Your data.
We store the minimum needed to run an audit and keep its report link working: a URL, an email, a hash of your IP, and the public facts and engine answers that make up the report. No analytics, no advertising, no cookies of our own.
Who is responsible
The data controller is Lundra AB, Sollentuna, Sweden (organisation number 559302-7716). Contact for anything in this notice: the contact form (topic "Privacy request") or by email to privacy [at] citeshare.ai. We are not required to appoint a data protection officer and have not done so; privacy requests are handled by the company directly.
What we collect, why, and on what legal basis
| Data | From | Why | Legal basis (GDPR art. 6) | Kept for |
|---|---|---|---|---|
| Website URL and domain | You | To run the audit and identify the report | Contract, art. 6(1)(b) | With the audit record |
| Email address | You | Report link, failure/refund notice, answering you | Contract, art. 6(1)(b) | With the audit record |
| Hash of your IP address | Your connection | Per-network daily limit and abuse prevention. SHA-256 of the IPv4 address or IPv6 /64 prefix; the address itself is not stored and the hash cannot be reversed | Legitimate interest, art. 6(1)(f) — protecting a metered service from automated abuse | With the audit record |
| Facts crawled from the audited public site | The public site | Identify the product, write the buyer questions, build the fixes pack | Contract, art. 6(1)(b) | With the audit record |
| Generated questions, engine answers, cited links | Our systems and the engine providers | They are the report | Contract, art. 6(1)(b) | With the audit record |
| Payment record | Stripe | Stripe session and payment ids, amount, currency, refund status — to match a payment to an audit, refund a failed audit, and keep the books | Contract, art. 6(1)(b); legal obligation, art. 6(1)(c) (Swedish Bookkeeping Act) | 7 years after the financial year |
| Messages you send us | You, through the contact form or by email | To answer you. Form submissions are emailed to us and not stored anywhere else | Legitimate interest, art. 6(1)(f) | Deleted within 12 months of the matter closing |
| Turnstile signals | Your browser, via Cloudflare | Telling people from bots on the snapshot form | Legitimate interest, art. 6(1)(f) | Not stored by us |
| Request logs | Your connection | Security and troubleshooting at our hosting provider | Legitimate interest, art. 6(1)(f) | Short rolling window at Cloudflare; no copy kept by us |
We do not collect anything else. We run no analytics, advertising or tracking scripts and set no cookies of our own. Cloudflare Turnstile may store a challenge token in your browser for the form; Stripe's checkout page (on stripe.com) uses its own cookies under Stripe's notice.
Providing the URL and email is necessary to run an audit; without them there is nothing to deliver. We make no decisions about you by automated means that have legal or similarly significant effects.
Who receives data
We use these processors and independent services. None of them may use your data for their own purposes except where stated.
| Recipient | Role | What they get | Location and safeguard |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, database, background jobs, bot check (Turnstile), inbound email routing | Everything we store; request logs; Turnstile signals | EU/US; EU-US Data Privacy Framework and EU standard contractual clauses |
| Stripe | Payment (Stripe Technology Europe, Ltd / Stripe Payments Company, and Link). For the payment transaction Stripe/Link is the merchant of record and an independent controller | Your payment details, email, billing country; the audit id and domain as order metadata | EU/US; Stripe's own privacy notice governs the payment |
| Resend, Inc. | Sends our transactional emails | Your email address, the report link and the figures in the email | US; EU-US Data Privacy Framework / standard contractual clauses |
| OpenAI; OpenCode (Zen) | Language models that identify the product and write the buyer questions and the fixes pack | Facts crawled from the public audited site; no personal data about you | US; standard contractual clauses |
| OpenAI, Anthropic (via OpenRouter), Google, xAI, Perplexity (via OpenRouter) | The AI engines we query | Only the generated buyer questions, which never name you or your email | US; standard contractual clauses |
We do not sell or share personal data for advertising. We disclose data to authorities only where the law requires it.
Where data is processed
Our infrastructure runs on Cloudflare's global network; data is stored in Cloudflare's database service and may be processed in the EU and the United States. Transfers outside the EU/EEA rely on the EU-US Data Privacy Framework where the recipient is certified and otherwise on the European Commission's standard contractual clauses.
How long we keep it
- Audit records (URL, email, IP hash, crawled facts, questions, answers, fixes pack) are kept so that the report link keeps working, until you ask us to delete them. Deleting the record removes everything above at once.
- Payment records are kept 7 years after the end of the financial year, as Swedish bookkeeping law requires. Only the ids, amount, currency and refund status are kept by us; card data is held by Stripe.
- Support email is deleted within 12 months of the matter closing.
Your rights
You can ask us at any time to: access the personal data we hold about you; correct it; delete it; restrict or object to its processing; and receive the data you gave us in a portable form. Where we rely on legitimate interest you may object on grounds relating to your particular situation.
To exercise a right, use the contact form with topic "Privacy request" and the email address you gave for the audit (that is how we verify it is you), including the report link; or write to the address in section 01 from that same address. We answer within one month. Deletion requests that reach us through Stripe for a Managed Payments purchase are honoured the same way.
You also have the right to complain to a supervisory authority. Ours is the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), Box 8114, SE-104 20 Stockholm, www.imy.se. You may complain to the authority in the EU/EEA country where you live instead.
Security
All traffic is encrypted in transit (TLS). Secrets are held in the hosting provider's secret store, never in code or pages. We store the minimum: no card data, no raw IP addresses, no passwords (there are no accounts). Report links are long random tokens; they are unlisted rather than access-controlled, so anyone with a link can view that report — the report shows the audited domain and public data, never your email.
Children
The service is for adults and businesses. We do not knowingly process data of anyone under 18; if you believe we have, email us and we will delete it.
Changes to this notice
Each version carries a number and effective date at the top. Material changes are announced on the site; the current version is always at citeshare.ai/privacy.
Version history
- 1.2 (2026-09-13) — contact form as the primary route for privacy requests.
- 1.1 (2026-09-13) — privacy contact moved to a dedicated privacy mailbox; no individual named.
- 1.0 (2026-09-13) — first version. Replaces the privacy section of the combined terms page published earlier the same day.