BeCitedLegal

Privacy Policy

Effective July 25, 2026

This Privacy Policy explains how BeCited ("BeCited," "we," "us," or "our"), operated by Astro Tasarım Simay Yenice ("Company"), collects, uses, and protects information when you use becited.co and our GEO/SEO visibility measurement service (the "Service"). It is written to satisfy the EU General Data Protection Regulation (GDPR) and, where applicable, Turkey's Law No. 6698 on the Protection of Personal Data (KVKK). A Turkish-language KVKK notice is provided separately at /kvkk; where the two texts differ due to translation, this English Privacy Policy governs except for KVKK-specific rights, which are governed by the Turkish text.

1. Who We Are (Controller)

Astro Tasarım Simay Yenice, registered in Türkiye (full registered address available on request at hello@becited.co), is the data controller responsible for your personal data under GDPR Article 4(7) and the "veri sorumlusu" under KVKK Article 3. For all privacy questions, contact us at hello@becited.co.

If and when we serve users in the EU/EEA on a regular basis, we will appoint an EU representative under GDPR Article 27 and update this notice accordingly.

2. What Information We Collect

We only collect what the Service needs to function. We do not run behavioral advertising trackers and we do not buy or sell personal data.

CategoryExamplesSource
Account identifiersName and email address from Google or Apple sign-in (via Clerk)You, via Google/Apple
Contact dataEmail address you leave to unlock a full reportYou
Measurement inputThe domain you submit for audit, and the publicly available pages BeCited crawls from that domainYou / public web
Derived dataVisibility scores, citation counts, and report content computed from the aboveGenerated by BeCited
Billing dataSubscription plan, status, and payment metadata (invoice ID, amount, timestamps)Creem (our payment processor)
Integration dataOAuth tokens for Google Search Console, stored encrypted, if you choose to connect your propertyYou, via Google
Technical dataIP address, browser type, error logs, session identifiersAutomatically, via Vercel/Sentry

What we do not collect: we never see or store your card number, CVV, or full payment card details. Card data is handled entirely by Creem, our payment processor and Merchant of Record.

What our measurement queries send: when we run monthly (or on-demand) visibility checks, we send the submitted domain and generic, AI-generated buyer-intent search queries (e.g., "best project management tool for small teams") to our measurement subprocessors. These queries never contain your name, email, or any other contact or account data.

3. Purposes and Legal Bases (GDPR Article 6)

PurposeData usedLegal basis
Create and operate your accountName, email, auth identifiersPerformance of a contract (Art. 6(1)(b))
Run the GEO/SEO audit and generate your reportDomain, crawled public pages, computed scoresPerformance of a contract (Art. 6(1)(b))
Re-run monthly measurement for paid plansDomain, generic queriesPerformance of a contract (Art. 6(1)(b))
Process payment and manage subscriptionBilling metadata via CreemPerformance of a contract (Art. 6(1)(b))
Connect and read Google Search Console data you authorizeEncrypted OAuth token, GSC metrics for your own propertyPerformance of a contract / your explicit authorization (Art. 6(1)(b), (a))
Send transactional email (report ready, receipt, password/account notices)Email addressPerformance of a contract / legitimate interest (Art. 6(1)(b), (f))
Send product updates or marketing emailEmail addressConsent (Art. 6(1)(a)), separate opt-in, see Section 9
Detect and prevent abuse, secure the ServiceIP address, technical logsLegitimate interest (Art. 6(1)(f))
Debug errors and maintain reliabilityError logs, technical metadata via SentryLegitimate interest (Art. 6(1)(f))
Comply with tax, accounting, and legal obligationsBilling recordsLegal obligation (Art. 6(1)(c))

We do not use your report content, domain data, or account information to train third-party AI models beyond what is strictly necessary to generate your own measurement, and we do not use it for advertising.

4. Who We Share Data With (Subprocessors)

We use a small number of vetted subprocessors, each bound by a data processing agreement. We do not sell your data to anyone, and none of these vendors is permitted to use your data for their own advertising purposes. The current, versioned list is also published on its own page at /subprocessors, and our Data Processing Agreement describes the obligations we place on ourselves and on them.

