AI research you can defend.Your data stays yours.
We built Citaria to help product teams turn customer interviews and documents into AI-grounded insight — without giving up control of the sensitive material that fuels that insight. This page tells you exactly how that works.
- Transcription: we issue a vendor-side delete for the transcript as soon as ingestion completes
- Zero training: neither we nor our model and transcription providers train on the research material you upload (by contract or account setting)
- Row-level security scopes each signed-in database query to the caller’s own workspace
- 31-day soft-delete grace + audited hard purge from database and object storage
Our commitments
Five commitments backed by service-level guarantees, contractual obligation, or both.
- C1Data subject rights (GDPR aligned)
- Citaria assists customers in responding to data subject requests under GDPR Articles 15-21. We act on a customer’s verified instruction to delete within 30 days or to provide a copy of their content within 30 days, and we give notification of a personal data breach without undue delay after we become aware of it.
- C2Encryption
- All customer data is encrypted in transit with TLS 1.3. Our database, object storage, and hosting providers encrypt data at rest under their published security practices — the terms that apply to each are listed in the sub-processor table below. Encryption keys are managed by those providers; Citaria never holds raw encryption material.
- C3Access control & auditability
- Workspaces are separated by row-level security in our database. On the server-side and AI-agent paths that run with elevated database privileges, that separation is applied by our application code. No Citaria employee accesses customer content during normal operation. Supporting the Services may require access to specific content — for example, to diagnose a defect you have reported. Such access is limited to what the task requires and is logged.
- C4Sub-processor transparency
- We publish the full list of sub-processors with whom your data may be shared (see Section 02 below). We notify customers under a Data Processing Agreement at least 10 days before a new or replacement sub-processor begins processing their content, both by updating this page and by email to their designated privacy contact, and they may object on reasonable data-protection grounds within 10 days. Where a change is required to preserve the security, availability, or lawfulness of the service, we may make it immediately and will give notice within five business days, stating the reason.
- C5What we do use: Service Data
- Operational signals — logs, counts, timings, and whether a generated result was accepted, edited, or dismissed — let us run, secure, and improve the product, including tuning how results are ranked and scored. Service Data never includes the text of your recordings, transcripts, documents, or generated outputs, and we do not derive it by analysing their substance. We do not attempt to re-identify anyone from it, and we disclose it outside Citaria only to service providers acting on our behalf under written data protection terms, or in aggregated form. See Terms Sections 1 and 3.4.
Who processes your data on our behalf
The services we use to deliver Citaria. Each row states the data protection terms that apply to that vendor. The terms differ by vendor; the table states what applies to each.
The providers listed below are those we use as of the last updated date above.
| Vendor | Purpose | Location | Safeguards |
|---|---|---|---|
| Google (Gemini API) | AI model provider — analysis, synthesis, document evaluation, transcript understanding | Global endpoint | No training on paid-tier data — the Gemini API Additional Terms of Service state that Google does not use your prompts or responses to improve its products (contractual, not an account toggle); API request storage disabled at project level; Cloud Data Processing Addendum incorporated by reference; encryption at rest |
| AssemblyAI | Audio transcription | US | DPA auto-applies with built-in SCCs; opted out of model training, benchmarking and de-identified-data training; audio is not uploaded — the vendor fetches it once through a link that expires in four hours; we issue a delete for the vendor-side transcript as soon as ingestion completes; account-level retention is set so the vendor begins deleting audio and transcripts one day after submission |
| OpenAI | Text embeddings only (semantic search index) | US | No training on API data — Services Agreement §4.2 (contractual, not an account toggle); data processing addendum signed. |
| Fireworks AI | AI model provider — hosted open-weight model used by the analysis agent | US, Japan, UK, Germany, Iceland (its published processing locations) | Its data processing addendum prohibits it from using our data to train, fine-tune or otherwise improve any shared or foundational model (DPA §4.3(f)), and its terms carry a second no-training commitment covering all Content, not only personal data (Terms §3.6). Under that DPA it does not retain prompt inputs or model outputs beyond the lifecycle of the request; the two carve-outs to that obligation are the Response API and prompt caching, and we use neither (DPA §4.5). Personnel access is limited to those with a business need, under obligations at least as protective as the DPA itself (§3(c)), and every downstream sub-processor must sign substantially similar confidentiality provisions. Prompts, inputs and outputs are excluded from “Usage Data” (§1.1). EU Standard Contractual Clauses Module Two, the UK Addendum and the Swiss annex are incorporated (§12 and Schedule 3). Sub-processors and their processing locations are listed in the contract itself, with 30 days’ notice of changes (Schedule 4, §6.4). |
| Brave Search | Web search | US | DPA incorporated by reference; sub-processors listed in its Annex IV are US-based; query logs retained 90 days. Brave’s DPA excludes search queries sent through the API from its scope |
| Supabase | Data infrastructure | US East | SOC 2; DPA with region-lock clause; encryption at rest |
| Cloudflare | Object storage and edge infrastructure | North America | SOC 2; DPA incorporated by reference; encryption at rest |
| Sentry | Error monitoring | US | DPA with SCCs; PII collection disabled (sendDefaultPii: false); session replay disabled; receives error telemetry and stack traces, not customer content |
| Resend | Transactional email | US | DPA; receives recipient address and message body for invitations and account email only; no customer content |
| Railway | Application hosting | US West | SOC 2; DPA |
How we tell you about changes: Any addition, removal, or change in role of a sub-processor is announced to customers under a Data Processing Agreement at least 10 days before it takes effect, both here and by email. See Commitment 4 above for the full terms, including the objection right and the exception for urgent changes required by security, availability, or legal compliance.
