Last updated17 August 2026
Privacy policy
Citerra stores the account details you sign up with and the documents, sources, and citations you create. This page names who is responsible, what is collected, why it is processed, and where it is stored. It then covers who else handles it, how long it is kept, how to export or delete it, and how changes are announced.
§ 1
Who is responsible
Citerra is run by Citerra GbR, a partnership of Fadi Al Eliwi, Fares Al Eliwi, Mauro Maus and Yefan Jiang. Its address is c/o Collective Incubator, Jülicher Straße 209q/s, 52070 Aachen, Germany. That partnership is the controller for the data described on this page. For any privacy question or request, write to contact@citerra.de.
§ 2
What Citerra collects
- Waitlist
- The email address entered in the waitlist form, plus a record of the consent it was given under. That record is the time, the page, the wording shown, and the IP address the form was sent from. The IP address is deleted after 1 year. Every waitlist email carries a link that stops them. The record of an unsubscribe is kept for 3 years as proof the request was honoured, then deleted. A signup never confirmed is deleted after 30 days.
- Newsletter
- If you subscribe on the updates page, your address and the same consent record as above, kept and deleted on the same schedule. The list itself is held by Resend, who send the messages. Every message carries a link that removes you, and a request to contact@citerra.de does the same.
- Account
- Your email address, name, and organization membership, managed by the authentication provider Clerk.
- Content
- The documents, source files, uploaded PDFs, and library data you create inside the application, including notes, annotations, AI conversations, generated analysis, and search indexes. Citerra treats this content as confidential, because it can include unpublished research, and it is readable only inside the organization that owns it.
- Diagnostics
- Error reports with personal data removed. Citerra sets no advertising trackers and never session-records editor surfaces.
§ 3
Why it is processed
Each purpose below is listed with the lawful basis it relies on.
- Providing the service (contract)
- Storing and compiling documents, searching literature, and managing citations.
- Running the AI features you ask for (contract)
- Citerra sends selected text and retrieved library excerpts to the model provider when an AI action runs. Citerra does not opt API content into model training.
- Making a source searchable (contract)
- Citerra splits a source added to a document's library into passages and sends them once to the model provider. The provider returns the index the assistant later retrieves from. This happens when the source is added, not when a question is asked.
- Keeping the service reliable and secure (legitimate interest)
- Error monitoring, rate limiting, and abuse prevention.
§ 4
Where it is stored
Citerra hosts the application database and the files it generates in the EU (Ireland). LaTeX compilation runs in the EU (Frankfurt), on machines that keep no state once a job finishes.
Not every provider in the next section operates inside the EU. The table names where each one operates.
§ 5
Who else processes it
Each provider below handles one slice of the data, and nothing beyond it.
An organization can point Citerra at its own model endpoint, in which case the assistant's answers are generated there instead of at OpenAI. Indexing a source and retrieving from it still reach OpenAI.
OpenAI may retain API content in abuse-monitoring logs for up to 30 days, unless applicable law requires longer retention. Citerra is not approved for zero data retention, which would remove that window.
Citerra queries public indexes: OpenAlex, arXiv, Europe PMC, Crossref, Semantic Scholar and Unpaywall. Searching the literature sends OpenAlex, arXiv, Europe PMC and Semantic Scholar the search terms. Importing or resolving a source sends Crossref, Semantic Scholar and Unpaywall that DOI or title. The assistant's web search sends Brave Search the terms it looks up. All of them are hosted in the United States, except Europe PMC in the United Kingdom. These receive the query, never the document. They process no personal data on Citerra's behalf, which is why the table above does not list them.
| Provider | What it receives | Where |
|---|---|---|
| Convex | Application database and generated artifacts. | EU (Ireland) |
| Resend | Email addresses on the waitlist and the newsletter, and the content of the messages Citerra sends to them. | EU (Ireland) for delivery; provider is US-based |
| Clerk | Sign-in identity: email address, name, and organization membership. | United States |
| UploadThing | Uploaded PDF and image files. | United States |
| Fly.io | LaTeX sources during compilation, deleted after each job. | EU (Frankfurt) |
| OpenAI | Text excerpts sent for AI assistance and search indexing. The provider's API terms exclude this content from training. | United States |
| Vercel | Requests to citerra.de and the application, and their server logs. | Global edge, EU region for server rendering |
| Sentry | Error reports with personal data removed. | EU |
§ 6
How long it is kept
Citerra keeps organization data for the lifetime of the organization, plus 30 days after deletion is requested. Citerra then removes it permanently, including uploaded files and search indexes. An organization admin can cancel deletion at any point during those 30 days.
Turning AI off stops new AI processing and hides AI features. It does not delete existing conversations, generated analysis, attachments, or search indexes. An organization admin can delete that retained AI data separately while AI is off. Documents, sources, accepted edits, annotations, and operational usage records remain.
Model-request metadata contains model names, token counts, latency, and identifiers, not prompt or response text. Citerra retains it for 90 days for security, billing, and service measurement.
Citerra removes export bundles and compiled artifacts prepared for download within 24 hours.
§ 7
Your rights
- Access and portability
- An organization admin can export all organization data as a zip from the organization settings page.
- Erasure
- An organization admin can delete retained AI data while keeping the organization. The same admin can schedule deletion of all organization data, with the 30-day grace window described above.
- Everything else
- For rectification, restriction, objection, or a complaint, write to contact@citerra.de. EU residents can also contact their local supervisory authority.
§ 8
Changes to this policy
Material changes are announced on this page at least 30 days before they take effect, with the date at the top updated to match.