Privacy Policy
Version of 30 July 2026. The Polish version at/pl/polityka-prywatnosci/ is the binding version in case of any discrepancy.
1. Data controller
The controller of personal data is ecopywriting.pl Karol Leszczyński, Papowo Biskupie 119/18, 86-221 Papowo Biskupie, Poland, VAT ID: 9562203948. For any data protection matter contactcontact@cytado.com. This policy coverscytado.com together with the user panel.
2. What data we process
- Account — email address, password (stored only as a bcrypt hash — we never see it), your chosen interface language; when signing in with Google, also your Google account identifier. Verification codes sent by email are stored only as hashes and only until used or expired.
- Project content — the thesis topic you enter, an optional outline, and paragraphs pasted into the source finder. This is the substance of your work — we treat it as confidential and process it solely to provide the service (finding and matching sources, see section 4). We do not publish it and do not share it with other Users.
- Bibliography submitted for checking — the list of sources you paste or upload (text file or PDF). We read only the text of the bibliographic entries; we do not retain the uploaded file after the analysis. We treat this content as confidential and process it solely to verify the sources (see section 4).
- Result history — we store the results of paragraph source searches and bibliography checks together with the query, so you can return to them in the panel and so a repeated query does not have to be computed again.
- AI request log — for diagnostics and cost accounting we store the content of requests sent to the AI model (which may include the topic, outline and paragraphs above) and the model's responses, together with costs. The log is accessible only to the Service administrator and is deleted together with your account.
- Payments — handled by Stripe, which is the controller of payment data (we never see or store card numbers). We receive payment confirmation and the data required for accounting.
- Correspondence — the content of messages from the contact form together with your email address and, if you request an invoice, the billing details you provide (name, address, VAT ID).
- Transactional email — verification codes for registration and password resets, sent via Amazon SES. We do not send marketing email.
- Technical data — standard server logs (IP address, request time) and usage counters, including a counter of free searches tied to an IP address — for security, service stability and enforcing limits.
- Analytics data — only after you consent in the cookie banner (section 7).
3. Purposes and legal bases
- creating and running your account, finding and matching sources, generating citations, exports, result history — performance of a contract (Article 6(1)(b) GDPR);
- settlements and sales documents — legal obligation (Article 6(1)(c) GDPR);
- handling correspondence and complaints — performance of a contract and the controller's legitimate interest (Article 6(1)(b) and (f) GDPR);
- service security, anti-abuse limits (including the per-IP counter), protecting forms against bots (reCAPTCHA), and the AI request log for diagnostics and defence against claims — the controller's legitimate interest (Article 6(1)(f) GDPR);
- traffic statistics — your consent (Article 6(1)(a) GDPR), which you may withdraw at any time in the cookie banner.
4. Recipients of data
We use the following providers:
- Amazon Web Services (AWS) — server infrastructure and transactional email delivery (Amazon SES);
- Stripe — payment processing (for payment data Stripe acts as an independent controller);
- Anthropic, PBC (USA) — provider of the artificial intelligence model. Anthropic receives the content necessary to deliver the service: the thesis topic, outline, pasted paragraphs, excerpts of analysed publications, and pasted or uploaded bibliography lists (to recognise the entries). This data is not used by Anthropic to train models (API without training retention);
- Academic databases and public registers — to find and verify sources we send them queries built from your thesis topic or from the bibliography entry being checked (without any data identifying you). These are: OpenAlex, Crossref, Semantic Scholar (Allen Institute for AI), CORE, Unpaywall, DOAJ, DOAB/OAPEN, Europe PMC, Google Books, Biblioteka Nauki (ICM, University of Warsaw), and for domain-specific sources — Statistics Poland (Local Data Bank), the Polish Parliament's legal act register, and case-law databases. These providers are established in the European Union, the United Kingdom and the United States;
- Serper (USA) — web search for publications; we send only search queries generated from the thesis topic or from the bibliography entry being checked (without any data identifying you);
- Text extraction service — the Provider's own infrastructure used to read the content and page numbering of publicly available documents; it processes document addresses and their content, not your personal data;
- Google — Google sign-in (at your choice), reCAPTCHA v3, and — subject to banner consent — traffic statistics in Google Analytics 4;
- Email hosting provider — operates the Provider's contact mailbox, which receives correspondence sent to the address in section 1.
We do not sell your data and do not share it with third parties for marketing purposes. Transfers outside the European Economic Area rely on the European Commission's adequacy decision (EU–US Data Privacy Framework) or standard contractual clauses.
5. How long we keep data
- account data, Projects and the AI request log — until you delete your account (you can do this yourself in the Account tab; deletion is immediate and irreversible);
- result history — until account deletion; for reusing a stored result we consider entries from the last 30 days;
- correspondence and billing details — for as long as needed to handle the matter, with accounting data kept for the period required by tax law;
- sales documents — 5 years from the end of the tax year (statutory requirement); payment history is also retained by Stripe;
- technical logs and limit counters — no longer than service security and limit accounting require;
- analytics data — according to the tool's retention setting (max. 14 months).
6. Your rights
You have the right to access your data, rectify it, erase it, restrict processing, port it, object to processing based on legitimate interest, and withdraw consent at any time. Requests can be sent to contact@cytado.com. You also have the right to lodge a complaint with a supervisory authority — in Poland, the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl) — or with the authority in your EU country of residence.
Providing data is voluntary, but without an email address you cannot create an account, and without a thesis topic we cannot search for sources. We do not take decisions about you based solely on automated processing that would produce legal effects concerning you or similarly significantly affect you. Automated assessment applies to publications (how well they match a topic), not to you as a person.
7. Cookies, localStorage and Consent Mode v2
- Essential — the session cookie for signed-in users, protection of Google sign-in (state), and storage of your cookie choice, language and theme preference. The Service does not work without them; they do not require consent.
- Analytics — only with your consent. We operate in Consent Mode v2: analytics is disabled by default and no analytics cookies are stored until you click “Accept” in the banner. You can withdraw consent at any time (“Cookie settings” in the footer). A choice made on the public site also applies inside the panel.
- reCAPTCHA — Google reCAPTCHA v3 protects the sign-in and registration forms and may set its own cookies needed to tell humans from bots.
8. Security
Connections to the Service are encrypted (HTTPS). Passwords are stored only as bcrypt hashes and sessions in a cookie that is not accessible to scripts. Access to the database and the request log is limited to the Service administrator.
9. Changes and contact
We will announce material changes to this policy in the Service. For data protection matters write to contact@cytado.com. The rules of the service itself are set out in the terms of service.