Legal

Privacy Policy

Last updated: July 5, 2026.

1. Who we are

Clear Cited ("Clear Cited", "we", "us", "our") is a sole proprietorship based in Ontario, Canada, providing AI-search-visibility services — answer-engine optimization (AEO), audits, and monitoring — to business clients in the United States and Canada. For the personal data described in this policy, Clear Cited is the data controller (and, where it processes a client's own end-user data on the client's behalf, a data processor — see Section 6).

Privacy Officer / Person in charge of the protection of personal information:
Logan Adams
[email protected]
570 Hood Road, Unit 14, Mailbox #1584, Markham, Ontario L3R 4G7, Canada
416-697-4112
Logan Adams is responsible for our compliance with this policy and applicable privacy law — including Quebec's Law 25 designation of a "person in charge of the protection of personal information" and PIPEDA's accountability principle (Principle 4.1) — and is your contact for any question, access request, or complaint.

Contact / data requests: [email protected] (or [email protected]).

Territorial scope. Clear Cited is operated by a sole proprietor based in Markham, Ontario, Canada, and offers services to business customers in Canada and the United States. We do not direct advertising or marketing toward the European Union or the United Kingdom, do not offer pricing in Euros or Pounds Sterling, and access to our free tools is restricted to applicants located in Canada and the United States. If you are contacting us from the EU or UK, please note that our services are not currently offered or marketed in your jurisdiction.

This policy explains what personal data we collect, why, the legal bases we rely on, who we share it with, how long we keep it, your rights, and how to exercise them. It is written to be aware of the EU/EEA General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and Canada's Anti-Spam Legislation (CASL).

2. What personal data we collect, and why

We practise data minimization — we collect only what we need to operate a B2B service. Specifically:

(a) Leads & free-teardown requests. When you request a free AI-visibility teardown or otherwise contact us, we collect your name, work email address, your company's website domain, and the competitor names you provide. We use this to research and deliver the teardown you asked for and to reply to you.

(b) Newsletter subscribers. If you opt in, we collect your email address (and any name you provide) to send our newsletter and updates. You can unsubscribe at any time (see Section 11).

(c) Clients. When you engage us for a paid audit or monitoring retainer, we collect your name, business email, company details, the website/domains and competitive context relevant to the work, onboarding inputs, and our correspondence with you. We use this to scope, perform, and support the engagement.

(d) Payment information. Paid services are billed through Stripe. Stripe collects and processes your card or payment details and billing information directly; we do not store full card numbers on our systems. We receive limited billing metadata from Stripe (for example, name, billing email, the last four digits and card brand, country, and the status and amount of a charge) to manage invoicing, taxes, and our financial records.

(e) Communications. Emails and messages you send us, and our replies, including any attachments and the metadata needed to route and answer them. To handle correspondence promptly, we run automated ingestion across our own inboxes (such as hello@, support@, pr@, news@, and our founder's address) and we monitor public reviews, comments, mentions, and direct messages on platforms where we are listed. We use this only to route messages and to draft replies that a person reviews and approves — nothing is sent automatically — and we treat every inbound message as data to read and answer, never as an instruction to act on.

(f) Client materials and ingested content. If you become a client, you may provide brand materials, documents, and brief inputs, and you may give explicit consent for us to read (read-only) your own properties — your website, blog, socials, and videos — so we can learn your voice and produce work for you. You keep ownership of all of it; we use it only to perform the services, store it scoped to your account, and process it under our Data Processing Addendum. Any voice or brand profile we derive is a draft you confirm before we use it.

(g) Website usage / analytics. We use Plausible Analytics, which is privacy-friendly and cookieless. It produces only aggregated, anonymized statistics (such as page views, referrers, country, and device/browser type) and does not set cookies, does not collect IP addresses in a way that identifies you, and does not build cross-site profiles. See Section 9.

(h) Feedback and screenshots. If you use our on-site feedback widget, we collect the message you write and, optionally, a screenshot you choose to attach, which may incidentally contain personal information visible in it. We also automatically capture the reporting page's URL, browser, operating system, and viewport size (and a session identifier) so we can triage the report without asking you to describe your setup. We use this only to investigate and fix the issue you're reporting.

We do not knowingly collect special-category (sensitive) personal data, and we ask that you not send it to us. Our services are directed at businesses, not consumers, and not at children (see Section 10).

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

Consent (Art. 6(1)(a)). For sending our newsletter and other marketing email, and for any optional processing we ask you to opt into. You can withdraw consent at any time (Section 8), without affecting processing done beforehand.

