Citation Risk

Privacy Policy

Effective date: 28 July 2026

This Policy explains what Citation Risk collects, why it is used, how long it is kept, and the choices available to you.

1. Data controller

The controller is LinkedGrowth, obrt za usluge, vl. Sean Anthony Honan, Ulica grada Vukovara 226A, Zagreb, Croatia, OIB 15991634041, VAT ID HR15991634041. Contact: sean@linkedgrowth.net.

2. Data we process

Account and authentication data

We process your email address, encrypted authentication credentials managed by our authentication provider, email-verification status, account identifiers, session information, password-reset events, and account status.

Citation checks and history

We process the citation text you submit, the resulting verdict, matched bibliographic metadata, detected mismatch or issue, suggested action, source links, check date, saved check name, and usage totals. Completed checks are stored so you can reopen and download the exact historical results.

Do not submit manuscripts, full papers, special-category personal data, confidential material, or personal information that is not necessary for citation verification.

Technical and security data

Our hosting and authentication providers may process IP address, browser and device information, timestamps, request logs, cookies or similar session data, and security events needed to deliver and protect the Service.

Communications and optional marketing

If you contact us, we process your message and contact details. If you separately choose to receive occasional Citation Risk updates, we record that choice. Marketing consent is optional and can be withdrawn at any time without affecting your account.

3. Why we process data and our legal bases

4. Scholarly metadata lookups

To verify a citation, the Service queries scholarly metadata providers using citation identifiers or bibliographic search terms. The submitted reference may therefore be transmitted to relevant providers such as Crossref, OpenAlex or arXiv. We do not intentionally send your account password or full account profile to those providers.

5. Service providers and recipients

We use service providers for hosting and serverless processing, authentication and database storage, email delivery, scholarly metadata lookup, and—only where applicable—contact or marketing automation. These providers process data under their own security and contractual arrangements and only for the functions we use.

We may also disclose data where required by law, to protect legal rights or security, or in connection with a genuine transfer of the business, subject to applicable safeguards.

6. International transfers

Some providers may process data outside Croatia or the European Economic Area. Where GDPR requires it, transfers are protected by an adequacy decision, Standard Contractual Clauses, or another lawful safeguard. You may contact us for information about the relevant safeguards.

7. Retention

8. Account deletion and the anti-abuse record

When you delete your account, Citation Risk removes the readable email, login identity, password credentials, saved checks, citation results, entitlement and account-linked usage records.

To prevent the same email address from repeatedly receiving a fresh introductory allowance, we retain a keyed, non-readable fingerprint derived from the normalized email address together with cumulative introductory allowance usage. The readable email cannot be recovered from the stored record without access to the secret key and testing a candidate address. This record is not used to contact you, rebuild your account, or restore deleted citation history. If you create a new account using the same email address, the remaining introductory allowance—not a fresh allowance—is applied.

This minimal record is retained while the introductory allowance programme and related abuse-prevention need continue, and is reviewed when that purpose ends. The legal basis is our legitimate interest in preventing abuse and enforcing fair usage limits.

9. Your rights

Subject to the GDPR and applicable Croatian law, you may have rights to access, rectify, erase, restrict or object to processing of your personal data, and to receive data you provided in a portable format. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.

To exercise a right, email sean@linkedgrowth.net. We may need to verify your identity. You may also lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) or another competent supervisory authority.

10. Cookies and local storage

The application uses strictly necessary cookies or similar storage to authenticate you, maintain your session, preserve secure account flows, and operate the Service. We do not currently use advertising cookies in the authenticated application. If this changes, we will update this Policy and request consent where required.

11. Security

We use access controls, authenticated ownership checks, database row-level security, encrypted transport, restricted result fields, and other reasonable technical and organisational safeguards. No online service can guarantee absolute security.

12. Automated decisions

Citation verdicts are automated product outputs that assist your review. They do not produce legal or similarly significant effects about you. You remain responsible for reviewing the underlying citation and source.

13. Children

Citation Risk is intended for professional, academic and adult users and is not directed to children. Do not create an account if you are below the age at which you can validly agree to these terms under applicable law without parental authorisation.

14. Changes to this Policy

We may update this Policy when the Service, providers or legal requirements change. We will update the effective date and provide reasonable notice of material changes.