Privacy

What we do with your data - and what we don’t.

Citesvue holds the recordings teams use to make their most consequential decisions. This page is the operating manual for how we treat that data - what gets collected, why, where it lives, who can see it, how long it stays, and how to remove it. It is not a marketing summary. If anything here ever conflicts with the contractual DPA you’ve signed with us, the DPA wins.

Last updatedAugust 25, 2026Version1.4
Principles

Five rules we hold ourselves to before any clause in this page.

  1. 01Minimisation. We collect what we need to operate the product, and nothing else. If a field doesn’t serve a stated purpose, we don’t ask for it.
  2. 02Purpose limitation. Data collected for one stated purpose is not silently repurposed. New purposes require a new disclosure.
  3. 03Transparency over comfort. We’d rather publish an awkward truth than a comforting summary. Where the answer is "it depends," we say so and tell you on what.
  4. 04No model training on your content. Customer recordings, transcripts, optional visual evidence, and extracted artifacts are never used to train, fine-tune, or evaluate models - ours or any third party’s.
  5. 05Erasure means erasure. When you ask us to delete an account, we delete it end-to-end across primary stores, derived stores, search indices, and backups (on the rotation cycle), and we confirm when it is done.
Data we hold

Six buckets. That’s the whole list.

1. Account data

What. Name, work email, password hash, workspace and team membership, role, billing contact and address, payment method token (held by our PCI-DSS Level 1 payments processor - we never see card numbers).

Why. To authenticate you, scope your access correctly, bill the workspace, and contact you about service-affecting events.

Retention. Held for the life of the account. On account deletion, removed within 30 days from primary stores and on the next backup rotation cycle (≤30 days further).

2. Usage data

What. Sign-in events, IP address, user-agent, feature interactions (e.g. "exported PDF," "pushed to Jira"), error and crash diagnostics, and security events scoped to the workspace.

Why. Operating, securing, and debugging the product.

Retention. Diagnostic logs retained 30–90 days. Security-event entries in the internal audit trail retained 12 months by default.

3. Customer content

What. The recordings you upload (audio and/or video), transcripts derived from them, optional scene/OCR/frame evidence for videos you choose to analyze, embeddings, extracted artifacts (bugs, requirements, decisions, action items, etc.), comments your team adds, and exports your team generates.

Why. To deliver the product. This is the workload you hired us to do.

Retention. Uploaded media is retained in your workspace alongside the structured evidence layer so playback stays available, and it counts against your plan storage. Deleting a recording removes the media and everything derived from it (transcript, artifacts, search entries, and any requested visual evidence). Account deletion removes workspace data across our systems.

4. Connected account credentials

What. When you connect an external tool - Google (sign-in, calendar, or export), Microsoft (calendar), Jira, Linear, Notion, or Slack - we store the OAuth tokens or API credentials needed to act on your behalf, encrypted at rest with an additional application-level layer, plus the minimal identifiers of what you connected (for example a workspace name or site URL).

Why. To perform exactly the operations you asked for: signing you in, syncing your calendar, or delivering a push you triggered.

Retention. Until you disconnect the integration or delete the user/account. Credentials are shown only redacted after entry and are never logged.

5. Connected calendar data

What. The connected account email, read-only event details, and the credential and notification metadata needed to keep that calendar current.

Why. To show the connected user’s upcoming meetings in Citesvue. The detailed scope, storage, sharing, and deletion rules are in the next section.

Retention. Removed when the user disconnects the calendar or their Citesvue user/account is deleted. Expired cache rows are also removed on a rolling schedule.

6. Mobile app data

What. When the mobile companion is available to you, we register a device session, device/app metadata, a push-notification token, and delivery status needed to notify you about recordings and processing.

Why. To keep your signed-in device secure, deliver notifications you enable, and diagnose mobile reliability issues.

Retention. Removed when you revoke the device session, sign out where supported, unregister notifications, or delete the account. The mobile companion is currently in UAT and is not yet an App Store or Play Store availability claim.

Google sign-in

Identity only: your name, email, and profile photo.

When you choose Continue with Google on sign-up or sign-in, Google shares your basic profile: name, email address, and profile photo (the openid, email, and profile scopes). We use it to create or match your Citesvue account and nothing else - no contacts, no Drive contents, no calendar access is requested at sign-in.

This data is stored as part of your account record, protected and deleted under the same rules as account data (bucket 1 above). We do not sell it, use it for advertising, or use it to train or evaluate general-purpose AI models. You can use email and password instead at any time.

Citesvue’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Google Calendar

Read-only access, used only to show your upcoming meetings.

When you choose Connect Google Calendar, Google asks you to approve two scopes: your account email and read-only access to calendar events. Citesvue does not request permission to create, edit, or delete events.

