Why the register matters to you. Without a per-provider breakdown a reviewer cannot approve the purchase, and the deal stalls at a risk nobody can size. Each row below is the behaviour the CiteAngle code implements, sealed to the same discipline as our published figures, which is why your reviewer can approve this from the page instead of from a questionnaire.
A second cost falls on you, not on us. Without a named list of processors, you cannot meet your own compliance obligations by pointing at our page. The work of mapping our subprocessors lands on your team instead. That is the sort of hidden cost that shows up after signature.
Most privacy notices are written to be defensible. This one is written to be checked, and the difference shows up in section 3. A measurement service is, mechanically, a service that sends your business data through other companies' systems — search APIs, answer engines, analytics, payments. The question your reviewer actually needs answered is not whether we care about privacy. It is: which provider receives what, where does it sit, how long does the raw payload stay, and what happens if we decline this one? So each of those has its own column, per provider, and declining an optional connection leaves the rest of the measurement unchanged.
The retention periods below are the ones the code implements, not the ones a template suggested. Where an optional credential is used only while a screen is being handled, that is what it says; where a raw response is kept for diagnostics and deleted on a clock, the clock is printed. A vendor asking you to trust its numbers should be the first one to show its working, and this page is part of the same promise as the claims registry and the published measurement protocol.
1. Controller and scope
ARTIFEX Co., Ltd. (Korean name: 주식회사 아티펙스; Korean business registration number 239-88-03748) controls the personal information covered by this notice. The representative is Jungyeup Sim. The controller’s address is 1006, 391 Gangseo-ro, Gangseo-gu, Seoul, 07803, Republic of Korea, and its telephone number is +82-10-6342-7116.
CiteAngle is a B2B measurement and execution service. A business email, employee name, or account event can still be personal information and receives the protections in this notice. The service is not directed to children or anyone under 14.
2. Notice at collection: data and purposes
- Account and contact: email, one-way password hash, email-verification record, name, company and role; when Google sign-in is chosen, Google sub, verified email, name, and profile image — account creation, authentication, security, and contact verification.
- Inquiry and project: the full inquiry, reply address, brand, domain, industry, selected country and region, exact queries, target and competitor domains, supplied materials, measured responses, and review history — scoping, quoting, measurement, adjudication, and delivery.
- Transaction: proposal, agreement, amount, currency, payment status, transaction identifier, refund, invoice, and tax evidence — contract performance, accounting, disputes, and required records.
- Operations and security: connection IP, timestamp, path, browser or device characteristics, error and security events — delivery, abuse prevention, incident investigation, and availability.
- Choices and evidence: manually selected region, notice version, terms/privacy acceptance, timestamp, and separate marketing choice — applying and proving the choice.
- Web usage analytics: first-party cookie identifiers (
_ga,_ga_*), page URLs and referrers, usage events, browser and device class, and coarse IP-derived location — usage statistics and service improvement (details in sections 3 and 4). - Advertising: only while you have granted the advertising choice — cookie identifiers (
_fbp,_fbc), page URLs and referrers, browser and device type, IP address, and page-view and conversion events, all for measuring advertising performance and retargeting (details in sections 3 and 4).
Do not submit government identifiers, passwords, payment-card or bank data, health or biometric data, private customer lists, or personal information unnecessary for the project. CiteAngle does not claim to operate an automated PII detector. The current controls warn before submission and exclude sensitive content found during operational review or request a safe substitute.
3. Current provider, transfer, and choice register
US input first reaches CiteAngle’s primary hosting in Seoul, Republic of Korea. Only the exact query, public domain, market condition, or other minimum input required for a contracted measurement is then sent to the US-provider APIs listed in the register below. We do not sell personal information under any configuration. Sharing for cross-context behavioral advertising is governed by a separate advertising consent that is denied by default, and the one advertising tag on this site is the Meta Pixel, listed in the register below — loads only while that consent is stored and no opt-out preference signal is present; section 4 explains how that consent works.
