Privacy policy
The short version: we don't store the references you paste, we don't use tracking cookies, and you don't need an account.
The references you paste
When you run a check, your references are sent to our server and processed. We don't keep a copy of what you paste, and we don't write it to our logs.
To check them, we send parts of each reference to outside services:
- Scholarly databases. Identifiers such as DOIs and ISBNs, and details such as titles and author names, are sent to Crossref, DataCite, OpenAlex, Open Library, Google Books and PubMed to look up the published record.
- Anthropic. If a reference is too irregular to read with simple rules, its text is sent to Anthropic's API so their Claude model can split it into fields such as author and title. This only happens for references the simple rules couldn't read. Anthropic handles the data under its own commercial terms and privacy policy.
To make repeat checks faster, we keep a temporary cache of results for up to 30 days. Each entry is labeled with a one-way fingerprint (a hash) of the reference, not the reference itself. What's stored under that label is only the record we found in the databases and our verdict about it, never your text.
Before October 11, 2026, cached results could also include short pieces of the text that was checked, such as a title or author name. Those older entries are no longer used and are deleted automatically by November 10, 2026.
The citation builder
When you search in the builder, the words, DOI, ISBN or web address you type are sent to our server and on to the same databases listed above. If you enter a web address, our server fetches that public page to read its title, author and date. Search results are cached for 7 days. The sources you add to "My list" are kept only in your own browser (local storage) and are never sent to us. You can remove them with the "Clear" button or by clearing your browser data.
Reports you choose to send
If you use "Report a wrong result," the reference you report, the result we gave and any comment you add are saved so we can investigate. This is the only time we deliberately store reference text, and only because you chose to send it. To have a report deleted, email us.
Technical data
- IP addresses are used to enforce fair-use limits (for example, a number of checks per day) and to block abuse. Your address is held in a rate-limit counter until 24 hours after your last request. We also keep daily request counts per IP address for about a week to spot abuse, then delete them. None of this includes what you checked.
- Usage statistics such as the number of checks per day, the share of each verdict and the country requests come from are kept only as totals, never linked to you.
- Cloudflare hosts the site and runs Cloudflare Turnstile to tell people from bots. Turnstile may set a cookie or read browser details to do this. We don't run any analytics or advertising scripts. See Cloudflare's privacy policy.
- Saved in your browser: your light or dark theme, your chosen citation style, the tab you last used and your "My list" of sources. These stay on your device and are not sent to us.
What we don't do
- No accounts, no advertising, and no tracking or analytics scripts.
- We don't sell or share data with anyone beyond the services listed above.
Changes and contact
If this policy changes, we'll update this page and the date below. Questions: support@papercitation.com.
Last reviewed October 11, 2026