Privacy Policy

CiteClerk LLC ("CiteClerk," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy describes what information we collect, how we use it, who we share it with, and your rights regarding your data. This policy applies to your use of citeclerk.com and all CiteClerk services.

This version replaces the policy effective June 1, 2026. The previous version described a narrower product. It has been corrected in four material respects: it now describes what CiteClerk Draft stores and for how long; it states that a Doc Check document's text is transmitted to named third-party processors even though CiteClerk does not store it; it names the .edu verification record that is retained permanently and survives account deletion; and it replaces a stale list of subprocessors with the current one. Section 16 governs how we notify you of material changes.

1. Our Core Privacy Commitment

CiteClerk is designed for legal professionals who handle privileged and confidential information. Our approach to data is minimal by design, and where it is not minimal we say so rather than leaving it out:

2. Information We Collect

2.1 Account Information

When you create an account, we collect your name and email address through our authentication provider (Clerk). Clerk also applies a bot-protection challenge (Cloudflare Turnstile) at sign-up; see Section 4.

.edu verification. If you verify a school email address to obtain Student pricing, we do not store that address. We normalize it, combine it with a secret value held only by us, and store a one-way SHA-256 hash of the result. The hash lets us recognise that the same address has been used before; it does not let us — or anyone who obtained our database — read the address back out or send mail to it. We also store the school's domain (for example example.edu) separately, in order to operate the eligibility rules.

This record is permanent. It is retained indefinitely and is deliberately kept when the account it belongs to is deleted. It exists to enforce one rule — a school email may claim Student pricing on one account, once — and that rule would not survive its own deletion. It is the single documented exception to the deletion commitments in Sections 5 and 7. Because it is a one-way hash and not an address, retaining it is more protective than retaining the address would be.

Eligibility. Student tier eligibility is limited to registered students at ABA-accredited law schools and ends when you cease to be enrolled. We do not currently run an automatic clock that ends Student pricing after a fixed number of years.

Referrals show your name to one other person. If you sign up using someone's referral code, we show them your first name and last initial (for example, Jeremy P.) on their Referrals panel — from the moment you sign up with their code, not only once the bonus is earned. You see their name in the same form once the referral settles. We never show your email address, your full surname, or a profile picture to the other person, and if your account has no first name on file, nothing about you is shown at all.

Please bear in mind that referral codes are meant to be shared and can be forwarded on. If you sign up with a code that reached you second-hand, the person who created that code will see your first name and last initial, even if you do not know them. If you would rather not be shown, do not sign up using a referral code — nothing else in CiteClerk discloses your name to another user.

2.2 Payment Information

Subscriptions are sold and billed through Clerk, and card processing is handled by Stripe. CiteClerk does not collect, store, or have access to your credit card number, bank account details, or other sensitive payment information. We receive only a payment confirmation, subscription status, and the amounts and credits on your invoice.

2.3 Usage Data

We collect data about how you use CiteClerk, including:

2.4 Technical Data

We automatically collect standard technical information including IP address, browser type, device type, and referring URLs. This data is used for security, abuse prevention, and service improvement.

Analytics on our public pages. Our marketing pages — the pages you can read without an account — send a message to an analytics service each time one is viewed, recording which page was viewed, which page referred you, how far you scrolled and how long you stayed, together with the IP address and browser type that any web request carries. It sets no cookie and stores nothing on your device, so it cannot follow you to any other website, and we use it only to understand which pages people find useful. The signed-in application does not do this: the pages you work on once you have an account are not sent to any analytics service. The service is named in Section 4.

Device recognition on the free Clark widget. When you use the free Clark widget on our homepage without signing in, your browser computes a short identifier describing the device you are using. It is derived from characteristics your browser exposes — how your device renders graphics and audio, which typefaces are installed, and your screen dimensions — and it is computed entirely on your own device by an open-source library that runs as part of our own page. Nothing is sent to that library's authors or to any other third party; the identifier is sent only to us. We use it for one purpose: to recognise the same device across visits so that the single free question is granted once per device rather than once per browser session, and so that the cost of running the widget stays bounded. We store only a salted one-way hash of that identifier, alongside a salted one-way hash of your IP address — never the values themselves. It is not used for advertising, is not combined with your account, and is not shared with anyone. If your browser declines to provide these characteristics, the widget still works.

