Legal
Privacy Notice
This notice describes how CitePatch SL processes personal data when you use the product or the public site. It took effect on 21 August 2026. It has not yet been reviewed by outside counsel — see the legal-review note above — but it describes what we actually do, not what we intend to do eventually.
Who is responsible for your data
The data controller for CitePatch is CitePatch SL (Tax ID pending; registered address pending). For any privacy question or request, write to privacy@citepatch.com.
What we collect
We collect the data needed to run the accounts, billing, and product features described in the Terms of Service — not more.
- Account identity: name, business email, and authentication events (magic-link and Google OAuth sign-ins). We never see or store a password.
- Organization membership: which organization and role you belong to, and invitations sent or accepted.
- Billing identity: Stripe manages your card details directly; we hold only what Stripe returns to identify your subscription — plan, billing email, invoice history.
- Product usage and audit logs: the prompts monitored, patches drafted and approved, integrations connected, and the actions taken on your account, kept for accountability and support.
- Support correspondence: anything you send us when you ask for help.
- Content you control: your domain content, brand facts, and the data returned by integrations you connect (GitHub, GitLab, Bitbucket, WordPress, Webflow, Shopify, Contentful, Wix, Google Drive) or by Google Analytics 4 / Search Console once you authorize the connection. This content is yours; it may incidentally contain personal data belonging to your own employees, customers, or site visitors, and you are responsible for having a lawful basis to have us process it on your behalf.
Why we process it, and on what basis
Each purpose below rests on a specific legal basis under GDPR Article 6.
- Providing the service you signed up for — accounts, monitoring, patch drafting, publishing, billing — under the contract between us (Art. 6(1)(b)).
- Keeping the product secure, preventing abuse, and understanding how the product is used so we can improve it, under our legitimate interest (Art. 6(1)(f)), balanced against your right to privacy.
- Showing you analytics on the public marketing site, only after you consent through the cookie banner (Art. 6(1)(a)) — never inside the product itself.
- Issuing invoices and keeping accounting records, under our legal obligation as a business (Art. 6(1)(c)).
Who we share it with
We do not sell personal data, to anyone, ever.
- The vendors that help us run CitePatch are listed, and kept current, on the Subprocessors page — we point there instead of duplicating the list here, so it cannot drift out of date in two places.
- Google Analytics 4 and Google Search Console data comes in under your own Google authorization, for the property you connect; we do not obtain it independently.
- Integrations you connect receive only the content you instruct CitePatch to publish to them, using credentials you control and can revoke at any time.
- We disclose personal data to anyone beyond this only if the law requires it, or with your consent.
Where your data is processed, and international transfers
CitePatch's infrastructure runs on Google Cloud Platform, operated by Google Ireland Ltd., in the europe-west1 region (Belgium), with supporting virtual machines on DigitalOcean.
- Some of the AI model and search providers we send prompts and drafted content to are based in the United States — see the Subprocessors page for the current list.
- For those transfers we rely on the safeguards each provider offers, such as the EU-U.S. Data Privacy Framework or standard contractual clauses, where applicable. We have not yet completed a documented, verified assessment of every provider's transfer mechanism, and we are not going to claim one before we have — write to privacy@citepatch.com for the current status of a specific provider.
How long we keep it
Retention follows the product's actual configuration, not a policy written separately from it. These are the defaults in effect today, not a permanent commitment — if we change them, this notice will change with them.
- Archived agent threads: deleted 30 days after archiving.
- Idle agent threads: deleted after 365 days of inactivity.
- Public rate-limit counters, used to prevent abuse of public endpoints: deleted after 24 hours.
- Account, billing, and audit-log data: kept for as long as your account is active, and afterward only as long as needed for accounting, legal, or dispute-resolution purposes.
Automated processing, and why publishing is always a human decision
CitePatch's monitoring, contradiction detection, and patch drafting are automated. Nothing gets published, and no decision with a legal or similarly significant effect on you is made, without a human on your account approving it first.
Your rights
Under GDPR you can ask us to do any of the following. Write to privacy@citepatch.com and we will respond within the timeframe the law requires; if you are not satisfied with our response, you can complain to the Agencia Española de Protección de Datos (AEPD) or to the data protection authority in your own EU member state.
- give you access to the personal data we hold about you;
- correct it, if it is inaccurate;
- delete it, subject to what we must keep for accounting or legal reasons;
- restrict or object to certain processing, including processing based on our legitimate interest;
- give you a portable copy of the data you provided us.
Children
CitePatch is a business product. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, write to privacy@citepatch.com and we will delete it.
Changes to this notice
If we change what we collect, why, or for how long, we will update this notice and, if the change is material, notify account owners by email or in-product notice before it takes effect. The version and effective date are shown at the top of this page.