passcite
Legal

Privacy

Last updated

Passcite is run by one person. This page describes what the product actually stores today, not what a template says it might. If something here stops matching the software, the page is wrong and I want to know: hello@passcite.com.

What is collected

When you ask for a free report

The report form takes a client website address, optionally an industry and a service area, and your email address. That is all it stores.

Giving an email address here does not create an account, and does not add anything to an existing one. Anyone can type anyone's address into a form, so an address typed here is not treated as proof of identity. The request is held against the address on its own. It becomes part of an account only when someone signs in with Google on that same address, because Google has verified that they own it. Until that happens, nothing is sent to the address and nobody can see the request from inside the product.

When you sign in with Google

Google is asked for three scopes — openid, your email address, and your basic profile — and nothing else. Passcite has no access to your Gmail, Drive, contacts or calendar. From that, these are stored:

  • Your name, email address, and the URL of your Google profile picture.
  • A Google access token and ID token, kept so the sign-in works. No refresh token is requested, so Passcite cannot act on your Google account when you are not using it.
  • A session record: a random token, the IP address and browser user-agent the session was created from, and an expiry 7 days out.

What is not collected

  • No analytics and no tracking of any kind. There is no analytics script, no tag manager, no advertising pixel and no third-party cookie anywhere on this site.
  • One cookie, and only after you sign in. It holds the session token. It is marked Secure and SameSite=Lax, it is host-only — it is not shared with subdomains — and it lasts 7 days.
  • No passwords. Sign-in is Google only, so there is none to store.
  • No payment details. Passcite does not take payments yet; when it does, card details will go to the payment processor and never to Passcite.

What it is used for

  • The website address and industry are what the report is generated from.
  • Your email address identifies which requests are yours, so they appear in your dashboard after you sign in.
  • The session record keeps you signed in. The IP address and user-agent on it exist so a suspicious session can be recognised; they are not used to profile you or build an audience.
  • A daily cap of 5 report requests per email address is enforced by counting recent requests for that address. This is to stop someone filling the queue with another person's address.

Email

Passcite currently sends no email at all. When report emails start — the one email the report form promises, and later the weekly re-run summary — they will be sent through Resend, and only to an address that has been verified by signing in. An address that was typed into the form and never claimed will not be emailed. There is no newsletter, and your address is not shared or sold.

Who else touches the data

  • Vercel — hosting and serving this site (United States).
  • Neon — the Postgres database where the above is stored (AWS, US East).
  • Google — sign-in only.
  • Resend — email delivery. Not in use yet, as above.
  • Cloudflare — DNS, and email routing for hello@passcite.com.

When the report engine ships, the client website address in a request is also sent to the AI engines being tested — ChatGPT through the OpenAI API, Perplexity, and Gemini — as part of the questions asked about that business. Your email address is never sent to them.

How long it is kept

  • Report requests are kept while your account exists, so your dashboard keeps its history.
  • Sessions stop working 7 days after they are created. Signing out deletes that session record immediately.
  • An unclaimed report request — one filed against an address that never signed in — is kept so that the person can still claim it later. Ask and it will be removed.

Getting your data, or getting it deleted

Email hello@passcite.com and ask. You can ask for a copy of what is stored about you, ask for it to be corrected, or ask for all of it to be deleted. Deleting an account removes its report requests with it.

Being honest about the mechanics: there is no self-service delete button yet. Requests are handled by hand, by one person, and the aim is within 30 days. If that ever stops being fast enough, the button gets built.

Children

Passcite is a tool for marketing agencies and is not directed at anyone under 16. If you believe a child has given us personal data, email hello@passcite.com and it will be deleted.

Changes

If this page changes in a way that affects what is collected or who it goes to, the date at the top changes and the change is described here. The current version is the one you are reading.

Contact

Passcite, hello@passcite.com. It is one address, read by one person, and it is the same address for privacy questions, support and everything else. See also the Terms.