Legal

Privacy Policy

What we collect, why we collect it, who else touches it, how long we keep it, and what you can make us do about it. Written to be read, not to be skipped.

Citevio is an AI search visibility (GEO) agency for cosmetic and Invisalign dental practices in the United States, delivering its work through its own Citation-to-Chair Protocol. The protocol's discovery layer identifies the buying questions patients actually ask, and the question set is agreed with the practice. Citevio then analyzes daily how ChatGPT, Perplexity, Gemini and Google AI Overviews answer those questions, and the results set the direction of the next round of work. Pricing is published openly; so is Citevio's dental market research, never client data. Citevio is a trading name of Muhammed Veysel Erin LLC, a limited liability company registered in Wyoming, United States.

Plain-language summary, not a substitute for the sections below: this website runs two analytics tools — Google Analytics 4 and Microsoft Clarity — to see how pages are used, and they set cookies. No advertising pixels, and nothing follows you to other websites. We collect what you type into our tools and forms, plus what our scanner reads from public web pages. We never sell personal information. You can ask us to delete anything we hold about you.

1. The short version

Most privacy policies are long because the company is doing a lot of things it would rather you skimmed past. Ours is long because we would rather list everything than leave a gap.

Here is the whole picture in four lines. We measure how this site is used, with Google Analytics 4 and Microsoft Clarity, and we name both in section 3 rather than hiding them. We do not track you across the internet and we run no advertising pixels. We collect an email address only when you type one in. And the technical scan results we gather feed anonymized industry research — never with your practice named.

2. Who is responsible for your data

The controller of any personal information described here is Muhammed Veysel Erin LLC, a Wyoming limited liability company trading as Citevio, at 30 N Gould St, Ste 45178, Sheridan, WY 82801, United States.

For any privacy question or request, email contact@citevio.com. A person reads it, usually within one business day.

3. What happens when you just read this website

We measure how this website is used, and we would rather name the tools than describe them vaguely. There are no advertising pixels and no ad-targeting cookies on this site, and nothing here follows you to other websites. What we do run is two analytics tools:

  • Google Analytics 4. Counts page views: which pages were opened, roughly where in the world the visit came from, which site or search sent you, what device and browser you used, and how long you stayed. It sets a cookie (_ga) so a returning visit is not counted twice. We use Google's IP-anonymization default, and we have not enabled Google Signals or any advertising feature.
  • Microsoft Clarity. Records how pages are used — mouse movement, clicks, scrolling — and turns it into heatmaps and session replays, so we can see which parts of a page confuse people. It sets cookies (_clck, _clsk). Clarity masks text input by default, so what you type into a form or tool is not captured in a replay. We use it to fix the website, never to identify a visitor.

Both tools process data on our behalf as service providers, under Google's and Microsoft's privacy terms. We do not sell this data or share it for cross-context behavioral advertising. If you would rather not be measured at all, a browser in private mode, a tracker blocker, or your browser's "Do Not Track" / Global Privacy Control signal will keep you out of both — and you can also email us to have your data deleted.

Two ordinary technical things happen as well. Our hosting provider, Cloudflare, processes your IP address and browser type to serve the page and to block attacks — standard server operation, not profiling. And the page loads typefaces from Google Fonts, which means Google's font servers receive your IP address as part of that request.

That is the complete list for a passive visit. We do not learn your name, your email or your practice from simply reading the site — those reach us only when you type them into a form or tool.

4. What we collect when you run the free AI check

Our free checker takes a website address and reads that site the way an AI crawler would. It looks at public pages only — the same information any search engine sees.

For each scan we store:

  • The domain and URL you entered, and the date and time of the scan.
  • The technical result: the visibility score and grade, plus the individual signals behind it — whether a robots.txt exists, which AI crawlers are allowed or blocked, whether business and FAQ structured data are present, whether the address and phone in that data are complete, question-style headings, word count, sitemap status, freshness signals, bot protection and noindex flags.
  • Context about the request: the referring page, the country the request came from, how long the scan took, and which version of our engine ran it.
  • A salted hash of the IP address — not the address itself. It exists for one purpose: rate limiting, so one source cannot flood the tool. It cannot be reversed to identify you.

