan, WY 82801.