Skip to content
Cite Files

Privacy

Short version: we store the sites you scan and, if you make an account, your email address. We do not sell anything to anybody, we do not run advertising trackers, and nothing you scan leaves our own servers.

If you scan without an account

We store the address you entered, everything the scan measured, and your IP address. The IP is used for rate limiting — it is what stops one person running thousands of scans — and is not used to profile you.

We also set one cookie holding a random identifier. Its only job is to let you claim a scan you started before signing up. It is not shared with anyone and it does not follow you to other sites.

If you make an account

We store your email address, your name if you gave one, and your password as a bcrypt hash — we cannot read your password and neither can anyone who steals the database. Sessions are stored as hashes of a random token in a cookie that is HTTP-only and same-site.

Your email is used for account matters only: confirming the address, resetting the password, and telling you if someone tries to register with it. There is no newsletter and no marketing email.

What we store about the sites you scan

Page titles, meta descriptions, headings, word counts, structured-data types, HTTP status codes, response headers relevant to crawling, and a text excerpt from each page we read. The excerpt is what lets us generate your llms.txt and run the answerability test.

We do not keep complete copies of pages, and we do not republish or resell anything we read. If you scan a site you do not own, be aware you are asking us to fetch its public pages on your behalf.

Passwords for staging sites

If you give us a username and password so we can reach a site behind HTTP basic auth, that credential is never written to our database. Not encrypted, not hashed — there is no column for it, so no future query can leak one. It is never written to a log either. It exists in the memory of the process running your scan, for thirty minutes, and then it is gone.

It is sent only to the site you entered. If that site redirects somewhere else, the credential is dropped rather than followed, so an open redirect cannot be used to collect it. The browser-based checks receive it scoped to that one origin, so it is never attached to a font, script or analytics request the page makes to somebody else. The performance audit is the one check that cannot scope a credential that way, so on a password-protected site we skip it and tell you we did.

The trade-off is that a restart loses it and you would enter it again. That is deliberate. Keeping your staging password alive across our deploys would be trading your security for our convenience.

The free tools

The single-purpose tools keep little. We keep a count of how many times each tool was run each day. To enforce the hourly limit, your IP address is held in a rate-limit counter that is deleted within two days. The address you test, the text you paste and the result are not stored.

A tool that fetches a site requests only what its own page says, as CiteFilesBot, and follows redirects only within the same site.

Language models

The models that write your report run on our own hardware. Your scan data is not sent to OpenAI, Anthropic, Google or any other model provider, and nothing you scan is used to train anything.

How long we keep it

Scans not attached to an account are deleted after 90 days. Scans in an account stay until you delete them or close the account. The rate-limit counter a free tool keeps for your IP address is deleted within two days; other rate-limit counters are deleted 30 days after their window opened. Ask us to delete your account and everything in it goes with it.

Who we share it with

Nobody, other than the service that delivers our email (Resend), which necessarily sees the address a message is sent to. There are no analytics scripts, no advertising pixels and no third-party embeds on this site.

Your rights

You can delete your own account, immediately, from your account page — the button removes your scans, reports, watches, batches, badges and feedback along with it, and cannot be undone. You can also ask for a copy of what we hold about you or ask us to correct it. If you cannot sign in, or you would rather we handled it, write to [email protected] and we will act within 30 days. Security reports go to [email protected].

Last reviewed . Maintained by Cite Files — corrections to [email protected].