2.5 Content You Give Us, Product by Product

What happens to the material you put into CiteClerk depends entirely on which product you put it into. The three are not the same and should not be assumed to be.

Doc Check — stored: nothing

We do not store the contents of a document you check. It is not written to our database, not added to your History, not logged, and not retained after the check completes. We cannot later produce, export, or disclose it, because we do not have it.

We do transmit it in order to check it. A check is not a local operation. During a run, the following leaves our servers:

If that transmission is not acceptable for a particular document, do not run Doc Check on it. We would rather tell you plainly than describe the feature as purely local when it is not.

CiteClerk Draft — stored: your matter, your sources, and your brief

CiteClerk Draft is a persistent drafting workspace and it stores your work so that it survives closing the tab. For each matter we store: the matter name and the case theory you give it; the argument profile and outline; the sources you upload (their extracted text, and passages of that text with search embeddings computed from them); the original files of record documents such as exhibits, declarations and transcripts, held in object storage; the text of the brief itself, saved continuously as you write; labelled snapshots of the brief taken at named points such as a save or a draft run, so you can look back and restore; your conversation with the drafting assistant; verification and grounding results per sentence; comments; and the notes you keep about a judge, which are kept per user and carry across your matters.

Confidential fields are encrypted at rest under a key unique to that matter. Deleting a matter deletes every row belonging to it, destroys that matter's encryption key — which makes any residual ciphertext unrecoverable — and queues the matter's stored files for deletion from object storage. Section 5 states the retention periods.

Drafting sends content to AI providers: the sources you upload, the passages retrieved from them, the text being drafted or edited, and your instructions to the assistant are sent to Anthropic, Google, and OpenAI as part of generating and checking the draft. Uploaded source text is also sent to Google to compute the search embeddings that make retrieval work. Scanned documents that need OCR are sent to Amazon Textract as page images. None of these providers may train on it.

CiteClerk Citations and CiteClerk Research — stored: your queries and results

Citations you generate and the queries you run are stored to power your History and your saved work, and are described in Section 2.3. Query text is sent to AI providers for processing and to CourtListener and other legal databases for lookup.

2.6 What We Do Not Collect

The previous version of this policy stated that we do not collect "the full text of briefs, motions, or any other legal documents you submit." That was true of Doc Check, which was the whole product when it was written, and it is not true of CiteClerk Draft, which stores the brief you write in it. The sentence has been removed and replaced with Section 2.5.

3. How We Use Your Information

We use the information we collect to:

We may also use anonymized and aggregated data — data that has been de-identified so that it does not identify you and cannot reasonably be used to identify you — for analytics, product improvement, and understanding how CiteClerk is used. This does not include the content of documents you upload, which is discarded after processing, and we do not use your document content or citation search history to train AI models.

We do not use your data for advertising or sell it to data brokers.

4. Subprocessors — Third Parties We Share Data With

CiteClerk uses the following third-party service providers to operate the service. Each receives only the data necessary for their specific function. This list is maintained against the code, not from memory.

4.1 Identity, Billing, and Infrastructure

Clerk (clerk.com): Authentication, user account management, and subscription and billing management. Processes your name, email address, session data, and subscription state.

Cloudflare (cloudflare.com): Bot protection, in two places. Clerk's hosted sign-up flow presents a Cloudflare Turnstile challenge to anyone attempting to sign up. CiteClerk also uses Turnstile to protect the free Clark widget on our homepage against automated abuse, and verifies challenge results with Cloudflare directly from our own servers. Whenever a Turnstile challenge runs in your browser, Cloudflare receives your IP address and browser characteristics; it receives no account information, no document content, and no citation or search query in either case.