| Status | Party and role | Data and purpose | Country and method | Retention and limits | Choice and impact | Basis |
|---|---|---|---|---|---|---|
| Active | Vultr · infrastructure processor operated by a US provider | Hosts account, inquiry, project and transaction databases, web requests, security logs, and backups | Primary storage and processing in Vultr’s Seoul, Korea region over HTTPS and controlled server access; limited international provider support or security access may occur. Vultr compliance information | Purpose-specific periods below; rotating infrastructure backups take about four weeks to age out | Required infrastructure; refusal prevents site, account, and report delivery | Requested steps and contract performance; secure service operation |
| Active | Resend · transactional and service-email processor | Recipient, reply-to, subject, and HTML body; HTML can contain the full inquiry or delivery notice | TLS from the Seoul server to Resend’s US-centered API and onward to the recipient mailbox. Resend DPA | Local terminal outbox payload is scrubbed once it is more than 30 days old. The Resend account’s open/click tracking and exact provider-side retention settings have not yet been verified; review precedes any reliance on tracking settings | Without an email address, automated quote and delivery notices are unavailable; an alternative channel may be agreed before contract | Responding to a request and performing the service contract |
| Active | Google-hosted operating mailbox · business-email processor | The full inquiry, sender and reply address, and any attachment later emailed to the operating team for review and response | Delivery through Resend to Google’s global mail infrastructure. The current Workspace data-region and DPA account settings have not yet been verified | Managed through the manual account-deletion and legal-record workflow when the inquiry closes or deletion is approved; provider deletion and backup behavior follows Google’s retention explanation | Refusal means email inquiry cannot be used; a minimum-data alternative channel can be agreed before contract | User-requested pre-contract steps and business communication |
| Optional | Google OAuth · optional authentication processor | Google sub, verified email, name, and profile image for account creation and login. OAuth access, refresh, and ID tokens are not retained in the database after the callback | TLS between the browser and Google and between the Seoul server and Google OAuth endpoints. Google OAuth documentation | Local account data remains until you close the account in Account settings or ask us to delete it; Google-side records follow the user’s Google account and provider policy | Email and password registration remains available if Google sign-in is declined | User-initiated optional authentication and account service |
| Optional connection | Google Search Console · customer-granted read access to search performance | For the properties a customer picks on the connect screen, we read search performance (queries, pages, clicks, impressions, average position) and the property list, then place those figures in that customer’s report. Access is read-only, so site settings stay as they are, and properties left unchecked stay unread | TLS from the Seoul server to the Google Search Console API. searchAnalytics.query documentation | Under the default configuration the credential is used only while that screen is being handled and is not stored. The raw response Google returns is kept for diagnostics and deleted after 30 days; figures published in a report follow the contract retention term. A customer can disconnect from the same screen at any time, and disconnecting withdraws the grant on Google’s side as well | Declining leaves every other measurement and report unchanged | User-initiated optional connection and performance of the contracted report |
| Active | Google Analytics 4 (Google LLC) · web-usage analytics processor | First-party cookie identifiers (_ga, _ga_*), page URLs and referrers, usage events, browser and device class, coarse IP-derived location (GA4 does not log or store IP addresses) — usage statistics and service improvement | TLS from the visitor’s browser to Google collection endpoints; processed in the United States. Google privacy policy · How Google uses partner-site data | Analytics data is retained in Google Analytics for 14 months; the _ga cookie lives in the browser for up to 2 years. Advertising features (Google Signals, remarketing) are off and ad storage is permanently denied in every region | Refusing never limits any page — decline in the EEA/UK/Switzerland banner, block or delete cookies, or install the GA opt-out add-on. Before consent or after refusal only cookieless, identifier-free pings are sent | Usage statistics for service improvement — consent in the EEA, UK, and Switzerland; notice through this policy elsewhere |
