Privacy Policy

What Citradar collects, which third parties it reaches, and how long data is kept. This describes the system as it is actually built — the sub-processor list below is checked against the codebase, not copied from a template.

Last updated 11 August 2026

1. Who is responsible

Citradar is operated by Rupamjit Ghosh, based in India, who is the controller of the personal data described here. Contact: hello@citradar.com.

For the data you put into the product about your own business and competitors, you are the controller and we act as your processor under a Data Processing Agreement. We don't publish that template — if your organisation needs one on file, email hello@citradar.com and we'll send a copy to countersign.

2. What we collect

Account data. Your name, email address, and a hashed password — or, if you sign in with Google, the name and email Google returns. We record when your email was verified and keep a record of active sessions so you can sign out of them.

Workspace data. The brand, domain and aliases you set up, the competitors you track, the questions you configure, and the answers and citations returned by the AI platforms.

Billing data. Your plan, subscription status and renewal date, plus identifiers issued by our payments provider. We never receive or store card numbers.

Technical data. IP addresses, used to apply rate limits on sign-in and signup and recorded against sessions; and error reports when something fails.

3. Cookies and tracking

Citradar sets no analytics, advertising or profiling cookies, and uses no product-analytics or session-recording tool. The only cookies set are the ones required to keep you signed in.

Because we set no non-essential cookies, there is no cookie banner and nothing to consent to. If that ever changes, this section changes first.

One third-party request is made by your browser rather than by us: website icons shown beside competitor and source domains are loaded from a public favicon service, which means that service sees those domain names and your IP address. It sets no cookie for us and receives no account data. It is listed as a sub-processor below for completeness.

4. Why we process it, and on what basis

  • To provide the service — running your tracked questions, storing results, showing your dashboard. Basis: performance of our contract with you.
  • To bill you — managing subscriptions and payment status. Basis: performance of contract.
  • To keep accounts secure — rate limiting sign-in attempts, verifying email addresses. Basis: legitimate interests in preventing unauthorised access.
  • To keep the service working — error monitoring and operational alerts. Basis: legitimate interests in maintaining a reliable service.
  • To send service email — address verification and account notices. Basis: performance of contract. We do not send marketing email from the product.

5. Sub-processors

These are every third party that receives data in the course of running Citradar. The list is maintained as data in the codebase and is checked automatically against the services actually integrated, so it does not drift out of date.

AI model providers

ProviderPurposeWhat it receives
AI model providersMultiple large-language-model providers run your tracked questions to produce the answers the dashboard analyzes, and one is used for onboarding tasks (brand analysis and initial question generation) and to read those answers back for mention detection.The text of your tracked questions; for the mention-detection and onboarding step, the text of AI answers about your tracked questions and your website's public content. No customer account data.

Web search and page reading

ProviderPurposeWhat it receives
Web search and page readingOne web search is run per tracked question, using redundant providers for reliability, and its results are shared across the AI providers above. A page-reading fallback is used during onboarding when your website can't be read directly.The text of your tracked questions, and — for the onboarding fallback — the URL of the website you enter.

Billing

ProviderPurposeWhat it receives
BillingA payment processor acts as merchant of record for subscriptions: it sells the subscription to you and handles payment.Your billing details, entered directly with the processor. Card numbers are never received or stored by us.

Email

ProviderPurposeWhat it receives
Email deliveryA transactional email provider sends account emails: address verification, sign-in codes, and billing notices.Your email address and name.

Sign-in

ProviderPurposeWhat it receives
Sign-inAn optional sign-in provider, used only if you choose to sign in with it instead of an emailed code.Your account email and name, received from that provider when you authorise sign-in.

Infrastructure

ProviderPurposeWhat it receives
InfrastructureCloud infrastructure providers run the product: hosting the web application and the background jobs that run your tracked questions, storing the database, providing short-lived caching and rate-limiting, and monitoring for errors.All account, brand, prompt and result data (database); short-lived cached reads and rate-limit counters (cache); error reports, which may include the identifiers of the records involved in a failed operation (monitoring); IP addresses, as part of ordinary web traffic (hosting).

Loaded by your browser

ProviderPurposeWhat it receives
Loaded by your browserWebsite icons shown beside competitor and source domains are loaded from a public favicon service, directly by your browser rather than by us.Your browser's request reveals the domain names shown on your screen and your IP address to that service. It sets no cookie for us and receives no account data.

The text of your tracked questions is sent to the AI and search providers above. Do not put personal data or confidential information into a tracked question — they are written to be asked publicly, and they leave our systems by design.

6. International transfers

The providers above operate outside your country in most cases, including in the United States. Where personal data is transferred out of the UK or EEA we rely on the transfer mechanisms offered by each provider, typically Standard Contractual Clauses incorporated into their terms.

7. How long we keep it

We do not automatically delete anything. Historical results are kept indefinitely by design — the value of the product is the trend line, and silently expiring last year's data would destroy it.

Records you remove in the product — a deleted question, a removed competitor — are marked as removed and stop being used, but the historical results already recorded against them are retained so past periods still reconcile.

Two things are genuinely short-lived: cached dashboard reads and rate-limit counters held in Redis, which expire within minutes to an hour, and the audit record of account changes, which is kept for as long as the account exists.

If you want your data erased, that is an explicit request rather than something that happens on its own — see below.

8. Your rights

If you are in the UK or EEA you have the right to access, correct, export, restrict or object to processing, and to erase your personal data. These rights apply wherever you are located as a matter of our policy.

Deletion. Because nothing is deleted automatically, erasure is a real, separate operation. Request it at hello@citradar.com from the address on the account and we will confirm, carry it out, and tell you when it is done. Deletion removes your account and the workspace data attached to it; it cannot be undone, and cancelling a subscription is not the same thing.

You can also complain to your local supervisory authority.

9. Security

  • Data is isolated per tenant at the database level, so one customer's queries cannot return another customer's rows.
  • Passwords are stored hashed, never in plain text.
  • Sign-in, signup and password-reset endpoints are rate limited to resist brute-force attempts.
  • Traffic is encrypted in transit, and access to production systems is restricted.

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and the relevant authority as required by law.

10. Children

Citradar is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.

11. Changes to this policy

We will update this page when what we do changes — including whenever a sub-processor is added or removed. Material changes are notified to your account email.