Data accessed and stored

We access your connected account email and calendar event fields needed for Upcoming: event title, start and end time, timezone, organizer and attendee names/emails, meeting URL, recurrence identifiers, update time, and cancellation status. We also store Google sync cursors and push-channel identifiers so reschedules and cancellations stay current.

How it is used and protected

This data is used only to display and synchronize the connected user’s upcoming meetings. The Google refresh credential is encrypted at rest with a service-held key; short-lived access tokens are used only while calling Google and are not stored in the browser or event cache. Calendar data remains scoped to the connected user and workspace.

Sharing and prohibited uses

We do not sell Google user data, use it for advertising, build advertising profiles from it, or use it to train or evaluate general-purpose AI models. We disclose it only to infrastructure providers acting for us to operate Citesvue, or where law requires disclosure, under the access and sub-processor controls described on this page.

Disconnect and deletion

Disconnecting Google Calendar immediately removes the local refresh credential, event cache, sync cursors, and push-channel metadata. Deleting the Citesvue user or account performs the same cleanup. Citesvue stops its push channel when Google is available. To remove the provider-side consent itself, use your Google Account permissions; Citesvue does not revoke an account-wide grant because the same Google account may be connected to another workspace. Existing Citesvue recordings are not deleted merely because a calendar is disconnected.

Citesvue’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Google Drive export

The narrowest Drive scope Google offers, used only to deliver files you export.

When you choose to export a recording, transcript, or findings file into your own Google account, Google asks you to approve the drive.file scope. This is Google’s narrowest Drive permission: Citesvue can create files in your Drive and later see or update only the files it created. It cannot read, list, or modify anything else in your Drive, Docs, or Sheets.

Data accessed and stored

We store the encrypted OAuth refresh credential for the connected Google account and the identifiers of files Citesvue itself created (so a repeat export can update the same file instead of duplicating it). The content written into those files is your own workspace content - the export you asked for.

Sharing and prohibited uses

We do not sell Google user data, use it for advertising, build advertising profiles from it, or use it to train or evaluate general-purpose AI models. We disclose it only to infrastructure providers acting for us to operate Citesvue, or where law requires disclosure, under the access and sub-processor controls described on this page.

Disconnect and deletion

Disconnecting Google, or deleting the Citesvue user or account, immediately removes the local refresh credential and stored file identifiers. Files already delivered to your Drive are yours and are never touched by a disconnect. To remove the provider-side consent itself, use your Google Account permissions.

Citesvue’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google Workspace export availability depends on the destination connection and workspace entitlement shown in the product.
Microsoft Calendar

Read-only Outlook access, used only to show your upcoming meetings.

When you choose Connect Microsoft Outlook, Microsoft asks for delegated, read-only Calendars.Read access plus the identity and offline-access scopes required to identify your account and keep the connection current. Citesvue does not request permission to create, edit, or delete events.

Data accessed and stored

We access your connected account identity and calendar event fields needed for Meetings: title, start and end time, timezone, organizer and attendee names/emails, meeting URL, recurrence identifiers, update time, and cancellation status. We store Microsoft Graph delta cursors and subscription identifiers so reschedules and cancellations stay current.

How it is used and protected

This data is used only to display and synchronize the connected user’s meetings. The Microsoft refresh credential is encrypted at rest with a service-held key. Short-lived access tokens are used only while calling Microsoft Graph and are not returned to the browser or stored with event data. Calendar rows remain scoped to the connected user and workspace.

Sharing and prohibited uses

We do not sell Microsoft calendar data, use it for advertising, build advertising profiles from it, or use it to train or evaluate general-purpose AI models. We disclose it only to infrastructure providers acting for us to operate Citesvue, or where law requires disclosure, under the controls described on this page.

Disconnect, provider consent, and deletion

Disconnecting Microsoft Outlook immediately removes the local refresh credential, event cache, delta cursors, and subscription metadata. Citesvue also asks Microsoft Graph to delete its notification subscription when Microsoft is available. Microsoft does not provide an app-specific refresh-token revocation endpoint here, so provider consent remains until you or your administrator remove Citesvue Calendar in Microsoft My Apps, Microsoft account privacy controls, or Entra. Deleting the Citesvue user or account performs the same local cleanup. Existing Citesvue recordings are not deleted merely because a calendar is disconnected.

Organizational Microsoft 365 tenants may require administrator approval before a user can connect. Approval grants only the delegated, read-only calendar permission configured for Citesvue; each user must still complete Connect to create their own encrypted connection.
Mobile companion

A device session and notification token, not a second customer profile.

