Skip to main content

Privacy

What we collect, why, how long we keep it, and the parts we deliberately do not store.

Updated

This document is a pre-launch draft. Bracketed values are unresolved and will be filled before WellCited accepts a payment. It is published early so nobody has to ask what our position is going to be.

The short version

We collect the minimum needed to run scans and bill for them. We do not sell personal data, we do not run advertising trackers, and the free audit works without an account at all.

What we collect

Three categories, and nothing else:

  • Account data — your email address, an optional display name, your plan, and your timezone.
  • Product data — the domains you add, the prompts you track, the competitor names you enter, and the answers, citations and scores each scan produced.
  • Operational data — request logs, error reports and rate-limit counters.

The free audit, specifically

A free audit runs without a login. We store the report, the domain and a generated slug so the scorecard has a URL. We also store a salted SHA-256 hash of the requesting IP address and user-agent — the hash, never the raw value — solely to detect abuse of an endpoint that fetches other people's sites on request.

If you later create an account and claim the audit, it is linked to your account and the email you signed up with is associated with it.

Answer engine providers

Running a scan sends your prompts to third-party answer engines — currently OpenAI, Perplexity and Google — under our API accounts. Prompts are the questions you chose to track; they should not contain personal or confidential information, and the product gives you no reason to put any there.

Raw provider responses are stored in object storage at [OBJECT STORAGE REGION] so a score can always be traced back to the text that produced it.

Processors we use

We rely on a small set of subprocessors. The current list, with the purpose of each, is maintained in the data processing addendum.

  • [HOSTING PROVIDER] — application hosting, [REGION].
  • [DATABASE PROVIDER] — application database and authentication, [REGION].
  • [OBJECT STORAGE PROVIDER] — raw scan responses and exports.
  • [PAYMENT PROCESSOR] — payments and invoices, as merchant of record.
  • [EMAIL PROVIDER] — transactional and digest email.
  • [ERROR MONITORING PROVIDER] — error reporting.
  • Answer engine providers — OpenAI, Perplexity, Google — for the prompts you choose to run.

Retention

Account and product data are kept while your account is open and deleted within [DELETION WINDOW] of account deletion. Raw provider responses are kept for [RAW RETENTION]. Operational logs are kept for [LOG RETENTION]. Abuse hashes on free audits are kept for [ABUSE RETENTION].

Your rights

You can export your data, correct it, or delete your account from the account page. For anything the interface does not cover — including access requests and objections — write to [PRIVACY EMAIL] and we will respond within [RESPONSE WINDOW].

Cookies

We set a session cookie when you sign in and a preference cookie for your theme. There is no analytics cookie, no advertising pixel and no consent banner, because there is nothing to consent to.