Legal
Privacy Policy
Last updated: July 27, 2026
This policy covers Citelink’s website, verification tool, browser extension, and newsletter. It describes what we collect, why, who else sees it, and how to reach us about it.
Who operates Citelink
Citelink is operated by Hollow Prism LLC (“Citelink,” “we,” “us”). For anything in this policy, contact citelink.news@protonmail.com or use /contact.
Information we collect
Account data. If you sign in with Google, we receive your email address, name, profile image, and Google account ID. GitHub sign-in is reserved for internal editors and administrators and returns the same categories from GitHub. We store your email, display name, avatar URL, account role, and account timestamps, plus the OAuth tokens needed to keep the session active.
Verification submissions. The claim, URL, or social post text you submit to the verify tool, the report we generate from it, and the confidence and evidence data behind that report. Submissions are linked to your account.
Saved reports. Notes you attach to a saved verification report.
Newsletter signups. The email address you submit to subscribe. Nothing else you send with that request is stored.
Outbound link clicks. When you click a source or evidence link from an article or report, we record the destination URL with its query string and fragment removed, which article or verification it came from, and a category label. This record is not linked to your account or to any identifier that would let us tie it back to you.
Operational logs. Our logging layer only accepts primitive values (no request bodies, headers, or stack traces) and strips fields like tokens, secrets, and passwords before anything is written, so operational logs carry route names, status codes, and error codes rather than personal data. The verify endpoint requires an account and is rate-limited per account rather than by network address. Endpoints that take no account fall back to limiting by IP address; where that happens the address is held in server memory only for as long as the limit window lasts and is never written to a database.
Verification submissions and Google
When you submit a claim, URL, or post, the text is sent to Google’s Vertex AI and Discovery Engine services to search our curated evidence corpus, fall back to open web search when the corpus has nothing on the subject, and check whether a candidate answer is actually supported by the sources returned. This means the text you submit leaves Citelink’s infrastructure and is processed by Google as part of generating your report.
The verify tool requires an account and is capped at 25 verification requests per account per rolling 24-hour period, with a site-wide cap of 500 requests per day across all accounts. Requests are also short-window rate-limited per account. These caps exist to control the cost of the Google services above and to prevent abuse; they are enforced automatically and a request that exceeds either cap is rejected, not queued.
Browser extension
The extension identifies itself to our API with a custom header and a chrome-extension:// origin. The reachability check it uses to confirm the API is available returns no personal data. Verification requests made from the extension use the same authenticated session as the website and are covered by the “Verification submissions” and rate-limit terms above.
Who we share data with
- Supabase hosts our Postgres database. Every table described above lives there.
- Vercel hosts and serves the application.
- Google Cloud (Vertex AI / Discovery Engine) receives verification submission text to ground and search claims, as described above.
- Google (sign-in) provides Google OAuth for account sign-in.
- GitHub provides OAuth sign-in for internal editors and administrators.
- Google AdSense serves ads on the site where configured. AdSense can set its own cookies and identifiers to select and measure ads; we do not control what Google does with that data beyond the standard AdSense terms.
- Amazon Associates receives an affiliate tag appended to outbound Amazon product links, which tells Amazon the click came through Citelink’s affiliate account. No account or personal data is sent with that tag.
We do not sell personal data.
Cookies
Strictly necessary. A session cookie keeps you signed in, for a 30-day session backed by our database, along with the cookies that protect the sign-in form against cross-site request forgery. Citelink does not function without these; they are not optional and are not subject to ad-consent controls.
Advertising. Where Google AdSense is enabled, its script can set advertising and measurement cookies to select and frequency-cap ads. These are set by Google, not by Citelink’s own code.
Data retention
Citelink does not run an automated retention schedule: records are kept until you delete your account or ask us to remove them.
Deleting your account. You can do this yourself at any time from Settings, by typing your account email to confirm. It immediately and permanently removes your profile, your linked sign-in connections, your active sessions, and your saved reports. Two things are not deleted: verification requests you submitted, and any articles you authored. Both remain, but are detached from your identity in the same operation, so nothing about them continues to reference your account. This cannot be undone and there is no recovery window.
Newsletter. You can unsubscribe at any time. Each message links to a private per-recipient page; opening it and clicking to confirm removes your address immediately. The confirmation is a separate deliberate step, so a link scanner or email preview cannot unsubscribe you by fetching the link. You can also email citelink.news@protonmail.com and we will remove the entry by hand.
Your rights
Under the GDPR and similar frameworks, you can ask us to access, correct, delete, restrict, or export your personal data, and you can object to processing based on our legitimate interests. We process account data to provide the service (contract necessity), verification and click data to run and improve the product and prevent abuse (legitimate interest), and newsletter email to send the briefing you asked for (consent, given at signup).
Under the CCPA/CPRA (California), you can ask what personal information we hold, request deletion, and request correction. Citelink does not sell personal information. Ads served through Google AdSense may count as “sharing” personal information for cross-context behavioral advertising under the CPRA; we do not currently have an in-product “Do Not Sell or Share” toggle, so to opt out of AdSense personalization use Google’s own Ads Settings or contact us and we will action the request manually.
Deletion and newsletter unsubscribe are self-service — see “Data retention” above. For anything else on this list, including access, correction, export and objection, email citelink.news@protonmail.com. Those are handled by hand and we will confirm with you once complete.
International data transfers
Supabase, Vercel, and Google operate infrastructure in the United States and may process or store data there and in other countries where they run infrastructure. By using Citelink you understand your data may be processed outside your own country.
Children's privacy
Citelink is not directed at children and we do not knowingly collect personal data from anyone under 13. If you believe a child has provided us data, contact citelink.news@protonmail.com and we will remove it.
Changes to this policy
We update this page when our data practices change and update the date at the top when we do. Continued use of Citelink after a change means you accept the revised policy.