| Active | Microsoft Clarity (Microsoft Corporation) · web-usage behavior analytics processor | Cookie identifiers (_clck, _clsk), page navigation, click and scroll behavior, browser and device class — heatmaps and session replay for usability improvement. Sensitive content such as input fields is masked by Clarity’s default masking | TLS from the visitor’s browser to Microsoft collection endpoints (clarity.ms); processed in the United States. Microsoft privacy statement | Session recordings are retained for 30 days from recording; sampled and aggregated data for up to 13 months (Clarity retention FAQ) | Refusing never limits any page — block or delete cookies in your browser at any time. Private surfaces (dashboard, report URLs, operations console) carry no Clarity tag | Usage-behavior analytics for service improvement — notice through this policy |
| Active on consent | Meta Pixel · your counterparty is either Meta Platforms Ireland Limited or Meta Platforms, Inc., and which one depends on where you are, under Meta’s own terms (linked in the next column), which are the authority on that split · advertising measurement and retargeting tag | Cookie identifiers (_fbp, _fbc), the page URL you are on, the referring URL, browser and device type, IP address, and page-view and conversion events, used for measuring how our advertising performs and showing our ads again to people who have already visited | TLS from the visitor’s browser to Meta collection endpoints (connect.facebook.net, www.facebook.com); processed in the United States. Meta Privacy Policy · Meta Business Tools Terms. The tag is issued for this site only and is never loaded before an explicit advertising choice is stored in the browser | Meta sets the expiry of both cookies and does not publish it, so no duration is stated here (checked 2026-08-13 against Meta’s cookie policy and its _fbp/_fbc developer page); clearing cookies in the browser removes them immediately. _fbc is written only when a visit arrives from an ad click. Retention on Meta’s side follows the Meta Privacy Policy, and we keep no separate copy of what this tag sends. No server-side transfer of conversion data runs today. Provider-side retention is not represented as verified | Refusing never limits any page. The choice is denied by default, can be withdrawn in the controls in section 4 at any time, and an opt-out preference signal keeps it denied. You can also block or delete cookies in your browser or change your Meta ad settings. Private surfaces (dashboard, report URLs, operations console) carry no advertising tag | Explicit stored advertising consent, the same rule in every region, never a notice-only basis |
| Active · server-local | MaxMind GeoLite2 · geolocation database supplier (not a personal-data processor) | The connection IP is matched against the GeoLite2 database file inside our Seoul server to propose a default measurement region and the first-visit language surface. The IP address is not sent to any external provider and raw IP is never stored in the result | The lookup runs locally on the Seoul, Korea server — no cross-border transfer of visitor data. The only traffic to MaxMind (US) is the weekly database update download, which carries our account credentials only. MaxMind GeoLite2 | The database file is replaced by the weekly update. The result is a convenience default only, never measurement evidence | The language switcher and manual region selection override the default at any time — a manual choice always wins; declining changes nothing else | Requested service operation — an on-server convenience default |
| Active measurement | OpenAI API · AI-search measurement processor | Exact measurement query, public brand and target domain, market conditions, and generated response; business contact details are not intentionally included | TLS from the Seoul server to the OpenAI API; processed and stored in the United States per the configured data-residency region; requests set store:false | API input and output are not used to train OpenAI models by default (opt-in only). store:false opts out of response storage but is not ZDR; abuse-monitoring logs are retained for up to 30 days and then deleted. OpenAI API privacy and retention | Declining removes OpenAI from the measurement and requires a revised scope and quote | Requested B2B measurement and contract performance |
| Active measurement and judging | Anthropic API · AI measurement and adjudication processor | Exact query and response, target and competitor domains; the judge also receives output from other providers for cross-provider adjudication | TLS from the Seoul server to the Anthropic API; data is stored in the United States, and inference may be routed across US, European, Asian, and Australian infrastructure | Inputs and outputs are not used for model training and are automatically deleted within 30 days by default (trust-and-safety review can extend this); CiteAngle does not represent that a separate ZDR agreement is active. Anthropic retention information | Declining removes Anthropic measurement and judging and requires a revised verification method | Contracted measurement and result verification |
| Active measurement | Perplexity API · AI-search measurement processor | Exact query and response with public brand and domain conditions | TLS from the Seoul server to the API of Perplexity AI, Inc., a US company | API prompts and responses are not retained (ZDR) and are not used for model training; billing and usage metadata is retained. Perplexity API privacy and security | Declining removes Perplexity from the measurement and requires a revised scope and quote | Requested B2B measurement and contract performance |
