Legal

Privacy Policy

What we collect, why we collect it, who else touches it, how long we keep it, and what you can make us do about it. Written to be read, not to be skipped.

Citevio is a US-based AI visibility (GEO/AEO) agency that helps cosmetic dentistry and Invisalign clinics get recommended by AI search engines including ChatGPT, Perplexity and Google Gemini. Citevio is a trading name of Muhammed Veysel Erin LLC, a limited liability company registered in Wyoming, United States.

Plain-language summary, not a substitute for the sections below: this website sets no tracking cookies and runs no analytics. We collect what you type into our tools and forms, plus what our scanner reads from public web pages. We never sell personal information. You can ask us to delete anything we hold about you.

1. The short version

Most privacy policies are long because the company is doing a lot of things it would rather you skimmed past. Ours is long because we would rather list everything than leave a gap.

Here is the whole picture in four lines. We do not track you across the internet. We do not run analytics on this site. We collect an email address only when you type one in. And the technical scan results we gather feed anonymized industry research — never with your practice named.

2. Who is responsible for your data

The controller of any personal information described here is Muhammed Veysel Erin LLC, a Wyoming limited liability company trading as Citevio, at 30 N Gould St, Ste 45178, Sheridan, WY 82801, United States.

For any privacy question or request, email contact@citevio.com. A person reads it, usually within one business day.

3. What happens when you just read this website

Almost nothing. This site runs no analytics software, no advertising pixels and no tracking cookies. We do not know that you visited, which pages you read, or how long you stayed.

Two ordinary technical things still happen. Our hosting provider, Cloudflare, processes your IP address and browser type to serve the page and to block attacks — standard server operation, not profiling. And the page loads typefaces from Google Fonts, which means Google's font servers receive your IP address as part of that request.

That is the complete list for a passive visit. If you leave without typing anything into a form or tool, we hold no personal information about you.

4. What we collect when you run the free AI check

Our free checker takes a website address and reads that site the way an AI crawler would. It looks at public pages only — the same information any search engine sees.

For each scan we store:

  • The domain and URL you entered, and the date and time of the scan.
  • The technical result: the visibility score and grade, plus the individual signals behind it — whether a robots.txt exists, which AI crawlers are allowed or blocked, whether business and FAQ structured data are present, whether the address and phone in that data are complete, question-style headings, word count, sitemap status, freshness signals, bot protection and noindex flags.
  • Context about the request: the referring page, the country the request came from, how long the scan took, and which version of our engine ran it.
  • A salted hash of the IP address — not the address itself. It exists for one purpose: rate limiting, so one source cannot flood the tool. It cannot be reversed to identify you.

We do not store your raw IP address for the checker, and we do not require an email address to use it. If you run the tool and type nothing else, we have a technical record of a website — not of a person.

5. What we collect when you request the free deep scan

If you ask for the free 24-hour deep scan, or leave your details inside the checker to receive the full report, you give us information directly. That is: your email address, and where you provide them, your name, practice name, website and city.

The deep scan request form is hosted by Tally, which processes those answers on our behalf and passes them to us. In-tool report requests are stored in our own database, linked to the scan they came from.

We use these details to run the scan, send you the report, and follow up about it. You can tell us to stop at any time and we will.

6. What we collect when you become a client

When you buy a plan, we collect your name, business name, billing address, email address and the details of what you purchased.

We never see or store your full card number or bank account number. Payments run through Stripe, which collects those directly. We receive only what Stripe shows us: the last four digits, the card brand, whether a payment succeeded, and the invoice record.

To deliver the work, you also give us access to systems that belong to you — your website or CMS, Google Business Profile, listing and review platforms. We treat those credentials as confidential, use them only to perform the services, and give them up when the engagement ends.

7. What happens when we email you first

We sometimes contact dental practices that are not yet clients, to offer a free visibility scan. When we do, we use business contact information: a practice name, a practice website, and a work email address, gathered from public sources such as the practice's own website and public business listings.

We do not buy consumer data, and we do not contact private individuals at personal addresses.

Every message we send includes a way to opt out. If you tell us to stop — by replying, unsubscribing, or emailing us — we remove your details and do not contact you again. You do not need to give a reason.

8. Why we use your data

What we useWhat for
Scan inputs and resultsProducing your report, and improving the accuracy of the scanning engine
Email address and practice detailsSending the report you asked for, answering you, and following up about it
Client and billing recordsDelivering the services, taking payment, issuing invoices, meeting tax and accounting obligations
Hashed IP addressRate limiting and abuse prevention only
Aggregated, anonymized scan dataIndustry research we publish — see section 9

We do not use your data to build advertising profiles, and we do not feed it to third-party AI training systems.

9. How scan data appears in our research

We publish research about how visible dental practices are to AI search engines, built from the scans our own engine runs. This is worth stating clearly rather than burying.

