Plain-language summary, not a substitute for the sections below: this website sets no tracking cookies and runs no analytics. We collect what you type into our tools and forms, plus what our scanner reads from public web pages. We never sell personal information. You can ask us to delete anything we hold about you.
1. The short version
Most privacy policies are long because the company is doing a lot of things it would rather you skimmed past. Ours is long because we would rather list everything than leave a gap.
Here is the whole picture in four lines. We do not track you across the internet. We do not run analytics on this site. We collect an email address only when you type one in. And the technical scan results we gather feed anonymized industry research — never with your practice named.
2. Who is responsible for your data
The controller of any personal information described here is Muhammed Veysel Erin LLC, a Wyoming limited liability company trading as Citevio, at 30 N Gould St, Ste 45178, Sheridan, WY 82801, United States.
For any privacy question or request, email contact@citevio.com. A person reads it, usually within one business day.
3. What happens when you just read this website
Almost nothing. This site runs no analytics software, no advertising pixels and no tracking cookies. We do not know that you visited, which pages you read, or how long you stayed.
Two ordinary technical things still happen. Our hosting provider, Cloudflare, processes your IP address and browser type to serve the page and to block attacks — standard server operation, not profiling. And the page loads typefaces from Google Fonts, which means Google's font servers receive your IP address as part of that request.
That is the complete list for a passive visit. If you leave without typing anything into a form or tool, we hold no personal information about you.
4. What we collect when you run the free AI check
Our free checker takes a website address and reads that site the way an AI crawler would. It looks at public pages only — the same information any search engine sees.
For each scan we store:
- The domain and URL you entered, and the date and time of the scan.
- The technical result: the visibility score and grade, plus the individual signals behind it — whether a robots.txt exists, which AI crawlers are allowed or blocked, whether business and FAQ structured data are present, whether the address and phone in that data are complete, question-style headings, word count, sitemap status, freshness signals, bot protection and noindex flags.
- Context about the request: the referring page, the country the request came from, how long the scan took, and which version of our engine ran it.
- A salted hash of the IP address — not the address itself. It exists for one purpose: rate limiting, so one source cannot flood the tool. It cannot be reversed to identify you.
We do not store your raw IP address for the checker, and we do not require an email address to use it. If you run the tool and type nothing else, we have a technical record of a website — not of a person.
5. What we collect when you request the free deep scan
If you ask for the free 24-hour deep scan, or leave your details inside the checker to receive the full report, you give us information directly. That is: your email address, and where you provide them, your name, practice name, website and city.
The deep scan request form is hosted by Tally, which processes those answers on our behalf and passes them to us. In-tool report requests are stored in our own database, linked to the scan they came from.
We use these details to run the scan, send you the report, and follow up about it. You can tell us to stop at any time and we will.
6. What we collect when you become a client
When you buy a plan, we collect your name, business name, billing address, email address and the details of what you purchased.
We never see or store your full card number or bank account number. Payments run through Stripe, which collects those directly. We receive only what Stripe shows us: the last four digits, the card brand, whether a payment succeeded, and the invoice record.
To deliver the work, you also give us access to systems that belong to you — your website or CMS, Google Business Profile, listing and review platforms. We treat those credentials as confidential, use them only to perform the services, and give them up when the engagement ends.
7. What happens when we email you first
We sometimes contact dental practices that are not yet clients, to offer a free visibility scan. When we do, we use business contact information: a practice name, a practice website, and a work email address, gathered from public sources such as the practice's own website and public business listings.
We do not buy consumer data, and we do not contact private individuals at personal addresses.
Every message we send includes a way to opt out. If you tell us to stop — by replying, unsubscribing, or emailing us — we remove your details and do not contact you again. You do not need to give a reason.
8. Why we use your data
| What we use | What for |
|---|---|
| Scan inputs and results | Producing your report, and improving the accuracy of the scanning engine |
| Email address and practice details | Sending the report you asked for, answering you, and following up about it |
| Client and billing records | Delivering the services, taking payment, issuing invoices, meeting tax and accounting obligations |
| Hashed IP address | Rate limiting and abuse prevention only |
| Aggregated, anonymized scan data | Industry research we publish — see section 9 |
We do not use your data to build advertising profiles, and we do not feed it to third-party AI training systems.
9. How scan data appears in our research
We publish research about how visible dental practices are to AI search engines, built from the scans our own engine runs. This is worth stating clearly rather than burying.
That research uses aggregated and anonymized data: counts, percentages, engine-by-engine breakdowns and patterns across many practices. Individual findings appear only in a form that cannot identify a practice — we write "a 4.8-star practice with 300+ reviews", never a clinic's name.
