Five rules we hold ourselves to before any clause in this page.
- 01Minimisation. We collect what we need to operate the product, and nothing else. If a field doesn’t serve a stated purpose, we don’t ask for it.
- 02Purpose limitation. Data collected for one stated purpose is not silently repurposed. New purposes require a new disclosure.
- 03Transparency over comfort. We’d rather publish an awkward truth than a comforting summary. Where the answer is "it depends," we say so and tell you on what.
- 04No model training on your content. Customer recordings, transcripts, optional visual evidence, and extracted artifacts are never used to train, fine-tune, or evaluate models - ours or any third party’s.
- 05Erasure means erasure. When you ask us to delete an account, we delete it end-to-end across primary stores, derived stores, search indices, and backups (on the rotation cycle), and we confirm when it is done.
Six buckets. That’s the whole list.
1. Account data
What. Name, work email, password hash, workspace and team membership, role, billing contact and address, payment method token (held by our PCI-DSS Level 1 payments processor - we never see card numbers).
Why. To authenticate you, scope your access correctly, bill the workspace, and contact you about service-affecting events.
Retention. Held for the life of the account. On account deletion, removed within 30 days from primary stores and on the next backup rotation cycle (≤30 days further).
2. Usage data
What. Sign-in events, IP address, user-agent, feature interactions (e.g. "exported PDF," "pushed to Jira"), error and crash diagnostics, and security events scoped to the workspace.
Why. Operating, securing, and debugging the product.
Retention. Diagnostic logs retained 30–90 days. Security-event entries in the internal audit trail retained 12 months by default.
3. Customer content
What. The recordings you upload (audio and/or video), transcripts derived from them, optional scene/OCR/frame evidence for videos you choose to analyze, embeddings, extracted artifacts (bugs, requirements, decisions, action items, etc.), comments your team adds, and exports your team generates.
Why. To deliver the product. This is the workload you hired us to do.
Retention. Uploaded media is retained in your workspace alongside the structured evidence layer so playback stays available, and it counts against your plan storage. Deleting a recording removes the media and everything derived from it (transcript, artifacts, search entries, and any requested visual evidence). Account deletion removes workspace data across our systems.
4. Connected account credentials
What. When you connect an external tool - Google (sign-in, calendar, or export), Microsoft (calendar), Jira, Linear, Notion, or Slack - we store the OAuth tokens or API credentials needed to act on your behalf, encrypted at rest with an additional application-level layer, plus the minimal identifiers of what you connected (for example a workspace name or site URL).
Why. To perform exactly the operations you asked for: signing you in, syncing your calendar, or delivering a push you triggered.
Retention. Until you disconnect the integration or delete the user/account. Credentials are shown only redacted after entry and are never logged.
5. Connected calendar data
What. The connected account email, read-only event details, and the credential and notification metadata needed to keep that calendar current.
Why. To show the connected user’s upcoming meetings in Citesvue. The detailed scope, storage, sharing, and deletion rules are in the next section.
Retention. Removed when the user disconnects the calendar or their Citesvue user/account is deleted. Expired cache rows are also removed on a rolling schedule.
6. Mobile app data
What. When the mobile companion is available to you, we register a device session, device/app metadata, a push-notification token, and delivery status needed to notify you about recordings and processing.
Why. To keep your signed-in device secure, deliver notifications you enable, and diagnose mobile reliability issues.
Retention. Removed when you revoke the device session, sign out where supported, unregister notifications, or delete the account. The mobile companion is currently in UAT and is not yet an App Store or Play Store availability claim.
Identity only: your name, email, and profile photo.
When you choose Continue with Google on sign-up or sign-in, Google shares your basic profile: name, email address, and profile photo (the openid, email, and profile scopes). We use it to create or match your Citesvue account and nothing else - no contacts, no Drive contents, no calendar access is requested at sign-in.
This data is stored as part of your account record, protected and deleted under the same rules as account data (bucket 1 above). We do not sell it, use it for advertising, or use it to train or evaluate general-purpose AI models. You can use email and password instead at any time.
Read-only access, used only to show your upcoming meetings.
When you choose Connect Google Calendar, Google asks you to approve two scopes: your account email and read-only access to calendar events. Citesvue does not request permission to create, edit, or delete events.
