Skip to content

Privacy policy

Last updated: August 28, 2026

CiteScript turns video scripts into written content. This policy explains what data we collect while you use it, why we collect it, how long we keep it, and the rights you have over it. The short version: we collect the minimum needed to run the service, your scripts are not used to train AI models, and we never sell personal data.

Who we are

CiteScript (citescript.com) is operated from the United Kingdom. For the purposes of UK data protection law, CiteScript is the controller of the personal data described in this policy. You can reach us at support@citescript.com.

If you use CiteScript without an account

You can convert one video per month without signing up. To enforce that limit, we store a salted hash of your IP address in Cloudflare KV for up to 40 days. The hash cannot be reversed back into your IP address, and it expires on its own.

The script you paste is processed in memory. It is sent to Anthropic to generate your content, the result is returned to you, and neither the script nor the output is stored by CiteScript. The only thing we keep is a one-way hash of the script, used to count usage. The hash contains none of the script text.

If you create an account

Accounts use magic links sent by email, with optional Google sign-in. There are no passwords, so we never store one. For account holders we store:

  • Your email address.
  • Your name, if Google provides it when you sign in with Google.
  • Session data: the IP address and user agent of your sign-in sessions, used to keep your account secure.
  • Usage records: which script hashes were used in which month, so we can apply plan limits. Script hashes are one-way and contain no script text.

If you subscribe to Pro

Pro subscribers get generation history: the outputs you generate are stored so you can come back to them. They stay stored until you delete them or your account closes.

Payments are handled entirely by Polar (polar.sh), which acts as the merchant of record. CiteScript never sees your card details. Polar has its own terms and privacy policy, and those apply to your payment data.

How your scripts are processed

Scripts and generated outputs are sent to Anthropic, whose Claude API produces the written content. Under Anthropic’s commercial API terms, API inputs and outputs are not used to train Anthropic’s models.

Our lawful bases

UK GDPR requires a lawful basis for each use of personal data. Ours are:

  • Performance of a contract: running your account, generating your content, and sending you login links and receipts.
  • Legitimate interests: enforcing the free tier limit with the salted IP hash, keeping the service secure with session data, and understanding aggregate usage through cookieless analytics.
  • Legal obligation: keeping records where the law requires it, such as billing records held by Polar as merchant of record.

Services we rely on

A small set of providers process data on our behalf to run CiteScript:

  • Anthropic: processes scripts and generates outputs.
  • Cloudflare: hosts the service on Cloudflare Workers, stores the salted IP hashes in Cloudflare KV, and provides Cloudflare Web Analytics.
  • Neon: hosts our Postgres database.
  • Resend: sends transactional email such as login links.
  • Polar: handles payments and receipts as merchant of record.

That is the full list. We use no advertising trackers and we do not sell or rent personal data to anyone.

International transfers

We operate from the United Kingdom, and the providers above (Anthropic, Cloudflare, Neon, Resend, and Polar) are US companies, so some data is transferred to the United States. These transfers are covered by standard contractual clauses as recognized under UK data protection law.

How long we keep data

  • Anonymous scripts and their outputs: not stored at all. They are processed in memory and discarded.
  • Salted IP hashes for anonymous usage: up to 40 days.
  • Account data, session data, and usage records: kept while your account is open and deleted when it closes.
  • Generation history (Pro): kept until you delete it or your account closes.

Your rights

Under UK GDPR you can ask us for a copy of your personal data, ask us to correct it, ask us to delete it, ask for it in a portable format, and object to or restrict certain processing. Email support@citescript.com and we will respond within one month.

You also have the right to complain to the UK’s data protection regulator, the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to resolve any concern first, but you do not need our permission to go to the ICO.

Analytics and cookies

We use Cloudflare Web Analytics, which is privacy-friendly and does not use cookies. If you sign in, we set a cookie to keep you signed in. There are no advertising or cross-site tracking cookies.

Age

CiteScript is for people aged 16 and over. We do not knowingly collect data from anyone younger. If you believe we have, email support@citescript.com and we will delete it.

Changes to this policy

If we change this policy, we will post the new version here and update the date at the top. We will not weaken your rights without telling you.

Contact

Questions about this policy or your data: support@citescript.com.