14

Last updated September 14, 2026. Turing LLC, doing business as Citeaxis.

01

Scope

This Privacy Policy explains how Turing LLC (“Citeaxis”, “we”), which owns and operates the Citeaxis brand, collects, uses, shares, and protects information when you visit https://citeaxis.io, submit a contact form, create an account in the members area at https://citeaxis.io/app, join an organization, use the project chat, receive a proposal, generate or unlock a Blueprint, subscribe to a plan, buy expert work, or otherwise interact with the Service described in our Terms of Service.

It applies to personal information about our customers, their team members, the people they name as proposal recipients, and visitors. When we perform expert work inside your environment, we process data in that environment on your instructions; your own privacy notice covers your end users, and a statement of work or data processing terms may add to this Policy.

Legal entity: Turing LLC.

Principal office: 30 N Gould St, STE R, Sheridan, WY 82801.

Mailing address: 30 N Gould St, STE R, Sheridan, WY 82801.

Registered agent: Registered Agents Inc, 30 N Gould St Ste R, Sheridan, WY 82801.

Contact for privacy requests: contact@citeaxis.io.

02

Information you give us

Account. Your email, name, and a password we store only as a salted hash. If you sign in with Google or Microsoft, we receive your email, name, profile picture URL, and the provider’s account identifier. We record when you verified your email and when you last signed in.

Organization. The organization’s name, email domain, country, sector, size, and website, entered by its owner or managers. Country drives the billing currency and is used with your billing address for tax purposes.

Invitations and team. The email addresses of people you invite, the roles you assign, and who accepted.

Projects. Everything you write in the project chat: your goal, business context, data, systems, constraints, stack answers, and any follow-up questions. The name, email, company, and role you enter for the proposal, and the email addresses of the recipients you send it to. The proposal, the Blueprint plan, the scenarios, the generated code, and the manual we produce for you are stored with the project.

Contact form. The name, email, company, and message you send from /contact.

Payments. When you subscribe or buy, Stripe collects your card or other payment details directly. We receive and store your Stripe customer identifier, the email and name on the payment, the amount, currency, status, plan, billing period, and invoice status. We never receive or store full card numbers.

Support and expert work. Emails, meeting notes, and the access, documents, and data you share with our engineers to deliver the work you ordered.

03

Information collected automatically

Marketing analytics. Our marketing site records first-party, cookieless events: the page, the referrer, the event type, a per-tab session identifier kept in sessionStorage, and a visitor hash derived from your IP address and browser user agent with a secret salt that rotates daily. The hash cannot be reversed and cannot follow you from one day to the next. We do not use advertising cookies, third-party trackers, fingerprinting libraries, or a consent banner, because we run none of that kind of tracking.

Product activity. In the members area we log the events needed to run and secure the Service: sign-ins and sign-outs, session creation and revocation, project creation and archiving, Blueprint runs and their results, purchases, plan changes, and invitations. These records show who did what, when, inside an organization.

Abuse prevention. When a project is created we store the IP address, user agent, and referrer of the request, and we keep short-lived rate-limit counters keyed to your account or IP. Our servers keep standard access and error logs.

Emails. When we send you an email through our provider we may receive delivery and bounce information so we can tell you when an address does not work.

04

Cookies

We use only strictly necessary cookies, all first-party and httpOnly where the browser allows: a members session cookie (valid for up to thirty days, extended while you use the Service), a cookie remembering the organization you have open, a short-lived cookie that protects the Google or Microsoft sign-in round trip, cookies that protect the administration console used by Citeaxis staff, and a cache marker that tells your browser to refresh after we deploy. None of them are used for analytics or advertising, so no consent banner is shown. You can delete cookies in your browser; you will be signed out.

05

How we use information

To provide the Service: create and secure your account and organization, run the project chat, prepare and send proposals, plan, generate, verify, and deliver Blueprints, apply your free allowance or plan quota, process payments and refunds, and schedule and deliver expert work.

To communicate: transactional emails such as verification, password reset, invitations, proposal delivery, Blueprint ready, receipts, and payment failures; replies to your inquiries; and notices about changes to the Service or these documents. We do not send marketing email without your consent, and you can opt out of any marketing at any time.

To secure and improve the Service: detect and prevent fraud, abuse, and unauthorized access; debug problems; understand which features and pages are used, in aggregate; and review a sample of proposals and Blueprint outputs for quality. We do not use your content to train AI models of our own.

To comply with law: keep the tax, accounting, and payment records we must keep, respond to lawful requests, and enforce our Terms.

Where the GDPR, UK GDPR, or Brazil’s LGPD applies, our legal bases are performance of a contract with you (providing the Service you asked for), our legitimate interests (securing and improving the Service, communicating with customers, preventing abuse), compliance with legal obligations, and consent where we ask for it.

06

AI processing

Citeaxis generates proposals and code with large language models. To do that, we send the relevant content of your project (your chat messages, stack answers, organization sector and country, the scenario and plan we built, and the code produced so far) to our model provider. Our provider is currently Anthropic, PBC, accessed through its commercial API. Under that API’s terms the provider does not use our inputs or outputs to train its models and retains them only for the limited period its policies allow for abuse monitoring and reliability.