We do not store your raw IP address for the checker, and we do not require an email address to use it. If you run the tool and type nothing else, we have a technical record of a website — not of a person.

5. What we collect when you request the free deep scan

If you ask for the free 48-hour deep scan, or leave your details inside the checker to receive the full report, you give us information directly. That is: your email address, and where you provide them, your name, practice name, website and city.

The deep scan request form is hosted by Tally, which processes those answers on our behalf and passes them to us. In-tool report requests are stored in our own database, linked to the scan they came from.

We use these details to run the scan, send you the report, and follow up about it. You can tell us to stop at any time and we will.

6. What we collect when you become a client

When you buy a plan, we collect your name, business name, billing address, email address and the details of what you purchased.

We never see or store your full card number or bank account number. Payments run through Stripe, which collects those directly. We receive only what Stripe shows us: the last four digits, the card brand, whether a payment succeeded, and the invoice record.

To deliver the work, you also give us access to systems that belong to you — your website or CMS, Google Business Profile, listing and review platforms. We treat those credentials as confidential, use them only to perform the services, and give them up when the engagement ends.

7. What happens when we email you first

We sometimes contact dental practices that are not yet clients, to offer a free visibility scan. When we do, we use business contact information: a practice name, a practice website, and a work email address, gathered from public sources such as the practice's own website and public business listings.

We do not buy consumer data, and we do not contact private individuals at personal addresses.

Every message we send includes a way to opt out. If you tell us to stop — by replying, unsubscribing, or emailing us — we remove your details and do not contact you again. You do not need to give a reason.

8. Why we use your data

What we useWhat for
Scan inputs and resultsProducing your report, and improving the accuracy of the scanning engine
Email address and practice detailsSending the report you asked for, answering you, and following up about it
Client and billing recordsDelivering the services, taking payment, issuing invoices, meeting tax and accounting obligations
Hashed IP addressRate limiting and abuse prevention only
Aggregated, anonymized scan dataIndustry research we publish — see section 9

We do not use your data to build advertising profiles, and we do not feed it to third-party AI training systems.

9. How scan data appears in our research

We publish research about how visible dental practices are to AI search engines, built from the scans our own engine runs. This is worth stating clearly rather than burying.

That research uses aggregated and anonymized data: counts, percentages, engine-by-engine breakdowns and patterns across many practices. Individual findings appear only in a form that cannot identify a practice — we write "a 4.8-star practice with 300+ reviews", never a clinic's name.

We do not name, shame or identify any specific practice in published research without that practice's written permission. If you would rather your scan was excluded from aggregate research entirely, email us and we will remove it.

10. Who else processes your data

We keep the list of outside services deliberately short. These are the only ones that touch data connected to this site:

ProviderWhat it handles
CloudflareWebsite and scanner hosting, and the database that stores scan results
StripePayment processing, card and bank details, invoices, subscription management
TallyThe deep scan request form
Google FontsServing the typefaces this page uses; receives your IP as part of that request

Each of these acts on our instructions for the purpose listed, under its own privacy terms. We also use ordinary business email to correspond with you.

Review invitations are not on this list, on purpose. Where a client's plan includes review generation, the messages go out through a platform held in that practice's own account, connected to its own systems — it processes that data for the practice, not for us. If we ever engage a provider that processes data on our behalf, it will be added to the table above before it starts, and clients will be told.

Beyond that, we disclose personal information only when the law requires it, or if the business is ever sold or merged — in which case the buyer would be bound by this policy and we would tell you before anything changed.

11. Cookies and tracking

This website sets no advertising cookies and nothing here tracks you across other websites. It does set analytics cookies, and here is the full list:

CookieSet byWhat it doesLifetime
_ga, _ga_*Google Analytics 4Tells a returning visit from a new one, so page views are not double-countedUp to 2 years
_clckMicrosoft ClarityKeeps one anonymous ID for the browser across visits1 year
_clskMicrosoft ClarityJoins the page views of a single visit into one session1 day

None of these carry your name or email, and none are used for advertising. A tracker blocker, private browsing, or a Global Privacy Control signal will stop them; the site works normally without them.