| Active measurement | xAI API · AI-search measurement processor | Exact query, public brand and domain conditions, and generated response | TLS from the Seoul server to the xAI API; processed in the United States, where xAI maintains its primary data centers; requests set store:false | Inputs and outputs are not used for model training without explicit permission. store:false is used but is not ZDR; requests and responses are stored for 30 days for abuse auditing and then deleted. xAI API security and retention | Declining removes xAI from the measurement and requires a revised scope and quote | Requested B2B measurement and contract performance |
| Active search measurement | SerpApi · search-result collection processor | Exact query, location such as country/city/state, portal parameters, and returned search results | TLS from the Seoul server to the API of SerpApi, LLC, a US (Texas) company; the hosting server region is not published; deliverable measurement uses no_cache=true | no_cache is a freshness setting, not a privacy or no-retention setting. Search Archive can retain a result for up to 31 days. Archive information. Separate ZeroTrace activation is not currently verified | Declining removes the affected Google, Bing, or other portal measurements and requires a revised scope and quote | Contracted regional search measurement |
| Conditional enrichment | YouTube Data API · public video-metadata enrichment | Sends only a public video ID already found in measurement to enrich public title, channel, and statistics; no account or inquiry data | TLS from the Seoul server to Google’s API. videos.list documentation | Local measurement-source period: 90 days for a free snapshot or up to five years for paid-audit evidence. Current provider-log account settings are not represented as verified | If declined or no key is configured, video enrichment is omitted and the core audit continues | Contracted public-surface measurement |
| Disabled now | Cloudflare · potential future CDN, security, and coarse-region processor | If enabled, the edge would process connection IP and request metadata and send only coarse country/region headers to origin; raw IP would not be stored in a location receipt | Cloudflare trusted headers are currently disabled — the current default comes from the server-local GeoLite2 lookup above and manual selection. Global edge processing can begin only when SNAP_GEO_PROXY_PROVIDER=cloudflare and SNAP_GEO_ORIGIN_LOCKED=true are both verified. Cloudflare DPA | Exact retention and account configuration will be disclosed before activation; no current Cloudflare location processing | Manual region selection remains available, so declining has no core-service impact | No current processing basis; if activated, service security and a requested coarse default |
| Onboarding; inactive | Paddle.com Market Limited (United Kingdom) · Toss Payments (Korea) | On activation: transaction identifier, amount, currency, payment and refund status | No live checkout screen and no API transfer today. US (USD) and Japan (JPY) online card checkout is being set up with Paddle.com Market Limited as merchant of record; that company is located in the United Kingdom, so once it is live this transfer is an overseas transfer of personal data. Korea: Toss Payments direct integration under review (KRW) | No activation until credentials, recorded legal/tax approvals, and provider-specific retention are finalized | No present impact; orders continue on the quote and invoice route after inquiry | No current processing basis; before activation we state the destination country, the provider’s data-protection posture, and your rights in the checkout notice, and we fix the contract basis for performance |
A mailbox provider selected by the user or the user’s employer receives email at that recipient’s direction. It is an independent recipient facility, not a processor selected or managed by ARTIFEX Co., Ltd. We may also disclose information under valid legal process, to protect rights and security, or in a business transfer with equivalent safeguards.
4. Region and language defaults, required cookies, and analytics
The default measurement region and the first-visit language surface are derived by matching the connection IP against the MaxMind GeoLite2 database inside our Seoul server. The lookup is server-local: the IP address is not sent to any external provider, and raw IP is never stored in the result. Language routing applies only to the first entry at the site root — a Korean connection stays on the Korean surface (/), Japan is guided to /jp/, and every other country to /en/; if the lookup fails we fall back to your browser's Accept-Language header, and with no signal at all the current Korean page is served. Search-engine and AI crawlers are excluded. When the region default cannot be confirmed, the form quietly stays on manual selection. CiteAngle does not request GPS or precise device-location permission, and a manual choice — the language switcher or your own region selection — always wins over any automatic default. A Cloudflare edge default could be used only after both trust settings and the origin lock above are verified. This product includes GeoLite2 data created by MaxMind (maxmind.com).
