CiteMatch policy 2026-07-29-prelaunch

Privacy and data handling

Document text remains on the computer running Microsoft Word. CiteMatch hosts the operational records needed to provide accounts, paid access, source retrieval, support, security, and refunds.

Seller and role

Cited Authorities LLC provides CiteMatch as software. It does not provide legal services through CiteMatch, and purchase or use does not create an attorney-client relationship.

What stays local

CiteMatch reads quotations, citations, surrounding prose, and other document text inside the Word add-in. Document text is not uploaded to CiteMatch for checking, support, analytics, model inference, or training.

Do not send documents or document excerpts to support. Remove names, matter details, quotes, and citations from screenshots before sending them.

What source retrieval sends

To retrieve public source text, CiteMatch may send the citation details already printed in a citation, such as a reporter volume, reporter, page, court, year, title, section, or regulation number. A user-supplied source-provider key may accompany that provider request.

Source providers receive the citation details needed for the request under their own privacy practices. CiteMatch may keep a reusable copy of public source text. That copy is not tied to the document or requesting user.

Local model package

A supported release may download an encrypted local model package of roughly 1 GB. It is used only to select among supplied quote-to-citation candidates or abstain. It does not issue a verification verdict.

The cached package is encrypted and bound to an activated installation. Plaintext must exist briefly in device memory for local inference. Encryption makes casual copying harder but cannot guarantee that a determined user with control of the device cannot extract the model.

Hosted information

  • account identity and authentication records;
  • subscription, charge, cancellation, refund, and policy-assent records;
  • installation codes, security-key checksums, platform labels, and access status;
  • support messages that you choose to send;
  • security events and privacy-safe operational error codes;
  • aggregate funnel events such as signup, checkout, activation, review completion, cancellation, and refund.

Operational logs must not contain document text, quotes, citation content, model responses, support-message bodies, training identifiers, or local filesystem paths.

Payments and refunds

Stripe Managed Payments processes eligible checkout transactions as merchant of record. Stripe processes payment credentials, taxes, disputes, transaction support, and refunds under its own terms. CiteMatch retains correlations and states needed to provide access, display refund status, reconcile events, and prevent duplicate refunds.

Service providers

CiteMatch uses or plans to use these provider categories:

  • Stripe: merchant-of-record checkout, payment, tax, disputes, transaction support, and refunds.
  • Vercel: website and service hosting.
  • Managed PostgreSQL: account, entitlement, device, assent, and refund records.
  • Transactional email: sign-in and service messages.
  • Cloudflare: private encrypted model-package delivery when that feature is enabled.
  • Human support tooling: support conversations, without document content or payment credentials.

Public-facing vendor names will be updated if the production provider changes.

Retention

RecordCurrent target
Account recordsAccount life plus 30 days
Billing, assent, and refund recordsUp to 7 years where needed for legal and accounting obligations
Security events180 days unless a security or legal need requires longer
Retrieved public source copiesWhile useful for source retrieval

Fraud prevention, disputes, legal holds, or mandatory law may require a limited record to be kept longer.

Access, export, and deletion

Signed-in users can request an export of account and subscription information or request account deletion. Public source copies are not included because they are not tied to an account. Billing, assent, refund, fraud-prevention, and legal-hold records may be retained as required.

Effective July 29, 2026. This prelaunch policy requires targeted outside-counsel review before public checkout. Questions? team@citematch.app.