Privacy Policy

What we collect

  • URLs you submit for audit and the audit results derived from publicly accessible pages of that site.
  • Email address — only if you provide it to unlock a report, subscribe, or purchase.
  • Payment data — processed entirely by Stripe. We never receive or store your card number.
  • Operational data — a salted hash of your IP for rate limiting (we do not store raw IPs with audits), and standard server logs retained briefly for abuse prevention.
  • Analytics — privacy-respecting aggregate usage events (page views, tool usage). No advertising pixels, no cross-site tracking, no sale of analytics data.

How we use it

  • To run the audit you requested and deliver its report and fix files.
  • To email you the report you asked for and, if you opted in, relevant follow-ups. Every email has a working unsubscribe.
  • To prevent abuse (rate limiting, bot protection via Cloudflare Turnstile).
  • In aggregate, anonymized form for research (e.g. "X% of audited sites block GPTBot"). Aggregates never identify a specific customer's domain without permission.

Retention

  • Audit reports and generated artifacts: deleted after 90 days unless attached to a paid account.
  • Email subscription data: until you unsubscribe or request deletion.
  • Purchase records: retained as required for tax and accounting.

Sharing

We use these processors: Cloudflare (hosting, bot protection), Stripe (payments), Resend (email delivery), Anthropic (passage scoring — passages from your public pages only, no personal data), and Google PageSpeed Insights (performance checks). We do not sell personal information collected through citefuel.com.

Cloudflare Traffic Connect (optional, paid audits and Monitor subscriptions)

You may optionally connect your own Cloudflare zone so we can show real AI-crawler traffic alongside your results. Either way, you supply your Cloudflare Zone ID and a read-only API token (Zone.Analytics:Read scope) — that token can only read traffic stats, never modify your zone or account.

One-time paid audits: the token is sent directly to our worker, used once to query the Cloudflare GraphQL Analytics API, and then immediately discarded — it is never written to our database, object storage, or logs. We store only the resulting per-crawler aggregate hit counts (e.g. "GPTBot: 42 requests in the past 30 days") alongside the query time window and a fetch timestamp, keyed to your audit job.

Monitor subscriptions: because Monitor refreshes your crawler traffic every week, the token is encrypted (AES-256-GCM) and retained so we can refetch it weekly on your behalf, until you disconnect it. For this feature we store per-crawler aggregate hit counts and the top URL paths each crawler hit (up to 10 paths per bot, 50 total per week) — this powers the "top paths crawled" table in your dashboard. Disconnecting deletes your stored token and zone ID immediately; your already-recorded weekly history (hit counts and top paths) is kept as your measured trend, subject to our standard 90-day data retention.

In both cases: no individual request records or IP addresses from your Cloudflare logs are ever stored by CiteFuel.

Your rights (including CCPA)

You may request access to, correction of, or deletion of your personal information by emailing support@citefuel.com. We respond within 45 days. California residents: see also Do Not Sell or Share My Personal Information. We honor opt-out requests without penalty or degraded service.

Cookies

We set strictly functional cookies only (report-unlock state). Cloudflare sets security cookies for bot mitigation. No advertising cookies.

Contact

support@citefuel.com · CiteFuel, Florida, USA. We'll update this page as the product evolves; material changes get a dated changelog entry here.