Legal

Cookie Policy

Last updated: August 2026

1. Our Approach

CitePilot is deliberately cookie-minimal. The Service has no user accounts and no server-side sessions, so it does not need authentication or session cookies. It runs no advertising and no marketing analytics, so it sets no tracking cookies.

In practice, the Service sets at most one small first-party cookie (to remember a consent choice) and stores lightweight interface preferences in your browser's local storage instead.

2. Cookies We Set

Strictly necessary: cp_consent — stores your cookie consent choice (if a choice is offered) so we can respect it across visits. First-party, lasts 1 year, requires no consent.

Analytics and marketing cookies: none. We do not use web analytics tools, A/B testing platforms, session recording, ad networks, or retargeting.

Preferences (browser local storage): cp_style_pref, cp_view_pref, cp_theme and cp_filter_state remember your citation style, view mode, theme, and filter settings on your own device. Never transmitted to our servers.

3. Third-Party Cookies

PayPalhandles subscription checkout on its own hosted pages (paypal.com) and may set its own cookies there for fraud prevention and security, governed by PayPal's privacy policy. PayPal does not set cookies on citepilot.com.

Our other providers — Google (Gemini API), Crossref, doi.org, OpenAlex, and PubMed — are called server-side and do not set cookies in your browser.

4. Managing Cookies

Because there are no accounts and no analytics cookies, there is nothing to configure in-app. You can block or delete cookies in your browser settings at any time; the Service works fully without cookies (preferences simply reset to defaults).

5. Contact

For questions about our cookie use, contact us at privacy@citepilot.com.