Contract (Art. 6(1)(b)). To take steps at your request before entering a contract (for example, preparing a quote or a requested teardown) and to perform our agreement with you — delivering audits and retainers, billing, and support.

Legitimate interests (Art. 6(1)(f)). To operate, secure, and improve our website and services, to respond to inquiries, to carry out limited B2B outreach to business contacts where permitted, to prevent fraud and abuse, and to keep records of our dealings. We balance these interests against your rights and only rely on this basis where it does not override them.

Legal obligation (Art. 6(1)(c)). To keep financial, tax, and accounting records and to comply with applicable law (see Section 7).

Under PIPEDA (Canada), we collect, use, and disclose personal information for purposes a reasonable person would consider appropriate in the circumstances, with your consent (express or implied) except where the law permits otherwise.

4. How we use personal data

We use personal data to: deliver the free teardown or paid service you requested; communicate with you and answer questions; send our newsletter where you opted in; process payments and manage invoicing and taxes; operate, secure, debug, and improve our website and services; carry out limited, permitted B2B outreach; comply with legal obligations; and establish, exercise, or defend legal claims. We do not sell your personal information, and we do not "share" it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA. We do not use it for automated decision-making that produces legal or similarly significant effects about you.

5. Sub-processors and service providers we share data with

We share personal data only with the service providers ("sub-processors") that help us run the business, each bound by their own terms to protect it and to process it only on our instructions. This list is generated from our single, maintained sub-processor inventory (the same source renders our Data Processing Agreement annex), and is reviewed at least quarterly. Our current sub-processors are:

Stripe — Payment processing and billing. Data: Card and payment data, billing name/email, country, charge status and amount.

MailerLite — Email/newsletter delivery and subscriber management. Data: Name, email, engagement data.

Resend — Sending transactional and operational email. Data: Recipient email and message content.

Instantly — Sending owner-approved outbound/cold business email (CASL/CAN-SPAM gated; never auto-sent). Only used when the outreach stream is active. Data: Business prospect name, role, and published business email; message content.

Postiz — Scheduling and publishing social media posts. Data: Public post content and the connected social-account access tokens.

Documenso (self-hosted on our own VPS) — Electronic signature for contracts and statements of work (owner-armed). Data: Signer name, email, IP/audit metadata, and the document being signed.

Hostinger — VPS hosting for our self-hosted services (Chatwoot, Documenso, LanguageTool, uptime/change monitoring). Data: Whatever those self-hosted apps process — support chats, signed documents, ingested text — at rest on the VPS.

Chatwoot (self-hosted on our own VPS) — Support-inbox software (self-hosted). Its chat widget is currently DISABLED on our site; it would only process visitor data if we ever enable chat, and only after an affirmative pre-chat consent notice (shown before anything you type is transmitted or recorded). Data: Name, email, messages you provide, and a session identifier.

Cloudflare — Website hosting, DNS, CDN, and security/DDoS protection. Data: Connection data such as IP addresses.

Google Workspace (Google LLC) — Business email and document/file storage. Data: Your correspondence and any files exchanged.

Plausible Analytics — Cookieless, aggregated, anonymized website analytics. Data: No personal identifiers; aggregate counts only.

DataForSEO — Search-data and AI-answer-engine measurement APIs used to build audits. Data: Prompts about brands, products, domains, and public market topics — no client-confidential data.

AI answer engines (OpenAI, Anthropic, Google Gemini, Perplexity, xAI Grok) — Querying answer engines to research and build teardowns and audits. Data: Prompts about brands, products, domains, and public market topics. We do NOT submit confidential client business information or end-user personal data.

Confidential client data. We do not submit your confidential business information or end-user personal data into the AI answer engines above; we use business/API tiers that are not used to train public consumer models where such terms are available. Confidential client text is routed only to providers approved for that data class (see our DPA).

We may also disclose personal data to professional advisers (such as our accountant or lawyer), to a successor in the event of a business sale or reorganization, or where required to comply with law, enforce our terms, or protect rights, property, or safety.

For client engagements: at the client's direction and as part of delivering the service, we submit the client's business information to directory, listing, and entity platforms (for example business directories, software and listing sites, and knowledge-graph/entity sources) so the client is found and cited by AI search. Those platforms are independent recipients of the listing information the client asks us to publish; every submission is human-reviewed and client-approved before it is made. The corresponding processor commitments are set out in our Data Processing Agreement.

