CardCite

CardCite for Google Docs: Privacy Policy

CardCite for Google Docs ("the add-on") is a Google Docs editor add-on that lets you insert citations from your CardCite library into a Google Document. This policy explains what the add-on accesses, why, and how your information is handled.

Effective date: June 30, 2026

This policy covers the Google Docs add-on only. The CardCite Chrome extension has its own privacy policy.

What the add-on can access

When you install the add-on, Google asks you to approve four things:

  • Your Google account identityYour email address and the standard sign-in identifiers. They are used to sign you in and to match you to your own CardCite library, and for nothing else.
  • The document you have openGoogle's "current document only" access, so a citation can be written at your cursor. The add-on writes the citation you choose and does not read, collect or store what the document contains.
  • A sidebarPermission to draw the add-on's panel inside Google Docs.
  • A secure connection to CardCiteUsed to load the citations you have saved.

What the add-on stores

The add-on stores none of your data. It keeps no database, no copy of your citations and no copy of your document. It reads the library your CardCite account already holds at the moment you open the sidebar, writes the citation you pick into the document, and keeps nothing afterwards.

How your information is shared

Your information is not sold, rented, or shared with third parties. The only services involved are Google (for sign-in and Google Docs) and Google Cloud / Firebase (which hosts your CardCite library). No advertising or tracking services are used.

This website

This website, cardcitesource.com, uses Google Analytics to count visits and to see which pages people read. Google Analytics sets cookies in your browser and sends Google information such as the pages you view, the site that linked you here, and your browser and device type. This applies to the website only. The CardCite extension and the Google Docs add-on do not use Google Analytics.

You can block Google Analytics with your browser's privacy settings or an ad blocker, or with Google's opt-out add-on.

How your information is protected

All communication between the add-on and its backend happens over encrypted HTTPS/TLS connections, including sign-in requests and requests that load your citation library. Your citation library is stored in Google Cloud Firestore, protected by per-user security rules: each signed-in user can read and write only their own library, and no other user or party can access it.

The add-on never sees or stores your Google password. Sign-in is handled entirely by Google's own OAuth consent flow, and the add-on holds only the short-lived token Google issues for your session.

Data retention and deletion

Your citation library is controlled through your CardCite account. You can remove citations or stop syncing at any time using the CardCite extension; deleting a citation removes it from the synced library in Firestore. Signing out of the add-on ends its access to your account on that device.

To request deletion of your entire account and all synced data, email elliott7987@gmail.com and it will be removed.

Limited Use disclosure

CardCite for Google Docs' use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Questions about this policy?

Email elliott7987@gmail.com.