Privacy Policy
How CiteArk collects, uses, stores, and protects your data.
Last updated: August 30, 2026
In short: we collect only the minimum data needed to run the service; we do not sell your data or use it for ad targeting; you can request access, correction, export, or deletion of your data at any time.
This policy explains what data Hangzhou Ligu Network Technology Co., Ltd. ("CiteArk", "we") collects while providing the CiteArk service, why we use it, how long we keep it, and what rights you have. We serve users worldwide and work to comply with applicable laws, including the Personal Information Protection Law of the People's Republic of China (PIPL) and the EU General Data Protection Regulation (GDPR).
Data we collect
- Account and identity data: email address, display name, avatar, sign-in provider identifiers, organization membership, and email verification status.
- Security data: securely hashed passwords, database sessions, API Key hashes, sign-in IP addresses, and browser information; we do not store plaintext passwords or full API Keys.
- Payment and credit data: selected credit package, Paddle customer and transaction identifiers, currency, amount, order status, refund or dispute status, and credit ledger entries. Paddle handles full payment-card details; we do not store them.
- Content you submit: paper PDFs, repository names, descriptions, GitHub links, and similar materials.
- Research records generated by the platform: Claims extracted from papers, experiment plans, run records, metrics, logs, and signature information.
- Basic access logs: recorded by the edge proxy and servers for security protection and troubleshooting.
- Site usage data: pages visited, referrers, device and browser type, coarse region, and on-site interactions, in aggregate form.
How we use data and our legal bases
We use data to:
- display, index, and verify publicly published research repositories (performance of our service agreement with you);
- authenticate accounts, enforce access control, manage organization collaboration, reproduction quotas, and Agent API Keys (performance of the service agreement);
- create credit purchases, confirm payment, process refunds and payment disputes, and maintain the credit ledger (performance of the service agreement, legal obligations, and legitimate interests in fraud prevention);
- generate and preserve execution records, evidence, and verification results (performance of the service agreement and legitimate interest — maintaining the integrity of the scientific record);
- improve the quality of services such as paper parsing and experiment reproduction (legitimate interest);
- understand how site features are used, identify experience problems, and measure product improvements (legitimate interest; see "Cookies and site analytics");
- comply with legal obligations and respond to law enforcement and regulatory requests (legal obligation).
We do not sell your data and do not use it for ad targeting.
Storage locations and processors
We use the following third-party processors (subprocessors) to provide the service. Each category of data is handled by them only to the extent relevant to the service purpose:
| Processor | Purpose | Data categories |
|---|---|---|
| Neon PostgreSQL | Structured database | Structured data such as accounts, repositories, Claims, and run records |
| Cloudflare R2 | Object storage | Paper PDFs, resource bundles, and other binary objects |
| Cloudflare (edge network) | DNS, HTTPS, and reverse proxy | Access logs, IP addresses, request metadata |
| Google Cloud Run | Application runtime | Processing of the above data categories while the service runs |
| Resend | Transactional email delivery | Email addresses, verification and notification email content |
| GitHub / Google | Third-party sign-in | Identity information you authorize to be shared |
| Google Analytics 4 | Site usage analytics | Anonymized usage data (see the next section) |
| Paddle | Checkout, payment, tax, order, refund, and payment-dispute processing | Email, location, order and payment information, Paddle customer and transaction identifiers |
OAuth tokens are stored encrypted in the database. Traffic is proxied through the Cloudflare edge network with HTTPS enabled.
Cookies and site analytics
We use a small number of cookies that are strictly necessary for sign-in sessions and security. We do not use advertising cookies.
We use Google Analytics 4 to measure site traffic and feature usage. CiteArk has disabled Google signals and ad personalization signals, and we do not use this data for ad targeting. Google may process analytics data through browser identifiers, network, and device information; you can restrict or clear the related cookies through your browser settings.
Paper licenses
Submitted papers are evaluated through the License Gate. For papers whose licenses do not permit re-hosting, we retain only metadata and link back to the original source. If you believe certain content infringes your rights, please request removal through the contact and takedown page.
Data sharing
Except for the processors listed above and the circumstances below, we do not disclose your personal data to third parties:
- when you set a research repository to public, its content becomes visible to all visitors;
- when necessary to comply with the law, court orders, or regulatory requirements;
- in a merger, reorganization, or asset sale, in which case we will require the recipient to continue honoring this policy;
- in other cases with your explicit consent.
Data retention and deletion
- Account, organization, and permission data is kept for the life of the account; after account closure, non-essential identity data is typically deleted or de-identified within 30 days.
- Sessions, verification tokens, and rate-limit counters are kept for the shortest period required for security and are periodically purged once expired.
- Support requests are typically retained for 24 months; where security, rights disputes, or legal obligations are involved, retention may extend until the matter is resolved.
- Public research repositories, execution records, and audit attestations are retained long-term by default to preserve scientific traceability; when content is taken down, public access is restricted, but minimal integrity and dispute-resolution records may be retained.
Your rights
You may request to:
- access your personal data;
- correct inaccurate data;
- export your data (in a portable, commonly used format);
- delete your data, or restrict or object to specific processing;
- withdraw a pending submission or consent you have given (without affecting the lawfulness of processing carried out before withdrawal).
Please submit requests through the contact and takedown page. We will first verify the requester's relationship to the data subject, then process the request in accordance with applicable law and scientific record integrity requirements, typically responding within 30 days. If you believe our processing infringes your rights, you may also lodge a complaint with the data protection authority in your jurisdiction.
Cross-border transfers
Our operating entity is located in China, and the service runs on cloud infrastructure in a United States region and a global edge network, so your data may be transferred and stored across borders. For personal information protected by PIPL, we perform the legally required assessment, notification, and protection measures for cross-border provision; for data protected by the GDPR, we rely on appropriate transfer safeguards.
Security
We protect data with encryption in transit, least-privilege access, managed key custody, object digests, and append-only audit records; however, no internet service can guarantee absolute security. If you discover a vulnerability, please select "Security vulnerability" on the contact page and do not disclose details publicly until a fix is complete.
Minors
The service is intended for users aged 16 and above. We do not knowingly collect personal data from minors under 16; if such data is discovered, it will be deleted.
Changes to this policy
We may revise this policy from time to time. Material changes will be announced on the website at least 14 days in advance, and the "Last updated" date will be revised. By continuing to use the service after a change takes effect, you accept the revised policy.
Contact us
The data controller is Hangzhou Ligu Network Technology Co., Ltd. (Hangzhou, Zhejiang Province). If you have any questions about this policy or your data, or wish to exercise the rights above, please reach us through the contact page or email us at support@citeark.com.