Citepool

Privacy Policy

This policy explains how [Company legal name] (ABN [ABN]) (we, us, our) collects, uses, discloses and protects personal information when you use Citepool, including our website, web app and Microsoft Word add-in. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. Information we collect

Account information

When you sign in with Microsoft, Google or Apple, we receive your name, verified email address and, if available, profile picture. We do not receive or store your Microsoft, Google or Apple password, and Citepool has no passwords of its own.

Workspace content

References, PDFs, notes, custom fields, citation styles and other material you or your team add. This content may include personal information about authors or others, which your organisation controls.

Web copies and the browser button

When you ask Citepool to save a copy of a web page (or add one with the “Save to Citepool” browser button), our servers visit that address and store the page or PDF in your workspace. The browser button sends us the address and citation details of a page only when you click Save — it does not track your browsing.

Billing information

The workspace owner’s billing name, email, address and the number of users. Card details are collected and stored by Stripe, not by us; we only see limited details such as the card brand, last four digits and expiry.

Usage and technical information

Log data such as IP address, browser and device type, times of access and actions taken, which we use to run, secure and troubleshoot the Service. We use cookies that are needed to keep you signed in and to protect against forgery; we do not use advertising cookies.

2. How we use information

We do not sell personal information, and we do not use your workspace content to train AI models.

3. Who we share information with

We use a small number of service providers (sub-processors) to run Citepool:

ProviderPurposeWhat they receive
StripePayments and invoicingBilling contact details, card details, subscription and user count
Microsoft AzureFile storagePDFs and files you upload
Microsoft, Google and AppleSign-inThe sign-in request; they return your name and email to us
Anthropic or OpenAI (only if your workspace connects its own API key, and only the one you choose)In-app AI: answering questions, checking citations, reading PDF detailsThe question and the relevant passages from your library’s PDFs; processed under your organisation’s own Anthropic or OpenAI account
Your AI assistant (e.g. Anthropic Claude, OpenAI ChatGPT, Microsoft Copilot), if you connect oneAnswering your requests using your libraryOnly what the assistant requests from Citepool on your behalf; governed by your agreement with that provider
CrossrefDOI lookupsOnly the DOI you look up — no personal information
[Hosting and database provider]Application hosting and databaseAccount information, workspace content and logs
[Email provider]Sending service emailsName and email address

Within a workspace, other members can see your name, email and the content you add. We may also disclose information if required by law, or to a buyer of our business, subject to this policy.

4. Overseas disclosure

Some of our providers store or process information outside Australia, including in the United States and other countries where they operate. We take reasonable steps, including contractual protections, to ensure they handle personal information consistently with the APPs.

5. How we protect information

No system is perfectly secure. If we become aware of a data breach likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

6. How long we keep information

We keep account and workspace information while your workspace is active. After a workspace is cancelled we keep it for a limited period so it can be restored or exported, then delete it. We keep billing records for as long as Australian tax law requires.

7. Your organisation’s role

If you use Citepool through your employer or another organisation, that organisation controls the workspace and its content. Some requests — for example, to delete content from a shared library — may need to go to your workspace owner.

8. Access and correction

You can view and update most of your information in the app. You may also ask us for access to, or correction of, the personal information we hold about you by contacting us below. We will respond within a reasonable time, usually 30 days.

9. Complaints

If you have a concern about how we have handled your personal information, please contact us first and we will try to resolve it. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

If you are in the UK, European Union or elsewhere

We process personal information to provide the Service under our contract with your organisation, and for our legitimate interests in securing and improving it. Depending on where you live — for example under the GDPR or UK GDPR — you may have rights to access, correct, delete, restrict or object to processing of your personal information, and to receive a copy of it in a portable format. Contact us to exercise them. You may also complain to your local data protection authority.

Your workspace owner (usually your employer) controls the library and decides who can use it; for that content we act on their behalf. Business customers can request a data processing agreement by contacting us.

10. Changes to this policy

We may update this policy from time to time. We will post the new version here with a new “last updated” date, and tell you by email or in the app if a change is significant.

11. Contact us

Privacy Officer, [Company legal name]
[Registered address]
Email: [Privacy contact email]

See also our Terms of Service.