Privacy Policy
The shortest, most aggressive privacy policy in academic software. No legal traps, no tracking telemetry, and zero manuscript ingestion.
The Engine
Your document is read inside your browser. The manuscript body — your unpublished research, drafts, data and prose — is discarded there and is never transmitted. What reaches our engine is the reference list itself: citations to published works, the same identifiers your browser already sends to Crossref. It is adjudicated in memory and discarded — never stored, never written to disk, never logged, and not linked to your account.
The Analytics
We collect standard, anonymous web traffic data solely to maintain server availability and protect upstream academic registry rate limits. No user fingerprinting or third-party ad networks.
The Payments
All billing and card transactions are handled securely off-site by Stripe. StrictCite never sees, transmits, or stores your credit card details or banking credentials.
Data Isolation Breakdown
What reaches our infrastructure versus what remains permanently offline.
- Manuscript text & drafts: Never submitted or uploaded.
- Unpublished lab findings & data: Zero exposure to any server.
- Bibliography segmentation: Regex engine runs entirely client-side.
- Public DOIs & titles: sent from your own browser, on your own IP, straight to Crossref, DataCite, OpenAlex, DBLP, doi.org and OpenLibrary. They never pass through us.
- Registry responses: Cached ephemerally to avoid rate-limiting.
- Your reference list: sent to our engine, checked against the registries, and returned. On the free tier nothing survives the request.
- Saved audits (Pro and Lab): a bibliography is a list of other people’s published work — DOIs, titles and journals that are already public records. Cloud History keeps the finished report so you can reopen it, and indexes those DOIs so we can warn you if a paper you cited is retracted next year. Neither feature can exist without remembering them; that is what the plan buys.
- Never your writing: the manuscript, the drafts, the unpublished data and results. Read in your browser, never sent — on every plan, including the paid ones.
- Yours to erase: Clear All in the workspace deletes every saved audit from our servers, and the retraction index goes with it. Nothing is kept back for our own records.
Why Commercial LLMs Cannot Scrape Your Research
Unlike cloud-based 'AI citation assistants' that ingest your full manuscript into OpenAI or Anthropic servers, StrictCite never receives your writing. Because your unpublished hypotheses, equations, and prose never leave your device, AI bots and web scrapers are physically unable to memorize or harvest your work.