Citeply
PrivacyTermsTrust

Privacy

Privacy statement

This statement explains the information Citeply handles, why it is needed, and the controls available to customers.

Last updated 3 August 2026

1. Scope

Citeply is the product name of an independently published, pre-release software service for evidence-backed security questionnaire workflows. This statement applies to the Citeply web application, its Microsoft 365 connector, and related support interactions. It does not replace the privacy notices of Microsoft or a customer's organization.

2. Information Citeply handles

  • Account data: name, business email address, tenant identifier, role, and authentication identifiers supplied by Microsoft Entra ID.
  • Customer content: questionnaires, selected evidence documents, answer-library records, citations, reviewer decisions, and audit events that an authorized user chooses to process.
  • Connector data: Microsoft tenant, drive, site, file, and permission identifiers needed to retrieve customer-selected content.
  • Service data: security logs, error diagnostics, device and browser information, and usage events needed to operate and protect the service.
  • Support data: messages and files a user voluntarily provides when requesting help.

The current local preview analyzes a workbook in the browser and does not upload its cell content. Cloud processing will not be enabled until the production service and customer terms are activated.

3. Why information is used

Citeply uses information only to provide, secure, maintain, and improve the requested service; authenticate users; preserve tenant isolation; generate evidence-linked response suggestions; record approvals; prevent abuse; and respond to support or legal requests.

Citeply does not sell customer content or account data and does not use customer documents for advertising. Customer content will not be used to train a general-purpose model unless a customer expressly agrees to a separate written arrangement.

4. Microsoft 365 access

The planned connector uses delegated Microsoft Graph access. It requests the minimum permission needed for the feature being used, beginning with basic sign-in and read access to a file the signed-in user selects. Citeply does not receive a user's Microsoft password. Administrators can revoke the application's consent in Microsoft Entra ID.

5. Sharing and service providers

Information may be processed by hosting, database, storage, security, email, and support providers acting under instructions needed to operate Citeply. A current subprocessor list and production hosting regions will be published before customer cloud data is accepted. Information may also be disclosed when required by law or to protect users and the service.

6. Retention and deletion

Customer content will be retained for the subscription period and a documented recovery window, then deleted or de-identified unless law or a written customer instruction requires otherwise. Security and audit records may be kept longer when necessary to investigate abuse, demonstrate authorized activity, or meet legal obligations. Production retention periods will be stated in the service agreement before launch.

7. Security and tenant boundaries

Citeply is designed around per-tenant authorization, least-privilege connector grants, evidence-scoped answers, append-only audit events, and blocked automation when evidence is missing. No Internet service can promise absolute security. Current implementation status and activation dependencies are published on the Trust page.

8. Choices and rights

Depending on location, a user may have rights to access, correct, export, restrict, object to, or delete personal information. Requests can be sent to privacy@citeply.com after the domain is activated. Citeply may need to verify the requester and coordinate with the customer organization that controls the workspace.

9. Changes and contact

Material changes will be posted here with a revised date. The privacy contact for the production service will be privacy@citeply.com. This domain-based mailbox must be activated and tested before public launch.

© 2026 CiteplyEvidence-backed answers. Human-approved claims.