Privacy Policy

Last updated 1 September 2026

Citable serves AI crawlers a clean, machine-readable copy of a merchant’s storefront and records which crawlers read which pages. It is built around catalogue data and crawler traffic.

Citable does not collect, store or process any customer personal data. It never requests access to orders, customers or checkout, so Shopify does not grant it any. The only visitors it records are automated crawlers.

What Citable stores

DataWhyKept for
Shop domain and access tokenTo authenticate with Shopify on the merchant’s behalfUntil uninstall
App settingsOn/off, render mode, chosen products, cache lifetimeUntil uninstall
Crawl eventsWhich crawler (e.g. GPTBot), which page path, response size, and the product price shown at that moment30–730 days, by plan

What Citable never accesses

Orders, customers, checkout, payment details, email addresses, personal data of any kind. The permissions the app requests are read-only across products, inventory, content, pages, navigation, locales, translations and markets. It holds exactly one write permission — themes — used solely to add an optional, clearly-marked and fully reversible block to robots.txt.liquid when a merchant asks for it.

The app proxy strips Shopify’s logged_in_customer_id parameter from every request before anything is recorded, so a signed-in shopper is never identifiable in a log.

Crawler identification

Citable records the user-agent string of automated crawlers, and may compare the connecting address against the IP ranges OpenAI, Anthropic and Perplexity publish, to confirm a crawler is genuinely theirs. The address is used for that check alone and is never stored— only the verdict is.

Sub-processors

ProviderPurposeRegion
Amazon Web Services (Lightsail)Application hostingMumbai, India
NeonDatabaseSingapore
CloudflareOptional Edge Mode, when a merchant enables itGlobal

Deletion

Uninstalling removes the session immediately. Settings and crawl history are kept for 90 days so a reinstall does not lose a merchant’s analytics, then deleted. Shopify’s shop/redact request erases everything for that shop at once.

Citable implements all three of Shopify’s mandatory compliance webhooks. Because no customer data is held, a customers/data_request or customers/redact request is acknowledged with nothing to report — there is nothing to hand over or erase.

Security

All traffic is served over HTTPS. Credentials are held as environment variables readable only by root, never in source control. The application listens on loopback behind a reverse proxy and is not reachable directly from the internet.

Contact

Questions, or a request to erase data: helpwavx@gmail.com