Privacy Policy for Citely

Effective date: August 11, 2026

Citely is a research literature platform that helps researchers verify references and trace citations. This policy explains what information Citely processes when you use the website, developer API, hosted MCP server, or Codex plugin.

Information We Process

  1. Account information. We process your email address, name or nickname, profile image, login provider, account identifiers, locale, and verification status to create and secure your account.
  2. Citation-check content. We process the individual citation strings that you choose to submit, any metadata extracted from them, and the resulting matches or technical errors. The Codex plugin is designed to split references locally, preview them, and ask for confirmation before sending the selected citation strings. It does not need to send the rest of your manuscript.
  3. API and authentication data. We process API-key identifiers, OAuth token claims, scopes, task identifiers, idempotency keys, request counts, and security logs to authenticate requests, prevent abuse, and operate the service. Keep API keys confidential. Citely does not need your OpenAI password.
  4. Usage, support, and device data. We may process feature usage, customer-support messages, timestamps, IP address, browser or device information, cookies, and diagnostics to provide support, protect the service, and improve reliability.
  5. Billing records. Our payment providers process payment-card details. Citely receives transaction, order, and Credit-balance information needed to operate billing; we do not need to store full card details ourselves.

How Citation Verification Works

Citely may send citation-derived titles, identifiers, authors, years, or search queries to scholarly data sources and service providers used by the verification pipeline. These may include Crossref, OpenAlex, Google Scholar search results accessed through a search service provider, Wanfang, Metaso, and other research metadata services. The exact sources used can vary by language, availability, and the information present in a citation.

We use this information to locate candidate publications, compare metadata, return evidence, calculate Credits, diagnose technical failures, and prevent duplicate processing. A not_found result means that no reliable match was found in the sources checked; it is not proof that a citation is fabricated.

Storage and Retention

Citation tasks and results may be stored in your Citely history so that you can retrieve them from the API or website. Account, billing, security, and operational records are retained for as long as reasonably necessary to provide the service, meet legal obligations, prevent fraud, and resolve disputes. You may ask us to delete eligible account data by contacting us. Some records may be retained where required by law or necessary for security and financial reconciliation.

Sharing and Service Providers

We do not sell your personal information. We share information only when reasonably necessary:

Third-party providers process information under their own terms and privacy practices. Citation strings or citation-derived queries should not contain confidential manuscript text or personal information that is unnecessary for verification.

Customer Support Chat

Citely uses Crisp to provide customer-support chat. When you use the chat, Crisp may process your messages, IP address, browser information, cookies and, if you are signed in, your email address, nickname, and Citely user identifier. Do not send confidential manuscript content, passwords, API keys, or payment information in support messages.

Security and Your Choices

We use access controls, transport encryption, monitoring, and other safeguards appropriate to the service. No online system is completely secure. You are responsible for protecting API keys and account credentials and should revoke a key if it may have been exposed.

You may access or correct profile information through your account, revoke API keys in the API Keys console, and contact us to request access to or deletion of eligible personal data. Browser controls can be used to manage cookies where applicable.

International Processing and Children

Citely and its providers may process data in countries other than your own. Citely is intended for researchers and students who are legally able to use the service and is not directed to children under the minimum age required by applicable law.

Changes to This Policy

We may update this policy as Citely evolves. We will post the revised policy here and update the effective date. Material changes may also be communicated through the service when appropriate.

Contact Us

Questions, privacy requests, and security concerns can be sent to [email protected].

Service operator: Citely / citely.ai