ca_state: random anti-forgery value for optional Google OAuth; 10 minutes and deleted after callback.ca_next: safe same-site return path after OAuth; 10 minutes and deleted after callback.ca_sess: login session containing email, expiration, and an HMAC signature; 30 days.ca_locale: your explicit language choice (kr·en·jp), stored for one year only when you click the language switcher — automatic routing never overrides it.
ca_state, ca_next, and ca_sess are HttpOnly, SameSite=Lax, and Path=/; Secure is set when the public base URL is HTTPS. ca_locale is a SameSite=Lax, Path=/ cookie written by your browser only when you click the language switcher; merely viewing a page never creates it, and deleting it simply means the site proposes a language from the connection country again. The first two are not created unless OAuth is used. Blocking the session cookie leaves public pages available but disables login.
For usage statistics we run Google Analytics 4 (Google LLC, US): first-party cookies _ga and _ga_* (browser lifetime up to 2 years), page URLs, referrers, usage events, browser and device class, and coarse IP-derived location (GA4 does not log or store IP addresses). Analytics data is retained for 14 months. Advertising features (Google Signals, remarketing, ad personalization) are off, and ad-storage consent is permanently denied in every region. Visitors from the EEA, UK, and Switzerland see a consent banner; before consent or after refusal no analytics cookie is set and only cookieless pings without user identifiers reach Google, which uses them for aggregate modeling. You can refuse in the banner, block or delete cookies in your browser, or install the Google Analytics opt-out add-on (tools.google.com/dlpage/gaoptout) at any time; refusing does not limit any page. Private surfaces — dashboard, report URLs, the operations console — carry no analytics tag.
For usability improvement we also run Microsoft Clarity (Microsoft Corporation, US): cookie identifiers _clck and _clsk, page navigation, click and scroll behavior, and browser and device class — used for heatmaps and session replay. Sensitive content such as input fields is masked by Clarity’s default masking. Session recordings are retained for 30 days and sampled/aggregated data for up to 13 months (Clarity retention FAQ). You can refuse at any time by blocking or deleting cookies in your browser; refusing does not limit any page. Cross-border details follow the Microsoft Clarity row in the register in section 3 above.
Scope note for the English pages you are reading: the two analytics services above are the ones that run here. The Korean-language pages at citeangle.com additionally run Naver Analytics (NAVER Corp., Republic of Korea) to measure Korean search referrals, and that tag is scoped to those pages. If you visit the Korean pages, the Korean privacy policy documents exactly what it collects and how to refuse it.
Advertising cookies and tags
An advertising cookie or a third-party advertising tag runs only while a separate advertising consent is stored, and that consent is denied by default. One advertising tag is configured on this site, the Meta Pixel, and it appears in the register in section 3; it runs only while that choice is granted, so before that there is no advertising cookie. We do not sell personal information under any configuration.
For advertising performance measurement and retargeting we run the Meta Pixel (your counterparty is Meta Platforms Ireland Limited or Meta Platforms, Inc. for everyone else; processed in the United States): cookie identifiers _fbp (Meta sets the expiry and does not publish it, so no duration is stated here) and _fbc (written only when your visit arrives from an ad click), the page URL you are on, the referring URL, browser and device type, IP address, and page-view and conversion events. The purpose is to measure how our advertising performs and to show our ads again to people who have already visited. The tag loads only while an explicit advertising choice is stored in this browser and no opt-out preference signal is present, so a first visit creates no advertising cookie. You can withdraw the choice in the controls below at any time, block or delete cookies in your browser, or change your Meta ad settings; refusing does not limit any page. Private surfaces — dashboard, report URLs, the operations console — carry no advertising tag.
How that consent is obtained follows the law where you connect from. In the EEA, the UK, and Switzerland an advertising tag may load only after prior consent (ePrivacy Directive 2002/58/EC, Article 5(3)). In Korea we disclose the practice in this notice and keep refusal open at any time. In the United States we treat a browser opt-out preference signal as a valid request to opt out of sale and sharing (CCPA Regulations § 7025). One rule decides the outcome everywhere and it is the strictest of the three: an advertising tag loads only when an explicit stored grant exists and no opt-out preference signal is present. A signal overrides a stored grant.
