# CiteKit Privacy Notice (draft) **Status:** Draft for a pre-launch prototype. Not lawyer-reviewed. Not an offer of legal advice. **Last updated:** 1 September 2026 ## What we collect - **The URL you submit**, so we can generate the pack from that origin. - **HTML we fetch from that origin** (up to 8 pages, 2 MB each, 10 s budget) to build the files. - **Payment records** handled by Polar (merchant of record). We do not store full card numbers. Polar may collect an email for the receipt; CiteKit does not require an account or email to download the zip. - **Server logs** (IP, user-agent, timestamps) for abuse and debugging. We do **not** ask for passwords, CMS tokens, or SSH keys. We do **not** fetch third-party sites linked from your pages. ## How long we keep it Paid unlocks and pack artifacts are kept **up to 7 days**, then deleted from CiteKit storage, unless a refund or dispute is open (kept until that closes). Polar keeps payment records for as long as tax and card-network rules require. ## What we do not do - We do not sell your URL list. - We do not train a public model on your HTML. - We do not run a background crawler after the pack is built. - We do not use the pack as “proof” that any agent cited you. ## Processors (expected in production) Polar (checkout), optional email from Polar, host logs. This prototype stores state on the app’s disk (`data/fulfill.json`). ## Contact privacy@adjudi.com (or privacy@citekit.adjudi.com once DNS is live) (placeholder until the public domain is live). If you want a pack deleted earlier than 7 days, email with the order id or the URL you submitted.