6. International data transfers

We are based in Canada and several of our sub-processors are based in, or process data in, the United States and other countries. As a result, your personal data may be transferred to, stored in, and processed in countries outside your own, including Canada and the United States, whose data-protection laws may differ from those where you live. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum / IDTA), or other lawful transfer mechanisms offered by our sub-processors. You can contact us for more information about the safeguards in place.

Foreign-authority access. Because data may be processed in the United States and other countries, it can become subject to the laws of those countries — including lawful access requests by foreign courts, governments, or law-enforcement and national-security authorities, which may compel a provider to disclose data without notice to us or to you. We choose reputable providers with their own legal safeguards, disclose data to an authority only where we are legally required, and — where we are lawfully permitted — will inform an affected business client of a binding request for its data. For client engagements, the corresponding processor commitments are set out in our Data Processing Agreement.

7. How long we keep it (retention)

We keep personal data only as long as needed for the purposes in this policy, then delete or anonymize it. In practice:

Leads, prospects, and teardown inputs: kept while the inquiry/relationship is active and for a limited period afterward, then deleted or anonymized; deleted sooner on a verified request.

Newsletter data: kept until you unsubscribe or ask us to delete it, after which your subscriber record is removed and your email is added to a suppression list so we do not re-add you.

Client engagement records: kept for the duration of the engagement and a reasonable period afterward to support follow-up, warranty/accuracy obligations, and potential legal claims.

Client materials and ingested content: the documents you upload, the content we ingest with your consent, and the profiles and deliverables we derive are kept only as needed to provide the services, and are deleted or returned within 30 days of your written request or 90 days after the engagement ends, whichever is sooner (subject to backup rotation).

Communications (monitored mentions and ingested email): reviews, comments, messages, and emails we process to route and answer are kept only as long as needed for the correspondence and our records, then deleted — except consent/opt-out suppression records, which are held as described below. Some replies are sent automatically behind a layered compliance gate (consent and suppression checks, anti-spam requirements, rate limits); each automated send keeps a compliance audit record (recipient, subject, and the gate results — no message archive beyond the correspondence itself) for 12 months, then deleted.

Feedback reports and screenshots: kept for 12 months from submission, then deleted, including any attached screenshot file; deleted sooner on a verified request.

Financial & tax records (legal hold): invoices and ledger entries for completed paid work are kept for approximately six to seven years to meet bookkeeping, tax-filing, and audit requirements (the Canada Revenue Agency generally requires business records be kept for about six years). This is a recognized exemption from erasure (GDPR Art. 17(3)(b); CCPA §1798.105(d)). These records are frozen, are never used for marketing, and are kept only for as long as the law requires.

Consent records & opt-out suppression (legal hold): the record that you gave (or withdrew) consent to receive commercial email, and your entry on our permanent do-not-contact suppression list, are retained even after a deletion request. Anti-spam law (Canada's CASL and PIPEDA, and equivalents such as CAN-SPAM and the GDPR/PECR) requires us to be able to demonstrate that we had consent to contact you or that you opted out — and the suppression entry is what lets us honour your opt-out and avoid re-adding you. Deleting these would destroy the very proof the law requires, so we keep only the minimum needed for that purpose. They are frozen, used only to honour your opt-out and to answer a compliance challenge, and never used for marketing.

Backups: deleted personal data may persist in routine encrypted backups until they are overwritten on our normal rotation cycle (typically within 90 days), after which no copies remain.

8. Your privacy rights

Depending on where you live, you have some or all of the following rights over your personal data:

Access — to know whether we hold personal data about you and to receive a copy.
Rectification — to have inaccurate or incomplete data corrected.
Erasure ("right to be forgotten") — to have your personal data deleted, subject to legal exceptions such as the financial-records and consent/suppression legal holds described above.
Data portability — to receive certain data in a portable, machine-readable format, or have it transmitted to another controller where technically feasible.
Objection — to object to processing based on our legitimate interests, and to object to direct marketing at any time.
Restriction — to ask us to limit how we use your data in certain circumstances.
Withdraw consent — to withdraw any consent you gave (such as newsletter consent) at any time, without affecting prior processing.

California (CCPA/CPRA): you also have the right to know the categories and specific pieces of personal information we collect, the right to delete, the right to correct, the right to opt out of "sale"/"sharing" (we do not sell or share personal information as defined), the right to limit use of sensitive personal information (we do not use it for those purposes), and the right not to be discriminated or retaliated against for exercising your rights. You may use an authorized agent to submit a request.