Plausible Analytics (plausible.io): Website analytics for our public marketing pages. Your browser loads a small script from plausible.io and sends it one message per page you view: the address of the page, the address of the page that referred you, and counts describing how far you scrolled and how long you stayed. As with any request your browser makes, Plausible also receives your IP address and browser type. It sets no cookie, stores nothing on your device, and receives no account information, no document content, and no citation or search query. It does not run on the signed-in application — see Section 2.4.

Stripe (stripe.com): Payment processing, behind Clerk's billing. Processes your payment information directly. CiteClerk does not receive or store your payment credentials.

Fly.io (fly.io): Application hosting. Every CiteClerk application runs on Fly.io, which processes request metadata in connection with serving the application. CiteClerk previously ran on Vercel; it no longer does, and Vercel is no longer a subprocessor.

Neon (neon.tech): Database hosting. Stores your account data, citation and research history, usage and metering records, referral records, the .edu verification hash, and all CiteClerk Draft matter content.

Redis (Redis Ltd., redis.io): Caching, rate limiting, and usage counters. Holds cached citation results for seven days and short-lived counters. This service was previously described as "Vercel KV"; that was inaccurate.

Amazon Web Services (aws.amazon.com): Two functions in CiteClerk Draft. Amazon S3 stores the original files of record documents you upload to a matter — exhibits, declarations, pleadings, transcripts — encrypted at rest. Amazon Textract performs optical character recognition on scanned documents; page images of those documents are sent to Textract to be read.

Resend (resend.com): Outbound email. Receives the recipient address and the contents of any message CiteClerk sends you, such as a verification code.

ntfy (ntfy.sh): Operational alerting. Receives error notifications and failed-job notices from our servers so that faults are noticed. These carry error text, the failing endpoint, and internal identifiers such as a matter's numeric id. They are not intended to carry, and are not used to carry, your document content or account details. ntfy is a message broker and delivers to a topic address; CiteClerk's topic is a high-entropy name that is not published or guessable.

Content delivery: our own origin, with two named exceptions. Our pages previously loaded typefaces from Google Fonts (fonts.googleapis.com and fonts.gstatic.com) and the authentication script from jsDelivr (jsdelivr.com), which gave both networks the IP address and browser type of every visitor to every page, including this one. Neither is used any more. Every typeface, stylesheet, image and script that makes up this site is served from CiteClerk's own origin, with exactly two exceptions, both named in this section: the authentication script, which is served by Clerk and which your browser contacts in order to sign you in regardless, and the analytics script described in Section 2.4, which runs on our public marketing pages only. No other third party receives a request from your browser on any page of this site, and no typeface, stylesheet or image is loaded from a third-party content delivery network.

4.2 AI Providers

These providers receive the content described in Section 2.5. All three receive it through paid commercial API tiers, and all three of those tiers are governed by terms that do not permit the provider to use data submitted through the API to train or improve its models. Every processor that receives the content of a document you check is on this footing. Until August 2026 one was not — see the note at the end of Section 4.3.

Google (Gemini API): The primary citation extractor for Doc Check — the text of a document you check is sent to Google. Also computes the search embeddings for sources you upload to CiteClerk Draft, and is used for generation in CiteClerk Draft. CiteClerk uses Gemini's paid tier, under which Google states that submitted prompts and responses are not used to improve its products. Google's free Gemini tier carries different data-use terms; CiteClerk does not use it.

Anthropic (anthropic.com): The primary provider for CiteClerk Research and for drafting and reviewing in CiteClerk Draft. Also a fallback citation extractor for Doc Check, which means it may receive the text of a document you check.

OpenAI (openai.com): A fallback provider for citation formatting, for Doc Check extraction, and for CiteClerk Draft. It may receive the text of a document you check.

The previous version of this policy said that document content from Doc Check is never sent to OpenAI, and applied the same limitation to Google and Anthropic. That was not correct. Extracting the citations from a document requires reading the document, and that reading is done by these providers. The statement has been removed.