Data accessed and stored
We access your connected account email and calendar event fields needed for Upcoming: event title, start and end time, timezone, organizer and attendee names/emails, meeting URL, recurrence identifiers, update time, and cancellation status. We also store Google sync cursors and push-channel identifiers so reschedules and cancellations stay current.
How it is used and protected
This data is used only to display and synchronize the connected user’s upcoming meetings. The Google refresh credential is encrypted at rest with a service-held key; short-lived access tokens are used only while calling Google and are not stored in the browser or event cache. Calendar data remains scoped to the connected user and workspace.
Sharing and prohibited uses
We do not sell Google user data, use it for advertising, build advertising profiles from it, or use it to train or evaluate general-purpose AI models. We disclose it only to infrastructure providers acting for us to operate Citesvue, or where law requires disclosure, under the access and sub-processor controls described on this page.
Disconnect and deletion
Disconnecting Google Calendar immediately removes the local refresh credential, event cache, sync cursors, and push-channel metadata. Deleting the Citesvue user or account performs the same cleanup. Citesvue stops its push channel when Google is available. To remove the provider-side consent itself, use your Google Account permissions; Citesvue does not revoke an account-wide grant because the same Google account may be connected to another workspace. Existing Citesvue recordings are not deleted merely because a calendar is disconnected.
The narrowest Drive scope Google offers, used only to deliver files you export.
When you choose to export a recording, transcript, or findings file into your own Google account, Google asks you to approve the drive.file scope. This is Google’s narrowest Drive permission: Citesvue can create files in your Drive and later see or update only the files it created. It cannot read, list, or modify anything else in your Drive, Docs, or Sheets.
Data accessed and stored
We store the encrypted OAuth refresh credential for the connected Google account and the identifiers of files Citesvue itself created (so a repeat export can update the same file instead of duplicating it). The content written into those files is your own workspace content - the export you asked for.
Sharing and prohibited uses
We do not sell Google user data, use it for advertising, build advertising profiles from it, or use it to train or evaluate general-purpose AI models. We disclose it only to infrastructure providers acting for us to operate Citesvue, or where law requires disclosure, under the access and sub-processor controls described on this page.
Disconnect and deletion
Disconnecting Google, or deleting the Citesvue user or account, immediately removes the local refresh credential and stored file identifiers. Files already delivered to your Drive are yours and are never touched by a disconnect. To remove the provider-side consent itself, use your Google Account permissions.
Read-only Outlook access, used only to show your upcoming meetings.
When you choose Connect Microsoft Outlook, Microsoft asks for delegated, read-only Calendars.Read access plus the identity and offline-access scopes required to identify your account and keep the connection current. Citesvue does not request permission to create, edit, or delete events.
Data accessed and stored
We access your connected account identity and calendar event fields needed for Meetings: title, start and end time, timezone, organizer and attendee names/emails, meeting URL, recurrence identifiers, update time, and cancellation status. We store Microsoft Graph delta cursors and subscription identifiers so reschedules and cancellations stay current.
How it is used and protected
This data is used only to display and synchronize the connected user’s meetings. The Microsoft refresh credential is encrypted at rest with a service-held key. Short-lived access tokens are used only while calling Microsoft Graph and are not returned to the browser or stored with event data. Calendar rows remain scoped to the connected user and workspace.
Sharing and prohibited uses
We do not sell Microsoft calendar data, use it for advertising, build advertising profiles from it, or use it to train or evaluate general-purpose AI models. We disclose it only to infrastructure providers acting for us to operate Citesvue, or where law requires disclosure, under the controls described on this page.
Disconnect, provider consent, and deletion
Disconnecting Microsoft Outlook immediately removes the local refresh credential, event cache, delta cursors, and subscription metadata. Citesvue also asks Microsoft Graph to delete its notification subscription when Microsoft is available. Microsoft does not provide an app-specific refresh-token revocation endpoint here, so provider consent remains until you or your administrator remove Citesvue Calendar in Microsoft My Apps, Microsoft account privacy controls, or Entra. Deleting the Citesvue user or account performs the same local cleanup. Existing Citesvue recordings are not deleted merely because a calendar is disconnected.
A device session and notification token, not a second customer profile.
The Citesvue mobile companion is currently in UAT. If you use it, the app registers a device session so you can sign in securely and revoke that device later. It also registers a push token only to deliver notifications you enable, such as recording-ready, evidence-ready, and processing-failure notifications.