Common questions, direct answers
- Can other Citaria customers see my data?
- No. A query issued with your own signed-in credentials returns rows only from the workspaces you belong to; PostgreSQL row-level security policies enforce that inside the database. Parts of our backend — including the AI agent that reads your documents — connect with a privileged database role that row-level security does not restrict, and on those paths isolation depends on our application code rather than on the database. One case is worth naming explicitly: if you publish an artifact through a share link, that artifact and the sources it cites become readable to anyone holding the link, without a Citaria account.
- Who at Citaria can access my data?
- No Citaria employee accesses customer content in normal operation. Engineering access is limited to operational metadata (logs, performance metrics) without content. Supporting the Services may require access to specific content — for example, to diagnose a defect you have reported. Such access is limited to what the task requires and is logged.
- Do you use my data to train AI models?
- No model is trained on your research material — not by us and not by our providers. We do tune and evaluate how results are ranked and scored using operational Service Data (see Commitment 5 above and Terms Section 3.4); that never includes the substance of your material. Our model providers operate under contractual no-training terms for our paid API accounts (see Sub-processors above). We have also disabled optional API request logging at the project level. Note that no-training and zero-retention are distinct commitments: providers retain data for a limited period for abuse monitoring under their own published policies. Transcription is the exception — we issue a delete for the vendor-side transcript as soon as ingestion completes. We do not upload audio to that vendor; it fetches the file once through a link that expires four hours after it is issued, and removes its own copy under its published retention policy.
- Do you sell or share my data with third parties?
- No. Citaria does not sell customer data. Sub-processors (listed above) are engaged to provide the service and are subject to the terms stated for each of them in the table above.
- Where is my data processed and stored?
- Storage, object storage and application infrastructure are in North America — see the Sub-processors table above for per-vendor location. Model inference runs on our AI provider’s global endpoint and is not pinned to a region. If region-locked inference is a requirement for your engagement, tell us before you send any material and we will confirm in writing what is achievable for your specific case.
- Is my data encrypted?
- Yes. TLS 1.3 in transit. Our database, object storage, and hosting providers encrypt data at rest under their published security practices; the terms that apply to each are listed in the sub-processor table above.
- How long do you keep my data after I delete it?
- When you delete data: (1) immediately, your data is removed from view in the product and stops being processed (soft delete); (2) after a 31-day grace period — which exists so an accidental deletion can be recovered through support — it is hard purged from the active database and object storage; the purge job runs daily, so this completes within about a day of the grace period ending; (3) backup snapshots containing the data expire on our providers’ own backup schedules. The 30-day commitment in Commitment 1 above is the window in which we act on a verified request, which happens at step 1.
- What if there’s a security breach?
- We notify affected customers without undue delay after we become aware of an incident. As a processor, that is our obligation under GDPR Article 33(2) — the 72-hour deadline in Article 33(1) applies to you as the controller, and our job is to give you what you need in time to meet it. Notifications include what data was affected, the nature of the incident, and the steps we are taking to remediate and prevent recurrence.
- Can I export my data?
- If you are a customer, you can export your workspace data at any time; contact privacy@citaria.com and we will assist. If your words appear in a Citaria workspace because you took part in an interview, the organisation that ran the research is the controller of that material — send your request to them, and we will act on their verified instruction to help them respond.
Documents and links
- Privacy PolicyView
- Terms of ServiceView
- Data Processing Agreement (DPA)Available on request
- Acceptable Use PolicyView
- Consumer Health Data Privacy PolicyView
- Sub-processor listSee Section 02 above
- Security WhitepaperAvailable on request
- Penetration test summaryNot currently performed
- Trust signals snapshotSee header above
- SOC 2 attestationOn roadmap — contact us for current posture
- GDPR processing baselineSee Section 01 above
- Service status / uptimeComing Q3 2026
- Changelog / security advisoriesComing Q3 2026
Talk to us
| Use for | |
|---|---|
| legal@citaria.com | Contracts, DPA, sub-processor questions |
| privacy@citaria.com | GDPR / CCPA data subject requests (access, deletion, portability, objection) |
| security@citaria.com | Vulnerability reports (see disclosure policy below) |
| support@citaria.com | Product questions |
For security researchers
We welcome security researchers. If you find a vulnerability:
- In scope
- citaria.com web app and APIs; authentication / authorization flaws; data exposure between workspaces; XSS / CSRF / SSRF / injection issues; authentication bypass.
- Out of scope
- DoS / volumetric attacks; social engineering of Citaria staff or users; physical attacks; self-XSS without significant impact; findings in third-party services (please report directly to the vendor; see Sub-processors above).
- How to report
- Email security@citaria.com with: affected endpoint / URL / feature, reproduction steps, impact assessment, and your preferred contact for acknowledgment (optional).
- Our commitment
- Acknowledge receipt within 24 hours; initial assessment within 5 business days; status update at least every 14 days until resolved; coordinated disclosure — we ask for 90 days before public disclosure and will work with you on extensions if needed.
- Safe harbor
- Citaria will not pursue legal action against researchers who act in good faith, follow this policy, do not access data beyond what is necessary to demonstrate the vulnerability, and do not damage data or service availability.
- No monetary bounty
- We do not currently offer a paid bug bounty program but will publicly acknowledge significant reports with researcher consent.