This notice names the advertising provider, the data it receives, and how to refuse, and it says so before the practice starts; any provider added later is written here before that processing begins. To keep code from running ahead of the notice, the control that turns advertising consent into a grant does not appear on screen until the advertising text in this notice has been published, so no advertising grant can exist before you can read this.
Opt-out preference signals
You have the right to opt out of the sale or sharing of your personal information. We process an opt-out preference signal such as Global Privacy Control in a frictionless manner: when the signal reaches us, advertising consent stays denied and cannot be granted, no fee is charged, and nothing about the site behaves differently for you. To send the signal, turn on Global Privacy Control in a browser that supports it — Brave, Firefox, and DuckDuckGo ship it, and extensions add it elsewhere (see globalprivacycontrol.org). You can also refuse in the controls below, block or delete cookies in your browser, or write to support@citeangle.com and we will record the refusal.
Choices stored in this browser
The controls below change what is stored in this browser. They live in this browser only and disappear when you clear its stored data.
5. Retention and deletion as implemented
- Email verification: the verification row is deleted before return when verification succeeds, expiry is evaluated, or the maximum attempt count is reached. A new code request replaces the earlier row.
- Email outbox: when a sent or terminal-failed message is more than 30 days old, recipient, subject, HTML, and last error are scrubbed while status, dedupe, and related-business metadata remain. Pending and sending payloads remain until terminal so durable delivery is not weakened.
- Free snapshot source data: 90 days for quality and reproducibility review.
- Paid-audit source data and delivery evidence: up to five years for contract verification, disputes, and required records.
- Infrastructure backups: about four weeks to age out through rotation.
- Account and ordinary inquiry data: handled through a manual account-deletion workflow after the purpose ends or an authenticated deletion request is approved; required contract, tax, and dispute records are separated and access-restricted.
Except for the explicit verification and outbox mechanisms above, CiteAngle does not represent that every general database row is covered by an active scheduled purge. Sign in and close your account in Account settings to run the deletion yourself. You can also send a request to support@citeangle.com, and we verify account or business authority before we run it. Either way, we identify any record that must remain under law or contract.
6. US privacy rights and email choices
You may request access, correction, deletion, or a portable copy; withdraw consent; or ask about categories, sources, purposes, and recipients. Where state law applies, you may appeal a denied request and use an authorized agent. We verify identity and authority with proportionate account and business-contact information, not customer phone identity verification, and do not discriminate for exercising a right. See the California Attorney General’s CCPA resource for California rights.
CiteAngle does not sell personal information under any configuration. Sharing for cross-context behavioral advertising, via the Meta Pixel described in section 4, happens only while you have granted the advertising choice in this browser and no opt-out preference signal is present, so the signal by itself is enough to stop it, and the choice can be withdrawn at any time. Global Privacy Control is honored as described in section 4 and holds advertising consent at denied; a signal is never read as consent, and the later absence of a signal is never read as an opt-in. Any further covered practice is described here before it starts.
Security, quote, contract, measurement-complete, and delivery messages are transactional. Promotional sending is disabled until a separate opt-in ledger, suppression check, sender identification, postal-address disclosure, and working opt-out have passed release tests. An opt-out will not affect contracted service, consistent with the FTC CAN-SPAM business guide.
7. Security and notice changes
Controls include least-privilege access, TLS transport, one-way password hashing, separation of authentication data, change records, restricted administrative access, and rotating backups. When this notice changes, we post the revised text here with the date it takes effect and identify what changed, so the previous and current wording can be compared. That posting happens when the change takes effect, and customers under contract also receive it through an appropriate service channel. A change that must be disclosed or consented to before it is lawful (beginning a transfer to a new provider or country, or using information already collected for a materially different purpose) is published here, or separately consented to, before that processing begins.
This notice works together with the Terms of Service and the Cancellation and Refund Policy. Those two set the scope of work and how money is returned; this notice sets how personal information is handled while that work runs.