CardCite

CardCite Chrome Extension: Privacy Policy

CardCite is a Chrome extension that builds a formatted citation from the web page or PDF you are viewing. This policy explains what the extension does with your data.

Effective date: September 23, 2026

This policy covers the Chrome extension only. The CardCite Google Docs add-on has its own privacy policy.

Local by default

CardCite does not collect or store your personal data on any external server. Your settings and the citations you save to your Citation Library are kept in Chrome's own storage on your device. CardCite never receives them.

The extension reads a page only when you open CardCite on it, by clicking its icon or pressing its keyboard shortcut. It reads the page's details, such as the title, author and date, along with any text you have selected, and builds the citation on your device.

Apart from the page you are citing, there are five times CardCite contacts anything outside your browser, and each is described below: a public catalog lookup, a request to the site a PDF is on, a request for an author's profile page on the site you are citing, reading a citation you paste into Settings if you allow it, and syncing your library if you turn sync on.

Public catalog lookups

When a page or PDF you are citing carries a DOI (the permanent ID printed on most journal articles and many reports) or an ISBN (the number printed on a published book), and a detail such as the author, date, page numbers or edition is not on the document itself, CardCite looks that detail up in a free public catalog: Crossref for a DOI, then DataCite when Crossref has no record of it, and Open Library for an ISBN.

The request carries only that identifier, never anything about you or the pages you visit, and CardCite keeps nothing from the answer.

When you cite a PDF

To read a PDF, CardCite loads it again from the site you are viewing it on. If the PDF leaves out a detail such as the author or date, CardCite may also read the page on that same site that links to the PDF, such as a report's page on a research institute's site, and use it only to fill in what is missing. Both are read on your device and are not stored or sent anywhere.

When your citation includes the author's qualification

The Author Qualification field is off until you add it to your citation format in Settings. Once you have, and the page you are citing names an author but does not say what the author's post or credentials are, CardCite may read the author's profile page on the same site, such as a writer's page on a news site, to find them.

It reads at most two such pages each time you open CardCite, only on the same site as the page you are citing, and never replaces a qualification the page itself shows. This happens on your device. The profile page is used only to fill in the qualification, and is not stored or sent anywhere.

When you paste a citation into Settings

In Settings you can paste a citation you already use, and CardCite copies its format. CardCite reads the pasted citation on your device first. The first time you paste one, it asks whether it may also send the citation's text to CardCite's server, which reads which words are the author, the title and the date more accurately. If you keep reading on this device only, nothing is sent. You can change the answer at any time with the checkbox under "Paste a citation" in Settings.

If you allow it, each citation you paste is sent to CardCite's server as plain text. Nothing about the pages you visit, your library or your account is sent with it. The server passes that text to OpenAI's API and uses what comes back to fill the fields shown in Settings. This is the only part of CardCite that uses AI. The words of a citation alone often cannot show whether a phrase describes the source or the author, such as a source description beside an author's qualification, and a language model is the only reliable way to tell them apart. CardCite does not store the citation. OpenAI does not use it to train models and keeps it for up to 30 days only to check for misuse, as OpenAI describes for its API. To prevent abuse, the server limits how many citations one connection can send in an hour. It counts them under a one-way code made from your network address, keeps the count only for the current hour, and never stores the address itself.

Optional sign-in and cross-device sync

CardCite includes an optional feature, off unless you choose to enable it, that lets you sign in with your Google account to sync your citation library across devices and to insert citations into Google Docs using the CardCite Google Docs add-on.

Google shares your email address, a sign-in ID, your name and your profile picture with CardCite. Your email address and that ID connect you to your own library; your name and picture are kept with the sign-in record and are not used.

With sync on, your citation library, including any notes you have added, is stored in CardCite's database on Google Cloud (Firebase), so that your other devices and the Google Docs add-on can read it. Each library is private to its own account, protected by per-user security rules, and is never sold or shared. The Google Docs add-on policy covers what the add-on does with it.

You can turn sync off and sign out at any time. Signing out ends the extension's access to your Google account on that device.

No analytics or tracking in the extension

The CardCite extension does not use analytics, advertising, or third-party tracking. Besides the page you are citing, the only services it contacts are the public catalogs Crossref, DataCite and Open Library, which receive only a document's DOI or ISBN; the website a PDF is on and the site you are citing, for the pages described above; CardCite's server and OpenAI's API, which receive a citation you paste into Settings, only if you allow it; and Google Cloud (Firebase), to store your library, if you turn on sync.

This website

This website, cardcitesource.com, uses Google Analytics to count visits and to see which pages people read. Google Analytics sets cookies in your browser and sends Google information such as the pages you view, the site that linked you here, and your browser and device type. This applies to the website only. The CardCite extension and the Google Docs add-on do not use Google Analytics.

You can block Google Analytics with your browser's privacy settings or an ad blocker, or with Google's opt-out add-on.

Data retention and deletion

Your settings stay until you change them. Your library holds up to 250 citations: once it is full, saving a new citation removes the oldest one. You can also delete individual citations or clear your library from within the extension. If you have enabled sync, a citation removed in any of these ways is removed from your synced library as well.

If you have used sync and you want the backed-up copy removed entirely, email elliott7987@gmail.com and your account and all synced data will be deleted.

Limited Use disclosure

CardCite's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Questions about this policy?

Email elliott7987@gmail.com.