Last updated 1 August 2026
Privacy Policy
This policy explains what we collect, why, and what you can ask us to do about it. It is written to be read rather than skimmed past. If anything here is unclear, email us and we will explain it in plain terms.
Who we are
Recited AI provides an AI search visibility platform. In this policy, "we" and "us" mean Recited AI. For any privacy question, contact hello@recitedai.com.
For personal data you upload or generate while using the platform, you are the controller and we act as your processor. For your own account and billing data, we are the controller.
What we collect
- Account data: name, work email, company, role and password hash.
- Workspace data: the domains, prompts, competitors, tags and markets you configure.
- Product data: answers we retrieve from public answer engines on your behalf, and the citations within them.
- Billing data: plan, invoices and payment status. Card details are handled by our payment processor and never reach our servers.
- Usage data: pages viewed, features used, and error diagnostics, so we can find and fix problems.
What we do not collect
We do not install a tracking script on your website. We do not receive your customer records, your CRM, or your analytics data. Recited AI reads public answer engines and public web pages, so there is generally nothing sensitive for us to hold in the first place.
Why we process it
- To provide the service you signed up for, which is the main reason for nearly all processing.
- To bill you and keep the records our accountants and tax authorities require.
- To secure the platform, investigate abuse and diagnose faults.
- To send service messages. Marketing email only ever goes out with your consent, and every message has a working unsubscribe link.
Model providers and sub-processors
Running the product means sending prompts to third-party answer engines and using model providers to structure the responses that come back. Those prompts are the ones you configured; we do not send your account data or your customers' data to any model provider.
We keep a current list of sub-processors covering hosting, model providers, payments, email and error monitoring. Ask us for it and we will send it, and Enterprise customers are notified before we add a new one.
How long we keep it
Workspace and product data is retained for the life of your account, because visibility history is the point of the product. Delete a project and its data is removed within thirty days, including from backups on the normal backup rotation.
Close your account and we delete personal data within ninety days, other than records we are legally required to retain, such as invoices.
Where it lives
Data is hosted in the United States by default and in the EU on request. Where personal data moves between regions, we rely on Standard Contractual Clauses. Enterprise customers can pin processing to a specific region.
Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing. You can also withdraw consent for marketing at any time.
Email hello@recitedai.com and we will respond within thirty days. We will not charge you for a reasonable request, and we will not make the product worse for you because you exercised a right.
Security
- Encryption in transit and at rest.
- Role-based access control, with SSO and SAML available on Enterprise.
- Least-privilege internal access, reviewed regularly and logged.
- Automated backups with tested restores.
Cookies
We use a small number of cookies, described in our Cookie Policy. Non-essential cookies are only set once you agree to them.
Changes
If we make a material change we will email account holders and update the date at the top of this page before it takes effect. Continuing to use the service after that date means the updated policy applies.