The Citesvue mobile companion is currently in UAT. If you use it, the app registers a device session so you can sign in securely and revoke that device later. It also registers a push token only to deliver notifications you enable, such as recording-ready, evidence-ready, and processing-failure notifications.

What we store

We store the device label, operating-system and app-version metadata, refresh-session metadata, push token, and delivery status. Notification payloads use a recording identifier and deep link; they do not include transcript text, meeting content, or other sensitive recording details.

Control and deletion

You can revoke a device session from the product when that control is available, disable notifications in your device settings, or delete your account. Revoking a session invalidates its refresh credential; removing the push registration prevents future delivery to that device.

Meeting assistant

When the notetaker joins a call, everyone can see it - and deleting the recording deletes everything.

On paid plans, a workspace member can send Citesvue’s meeting assistant into a meeting - by pasting the meeting link, or (in closed beta) from a connected calendar. The assistant never joins on its own initiative.

What it records and shows

The assistant joins as a visible participant with a clear bot name and posts a consent notice in the meeting where the platform allows it. It records meeting audio and, when available, shared video. Core processing produces the transcript, recap, transcript-derived artifacts, and search index first. A workspace member can later request visual evidence for an eligible video capture; only that optional step creates scenes, OCR, visual findings, and frame citations. All data remains scoped to the workspace that dispatched it.

Consent responsibility

The workspace that dispatches the assistant is responsible for satisfying the notice and consent requirements that apply to its meetings and jurisdictions. Citesvue provides the visible presence and notice; it cannot know who is legally required to consent on your call.

Retention and deletion

Assistant-captured recordings follow the same retention and deletion rules as uploads: deleting the recording removes the media and everything derived from it, and captures count against the workspace’s plan limits. Meeting links handled during dispatch are encrypted at rest.

Connected integrations

Jira, Linear, Notion, Slack: your credentials, used only for pushes you trigger.

Connecting an integration - via OAuth or a pasted credential - stores the token encrypted at rest with an additional application-level layer. Citesvue uses it for exactly two things: listing the destinations you can pick (your projects, teams, pages, channels) and delivering the pushes your workspace triggers. Deliveries are recorded so you can see per-push status and retry failures.

What a push sends is what you selected: the finding, recap, transcript, or answer, with its evidence. Nothing is pushed automatically. Disconnecting an integration removes the stored credential immediately; content already delivered to your external tool remains there, under that tool’s terms.

Purpose-by-purpose

Six purposes. Anything outside this list is out of scope.

PurposeWhat it coversLawful basis (UK/EU GDPR)
Service deliveryIngesting recordings, generating the evidence layer, running Q&A, executing integration pushesContract
Calendar synchronizationShowing a connected user’s upcoming meetings and keeping reschedules, recurrence, and cancellations currentConsent / Contract
Account & billingAuthentication, workspace administration, invoicingContract
Security & abuse preventionAnomaly detection, rate limiting, fraud and account-takeover defenceLegitimate interests
Service communicationsIncident notices, security advisories, breaking-change notifications, billing alertsContract / Legitimate interests
Product communications (opt-in)Newsletters, release notes, occasional research interviewsConsent - opt out anytime
Legal & complianceResponding to lawful requests, defending claims, regulatory cooperationLegal obligation / Legitimate interests
We do not use customer content for advertising, profiling, or model training. We do not sell data - to anyone, ever, in any jurisdiction.
Access

Two circles: the people inside Citesvue, and the vendors that help us run it.

Internal access

  • Default-deny. Production access is denied by default and granted on a least-privilege, just-in-time basis with peer approval and time-bounded expiry.
  • Customer-content access. Engineers cannot read the contents of recordings or transcripts in normal duties. Targeted access (e.g. investigating a support ticket you’ve raised) requires a documented business reason, customer consent where applicable, and is recorded in the internal audit log.
  • Background checks. Required for all employees and contractors with potential access to production systems.
  • Onboarding & offboarding. Provisioned through SSO with role mapping; deprovisioning runs automatically within one business hour of role change.

Sub-processors (categories)

The named list of sub-processors is available on request via security@citesvue.com. The categories below describe what they do, not who they are.

CategoryPurposeRegion(s)
Cloud infrastructure providerCompute, storage, networking, queuesUS / EU
Speech transcription providerSpeaker-aware transcription of customer recordingsUS / EU
Visual / OCR analysis providerFrame analysis and on-screen text extractionUS / EU
Large-language-model provider(s)Artifact extraction and Q&A - zero-retention API mode where available; no training on inputsUS / EU
Email & transactional messagingService emails and notificationsUS / EU
Error & performance monitoringApplication observability, incident diagnosticsUS / EU
Customer support toolingTicketing and customer communicationsUS / EU
Payments processorCard processing - we do not store PAN dataUS / EU

We notify customers of new sub-processors with at least 30 days’ notice by email to workspace owners. Enterprise customers may object during the notice window per the DPA.

