Legal · CitedScore

Sub-processors

Last updated: August 15, 2026

A sub-processor is a third party we use to provide the Service. We use sub-processors to run the AI audit engine, host the site and the application, process payments, send email, and monitor for errors.

Depending on what you do on CitedScore, we send a sub-processor some combination of: the URL and public content of the domain you submit for audit, the queries our engine generates to test AI visibility, the answers AI platforms return to those queries, and your email address.

The audit engine fetches the public pages of the domain you submit. That crawling runs on our own infrastructure using a browser bundled into our audit container; no third-party crawling or scraping service is involved.

For services where we chose the hosting region ourselves, the region below is the one we selected. For every other service, it is the primary processing region the provider publishes.

How to know when this page changes

Every revision to this page is dated in the change log below. If you want to be notified directly, email [email protected].

AI sub-processors

These process data to generate and evaluate the AI audit queries a Report is built from.

OpenAIAI model provider, ChatGPT audit queriesUnited States
Data shared
The generated audit query text. Those queries are built from the audited business name, its category and the names of its competitors, so the query text carries all three. No account data, no email addresses.
Notes
Called through the OpenAI API with web search enabled, so the query also reaches OpenAI's search partners. API inputs are not used to train OpenAI's models under its published API data usage policy.
AnthropicAI model provider, buyer persona generation, report narrative, scoring and validationUnited States
Data shared
The audited domain's URL, page titles, meta descriptions, headings and page text captured during the crawl; the business name, category, location, services and competitors derived from it; and excerpts of the answers returned by the other AI platforms.
Notes
The broadest data exposure on this page: most of the written analysis in a Report is produced here. Inputs are not used to train Anthropic's models under its commercial terms.
Google (Gemini API)AI model provider, Gemini audit queriesUnited States
Data shared
The generated audit query text. Those queries are built from the audited business name, its category and the names of its competitors, so the query text carries all three. No account data, no email addresses.
Notes
Called with Google Search grounding enabled, so the query reaches Google Search as part of the request. Grounding citation URLs are resolved through vertexaisearch.cloud.google.com.
PerplexityAI model provider, Perplexity audit queriesUnited States
Data shared
The generated audit query text. Those queries are built from the audited business name, its category and the names of its competitors, so the query text carries all three. No account data, no email addresses.
Notes
Called through the Perplexity API.
DataForSEOSearch results data provider, Google AI Overviews retrievalUnited States
Data shared
The generated audit query text. Those queries are built from the audited business name, its category and the names of its competitors, so the query text carries all three. No account data, no email addresses. Sent with a country level location code (United States).
Notes
Used because Google publishes no API for AI Overviews. DataForSEO runs the search and returns the AI Overview and the sources it cites.

Public data sources

These return published data about a page. We send them the address of the page being audited, nothing about you.

Google (Chrome UX Report API)Public web performance dataset lookupUnited States
Data shared
The audited page URL and its origin. No customer-identifying data.
Notes
A read-only query against Google's public field performance dataset. When it is unavailable the Report is produced without it.

Infrastructure and operations

These run the site, deliver the product, and keep the business operating.

SupabaseDatabase, authentication and file storageUnited States (US West)
Data shared
Your account email address, the domains you submit, audit results and report data, and the generated PDF Reports.
Notes
The primary system of record. Also delivers the sign in link sent when you access your account.
RailwayCompute for the audit engineUnited States (US East)
Data shared
Everything an audit processes while it runs: crawled page content, generated queries, the answers returned by AI platforms, and the Report as it is assembled.
Notes
The engine runs here as a container. Results are written to Supabase, not stored on Railway; Railway retains runtime logs.
NetlifyHosting and delivery for the website and applicationGlobal edge network
Data shared
Request data for every page and API call, including IP address, browser user agent and the requested URL.
Notes
Serves the marketing site, the application and its API routes.
CloudflareDNS, proxy and bot verificationGlobal edge network
Data shared
Request data including IP address and browser user agent. For bot verification, the challenge response and the IP address it came from.
Notes
Bot verification protects the signup and audit request forms from automated abuse.
UpstashRequest rate limitingUnited States (US East)
Data shared
A salted, irreversible hash of the request IP address, plus the requested path. No raw IP address and no email address.
Notes
Counters expire on their own; nothing is retained past the rate limit window.
StripePayment processingUnited States
Data shared
Your email address and the domain the purchase is for. Card details are entered with Stripe directly and never reach CitedScore.
Notes
Checkout is hosted by Stripe. We receive the result of the payment, not the payment instrument.
Kit (ConvertKit)Email list management and marketing emailUnited States
Data shared
Your email address and the tags applied to it, such as waitlist member or customer.
Notes
Used for the waitlist, product announcements and lifecycle email.
ResendTransactional email deliveryUnited States
Data shared
Your email address, and the subject and body of the message. Report files are not attached to email; they stay in our storage and are served from your account.
Notes
Sends report ready notifications, scan results and account email.
SentryError and performance monitoringUnited States
Data shared
Error messages, stack traces and request URLs from the website, the API and the audit engine.
Notes
Configured with personal data capture disabled and session replay switched off. Cookies and request headers are removed from engine events before they are sent.
Google (Tag Manager and Analytics 4)Website analytics and tag managementUnited States
Data shared
Pages viewed, referring source, approximate location derived from IP address, device and browser details, and a first-party analytics identifier stored in a cookie.
Notes
Tag Manager loads the two measurement tools below. Google Signals is enabled on our Analytics property, associating activity across devices for visitors signed in to a Google account with Ads Personalization on. See the Cookies section of the Privacy Policy.
Microsoft (Clarity)Session recording and heatmapsUnited States
Data shared
A recording of your interaction with the pages you visit: mouse movement, clicks, scrolling, and the page content as it rendered for you.
Notes
Loaded through Google Tag Manager. Used to find usability problems.
Fontshare (Indian Type Foundry)Web font delivery (the Switzer typeface)Global CDN
Data shared
The standard data any font CDN request carries: your IP address, browser user agent, and the URL of the page you are viewing.
Notes
Loaded on every page of the site, as part of the shared page design. Every other typeface is self-hosted and never leaves our own servers.
HotjarSession recording and heatmapsEuropean Union
Data shared
A recording of your interaction with the pages you visit: mouse movement, clicks, scrolling, and the page content as it rendered for you.
Notes
Loaded through Google Tag Manager. Used to find usability problems.

Change log

August 15, 2026

Fontshare row widened: the Switzer typeface is now loaded on every page of the site rather than only on report pages, because the site design moved to a shared type system. Fontshare’s CDN therefore sees the standard font-request data (IP address, browser user agent, page URL) for any visit, not only for report visits. No other change to what is shared.

August 14, 2026

Fontshare (Indian Type Foundry) added: report pages load the Switzer typeface from Fontshare’s CDN, which sees the standard font-request data (IP address, browser user agent, referring page). Report routes only; every other typeface is self-hosted.

August 7, 2026

Resend row updated: completed reports are no longer emailed as PDF attachments. Report files stay in our storage and are served from your account; this applies going forward only, not to messages already delivered.

August 5, 2026

Initial publication of this page.