Privacy Policy
Last updated: 26 September 2026
This policy explains how [Company legal name] (ABN [ABN]) (we, us, our) collects, uses, discloses and protects personal information when you use Citepool, including our website, web app and Microsoft Word add-in. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Information we collect
Account information
When you sign in with Microsoft, Google or Apple, we receive your name, verified email address and, if available, profile picture. We do not receive or store your Microsoft, Google or Apple password, and Citepool has no passwords of its own.
Workspace content
References, PDFs, notes, custom fields, citation styles and other material you or your team add. This content may include personal information about authors or others, which your organisation controls.
Web copies and the browser button
When you ask Citepool to save a copy of a web page (or add one with the “Save to Citepool” browser button), our servers visit that address and store the page or PDF in your workspace. The browser button sends us the address and citation details of a page only when you click Save — it does not track your browsing.
Billing information
The workspace owner’s billing name, email, address and the number of users. Card details are collected and stored by Stripe, not by us; we only see limited details such as the card brand, last four digits and expiry.
Usage and technical information
Log data such as IP address, browser and device type, times of access and actions taken, which we use to run, secure and troubleshoot the Service. We use cookies that are needed to keep you signed in and to protect against forgery; we do not use advertising cookies.
2. How we use information
- to provide the Service, including signing you in and showing you your workspace;
- to manage subscriptions, trials, invoices and payments;
- to send service messages, such as trial reminders, invitations and billing notices;
- to keep the Service secure, prevent misuse and fix problems;
- to respond to support requests; and
- to meet our legal obligations.
We do not sell personal information, and we do not use your workspace content to train AI models.
3. Who we share information with
We use a small number of service providers (sub-processors) to run Citepool:
| Provider | Purpose | What they receive |
|---|---|---|
| Stripe | Payments and invoicing | Billing contact details, card details, subscription and user count |
| Microsoft Azure | File storage | PDFs and files you upload |
| Microsoft, Google and Apple | Sign-in | The sign-in request; they return your name and email to us |
| Anthropic or OpenAI (only if your workspace connects its own API key, and only the one you choose) | In-app AI: answering questions, checking citations, reading PDF details | The question and the relevant passages from your library’s PDFs; processed under your organisation’s own Anthropic or OpenAI account |
| Your AI assistant (e.g. Anthropic Claude, OpenAI ChatGPT, Microsoft Copilot), if you connect one | Answering your requests using your library | Only what the assistant requests from Citepool on your behalf; governed by your agreement with that provider |
| Crossref | DOI lookups | Only the DOI you look up — no personal information |
| [Hosting and database provider] | Application hosting and database | Account information, workspace content and logs |
| [Email provider] | Sending service emails | Name and email address |
Within a workspace, other members can see your name, email and the content you add. We may also disclose information if required by law, or to a buyer of our business, subject to this policy.
4. Overseas disclosure
Some of our providers store or process information outside Australia, including in the United States and other countries where they operate. We take reasonable steps, including contractual protections, to ensure they handle personal information consistently with the APPs.
5. How we protect information
- Data is encrypted in transit using TLS.
- PDFs are stored privately and are only accessible through short-lived signed links issued to signed-in members of the workspace.
- Access to a workspace is controlled by roles (owner, admin, member).
- Sign-in is handled by Microsoft, Google or Apple, so there are no Citepool passwords to be stolen.
- Access to production systems is limited to people who need it.
No system is perfectly secure. If we become aware of a data breach likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
6. How long we keep information
We keep account and workspace information while your workspace is active. After a workspace is cancelled we keep it for a limited period so it can be restored or exported, then delete it. We keep billing records for as long as Australian tax law requires.
7. Your organisation’s role
If you use Citepool through your employer or another organisation, that organisation controls the workspace and its content. Some requests — for example, to delete content from a shared library — may need to go to your workspace owner.
8. Access and correction
You can view and update most of your information in the app. You may also ask us for access to, or correction of, the personal information we hold about you by contacting us below. We will respond within a reasonable time, usually 30 days.
9. Complaints
If you have a concern about how we have handled your personal information, please contact us first and we will try to resolve it. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
If you are in the UK, European Union or elsewhere
We process personal information to provide the Service under our contract with your organisation, and for our legitimate interests in securing and improving it. Depending on where you live — for example under the GDPR or UK GDPR — you may have rights to access, correct, delete, restrict or object to processing of your personal information, and to receive a copy of it in a portable format. Contact us to exercise them. You may also complain to your local data protection authority.
Your workspace owner (usually your employer) controls the library and decides who can use it; for that content we act on their behalf. Business customers can request a data processing agreement by contacting us.
10. Changes to this policy
We may update this policy from time to time. We will post the new version here with a new “last updated” date, and tell you by email or in the app if a change is significant.
11. Contact us
Privacy Officer, [Company legal name]
[Registered address]
Email: [Privacy contact email]
See also our Terms of Service.