Legal
Privacy Policy
Last updated: June 2026
1. Who we are
Citevra is an AI search visibility tracking service for medical spas and aesthetic clinics, based in Tokyo, Japan. We help clinics see and improve how they appear across ChatGPT, Perplexity, Gemini, and Claude. For any questions about this policy or how we handle your data, reach us at hello@citevra.com. The data controller responsible for your information is Citevra.
2. What data we collect
- —Account data: your email address and name when you sign up.
- —Clinic data: your clinic name, city, services, website, and phone number — provided by you.
- —Scan data: the AI search results we collect when running tracked questions on your behalf.
- —Billing data: handled entirely by our payment processor (Lemon Squeezy). We never see or store your card details.
- —Usage data: standard web server logs (IP address, browser type, pages visited) via Vercel.
- —Analytics: aggregated, anonymized traffic data via Google Analytics 4.
3. How we use your data
- —To provide the service: run AI visibility scans, generate reports, and email results to you.
- —To communicate with you: send transactional emails (scan reports, alerts, account notices).
- —To improve the product: understand how features are used in aggregate.
- —To process payments: pass billing information to Lemon Squeezy.
We do not sell your data. We do not use your clinic data to train AI models.
4. Data storage and security
Your data is stored in Supabase (hosted on AWS in the United States) and processed on Vercel infrastructure. Data is encrypted in transit (TLS) and at rest. We use row-level security so each user can only access their own data.
5. Third-party services
- —Supabase — database and authentication
- —Vercel — hosting and edge infrastructure
- —Resend — transactional email delivery
- —Lemon Squeezy — payment processing (Merchant of Record)
- —OpenAI, Anthropic, Google, Perplexity — AI engine APIs used to run visibility scans
- —Google Analytics 4 — anonymized website analytics
When running scans, we send your tracked questions (not your personal data) to AI engine APIs. We do not send your clinic name or contact details to these APIs beyond what is needed to score the answer.
6. Your rights
You may request access to, correction of, or deletion of your data at any time by emailing hello@citevra.com. You can delete your account from the dashboard settings page. We will action data deletion requests within 30 days.
7. Cookies
We use cookies only for authentication (Supabase session) and anonymized analytics (Google Analytics 4). We do not use advertising or tracking cookies.
8. Data retention
We retain your data for as long as your account is active. Scan results are retained for 12 months, then automatically deleted. You can request earlier deletion at any time.
9. Changes to this policy
We may update this policy as the service evolves. Material changes will be notified by email. Continued use of the service after notice constitutes acceptance.
10. Contact
Questions about this policy: hello@citevra.com