4.3 Content and Legal Data Services

Free Law Project / CourtListener (courtlistener.com): Legal case database used for citation lookup and verification. Citation query strings (case names, reporter citations) may be sent to CourtListener's API. Document text, account information, and personal data are never sent to CourtListener.

Crawlbase (crawlbase.com): Headless browser service used as a fallback for webpage content extraction in the Webpage citation and Doc Check features. URLs submitted for webpage citation may be processed by Crawlbase. Document text is not sent to Crawlbase.

Public legal sources: To retrieve the text of statutes, regulations and legislative materials we query public government and academic sources, including govinfo.gov, the Congress.gov API, the U.S. House Office of the Law Revision Counsel, the Electronic Code of Federal Regulations, the Cornell Legal Information Institute, and state legislature websites. These receive a citation or a URL and nothing about you.

Until August 2026, Doc Check included a spelling and grammar check that sent the prose of a document you checked — up to roughly 228,000 characters per check, with citation spans masked but your argument, your facts and any party or client names outside a citation sent as written — to LanguageTool's free, public API endpoint, with which CiteClerk had no account, no API key and no data-processing agreement. It was the only processor on this page that received your content under no agreement at all. That feature has been removed from the product and LanguageTool is no longer a subprocessor. Nothing is sent to it.

4.4 Not Subprocessors

We use GPU compute (RunPod) to prepare search indexes over published statutory text. That is public law, not your data: no personal information, document content, or account data is sent to it, and it is therefore not listed above.

We do not share your data with any other third parties except as required by law. We do not share your contact information with partners for their own marketing. If we ever offer to, it will be on a separate opt-in you are asked for specifically, and this policy will be updated to describe it before it happens.

Data Processing Addendum: Business customers, including law firms and institutions, may request a Data Processing Addendum (DPA) governing CiteClerk's processing of personal data on their behalf. Contact legal@citeclerk.com to request a DPA.

5. Data Retention

Uploaded documents (Doc Check): Zero retention. Not written to our database, not logged, not retained after the check completes. Where the optional high-fidelity view is used, the file is written to a temporary working directory on our conversion machine for the duration of the conversion and deleted immediately afterwards; nothing persists.

CiteClerk Draft matters: Retained until you delete the matter or close your account. This includes the matter and its case theory, the argument profile and outline, uploaded sources and their extracted text, the text passages and search embeddings computed from them, the text of your brief, the labelled version snapshots of it, your conversation with the drafting assistant, verification and grounding results, comments, and chronology and exhibit metadata. Nothing here is deleted on a timer; a draft you leave alone stays where you left it.

CiteClerk Draft exhibit and record files: The original uploaded files are retained in object storage for as long as the matter exists. Deleting the matter or the source queues the file for deletion from storage.

Deleting a matter: Deletes every row belonging to it, destroys the encryption key unique to that matter — which renders any residual ciphertext unrecoverable — and queues its stored files for deletion. This is immediate and it is not reversible; there is no undelete and no recycle bin.

Judge notes: Kept per user rather than per matter, and retained until you delete them or close your account. Deleting a matter does not delete them.

Generated citations, research history, and saved work: Retained until you delete them or close your account.

Usage, metering, referral and pack records: Retained while your account is active, and for the period necessary to answer billing questions and to enforce lifetime caps.

Cached citation results: Held for 7 days, then automatically deleted. Results generated during a Doc Check run are never cached.

Account data: Retained while your account is active and for 30 days after account deletion, then permanently deleted.

.edu verification record — the one permanent exception: The one-way hash of a verified school email address, and its domain, are retained indefinitely and are not deleted when your account is deleted. Section 2.1 explains what the record is and why it cannot be removed: it exists so that one school address cannot claim Student pricing twice, and deleting it on request would defeat the only rule it serves. It contains no email address and cannot be reversed into one. Every other deletion commitment in this policy is subject to this exception, and this is the only exception.

Payment records: Retained for 7 years as required by law. Managed by our payment processor.

Subscription consent records: Records of your consent to automatic renewal terms are retained for 3 years, or 1 year after your subscription terminates, whichever is longer, as required by applicable subscription law.

