Privacy
Privacy notice
WhyCited is built for researchers and is designed to respect your privacy. This notice explains what the extension captures, when it captures it, where data is processed, and how long records are kept.
The short version
- Nothing leaves your browser until you explicitly request an analysis from a citation link or selected citation marker.
- When you do, only the immediate citation context is sent: never your browsing history, cookies, credentials, or other tabs.
- AI provider API keys live securely on our servers, never in the extension.
- Analysis requests are transient on our servers with no permanent paper archives or PDF storage.
- WhyCited never bypasses paywalls to fetch content.
What is captured, and when
The extension collects and sends nothing until you invoke the action on a citation link or selected citation marker and choose “Explain why this research is relevant”. At that moment it captures and sends to our backend:
- the current page URL and, when present, the clicked link URL;
- the link text or selected citation marker;
- the matching bibliography entry when a selected marker has no link;
- the citation sentence, its paragraph, neighbouring paragraphs, and the nearest section heading;
- paper metadata visible on the page, including title, DOI, authors, and abstract meta tags.
The content script runs on pages only so it can identify the exact citation element you right-clicked. It transmits nothing on its own.
What is never collected
Full page contents beyond the citation context, browsing history, cookies, credentials, form input, or anything from other tabs. There is no analytics beacon in the extension and no tracking of what you read.
Where your data goes
Analysis requests go over HTTPS to our backend at api.whycited.com. To retrieve the linked paper, the backend consults openly accessible pages and public scholarly services such as Crossref and arXiv. To produce the explanation, the citation context and openly retrieved content are processed by our AI providers (Google for standard analyses and Anthropic for deep analyses) acting as data processors on our behalf.
Provider API keys are held only in our server environment. They are never present in extension code, extension storage, or any request your browser makes.
Retention
- In your browser:your settings, and the in-flight analysis record, which is cleared when the browser closes. A local history of past analyses is opt-in and can be cleared at any time from the extension’s options page. Uninstalling the extension removes all of it.
- On our servers: analysis jobs are transient: held briefly to serve the result (on the order of an hour), then discarded. We do not build archives of papers, store PDFs, or keep copies of what you read.
- Feedback: if you rate a result or leave a comment, we keep that feedback to improve the product.
- Accounts: when accounts launch, we will hold your email address, plan, and usage counts to manage quotas and billing. Billing itself is handled by Stripe; we never see your card details.
No paywall circumvention
Retrieval uses only openly accessible pages and public metadata APIs. Where content cannot be accessed legitimately, the analysis says so and downgrades its confidence, rather than fetching what it should not.
Security measures
- All traffic between the extension and backend uses HTTPS.
- Backend fetches validate every URL and refuse private, loopback and reserved addresses (SSRF protection), with size and time limits.
- Retrieved paper text is treated as untrusted evidence: models are instructed to ignore instructions embedded in documents, and model output is schema-validated and rendered as plain text only.
- The backend accepts requests only from the extension’s origin and applies rate limiting.
Your choices
- Local history is opt-in, and clearable in one click.
- Uninstalling the extension removes everything stored in your browser.
- For questions, or to ask us to delete feedback or account data, write to hello@whycited.com.
Changes to this notice
If what we collect or how we process it changes, this page will be updated and the date below revised before the change takes effect.