What we store
We store the device label, operating-system and app-version metadata, refresh-session metadata, push token, and delivery status. Notification payloads use a recording identifier and deep link; they do not include transcript text, meeting content, or other sensitive recording details.
Control and deletion
You can revoke a device session from the product when that control is available, disable notifications in your device settings, or delete your account. Revoking a session invalidates its refresh credential; removing the push registration prevents future delivery to that device.
When the notetaker joins a call, everyone can see it - and deleting the recording deletes everything.
On paid plans, a workspace member can send Citesvue’s meeting assistant into a meeting - by pasting the meeting link, or (in closed beta) from a connected calendar. The assistant never joins on its own initiative.
What it records and shows
The assistant joins as a visible participant with a clear bot name and posts a consent notice in the meeting where the platform allows it. It records meeting audio and, when available, shared video. Core processing produces the transcript, recap, transcript-derived artifacts, and search index first. A workspace member can later request visual evidence for an eligible video capture; only that optional step creates scenes, OCR, visual findings, and frame citations. All data remains scoped to the workspace that dispatched it.
Consent responsibility
The workspace that dispatches the assistant is responsible for satisfying the notice and consent requirements that apply to its meetings and jurisdictions. Citesvue provides the visible presence and notice; it cannot know who is legally required to consent on your call.
Retention and deletion
Assistant-captured recordings follow the same retention and deletion rules as uploads: deleting the recording removes the media and everything derived from it, and captures count against the workspace’s plan limits. Meeting links handled during dispatch are encrypted at rest.
Jira, Linear, Notion, Slack: your credentials, used only for pushes you trigger.
Connecting an integration - via OAuth or a pasted credential - stores the token encrypted at rest with an additional application-level layer. Citesvue uses it for exactly two things: listing the destinations you can pick (your projects, teams, pages, channels) and delivering the pushes your workspace triggers. Deliveries are recorded so you can see per-push status and retry failures.
What a push sends is what you selected: the finding, recap, transcript, or answer, with its evidence. Nothing is pushed automatically. Disconnecting an integration removes the stored credential immediately; content already delivered to your external tool remains there, under that tool’s terms.
Six purposes. Anything outside this list is out of scope.
| Purpose | What it covers | Lawful basis (UK/EU GDPR) |
|---|---|---|
| Service delivery | Ingesting recordings, generating the evidence layer, running Q&A, executing integration pushes | Contract |
| Calendar synchronization | Showing a connected user’s upcoming meetings and keeping reschedules, recurrence, and cancellations current | Consent / Contract |
| Account & billing | Authentication, workspace administration, invoicing | Contract |
| Security & abuse prevention | Anomaly detection, rate limiting, fraud and account-takeover defence | Legitimate interests |
| Service communications | Incident notices, security advisories, breaking-change notifications, billing alerts | Contract / Legitimate interests |
| Product communications (opt-in) | Newsletters, release notes, occasional research interviews | Consent - opt out anytime |
| Legal & compliance | Responding to lawful requests, defending claims, regulatory cooperation | Legal obligation / Legitimate interests |
Two circles: the people inside Citesvue, and the vendors that help us run it.
Internal access
- Default-deny. Production access is denied by default and granted on a least-privilege, just-in-time basis with peer approval and time-bounded expiry.
- Customer-content access. Engineers cannot read the contents of recordings or transcripts in normal duties. Targeted access (e.g. investigating a support ticket you’ve raised) requires a documented business reason, customer consent where applicable, and is recorded in the internal audit log.
- Background checks. Required for all employees and contractors with potential access to production systems.
- Onboarding & offboarding. Provisioned through SSO with role mapping; deprovisioning runs automatically within one business hour of role change.
Sub-processors (categories)
The named list of sub-processors is available on request via security@citesvue.com. The categories below describe what they do, not who they are.
| Category | Purpose | Region(s) |
|---|---|---|
| Cloud infrastructure provider | Compute, storage, networking, queues | US / EU |
| Speech transcription provider | Speaker-aware transcription of customer recordings | US / EU |
| Visual / OCR analysis provider | Frame analysis and on-screen text extraction | US / EU |
| Large-language-model provider(s) | Artifact extraction and Q&A - zero-retention API mode where available; no training on inputs | US / EU |
| Email & transactional messaging | Service emails and notifications | US / EU |
| Error & performance monitoring | Application observability, incident diagnostics | US / EU |
| Customer support tooling | Ticketing and customer communications | US / EU |
| Payments processor | Card processing - we do not store PAN data | US / EU |
We notify customers of new sub-processors with at least 30 days’ notice by email to workspace owners. Enterprise customers may object during the notice window per the DPA.
