Most scholarly platforms watch what you read and sell the trail.
CiteStamp’s entire product is public records about papers — private records
about you are a liability we refuse to hold. This page lists everything we touch.
It is short because there is not much.
What this site does not do
No analytics. No tracking pixels. No fingerprinting. No ad tech.
No tracking cookies — which is why there is no cookie banner to click away.
No browsing history, reading list, or interest profile, on the site or in the
extension. We never learn what you read — only what you explicitly ask the graph about.
Open your browser’s network tab and count the trackers: the only third-party
request a page load makes is to Google Fonts for typeface files. Google sees that
request’s standard metadata (IP address, user agent); no analytics flow back to us
from it. Using the health check or the picker additionally makes client-direct lookups
to the open scholarly registries — listed below, under their own policies.
What stays in your browser
item
what it is
cs_theme
localStorage — your dark/light choice
citestamp_token
localStorage — only if you paste an API key on the main page; never set otherwise
cs_staged:<name>
localStorage — claims you stage in the writing picker, keyed by manuscript name. These never reach our servers; export is a file download.
cs_claim
cookie — set only after you sign in with ORCID to claim a paper; HttpOnly, expires in 24 hours
What crosses the wire
Asks. When you query the graph, the identifier you typed is the request.
Anonymous requests are rate-limited by IP address; the IP is held transiently in a
sliding-window counter and is not written to any record.
Picker searches. The writing picker searches OpenAlex directly from your
browser — your manuscript text never touches a CiteStamp server. OpenAlex sees the
search string under its own policy.
Bibliography checks. The health check parses what you paste in your browser
and looks each reference up one identifier at a time, client-direct: DOIs and titles go
to Crossref, DataCite, and OpenAlex under their own policies, and resolved identifiers
are checked against CiteStamp’s public graph endpoint. The pasted text itself is
never sent anywhere as a document, and no copy of your reference list is stored.
ORCID sign-in. Claiming a paper sends you to orcid.org; ORCID returns your
iD and public name to us, nothing else.
The short list of what we store
The public graph. Claims connecting public identifiers — no full text, no
abstracts, no personal data on any node. A claim you sign carries your public researcher
identifier, and it is permanent on an append-only log. That is not a privacy accident;
it is the product. The one thing we keep forever is the thing you asked us to publish.
Claim accounts. Your ORCID iD and the signing key we custody for you,
encrypted at rest. The iD is a public identifier by design.
The browser extension
The CiteStamp extension reads the page you are on locally to find a paper
identifier (a DOI). When it finds one, it sends only that identifier to
api.citestamp.com to fetch the paper’s public citation record. That is the entire
data flow. It collects no browsing history, runs no analytics, loads no remote code, and
sells nothing — there is nothing to sell. Anything you stage through it stays in your
browser, same as the table above.
Email
You will only ever get one kind of email from us: a reply to mail you sent. There is no
list to join and nothing to unsubscribe from — no newsletters you did not ask for, no
“we miss you.”
Changes
We run an append-only log for a living — we are not going to quietly rewrite a privacy
policy. When a change matters it appears here, and the change is dated.
Contact
Questions, deletion requests, anything:
info@citestamp.com. A human reads it.