Privacy Policy

Last updated: 30 August 2026

1. Who we are. Citarra (“we”) provides AI visibility tracking at citarra.com. This policy explains what personal data we collect and how we use it. Contact: hello@citarra.com.

2. Data we collect. Account data: name, email, company, password hash. Billing data: handled by our payment provider (Paddle) as merchant of record; we do not store card numbers. Service data: brand names, competitor names, prompt lists, and the AI answers and reports generated for your workspace. Usage data: log data, device and browser information, and cookies necessary for login and basic analytics.

3. How we use data. To provide and improve the Service, run your scheduled tracking, send reports and service emails, provide support, bill subscriptions, and meet legal obligations. We do not sell personal data and we do not use your workspace data to train AI models.

4. Third-party processors. We use infrastructure and service providers to operate Citarra, including hosting and database providers, AI model providers (your prompts are sent to them to generate the answers we analyse), email delivery, payment processing (Paddle), and error monitoring. Each processes data only to provide their service to us.

5. Cookies. We use essential cookies for authentication and limited analytics cookies. You can control cookies in your browser settings.

6. Retention. Account data is kept while your account is active. Workspace and report data is retained so your trends remain available; you may request deletion of a workspace or your entire account at any time, and we will delete associated personal data within 30 days except where law requires retention.

7. Your rights. Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict processing. Email hello@citarra.com to exercise these rights.

8. International transfers. Our providers may process data in other countries; where required we rely on appropriate safeguards such as standard contractual clauses.

9. Security. We use encryption in transit, access controls, and tenant isolation at the database level. No system is perfectly secure; notify us immediately of any suspected breach of your account.

10. Children. The Service is for business use and not directed at anyone under 18.

11. Changes. We will post updates here and notify you of material changes by email.