b/cited
Privacy

b/cited sees less than
you'd expect.

01

What b/cited receives

When you sign in, b/cited gets your Google email, name, and profile picture, plus a refresh token scoped only to Search Console (read-only). The refresh token is stored encrypted at rest with AES-GCM using a key in Cloudflare's secret store, and is used to pull your search analytics on your behalf and for no other purpose.

02

What b/cited reads

From Search Console: the last 90 days of query and page impressions, clicks, CTR, and average position. Stored in Cloudflare D1 in a project namespace tied to your user id. Queries are embedded with OpenAI's text-embedding-3-small via Cloudflare AI Gateway and stored in Vectorize, namespaced per project.

03

What b/cited doesn't do

  • / Doesn't train on your data.
  • / Doesn't sell or share with advertisers.
  • / Runs no session-recording, anywhere.
  • / Never writes back to Search Console.
04

Cookies & local storage

b/cited sets only strictly necessary cookies. There are no advertising or tracking cookies, and no cookies are set for analytics.

b/cited does run privacy-preserving product analytics (HeyCatch, which is built on PostHog) to see which pages get used. It sets no cookies, but it does store anonymous identifiers in your browser’s local storage — a device id, a session id, and nothing tied to a person. Events go to HeyCatch’s own endpoint. No account details are sent — not your email, not your name, not your plan — and it is never given your Search Console data.

Nothing is stored until you say yes — everywhere, not only where the law requires asking. A banner appears on your first visit, declining is one click, and if you decline nothing is written at all. The only thing kept either way is your answer, so the question is not asked again. You can change it here at any time.

NamePurposeDuration
__Host-fr_sessionAuthenticates your signed-in session30 days
__Host-csrfCross-site request forgery protectionSession
cf_clearanceCloudflare Turnstile bot verification (on /scan)30 min

Your theme preference (fr-theme) is also stored in localStorage, which never leaves your browser.

05

Google API compliance

b/cited's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, data b/cited receives from Google Search Console (webmasters.readonly) and Google Drive (drive.file) is used only to deliver the AEO/SEO features described above. b/cited does not transfer this data to third parties except as needed to provide or improve those features (Cloudflare for storage and compute, OpenAI for embeddings, Anthropic and Perplexity for AEO citation runs), does not use it for advertising, and does not allow humans — including b/cited's operator — to read the data except (a) with your explicit consent for specific items, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) in aggregated/anonymized form for internal operations.

05b

AI assistants, the scanner API, and connectors

b/cited is reachable from AI assistants in three ways, and each handles data differently from the web app.

Anonymous scanning. The free scanner at /scan, the ChatGPT GPT, the Claude Code plugin, and the public MCP server at mcp.bcited.ai/publicall run the same rule-based site scan. Each request carries the URL you asked about and arrives with a client IP address. The URL is fetched, checked, and the result returned; when Core Web Vitals are requested the URL is also sent to Google’s PageSpeed Insights API. IP addresses are held only in short-lived rate-limit counters (about an hour) and are never joined to an account. Scan results from the MCP server are cached for one hour and the cached result is served to anyone who asks about the same URL in that window. The MCP server also keeps an aggregate usage log of which tool was called and which domain, category, or term it was about, with no IP, no account, and no full URL path.

Connecting your account. When you connect b/cited to an AI assistant (for example as a Claude connector), you sign in here and approve what the application may read. b/cited then issues that application a token scoped to your account. What it can read is exactly what the consent screen lists: your projects, tracked prompts, citation runs per engine, competitor citations, topical clusters, and content briefs. Nothing is written to your account by a read permission. Two further permissions, shown separately on the same screen, let the application trigger a run of one of your tracked prompts or queue a content brief for one of your clusters. Each such action is recorded in your account exactly as if you had started it from the dashboard, counts against the same plan allowances, and is additionally limited per hour and per day when started by an assistant. The data the assistant requests is transmitted to that assistant’s provider under that provider’s own terms; b/cited does not use any of it to train models, and never has. A record of each connection (the application, the permissions, and when it was approved) is kept so tokens can be checked and revoked. Access tokens expire after an hour and are renewed silently for up to thirty days of use. The Connected apps page in your account lists every connection with its permissions and disconnects one immediately; removing the connection from the assistant’s own settings works too.

Independence is unchanged by any of this: b/cited is not affiliated with, endorsed by, or partnered with OpenAI, Anthropic, Perplexity, or Google, and a listing in an assistant’s connector directory is a listing, not a partnership.

06

Deletion

Delete your account at any time from the Account page of the dashboard, or remove a single property from its Settings page. Both are a hard delete from D1, Vectorize, and R2 — no soft-delete. Deleting the account also cancels any subscription, disconnects connected apps, and withdraws b/cited’s access to your Google account. Two things are kept: invoices already issued stay with Stripe, and the record of what each data-provider call cost stays, with nothing in it that points to you. Product analytics never held an account identifier to leave a tail with.

07

Contact