Usage and analytics data: Retained for 12 months in aggregate, anonymized form.

Technical logs: Retained for 90 days for security and debugging purposes.

6. Data Security

We implement security measures designed to protect your information, including:

However, no system is completely secure. We cannot guarantee absolute security of your data.

If we become aware of a data breach that affects your personal information, we will notify you without undue delay and within the timeframe required by applicable law.

7. Your Rights

You have the following rights regarding your personal data:

Access: You may request a copy of the personal data we hold about you.

Deletion: You may request deletion of your account and associated personal data. Upon requesting deletion, your account is deactivated immediately. Citation history, CiteClerk Draft matters and their contents, and other personal data are permanently purged within 30 days. One item is excepted and is not deleted: the .edu verification hash described in Sections 2.1 and 5. We state this rather than describing the purge as complete, because it is not.

Correction: You may update your account information through account settings.

Export: You may request an export of your citation history.

Communications and opt-out: We send two kinds of email, and they are treated differently.

Partner marketing: We do not share your contact information with partners for their own marketing, so there is nothing to opt out of. If we ever offer this, it will require your separate, affirmative opt-in and this policy will be updated first.

To exercise any of these rights, contact us at legal@citeclerk.com.

8. California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete personal information, and the right to non-discrimination for exercising your privacy rights. CiteClerk does not sell personal information, and does not share personal information for cross-context behavioural advertising. We do not disclose your contact information to third parties for those parties' own marketing purposes. Because we neither sell nor share personal information as those terms are defined by the CCPA, there is no "Do Not Sell or Share My Personal Information" opt-out to exercise; if that ever changes, we will provide the opt-out and update this policy before the change takes effect. Your right to delete is subject to the single exception stated in Sections 2.1, 5 and 7. To exercise your CCPA rights, contact us at legal@citeclerk.com.

9. Do Not Track

CiteClerk does not respond to browser Do Not Track signals. We do not engage in cross-site tracking, behavioral advertising, or the tracking behaviors those signals are designed to prevent. Our data collection is limited to what is described in this policy.

10. International Users

CiteClerk is operated from the United States. If you access CiteClerk from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country. By using CiteClerk, you consent to this transfer and processing.

11. European and UK Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, the following applies. CiteClerk LLC acts as the data controller for personal data processed through the service. We process your personal data on the following lawful bases: performance of our contract with you (to provide the service), our legitimate interests (to operate, secure, and improve the service), your consent (where applicable), and compliance with legal obligations.

You have the right to access, correct, delete, restrict, or object to the processing of your personal data, and the right to data portability. You also have the right to lodge a complaint with your local data protection authority. To exercise these rights, contact legal@citeclerk.com. Because CiteClerk processes data in the United States, international transfers are made in reliance on appropriate safeguards where required. Business customers requiring Standard Contractual Clauses may request them at legal@citeclerk.com.

12. Business Transfers

If CiteClerk LLC is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. We will require any successor to honor the commitments in this Privacy Policy, and we will notify you of any change in ownership or use of your personal data.

13. Government and Law Enforcement Requests

CiteClerk may disclose your information if required to do so by law, subpoena, court order, or other valid legal process. Where we are legally permitted to do so, we will make reasonable efforts to notify you before disclosing your information in response to such a request, so that you may seek to protect your rights. We may be prohibited from notifying you in certain circumstances, such as when a court order or law forbids it.

14. Children's Privacy

CiteClerk is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.

15. Cookies

CiteClerk uses essential cookies and local storage necessary for authentication and session management. We do not use advertising cookies or third-party tracking cookies. You may disable cookies in your browser settings, but doing so may prevent you from logging in.

16. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a prominent notice in the application at least 14 days before changes take effect. The effective date at the top of this policy reflects the date of the most recent update.

17. Contact Us

For privacy questions, data requests, or concerns, contact us at:

CiteClerk LLC

Email: legal@citeclerk.com

Website: https://citeclerk.com

CiteClerk LLC | https://citeclerk.com | Effective August 15, 2026