Two more sit outside our pages. If you go through Stripe's checkout, Stripe sets cookies it needs for payment security and fraud prevention. If you open the Tally form, Tally sets cookies needed to run the form. Those are governed by their own policies, and they apply only when you use those services.

12. We do not sell your data

We have never sold personal information, we do not sell it now, and we do not share it for cross-context behavioral advertising — the two things US state privacy laws specifically ask about.

If that ever changed, we would say so on this page before it happened, not after.

13. How long we keep things

DataKept for
Scan results and technical signalsIndefinitely, as a time series — this is what lets us show how visibility changes over time
Hashed IP addresses90 days, then deleted
Report requests and prospect emails24 months from last contact, unless you ask us to delete sooner
Client records and correspondenceFor the engagement, then 24 months
Invoices and payment records7 years, because tax law requires it

When a retention period ends, we delete the data or strip it of anything that could identify a person.

14. How we protect it

Data is encrypted in transit. Access is limited to the people who need it — in practice, a very small number. Payment credentials never reach our systems at all, which removes the highest-risk category of data entirely.

No system is perfectly secure and we will not pretend otherwise. If a breach affects your personal information, we will tell you and the relevant authorities without undue delay, and we will tell you what actually happened rather than a sanitized version.

15. Your rights

Wherever you are, you can ask us to:

  • Tell you what we hold about you, and where it came from.
  • Correct anything that is wrong.
  • Delete what we hold, subject to records we are legally required to keep, such as invoices.
  • Give you a copy in a portable format.
  • Stop contacting you, at any time, for any reason or none.

Email contact@citevio.com. We respond within 30 days, usually much sooner, and we do not charge for this. We may need to confirm your identity first, so that someone else cannot request your data.

We will never treat you differently — worse service, worse price, refusal to work with you — because you exercised any of these rights.

16. If you are a California resident

The California Consumer Privacy Act, as amended by the CPRA, gives California residents specific rights. Those are the rights already listed in section 15: the right to know, to delete, to correct, to portability, to opt out of sale or sharing, and to non-discrimination for exercising them.

Specifically, for the twelve months before the date at the top of this page: the categories of personal information we collect are identifiers (name, email address, business address) and commercial information (what you purchased). We collect them from you directly and from public business sources. We disclose them for business purposes to the providers listed in section 10. We have not sold or shared personal information, and we do not knowingly collect information from anyone under 16.

You may use an authorized agent to make a request. Email us the same way; we will verify the authorization before acting.

17. Patient health information

We do not want, ask for, or knowingly process patient health information. Our work concerns your practice's public presence, not your patients' records.

Review generation is the one part of our work that touches patient contact, so it is worth being exact about it. Invitations are sent through a platform connected to your practice management system, under your account and in your name. We configure and monitor that flow; patient names, contact details, appointment times and treatment information stay in your systems and do not reach us. Where any arrangement would place us in the position of a business associate under HIPAA, we will sign a Business Associate Agreement before that work begins.

Please do not send us patient names, treatment records, images or anything else that would fall under HIPAA. If we receive such information, we delete it and tell you.

18. Children

Our services are sold to businesses and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email us and we will delete it.

19. If you are visiting from outside the United States

Citevio is a US company serving US clients, and the data described here is processed in the United States. Privacy laws there may differ from those where you live.

If you are in the European Economic Area or the United Kingdom and you have given us personal data, you have the rights set out in section 15, and you may also lodge a complaint with your local supervisory authority. Where we rely on a legal basis, it is your consent for reports you asked us to send, our contract with you for client work, and our legitimate interest in operating and securing the site for everything else. You may withdraw consent at any time.

20. Changes to this policy

When this policy changes, we update the "last updated" date at the top of the page. If a change materially affects how we handle your information, we will email clients and anyone who has given us an address, at least 30 days before it takes effect.

We do not backdate changes, and we keep the effective date visible so you can tell which version applied when.

21. How to reach us

Email contact@citevio.com — for privacy requests, questions, or to tell us to delete everything we have. We reply within one business day.

Postal: Muhammed Veysel Erin LLC, 30 N Gould St, Ste 45178, Sheridan, WY 82801, United States.

For the commercial agreement between us, see our Terms of Service.