We do not name, shame or identify any specific practice in published research without that practice's written permission. If you would rather your scan was excluded from aggregate research entirely, email us and we will remove it.
10. Who else processes your data
We keep the list of outside services deliberately short. These are the only ones that touch data connected to this site:
| Provider | What it handles |
|---|---|
| Cloudflare | Website and scanner hosting, and the database that stores scan results |
| Stripe | Payment processing, card and bank details, invoices, subscription management |
| Tally | The deep scan request form |
| Google Fonts | Serving the typefaces this page uses; receives your IP as part of that request |
Each of these acts on our instructions for the purpose listed, under its own privacy terms. We also use ordinary business email to correspond with you.
Beyond that, we disclose personal information only when the law requires it, or if the business is ever sold or merged — in which case the buyer would be bound by this policy and we would tell you before anything changed.
12. We do not sell your data
We have never sold personal information, we do not sell it now, and we do not share it for cross-context behavioral advertising — the two things US state privacy laws specifically ask about.
If that ever changed, we would say so on this page before it happened, not after.
13. How long we keep things
| Data | Kept for |
|---|---|
| Scan results and technical signals | Indefinitely, as a time series — this is what lets us show how visibility changes over time |
| Hashed IP addresses | 90 days, then deleted |
| Report requests and prospect emails | 24 months from last contact, unless you ask us to delete sooner |
| Client records and correspondence | For the engagement, then 24 months |
| Invoices and payment records | 7 years, because tax law requires it |
When a retention period ends, we delete the data or strip it of anything that could identify a person.
14. How we protect it
Data is encrypted in transit. Access is limited to the people who need it — in practice, a very small number. Payment credentials never reach our systems at all, which removes the highest-risk category of data entirely.
No system is perfectly secure and we will not pretend otherwise. If a breach affects your personal information, we will tell you and the relevant authorities without undue delay, and we will tell you what actually happened rather than a sanitized version.
15. Your rights
Wherever you are, you can ask us to:
- Tell you what we hold about you, and where it came from.
- Correct anything that is wrong.
- Delete what we hold, subject to records we are legally required to keep, such as invoices.
- Give you a copy in a portable format.
- Stop contacting you, at any time, for any reason or none.
Email contact@citevio.com. We respond within 30 days, usually much sooner, and we do not charge for this. We may need to confirm your identity first, so that someone else cannot request your data.
We will never treat you differently — worse service, worse price, refusal to work with you — because you exercised any of these rights.
16. If you are a California resident
The California Consumer Privacy Act, as amended by the CPRA, gives California residents specific rights. Those are the rights already listed in section 15: the right to know, to delete, to correct, to portability, to opt out of sale or sharing, and to non-discrimination for exercising them.
Specifically, for the twelve months before the date at the top of this page: the categories of personal information we collect are identifiers (name, email address, business address) and commercial information (what you purchased). We collect them from you directly and from public business sources. We disclose them for business purposes to the providers listed in section 10. We have not sold or shared personal information, and we do not knowingly collect information from anyone under 16.
You may use an authorized agent to make a request. Email us the same way; we will verify the authorization before acting.
17. Patient health information
We do not want, ask for, or knowingly process patient health information, and nothing in our services requires it. Our work concerns your practice's public presence, not your patients' records.
Please do not send us patient names, treatment records, images or anything else that would fall under HIPAA. If we receive such information, we delete it and tell you.
18. Children
Our services are sold to businesses and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email us and we will delete it.
19. If you are visiting from outside the United States
Citevio is a US company serving US clients, and the data described here is processed in the United States. Privacy laws there may differ from those where you live.
If you are in the European Economic Area or the United Kingdom and you have given us personal data, you have the rights set out in section 15, and you may also lodge a complaint with your local supervisory authority. Where we rely on a legal basis, it is your consent for reports you asked us to send, our contract with you for client work, and our legitimate interest in operating and securing the site for everything else. You may withdraw consent at any time.
20. Changes to this policy
When this policy changes, we update the "last updated" date at the top of the page. If a change materially affects how we handle your information, we will email clients and anyone who has given us an address, at least 30 days before it takes effect.
We do not backdate changes, and we keep the effective date visible so you can tell which version applied when.
21. How to reach us
Email contact@citevio.com — for privacy requests, questions, or to tell us to delete everything we have. We reply within one business day.
Postal: Muhammed Veysel Erin LLC, 30 N Gould St, Ste 45178, Sheridan, WY 82801, United States.
For the commercial agreement between us, see our Terms of Service.