The whole policy in five bullets.
- Signed in, we set one cookie:
citesvue_session. It is what keeps you authenticated, so it cannot be switched off. - On the marketing site we run Google Analytics 4 through Google Tag Manager. Its cookies are set only after you accept analytics in the banner.
- Before you choose, and if you decline, analytics storage stays denied: no
_gacookie and no advertising identifier. Google's tag manager script itself still loads, and Google receives a cookieless, aggregated signal. - We load no advertising or retargeting trackers: no Google Ads, Meta Pixel, LinkedIn Insight, or TikTok Pixel, on any page.
- Your banner choice lives in local storage, not a cookie, and the footer link reopens it at any time.
Small text files, similar tech, same purpose.
A cookie is a small text file a site stores in your browser. We also use closely related technologies - local storage, session storage, and pixels (1×1 transparent images) - for the same purposes described here. Throughout this page, “cookies” means cookies and these similar technologies.
Cookies are either first-party (set by Citesvue) or third-party (set by another domain loaded by the page). They are session cookies (deleted when the browser closes) or persistent cookies (stay until the expiry date or until you delete them).
The full list, by category.
One cookie, plus browser storage that never leaves your device.
1. Strictly necessary
Required for the application to function. It cannot be disabled: without it the app cannot authenticate you. This is exempt from consent requirements under GDPR (Recital 32 / ePrivacy Article 5(3) “strictly necessary” exemption).
| Cookie | Set by | Purpose | Expiry |
|---|---|---|---|
| citesvue_session | Citesvue | Signed session token. Authenticates every request to the API; without it you cannot stay signed in | Session |
2. Local storage in the app
The application keeps some state in your browser rather than in cookies. It is never sent to a third party, and clearing site data removes it. Signing out clears the session keys.
| Key | Set by | Purpose | Retention |
|---|---|---|---|
| citesvue_jwt / citesvue_user | Citesvue | Keeps you signed in across page loads and renders your name and workspace without a round trip | Until sign-out |
| citesvue.processing-* / citesvue.ready-* | Citesvue | Tracks uploads and processing jobs so progress survives navigation, scoped to your account | Until dismissed |
| citesvue-google-connect / -oauth | Citesvue | Short-lived state for the Google Drive and Calendar connection flow | Minutes |
3. Analytics inside the app
None today. The authenticated product runs no analytics or session-replay tooling. If that changes, this page changes with it and the banner asks again.
Google Analytics, and only after you say yes.
The marketing site loads Google Tag Manager, and inside that container a single Google Analytics 4 tag. Analytics storage is set to denied before the container loads, so the cookies below appear only once you accept analytics in the banner. Decline, and Google still receives a cookieless, aggregated signal from the tag, which is how visit estimates are modelled without identifying you.
| Cookie | Set by | Purpose | Expiry |
|---|---|---|---|
| _ga | Google Analytics 4, loaded via Google Tag Manager | Distinguishes one browser from another so page views can be counted. Only set after you accept analytics | 2 years |
| _ga_LPJPYWTLHR | Google Analytics 4, loaded via Google Tag Manager | Maintains the analytics session for this property. Only set after you accept analytics | 2 years |
Your choice itself is stored locally rather than in a cookie:
| Key | Set by | Purpose | Retention |
|---|---|---|---|
| citesvue.consent | Citesvue | Your banner choice and the time you made it, stored in local storage rather than a cookie so it never fragments the edge cache | Until you change it |
We do not load Google Ads, Meta Pixel, LinkedIn Insight, TikTok Pixel, or any other ad-network tracker on this site, and there is no advertising tag in the container.
Who else can see anything, and what.
- Google (Tag Manager and Analytics 4). Marketing site only, consent-gated as described above. Property
G-LPJPYWTLHR. Google acts as our processor for this measurement data; we do not enable Google Signals or advertising features on the property. - Cloudflare. Hosts and serves the site and the application, and provides bot protection on sign-in. Processing here is strictly necessary to deliver the service.
- Stripe. Handles payment pages for paid plans. Card data never reaches Citesvue systems.
- Email and support tooling. Used after you contact us. Sets no cookies on this site.
How to opt in, opt out, and change your mind.
- Consent banner. Every visitor sees the banner on first visit, not only those in jurisdictions that require it, with three choices: accept all, reject all, or customise. Reject is one click, in the same place and the same size as accept. Strictly necessary cookies remain enabled regardless.
- Withdraw at any time. Use the “Cookie settings” link in the footer to reopen the choice and change it. Your decision is kept until you change it, and we ask again whenever the categories or vendors on this page change.
- Default is denied. Analytics and advertising signals are set to denied before any tag loads, so a visitor who never answers the banner is treated as having declined.
Block, delete, or be told about cookies before they’re set.
Most browsers let you view, manage, or delete cookies for any site. The exact path depends on the browser - these are the typical entry points:
- Chrome / Edge: Settings → Privacy & security → Cookies and other site data.
- Firefox: Settings → Privacy & Security → Cookies and Site Data.
- Safari (macOS): Settings → Privacy.
- Safari (iOS): Settings → Safari → Privacy & Security.
When this list changes, this page changes.
We update this page when we add, remove, or change a cookie. Material changes (a new category, a new vendor) are also surfaced via the consent banner so you can review and re-consent. Past versions are available on request.
The single inbox.
Questions about this policy: privacy@citesvue.com. Or use the form at /contact?topic=privacy.