Privacy policy
Last updated: 28 July 2026
This policy explains how we process personal data in connection with the CiteLyzer service at citelyzer.com - both the website and the application with customer accounts, subscriptions, and brand-visibility tracking. The service is intended for businesses and we do not process consumer data as customer data, but personal data of the people involved (such as user e-mail addresses or sole traders’ invoice details) remains protected under the GDPR as described here.
Who is responsible
The data controller is SOLID SOFTWARE Piotr Czerwiński, Szkolna 4, 55-114 Kryniczno, Polska, NIP: PL9151812835. For any privacy question or request, contact us at contact@citelyzer.com.
What we collect
Account data: your e-mail address. Signing in is passwordless - with one-time codes sent to your e-mail - so we store no password at all. Billing data: payments are handled by Stripe, and you provide your card details directly to Stripe - we do not store full card numbers; for invoicing we process the details you provide for the invoice (name or company name, address, tax ID), issued via Fakturownia. Product usage data: the configuration you create in the app - the domain and phrases you track, competitors you add - and the resulting metrics. Waitlist data: e-mail addresses submitted through the website waitlist form, with basic signup metadata (page language and form used). Early-access data: if you sign up for early access, we process your e-mail address, your website address and - if you choose to provide them - your first name, last name and company name; this data is stored in Brevo and used to notify you about the launch and to contact you about early access. Technical data: essential session cookies needed to keep you signed in, and product analytics collected via PostHog (EU region). One-off report orders: if you buy a report without an account, we also process the e-mail address, brand, domain, prompts and competitors you provide with the order, together with order, delivery and consent records.
Why we use it and on what legal basis
To provide the service - creating and securing your account, running the tracking you configure, processing subscriptions and payments, and customer support (performance of a contract, Art. 6(1)(b) GDPR). To issue and store invoices and meet tax and accounting obligations (legal obligation, Art. 6(1)(c) GDPR). To understand how the product is used, improve it, and keep the service secure and free of abuse (legitimate interest, Art. 6(1)(f) GDPR). To inform you about the launch and product updates if you joined the waitlist, and to send you e-mails about AI visibility and product news if you ticked the optional box when ordering a one-off report (consent, Art. 6(1)(a) GDPR - you can withdraw it at any time, and the report and invoice reach you regardless). We do not sell your data.
Cookies
We use essential session cookies that are necessary to sign you in and keep your session secure - the service cannot work without them. We also use PostHog (EU region) for product analytics, which helps us understand how the app is used; we do not include the domains or phrases you track in analytics event properties. Analytics includes session recordings of how the site and app are used (mouse movement, clicks, pages viewed); anything typed into forms is masked and never recorded. With your consent (the "Accept all" option in the banner) we also use Meta marketing cookies (Meta Pixel and the Conversions API) to measure ad effectiveness and select ad audiences; if you choose essentials only, the Pixel does not load and we send no such data to Meta.
Who processes it
We use a small number of providers acting as processors or independent controllers: Cloudflare (application hosting, database and bot protection on forms - Turnstile; data may be processed within Cloudflare’s global network with GDPR safeguards such as standard contractual clauses), Stripe (payment processing), Fakturownia (invoicing), PostHog with data hosted in the EU (product analytics), Brevo (e-mail delivery - waitlist and account e-mails such as sign-in messages) and - with your marketing consent - Meta Platforms Ireland (Meta Pixel and the Conversions API for ad measurement; data may be transferred to the US with GDPR safeguards such as standard contractual clauses). To run measurements we pass to AI engine providers and specialised technical intermediaries only the tracked phrases and the brand and domain names - never your contact or billing details. Where a provider processes data outside the EEA, transfers are covered by appropriate safeguards under the GDPR.
How long we keep it
Account and product data: until you delete your account - you can do this yourself at any time in the account settings, which permanently removes your data. Invoices and accounting records are the exception: we must keep them for the period required by tax and accounting law (as a rule, 5 years counted from the end of the relevant tax year). One-off report orders: unpaid orders are deleted automatically after 30 days, and data of completed orders is kept for as long as needed to deliver the report, handle complaints, and establish or defend legal claims (invoices - as above). Waitlist data: until you unsubscribe or ask us to delete it. We may retain limited data for as long as necessary to establish or defend legal claims.
Your rights
Under the GDPR you have the right to access your data, correct it, delete it (including the self-serve account deletion in the account settings), restrict or object to its processing, receive it in a portable format, and withdraw consent at any time where processing is based on consent. To exercise any of these, email contact@citelyzer.com. You also have the right to lodge a complaint with a supervisory authority - in Poland, the President of the Personal Data Protection Office (PUODO), or the authority in your country of residence.
How we protect your data
Signing in is passwordless: one-time codes sent to your e-mail are short-lived, allow only a few attempts, and their sending is rate-limited - there is no password that could leak. Connections to the service are encrypted, and access to production data is limited to what is necessary to operate the service.
Changes to this policy
If we materially change this policy, we will update the date at the top and, for changes that affect account holders, inform you by e-mail or in the app.