CiteMatch policy 2026-07-29-prelaunch
Privacy and data handling
Document text remains on the computer running Microsoft Word. CiteMatch hosts the operational records needed to provide accounts, paid access, source retrieval, support, security, and refunds.
Seller and role
Cited Authorities LLC provides CiteMatch as software. It does not provide legal services through CiteMatch, and purchase or use does not create an attorney-client relationship.
What stays local
CiteMatch reads quotations, citations, surrounding prose, and other document text inside the Word add-in. Document text is not uploaded to CiteMatch for checking, support, analytics, model inference, or training.
Do not send documents or document excerpts to support. Remove names, matter details, quotes, and citations from screenshots before sending them.
What source retrieval sends
To retrieve public source text, CiteMatch may send the citation details already printed in a citation, such as a reporter volume, reporter, page, court, year, title, section, or regulation number. A user-supplied source-provider key may accompany that provider request.
Source providers receive the citation details needed for the request under their own privacy practices. CiteMatch may keep a reusable copy of public source text. That copy is not tied to the document or requesting user.
Local model package
A supported release may download an encrypted local model package of roughly 1 GB. It is used only to select among supplied quote-to-citation candidates or abstain. It does not issue a verification verdict.
The cached package is encrypted and bound to an activated installation. Plaintext must exist briefly in device memory for local inference. Encryption makes casual copying harder but cannot guarantee that a determined user with control of the device cannot extract the model.
Hosted information
- account identity and authentication records;
- subscription, charge, cancellation, refund, and policy-assent records;
- installation codes, security-key checksums, platform labels, and access status;
- support messages that you choose to send;
- security events and privacy-safe operational error codes;
- aggregate funnel events such as signup, checkout, activation, review completion, cancellation, and refund.
Operational logs must not contain document text, quotes, citation content, model responses, support-message bodies, training identifiers, or local filesystem paths.
Payments and refunds
Stripe Managed Payments processes eligible checkout transactions as merchant of record. Stripe processes payment credentials, taxes, disputes, transaction support, and refunds under its own terms. CiteMatch retains correlations and states needed to provide access, display refund status, reconcile events, and prevent duplicate refunds.
Service providers
CiteMatch uses or plans to use these provider categories:
- Stripe: merchant-of-record checkout, payment, tax, disputes, transaction support, and refunds.
- Vercel: website and service hosting.
- Managed PostgreSQL: account, entitlement, device, assent, and refund records.
- Transactional email: sign-in and service messages.
- Cloudflare: private encrypted model-package delivery when that feature is enabled.
- Human support tooling: support conversations, without document content or payment credentials.
Public-facing vendor names will be updated if the production provider changes.
Retention
| Record | Current target |
|---|---|
| Account records | Account life plus 30 days |
| Billing, assent, and refund records | Up to 7 years where needed for legal and accounting obligations |
| Security events | 180 days unless a security or legal need requires longer |
| Retrieved public source copies | While useful for source retrieval |
Fraud prevention, disputes, legal holds, or mandatory law may require a limited record to be kept longer.
Access, export, and deletion
Signed-in users can request an export of account and subscription information or request account deletion. Public source copies are not included because they are not tied to an account. Billing, assent, refund, fraud-prevention, and legal-hold records may be retained as required.
Effective July 29, 2026. This prelaunch policy requires targeted outside-counsel review before public checkout. Questions? team@citematch.app.