A global edge network, with honest residency guidance.
- Where data lives. Citesvue runs on Cloudflare’s global network; data at rest is encrypted on managed storage and databases.
- Region selection. Single-region pinning is on the roadmap and not yet available. If your obligations require it, talk to us before onboarding regulated data.
- Cross-border transfers. Where data crosses jurisdictions, we rely on the EU Standard Contractual Clauses (2021) and the UK International Data Transfer Addendum, supplemented by the technical and organisational measures described in our DPA.
Defaults that are short. Controls that are yours.
| Data class | Default retention | Customer control |
|---|---|---|
| Raw media (audio/video) | Retained in the workspace with the evidence layer | Deleted with the recording; counts against plan storage |
| Transcripts & evidence layer | Life of the project | Per-project age-out rules; manual deletion |
| Embeddings & search indices | Life of the project | Purged on artifact deletion |
| Extracted artifacts | Life of the project | Manual deletion; bulk export before delete |
| Internal audit trail (security events) | 12 months default | Internal; relevant entries shared on legitimate request |
| Backups | Managed, encrypted platform storage | Restoration via support |
| Account & billing records | Life of the account, plus statutory tax/finance retention (typically 6–7 years for invoices) | N/A - statutory obligation |
| Service email & support tickets | 24 months | Deletion on request |
| Google OAuth refresh credential | Until the user disconnects Google Calendar or the user/account is deleted | Immediate local purge; provider consent remains under the user’s Google account control |
| Google Calendar event cache & push metadata | Rolling operational cache; expired event rows are removed within 90 days | Immediate purge on disconnect or user/account deletion |
| Microsoft OAuth refresh credential | Until the user disconnects Microsoft Outlook or the user/account is deleted | Immediate local purge; provider consent remains under the user’s Microsoft account or administrator control |
| Microsoft Calendar event cache, delta & subscription metadata | Rolling operational cache; expired event rows are removed within 90 days | Immediate purge on disconnect or user/account deletion |
| Integration credentials (Jira, Linear, Notion, Slack, Google export) | Until the integration is disconnected or the user/account is deleted | Immediate removal on disconnect; provider-side consent stays under your control at the provider |
| Integration delivery history | Rolling operational record of pushes and their status | Deleted with the account |
| Mobile device sessions and push registrations | Device label, operating-system/app version, refresh-session metadata, push token and delivery status while a signed-in device remains registered | Deleted on device-session revocation or account deletion; push tokens are removed when the app unregisters them |
Six rights under GDPR. One inbox.
Send any of the below to privacy@citesvue.com. We respond within 30 days (with one 60-day extension where the request is complex). For workspace members, we will route requests through the workspace controller where appropriate.
| Right | What it means here | How to exercise |
|---|---|---|
| Access | A copy of the personal data we hold about you | Email request - verified via account login |
| Rectification | Correction of inaccurate personal data | In-product for most fields; otherwise email |
| Erasure | Deletion of your personal data ("right to be forgotten") | In-product account deletion or email request |
| Portability | Machine-readable export of data you provided | In-product export (JSON, CSV, DOCX, PDF) |
| Restriction | Pause processing while a dispute is resolved | Email request |
| Objection | Object to processing based on legitimate interests | Email request |
You also have the right to lodge a complaint with a supervisory authority (e.g. the UK ICO, the Irish DPC, or your local EU/EEA authority).
Not intended for users under 16.
Citesvue is a B2B product for workplace use. We do not knowingly collect personal data from children under 16. If we learn we have, we will delete it.
Three routes, depending on what you need.
- Privacy questions & rights requests: privacy@citesvue.com
- Data Protection Officer: dpo@citesvue.com
- Security disclosures: security@citesvue.com
- Supervisory authority complaints: You may complain directly to your local supervisory authority. We’d appreciate the chance to resolve the issue first.
When this changes, we tell you.
Material changes are notified at least 30 days in advance via email to workspace owners and via an in-product banner. Non-material changes (typo fixes, link updates) are versioned at the top of this page. Past versions are available on request.