We never send payment details, passwords, session tokens, or secrets to a model provider, and we ask you not to paste them, or any special-category personal data, into the chat. The outputs generated for you are stored with your project so you and your team can return to them.

Our engineers may read a project’s chat, proposal, plan, and outputs to review quality, to answer a support request, to investigate abuse or a payment dispute, or to deliver the expert work you ordered. Access is logged.

07

Who we share information with

Processors that run the Service for us, under contracts that limit them to providing their service: hosting and database providers for the application, its background workers, and the isolated sandboxes where Blueprints are verified; Stripe for payments, subscriptions, invoices, and the Customer Portal; Anthropic for AI generation; Resend for transactional email; Google and Microsoft when you choose to sign in with them; and the form-delivery service that forwards messages from /contact to our inbox.

Your organization. Members of your organization see the organization’s projects, proposals, Blueprints, purchases, and plan according to their role; owners and managers see who is a member and their activity. When you send a proposal, the recipients you name receive it by email with your name and company.

Legal and corporate. We may disclose information if required by law or legal process, to protect the rights, property, or safety of Citeaxis, our customers, or the public, to enforce our Terms, or in connection with a merger, acquisition, financing, or sale of assets, in which case we will give notice where the law requires it.

We do not sell personal information, and we do not share it for cross-context behavioral advertising or targeted advertising. We have not done so in the preceding twelve months.

08

Retention

Account and organization data are kept while the account is active. Projects, proposals, and Blueprints are kept while the organization exists, including when you archive them, so your team can return to them; you can ask us to delete specific projects or the whole organization at any time.

Sessions expire after thirty days of inactivity and can be revoked earlier from Settings. Email verification links expire after twenty-four hours, password reset links after one hour, and sign-in codes after minutes; all are stored as hashes.

Payment, invoice, and refund records are kept for as long as tax and accounting laws require, generally seven years. Security and audit logs are kept for a limited period, in general no more than twelve months. Rate-limit counters last minutes to hours. Analytics events carry only the daily-rotating visitor hash, so they cannot be traced back to a person after the day they were recorded.

When you ask us to delete data or close an organization, we delete or anonymize it within thirty days, except for records we must keep by law, data needed to resolve an open dispute, and copies in encrypted backups that expire on their own schedule.

09

Security

We protect information with measures appropriate to its sensitivity: TLS in transit; passwords hashed with scrypt; session, admin, and OAuth cookies that are httpOnly, Secure, and host-bound; secrets encrypted at rest with AES-256-GCM; rate limiting on sign-in, code, and API routes; a two-factor code by email for the staff console; audit logs of administrative actions; least-privilege access for our team; and Blueprint verification in isolated, disposable sandboxes without access to our production data.

No system is perfectly secure. If we learn of a breach that affects your personal information, we will notify you and the competent authorities as the law requires. Please report vulnerabilities to contact@citeaxis.io.

10

Your rights and choices

Self-service. In Settings you can update your name, change your password, disconnect Google or Microsoft, and sign out other sessions; to change the email on your account, write to us. Organization owners and managers can edit the organization profile and manage members. Billing details, invoices, plan changes, and cancellation are in the Stripe Customer Portal linked from /app/billing. Projects can be archived from the project page.

Requests. You can ask us to access, correct, complete, delete, or port your personal information; to restrict or object to certain processing; to withdraw consent where processing relies on it; and to learn which categories of information we hold and share. Email contact@citeaxis.io from the address on your account, or from another address with enough detail for us to verify you. We answer within the time the applicable law sets (thirty days under the GDPR, forty-five days under US state laws, fifteen days under the LGPD), free of charge unless a request is manifestly excessive. If we refuse a request we will say why and how to appeal.

United States. Residents of California and other states with comprehensive privacy laws have the rights above, plus the right not to be discriminated against for exercising them. We do not sell or share personal information for targeted advertising, so there is nothing for a Global Privacy Control or Do Not Track signal to switch off; our analytics already avoid cookies and ad tracking.

European Economic Area, United Kingdom, and Switzerland. You may lodge a complaint with your supervisory authority. We rely on the legal bases described above and on the transfer safeguards described in the next section.

Brazil. You have the rights set out in Article 18 of the LGPD, including confirmation of processing, access, correction, anonymization, portability, deletion, information on sharing, and the right to petition the ANPD. Citeaxis acts as controller for the data in this Policy; our contact for LGPD matters is contact@citeaxis.io.

Authorized agents may submit requests on your behalf with written permission; we may still verify your identity directly.

11

International transfers

Citeaxis is based in the United States, and our processors run in the United States and in other countries where they operate. If you use the Service from outside the United States, including from Brazil, the European Economic Area, or the United Kingdom, your information is transferred to and processed in the United States. Where the law requires safeguards for such transfers, we rely on the processors’ standard contractual clauses or equivalent mechanisms and on the contractual and technical measures described in this Policy.

12

Children

The Service is for businesses and professionals, not for children under 18. We do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will delete it.

13

Changes

We may update this Policy as the Service or the law changes. The “Last updated” date at the top will change. For material changes we will post a notice on https://citeaxis.io and, when we have your email, send it there before the change takes effect. Your continued use after the effective date means you have read the revised Policy.

14

Contact

Privacy questions, requests, and complaints: contact@citeaxis.io. Turing LLC, 30 N Gould St, STE R, Sheridan, WY 82801.