Legal
Privacy Policy
How Citet handles personal data on the hosted instance, written for GDPR (EU 2016/679). Self-hosted installations are governed by the operator running them.
1. Controller
The controller responsible for the processing of personal data on the hosted Citet instance is the operator listed in the imprint. Privacy-related requests can be sent to privacy@citet.eu.
2. Scope
This policy applies to the hosted Citet instance reachable at this domain. If you access a self-hosted Citet deployment (for example, one operated by your university or research group), the operator of that deployment is the controller and you should consult their privacy policy.
3. Data we collect
3.1 Account data
When you create an account we store your email address, verification status, display name, profile image when provided, and the identifier of your Google or institutional sign-in account. We also store sign-in sessions and provider tokens used for authentication. This data is required to operate the editor and authenticate you.
3.2 Project content
Files you create, upload, or edit (LaTeX source, bibliographies, images, compiled PDFs) are stored on our infrastructure for the purpose of providing the editor. Project content is treated as confidential and is only made available to you and the collaborators you explicitly invite.
3.3 Collaboration metadata
When multiple people edit a document, we process presence information (who is currently connected, cursor position) and operation history (who edited which range and when). This is necessary for the collaborative editing feature to work.
3.4 Server logs
Our servers automatically log technical information for each request: IP address, timestamp, user agent, requested URL, response status. Logs are retained for up to 14 days for debugging and abuse prevention, and are deleted after that.
3.5 Optional integrations
If you connect a Zotero account, we store an OAuth refresh token and a reference to your Zotero library so that the citation picker can read it. If you connect Google Drive for backups, we store an encrypted refresh token and the Drive folder identifiers your project uses.
4. Legal basis
- Contract (Art. 6(1)(b) GDPR) — processing necessary to provide the service you signed up for: account, project storage, collaboration, compilation.
- Consent (Art. 6(1)(a) GDPR) — for optional integrations like Zotero and Google Drive backups, which only happen after you connect them.
- Legitimate interest (Art. 6(1)(f) GDPR) — short-lived server logs for security and reliability.
5. Sub-processors
Citet runs on infrastructure providers located in the European Union. The following sub-processors handle personal data on our behalf:
- Hosting infrastructure provider — virtual servers, managed PostgreSQL, and operational networking for the hosted instance. The hosted Citet instance is operated from European infrastructure where practical.
- Object storage provider — storage for project assets, compiled PDFs, and collaboration documents. Storage encryption depends on the deployment's provider configuration.
- Google LLC — when you choose Google sign-in or connect Google Drive for backups. Backup archives are ordinary ZIP files; Citet does not encrypt their content before upload. Stored Drive credentials are encrypted separately.
- Institutional identity provider — when you choose your university's sign-in method.
- Email delivery provider — when invitation email is configured, receives the recipient email, inviter name, project name, role, and project link needed to deliver the invitation.
- Zotero (Center for History and New Media) — only when you explicitly connect a Zotero library.
6. International transfers
Sub-processors located outside the EEA are only used for optional integrations you explicitly opt into (Zotero, Google Drive). Standard contractual clauses are in place where applicable.
7. Retention
- Account data — until you delete the account.
- Project content — until you delete the project, or 30 days after account deletion (whichever comes first).
- Server logs — up to 14 days.
- OAuth tokens for optional integrations — until you disconnect the integration.
8. Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you (Art. 15).
- Correct inaccurate data (Art. 16).
- Request erasure (Art. 17).
- Restrict processing (Art. 18).
- Receive a copy in a portable format (Art. 20).
- Object to processing based on legitimate interests (Art. 21).
- Withdraw consent for optional integrations at any time (Art. 7(3)).
- Lodge a complaint with the supervisory authority in your country (Art. 77).
To exercise any of these rights, email privacy@citet.eu. We aim to respond within 30 days.
9. Cookies
Citet uses a small number of strictly necessary cookies for authentication and CSRF protection. We do not use analytics or advertising cookies. See the Cookie Policy for details.
10. Children
The service is not directed at children under 16. We do not knowingly collect data from children under 16. If you believe a child has created an account, please contact us so we can delete it.
11. Changes
We may update this policy when we change the service or when the legal context changes. Material changes are announced in-app and via email to active accounts.
Last updated: 2026-09-30.