Privacy Policy
Effective date: 28 July 2026
1. Data controller
The controller is LinkedGrowth, obrt za usluge, vl. Sean Anthony Honan, Ulica grada Vukovara 226A, Zagreb, Croatia, OIB 15991634041, VAT ID HR15991634041. Contact: sean@linkedgrowth.net.
2. Data we process
Account and authentication data
We process your email address, encrypted authentication credentials managed by our authentication provider, email-verification status, account identifiers, session information, password-reset events, and account status.
Citation checks and history
We process the citation text you submit, the resulting verdict, matched bibliographic metadata, detected mismatch or issue, suggested action, source links, check date, saved check name, and usage totals. Completed checks are stored so you can reopen and download the exact historical results.
Do not submit manuscripts, full papers, special-category personal data, confidential material, or personal information that is not necessary for citation verification.
Technical and security data
Our hosting and authentication providers may process IP address, browser and device information, timestamps, request logs, cookies or similar session data, and security events needed to deliver and protect the Service.
Communications and optional marketing
If you contact us, we process your message and contact details. If you separately choose to receive occasional Citation Risk updates, we record that choice. Marketing consent is optional and can be withdrawn at any time without affecting your account.
3. Why we process data and our legal bases
- Provide the Service and manage your account: performance of our contract with you, including authentication, citation checks, saved history, CSV downloads, usage accounting, support and account deletion.
- Protect the Service and prevent repeated introductory allowances: our legitimate interests in preventing abuse, maintaining fair limits and securing the Service.
- Maintain essential records and respond to legal claims: compliance with legal obligations and, where applicable, our legitimate interests in establishing, exercising or defending legal claims.
- Send optional marketing: your consent, which you may withdraw at any time.
4. Scholarly metadata lookups
To verify a citation, the Service queries scholarly metadata providers using citation identifiers or bibliographic search terms. The submitted reference may therefore be transmitted to relevant providers such as Crossref, OpenAlex or arXiv. We do not intentionally send your account password or full account profile to those providers.
5. Service providers and recipients
We use service providers for hosting and serverless processing, authentication and database storage, email delivery, scholarly metadata lookup, and—only where applicable—contact or marketing automation. These providers process data under their own security and contractual arrangements and only for the functions we use.
We may also disclose data where required by law, to protect legal rights or security, or in connection with a genuine transfer of the business, subject to applicable safeguards.
6. International transfers
Some providers may process data outside Croatia or the European Economic Area. Where GDPR requires it, transfers are protected by an adequacy decision, Standard Contractual Clauses, or another lawful safeguard. You may contact us for information about the relevant safeguards.
7. Retention
- Account and saved citation history: retained while your account remains active, then deleted when you delete the account, except for the limited anti-abuse record described below or data that law requires us to retain.
- Security and infrastructure logs: retained for the shortest period reasonably required for security, debugging and provider operations, subject to provider retention settings.
- Support communications: retained while needed to resolve the request and for a reasonable period afterwards where required for continuity or legal claims.
- Optional marketing records: retained until you withdraw consent or the record is no longer needed to demonstrate your preference.
8. Account deletion and the anti-abuse record
When you delete your account, Citation Risk removes the readable email, login identity, password credentials, saved checks, citation results, entitlement and account-linked usage records.
To prevent the same email address from repeatedly receiving a fresh introductory allowance, we retain a keyed, non-readable fingerprint derived from the normalized email address together with cumulative introductory allowance usage. The readable email cannot be recovered from the stored record without access to the secret key and testing a candidate address. This record is not used to contact you, rebuild your account, or restore deleted citation history. If you create a new account using the same email address, the remaining introductory allowance—not a fresh allowance—is applied.
This minimal record is retained while the introductory allowance programme and related abuse-prevention need continue, and is reviewed when that purpose ends. The legal basis is our legitimate interest in preventing abuse and enforcing fair usage limits.
9. Your rights
Subject to the GDPR and applicable Croatian law, you may have rights to access, rectify, erase, restrict or object to processing of your personal data, and to receive data you provided in a portable format. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.
To exercise a right, email sean@linkedgrowth.net. We may need to verify your identity. You may also lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) or another competent supervisory authority.
10. Cookies and local storage
The application uses strictly necessary cookies or similar storage to authenticate you, maintain your session, preserve secure account flows, and operate the Service. We do not currently use advertising cookies in the authenticated application. If this changes, we will update this Policy and request consent where required.
11. Security
We use access controls, authenticated ownership checks, database row-level security, encrypted transport, restricted result fields, and other reasonable technical and organisational safeguards. No online service can guarantee absolute security.
12. Automated decisions
Citation verdicts are automated product outputs that assist your review. They do not produce legal or similarly significant effects about you. You remain responsible for reviewing the underlying citation and source.
13. Children
Citation Risk is intended for professional, academic and adult users and is not directed to children. Do not create an account if you are below the age at which you can validly agree to these terms under applicable law without parental authorisation.
14. Changes to this Policy
We may update this Policy when the Service, providers or legal requirements change. We will update the effective date and provide reasonable notice of material changes.