Region & residency

A global edge network, with honest residency guidance.

  • Where data lives. Citesvue runs on Cloudflare’s global network; data at rest is encrypted on managed storage and databases.
  • Region selection. Single-region pinning is on the roadmap and not yet available. If your obligations require it, talk to us before onboarding regulated data.
  • Cross-border transfers. Where data crosses jurisdictions, we rely on the EU Standard Contractual Clauses (2021) and the UK International Data Transfer Addendum, supplemented by the technical and organisational measures described in our DPA.
Retention schedules

Defaults that are short. Controls that are yours.

Data classDefault retentionCustomer control
Raw media (audio/video)Retained in the workspace with the evidence layerDeleted with the recording; counts against plan storage
Transcripts & evidence layerLife of the projectPer-project age-out rules; manual deletion
Embeddings & search indicesLife of the projectPurged on artifact deletion
Extracted artifactsLife of the projectManual deletion; bulk export before delete
Internal audit trail (security events)12 months defaultInternal; relevant entries shared on legitimate request
BackupsManaged, encrypted platform storageRestoration via support
Account & billing recordsLife of the account, plus statutory tax/finance retention (typically 6–7 years for invoices)N/A - statutory obligation
Service email & support tickets24 monthsDeletion on request
Google OAuth refresh credentialUntil the user disconnects Google Calendar or the user/account is deletedImmediate local purge; provider consent remains under the user’s Google account control
Google Calendar event cache & push metadataRolling operational cache; expired event rows are removed within 90 daysImmediate purge on disconnect or user/account deletion
Microsoft OAuth refresh credentialUntil the user disconnects Microsoft Outlook or the user/account is deletedImmediate local purge; provider consent remains under the user’s Microsoft account or administrator control
Microsoft Calendar event cache, delta & subscription metadataRolling operational cache; expired event rows are removed within 90 daysImmediate purge on disconnect or user/account deletion
Integration credentials (Jira, Linear, Notion, Slack, Google export)Until the integration is disconnected or the user/account is deletedImmediate removal on disconnect; provider-side consent stays under your control at the provider
Integration delivery historyRolling operational record of pushes and their statusDeleted with the account
Mobile device sessions and push registrationsDevice label, operating-system/app version, refresh-session metadata, push token and delivery status while a signed-in device remains registeredDeleted on device-session revocation or account deletion; push tokens are removed when the app unregisters them
Rights & how to use them

Six rights under GDPR. One inbox.

Send any of the below to privacy@citesvue.com. We respond within 30 days (with one 60-day extension where the request is complex). For workspace members, we will route requests through the workspace controller where appropriate.

RightWhat it means hereHow to exercise
AccessA copy of the personal data we hold about youEmail request - verified via account login
RectificationCorrection of inaccurate personal dataIn-product for most fields; otherwise email
ErasureDeletion of your personal data ("right to be forgotten")In-product account deletion or email request
PortabilityMachine-readable export of data you providedIn-product export (JSON, CSV, DOCX, PDF)
RestrictionPause processing while a dispute is resolvedEmail request
ObjectionObject to processing based on legitimate interestsEmail request

You also have the right to lodge a complaint with a supervisory authority (e.g. the UK ICO, the Irish DPC, or your local EU/EEA authority).

Children

Not intended for users under 16.

Citesvue is a B2B product for workplace use. We do not knowingly collect personal data from children under 16. If we learn we have, we will delete it.

Cookies

A short list. All functional or analytic.

CategoryPurposeSet by
Strictly necessaryAuthentication, session integrity, CSRF protectionCitesvue
FunctionalRemember preferences (timezone, theme, region)Citesvue
Analytics (first-party)Aggregate, privacy-respecting product analytics - no cross-site trackingCitesvue
Marketing on citesvue.comLimited use on marketing pages only; respects Do Not Track and consent bannerCitesvue / consent-gated

We do not use third-party advertising cookies inside the application.

Contact

Three routes, depending on what you need.

  • Privacy questions & rights requests: privacy@citesvue.com
  • Data Protection Officer: dpo@citesvue.com
  • Security disclosures: security@citesvue.com
  • Supervisory authority complaints: You may complain directly to your local supervisory authority. We’d appreciate the chance to resolve the issue first.
Versioning

When this changes, we tell you.

Material changes are notified at least 30 days in advance via email to workspace owners and via an in-product banner. Non-material changes (typo fixes, link updates) are versioned at the top of this page. Past versions are available on request.