SubprocessorRoleData involvedLocation
VercelApplication hostingAll application traffic, technical logsUnited States
NeonDatabase hostingAccount, report, and billing recordsUnited States (region-dependent)
ClerkAuthenticationName, email, auth identifiersUnited States
CreemPayment processing (Merchant of Record)Billing metadata; card data stays with Creem and its own PCI-DSS-compliant processors, not usUnited States / EU
ResendEmail delivery (transactional and, with consent, marketing)Email address, email contentUnited States
SentryError monitoringTechnical/error logs, may incidentally include IP addressUnited States
PerplexityAI-answer measurement queriesGeneric search query text, domain (no contact data)United States
SerpApiSearch-engine result measurementGeneric search query text (no contact data)United States
AnthropicQuery generation for measurementPublic homepage text (brand name, title, meta description)United States
OpenAIGEO measurement engine (optional, active when configured)Submitted domain, generic measurement queries (no contact data)United States
Google (Gemini)GEO measurement engine (optional, active when configured)Submitted domain, generic measurement queries (no contact data)United States
xAI (Grok)GEO measurement engine (optional, active when configured)Submitted domain, generic measurement queries (no contact data)United States
Google (Search Console)Optional integration you authorizeSearch performance data for the property you connectUnited States
InngestBackground job orchestration for scheduled monthly re-auditsAccount and subscription identifiers, scheduling metadataUnited States

5. International Data Transfers

Because our subprocessors are primarily based in the United States, personal data originating in the EU/EEA, UK, or Turkey is transferred internationally. For EU/EEA and UK transfers, we rely on Standard Contractual Clauses (SCCs) with our subprocessors and, where available, adequacy mechanisms; we review this list as vendors update their own compliance frameworks. For transfers governed by KVKK, we rely on the explicit consent or the statutory transfer mechanisms available under KVKK Article 9 (as amended), including standard contractual undertakings, pending guidance from the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu).

6. Data Retention

  • Account data: kept for as long as your account is active, plus a limited period after closure for legal/accounting purposes (typically up to the statutory retention period applicable in Turkey, generally up to 10 years for financial records under Turkish Commercial Code and tax law).
  • Report and measurement data: kept while your account is active so you can review historical trends; deleted or anonymized after account deletion.
  • Google Search Console tokens: deleted immediately if you disconnect the integration, and automatically invalidated if not refreshed.
  • Marketing consent records: kept until you withdraw consent, plus a short evidentiary period.
  • Error/technical logs: retained by Sentry per our configured retention window, typically 90 days, then purged.

7. Your Rights

Under GDPR (Articles 15-22) and KVKK (Article 11), you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request erasure ("right to be forgotten")
  • Restrict or object to processing
  • Data portability (receive your data in a structured, machine-readable format)
  • Withdraw consent at any time, without affecting prior lawful processing
  • Lodge a complaint with a supervisory authority (in the EU, your local Data Protection Authority; in Turkey, the Kişisel Verileri Koruma Kurumu)

To exercise any of these rights, email hello@becited.co. We will respond within one month under GDPR, and within the 30-day period required under KVKK Article 13. Upon a verified deletion request, we permanently delete your personal data within 30 days, except where retention is required by law (e.g., billing records).

8. Cookies

We use only strictly necessary, session-based cookies to keep you signed in and to remember your session state. We do not use third-party advertising cookies or cross-site tracking pixels. Because these cookies are essential to the Service, they do not require separate consent under applicable e-Privacy rules, but we disclose them here for transparency. See our Cookie Policy for the full list.

9. Marketing Communications

We only send product updates or marketing email if you separately and affirmatively opt in at sign-up or later in your account settings. This consent is never pre-checked. You can withdraw it at any time via the unsubscribe link in any marketing email or by writing to hello@becited.co, without affecting your ability to use the Service or receive transactional emails necessary to operate your account.

10. Children

The Service is not directed to individuals under 18, and we do not knowingly collect data from them.

11. Changes to This Policy

We will post material changes to this page and update the effective date above. Where required by law, we will notify you by email.

12. Contact

Questions, requests, or complaints: hello@becited.co

See also our Terms of Service and, for Turkish users, the KVKK Aydınlatma Metni.