That research uses aggregated and anonymized data: counts, percentages, engine-by-engine breakdowns and patterns across many practices. Individual findings appear only in a form that cannot identify a practice — we write "a 4.8-star practice with 300+ reviews", never a clinic's name.

We do not name, shame or identify any specific practice in published research without that practice's written permission. If you would rather your scan was excluded from aggregate research entirely, email us and we will remove it.

10. Who else processes your data

We keep the list of outside services deliberately short. These are the only ones that touch data connected to this site:

ProviderWhat it handles
CloudflareWebsite and scanner hosting, and the database that stores scan results
StripePayment processing, card and bank details, invoices, subscription management
TallyThe deep scan request form
Google FontsServing the typefaces this page uses; receives your IP as part of that request

Each of these acts on our instructions for the purpose listed, under its own privacy terms. We also use ordinary business email to correspond with you.

Beyond that, we disclose personal information only when the law requires it, or if the business is ever sold or merged — in which case the buyer would be bound by this policy and we would tell you before anything changed.

11. Cookies and tracking

This website sets no tracking cookies, no advertising cookies and no analytics cookies. There is no consent banner because there is nothing to consent to.

Two exceptions live outside our pages. If you go through Stripe's checkout, Stripe sets cookies it needs for payment security and fraud prevention. If you open the Tally form, Tally sets cookies needed to run the form. Those are governed by their own policies, and they apply only when you use those services.

12. We do not sell your data

We have never sold personal information, we do not sell it now, and we do not share it for cross-context behavioral advertising — the two things US state privacy laws specifically ask about.

If that ever changed, we would say so on this page before it happened, not after.

13. How long we keep things

DataKept for
Scan results and technical signalsIndefinitely, as a time series — this is what lets us show how visibility changes over time
Hashed IP addresses90 days, then deleted
Report requests and prospect emails24 months from last contact, unless you ask us to delete sooner
Client records and correspondenceFor the engagement, then 24 months
Invoices and payment records7 years, because tax law requires it

When a retention period ends, we delete the data or strip it of anything that could identify a person.

14. How we protect it

Data is encrypted in transit. Access is limited to the people who need it — in practice, a very small number. Payment credentials never reach our systems at all, which removes the highest-risk category of data entirely.

No system is perfectly secure and we will not pretend otherwise. If a breach affects your personal information, we will tell you and the relevant authorities without undue delay, and we will tell you what actually happened rather than a sanitized version.

15. Your rights

Wherever you are, you can ask us to:

  • Tell you what we hold about you, and where it came from.
  • Correct anything that is wrong.
  • Delete what we hold, subject to records we are legally required to keep, such as invoices.
  • Give you a copy in a portable format.
  • Stop contacting you, at any time, for any reason or none.

Email contact@citevio.com. We respond within 30 days, usually much sooner, and we do not charge for this. We may need to confirm your identity first, so that someone else cannot request your data.

We will never treat you differently — worse service, worse price, refusal to work with you — because you exercised any of these rights.

16. If you are a California resident

The California Consumer Privacy Act, as amended by the CPRA, gives California residents specific rights. Those are the rights already listed in section 15: the right to know, to delete, to correct, to portability, to opt out of sale or sharing, and to non-discrimination for exercising them.

Specifically, for the twelve months before the date at the top of this page: the categories of personal information we collect are identifiers (name, email address, business address) and commercial information (what you purchased). We collect them from you directly and from public business sources. We disclose them for business purposes to the providers listed in section 10. We have not sold or shared personal information, and we do not knowingly collect information from anyone under 16.

You may use an authorized agent to make a request. Email us the same way; we will verify the authorization before acting.

17. Patient health information

We do not want, ask for, or knowingly process patient health information, and nothing in our services requires it. Our work concerns your practice's public presence, not your patients' records.

Please do not send us patient names, treatment records, images or anything else that would fall under HIPAA. If we receive such information, we delete it and tell you.

18. Children

Our services are sold to businesses and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email us and we will delete it.

19. If you are visiting from outside the United States

Citevio is a US company serving US clients, and the data described here is processed in the United States. Privacy laws there may differ from those where you live.

If you are in the European Economic Area or the United Kingdom and you have given us personal data, you have the rights set out in section 15, and you may also lodge a complaint with your local supervisory authority. Where we rely on a legal basis, it is your consent for reports you asked us to send, our contract with you for client work, and our legitimate interest in operating and securing the site for everything else. You may withdraw consent at any time.

20. Changes to this policy

When this policy changes, we update the "last updated" date at the top of the page. If a change materially affects how we handle your information, we will email clients and anyone who has given us an address, at least 30 days before it takes effect.

We do not backdate changes, and we keep the effective date visible so you can tell which version applied when.

21. How to reach us

Email contact@citevio.com — for privacy requests, questions, or to tell us to delete everything we have. We reply within one business day.

Postal: Muhammed Veysel Erin LLC, 30 N Gould St, Ste 45178, Sheridan, WY 82801, United States.

For the commercial agreement between us, see our Terms of Service.