New session
Trust at Citaria

Your AI understands your users.Your data stays yours.

We built Citaria to help product teams turn customer interviews and documents into AI-grounded insight — without giving up control of the sensitive material that fuels that insight. This page tells you exactly how that works.

  • Transcripts deleted from third-party AI typically within 5 minutes of ingestion completion
  • Zero training: no customer data used to improve any AI model
  • Row-level isolation: workspaces never see each other’s data
  • 31-day soft-delete grace + hard purge from active database
Last updated 2026-07-20
01 · Commitments

Our commitments

Four commitments backed by service-level guarantees, contractual obligation, or both.

C1
Data subject rights (GDPR aligned)
Citaria honors data subject rights per GDPR Article 15-21: deletion within 30 days of a verified request, data export within 30 days of a verified request, and breach notification within 72 hours to affected customers and regulators.
C2
Encryption
All customer data is encrypted at rest with AES-256 and in transit with TLS 1.3 across every storage layer — database, object storage, and backups. Encryption keys are managed by our cloud providers; Citaria never holds raw encryption material.
C3
Access control & auditability
Workspaces are isolated by row-level security in our database, enforced at every read path. No Citaria employee accesses customer content during normal operation. Direct content access for incident response requires your prior consent and is logged.
C4
Sub-processor transparency
We publish the full list of sub-processors with whom your data may be shared (see Section 3 below). Any material change — adding, removing, or changing the role of a sub-processor — is announced to customers under a Data Processing Agreement at least 30 days before taking effect.
02 · Sub-processors

Who processes your data on our behalf

The services we use to deliver Citaria. Each is bound by a Data Processing Agreement and acts only on our processing instructions.

VendorPurposeLocationSafeguards
AssemblyAIAudio transcriptionUSOpted out of model improvement; rapid post-ingestion cleanup; DPA
TavilyWeb searchUSConfirmation in progress
AnthropicAI model providerUSZero data retention; no training; SOC 2; DPA
OpenAIAI model providerUSZero data retention; no training; SOC 2; DPA
GoogleAI model providerUSNo training on customer data; SOC 2; DPA; encryption at rest
SupabaseData infrastructureUS EastSOC 2; DPA; encryption at rest
CloudflareStorage and edge infrastructureNorth AmericaSOC 2; DPA; encryption at rest
RailwayApplication hostingUS WestSOC 2; DPA

How we tell you about changes: Any addition, removal, or change in role of a sub-processor is announced to customers under a Data Processing Agreement at least 30 days before the change takes effect.

03 · How we protect your data

Common questions, direct answers

Can other Citaria customers see my data?
No. Row-level security ensures full isolation between workspaces. Every read path in our service includes the customer’s workspace identifier as part of the database query, enforced at the database layer.
Who at Citaria can access my data?
No Citaria employee accesses customer content in normal operation. Engineering access is limited to operational metadata (logs, performance metrics) without content. Direct content access for incident response requires your prior consent.
Do you use my data to train AI models?
No. Anthropic, OpenAI, Google, and AssemblyAI all operate under zero / no-training policies for our account (see Sub-processors above). Citaria itself does not train any model — we use these third-party providers under their public API terms, which prohibit training on customer data.
Do you sell or share my data with third parties?
No. We never sell customer data. Sub-processors (listed above) are used solely to provide the service. They are bound by Data Processing Agreements and processing instructions that prohibit any other use of your data.
Where is my data stored?
All data resides in North America — see the Sub-processors table above for per-vendor location. EU residency is not available in our current generation; please contact us if this is a requirement.
Is my data encrypted?
Yes. TLS 1.3 in transit; AES-256 at rest across all storage layers (database, object storage, backups).
How long do you keep my data after I delete it?
When you delete data: (1) immediately, removed from your view in the product (soft delete); (2) 31 days later, hard purge from the active database and object storage cleanup; (3) +7 days, daily backup snapshots containing the data expire. Total physical retention is approximately 38 days from the moment you initiate deletion. The 30-day GDPR deletion SLA (Commitment 1 above) is measured from your verified deletion request to the completion of step 2.
What if there’s a security breach?
We notify affected customers within 72 hours of discovering an incident, per GDPR Article 33. Notifications include what data was affected, the nature of the incident, and the steps we are taking to remediate and prevent recurrence.
Can I export my data?
Yes. Submit a data portability request to privacy@citaria.com; we fulfill within 30 days per GDPR Article 20.
04 · Resources

Documents and links

Legal
Security
Compliance
Operational
  • Service status / uptimeComing Q3 2026
  • Changelog / security advisoriesComing Q3 2026
05 · Contact & Responsible Disclosure

Talk to us

EmailUse for
legal@citaria.comContracts, DPA, sub-processor questions
privacy@citaria.comGDPR / CCPA data subject requests (access, deletion, portability, objection)
security@citaria.comVulnerability reports (see disclosure policy below)
support@citaria.comProduct questions
Response SLA · legal@ / privacy@ / support@: 2 business days for first response. security@: 24 hours acknowledgment (see disclosure timeline below).
Responsible disclosure

For security researchers

We welcome security researchers. If you find a vulnerability:

In scope
citaria.com web app and APIs; authentication / authorization flaws; data exposure between workspaces; XSS / CSRF / SSRF / injection issues; authentication bypass.
Out of scope
DoS / volumetric attacks; social engineering of Citaria staff or users; physical attacks; self-XSS without significant impact; findings in third-party services (please report directly to the vendor; see Sub-processors above).
How to report
Email security@citaria.com with: affected endpoint / URL / feature, reproduction steps, impact assessment, and your preferred contact for acknowledgment (optional).
Our commitment
Acknowledge receipt within 24 hours; initial assessment within 5 business days; status update at least every 14 days until resolved; coordinated disclosure — we ask for 90 days before public disclosure and will work with you on extensions if needed.
Safe harbor
Citaria will not pursue legal action against researchers who act in good faith, follow this policy, do not access data beyond what is necessary to demonstrate the vulnerability, and do not damage data or service availability.
No monetary bounty
We do not currently offer a paid bug bounty program but will publicly acknowledge significant reports with researcher consent.