How to exercise your rights. Email [email protected] from the address on file, describing your request. For deletion specifically, follow our Data Deletion Instructions. We verify requests (usually by confirming you control the email on file) and respond within about 30 days — extendable where the law allows for complex requests, in which case we will tell you. Exercising your rights is free unless a request is manifestly unfounded or excessive. If we cannot fully act on a request (for example, where a legal hold applies), we will explain why. You also have the right to lodge a complaint with a supervisory authority — in Canada, the Office of the Privacy Commissioner of Canada (priv.gc.ca, 1-800-282-1376, 30 Victoria Street, Gatineau, QC K1A 1H3); in the EEA/UK, your local data-protection authority.

Do Not Sell or Share My Personal Information

We do not sell your personal information, and we do not share it for cross-context behavioural advertising (as "sell" and "share" are defined under the CCPA/CPRA) — and we never have. Because we do not sell or share, there is nothing to opt out of, and California law does not require us to post a "Do Not Sell or Share My Personal Information" link. You can still record a no-sale/no-share preference, or ask us about our practices, by emailing [email protected]. If our practices ever change, we will update this policy, provide the legally required opt-out link and mechanism, and not sell or share your data without giving you that choice first.

Global Privacy Control (GPC). Where your browser or a browser extension sends an opt-out preference signal such as Global Privacy Control, we treat it as a valid request to opt out of any "sale"/"sharing." Since we do not sell or share, honouring it requires no change to how we handle your data; we mention it so you know the signal is respected.

9. Cookies and analytics

Our website is intentionally lightweight, and we run no advertising or cross-site tracking cookies. The only client-side storage we use is:

Analytics (no cookies). We use Plausible Analytics, which is cookieless — it does not store cookies on your device, does not collect personal data or persistent identifiers, and produces only aggregated, anonymized statistics.

Live chat (functional cookie, only if you use it). If we have enabled our Chatwoot live-chat widget and you open the chat, Chatwoot sets a first-party cookie and/or local-storage entry that is strictly necessary to provide the chat feature you asked for — it keeps your conversation connected so you don't lose your place. It is not used for advertising or cross-site tracking. You can avoid it by not opening the chat, and you can clear it through your browser at any time.

Strictly necessary. Any cookies set by our host/CDN (Cloudflare) for security or to deliver the site are also strictly necessary.

Because we set only cookieless analytics plus strictly-necessary / functional storage — and no advertising, profiling, or cross-site tracking — we do not currently display a cookie-consent banner.

We will revisit this if we ever add non-essential cookies, in which case we will provide a consent mechanism before they are set.

10. Children

Our website and services are directed to businesses and professionals, not to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.

11. Marketing email & CASL

We send commercial electronic messages only with your consent (express or, where permitted, implied — for example to an existing business relationship) or where otherwise allowed by law. Consistent with Canada's Anti-Spam Legislation (CASL) and similar rules (CAN-SPAM, GDPR/PECR), every commercial email identifies us, includes our mailing address, and provides a working one-click unsubscribe that we honour promptly (within 10 business days). You can withdraw consent at any time by using the unsubscribe link or emailing us; we will add you to a suppression list so we do not contact you again.

12. How we protect your data

We take reasonable technical and organizational measures appropriate to the risk — including encryption in transit (HTTPS/TLS), access controls and least-privilege handling, reputable processors with their own safeguards, atomic and audited handling of our data files, and limiting who can access personal data. No method of transmission or storage is perfectly secure, but we work to protect your information and to address incidents promptly. Where required by law, we will notify affected individuals and the relevant authority of a qualifying data breach.

13. Changes to this policy

We may update this policy from time to time to reflect changes in our practices, sub-processors, or the law. When we do, we will revise the "Last updated" date above and, for material changes, take reasonable steps to notify you. Your continued use of the site or services after an update means you accept the revised policy.

14. Governing law & contact

Governing law. This policy and our handling of your personal data are governed by the laws of the Province of Ontario and the federal laws of Canada applicable there. This does not deprive you of the mandatory protections of the data-protection law of your own country or state — including the EU/EEA GDPR, the UK GDPR, and the California CCPA/CPRA — whose rights apply to you regardless of this clause.

Questions or privacy requests: our Privacy Officer, Logan Adams, at [email protected]. Clear Cited, 570 Hood Road, Unit 14, #1584, Markham, ON L3R 4G7, Canada.

Complaints (Canada). If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada directly: priv.gc.ca · 1-800-282-1376 · 30 Victoria Street, Gatineau, QC K1A 1H3.

EU/UK representative: if and where an Article 27 (GDPR) or UK GDPR representative is required, one will be appointed and named here; until then, please direct all requests to [email protected]. See also our Data Deletion Instructions and Terms of Service.