# CiteKit Privacy Notice (draft)

**Status:** Draft for a pre-launch prototype. Not lawyer-reviewed. Not an offer of legal advice.

**Last updated:** 1 September 2026

## What we collect

- **The URL you submit**, so we can generate the pack from that origin.
- **HTML we fetch from that origin** (up to 8 pages, 2 MB each, 10 s budget) to build the files.
- **Payment records** handled by Polar (merchant of record). We do not store full card numbers. Polar may collect an email for the receipt; CiteKit does not require an account or email to download the zip.
- **Server logs** (IP, user-agent, timestamps) for abuse and debugging.

We do **not** ask for passwords, CMS tokens, or SSH keys. We do **not** fetch third-party sites linked from your pages.

## How long we keep it

Paid unlocks and pack artifacts are kept **up to 7 days**, then deleted from CiteKit storage, unless a refund or dispute is open (kept until that closes). Polar keeps payment records for as long as tax and card-network rules require.

## What we do not do

- We do not sell your URL list.
- We do not train a public model on your HTML.
- We do not run a background crawler after the pack is built.
- We do not use the pack as “proof” that any agent cited you.

## Processors (expected in production)

Polar (checkout), optional email from Polar, host logs. This prototype stores state on the app’s disk (`data/fulfill.json`).

## Contact

privacy@adjudi.com (or privacy@citekit.adjudi.com once DNS is live) (placeholder until the public domain is live). If you want a pack deleted earlier than 7 days, email with the order id or the URL you submitted.