CardCite

CardCite for Chrome: Privacy Policy

CardCite is a Chrome extension that generates formatted source citations from web pages and PDFs. This policy explains what data the extension handles and how.

Effective date: September 14, 2026

This policy covers the Chrome extension only. The CardCite Google Docs add-on has its own privacy policy.

Local by default

CardCite does not collect, transmit, or store your personal data on any external server. The extension stores your preferences (such as your team name, citation formatting, and display settings) and any citations you save to your Citation Library using Chrome's built-in storage (chrome.storage.sync and chrome.storage.local). Preferences kept in chrome.storage.sync travel with your Chrome profile, so Chrome itself may copy them to other computers where you are signed in to Chrome. CardCite never receives them.

Unless you turn on the optional sync feature described below, this data stays on your device and your Chrome profile, is not transmitted anywhere by CardCite, and is not accessible to the developer. The only other times CardCite contacts anything outside your browser are the public catalog lookups and, when you cite a PDF, requests to the site that PDF is on. Both are described below, and neither sends anything about you to anyone other than the site you are already viewing.

The extension reads the web page you are currently viewing only when you open CardCite on it, by clicking its icon or pressing its keyboard shortcut. It reads the page's details, such as its title, author and date, along with any text you have selected, and uses them only to build a citation on your device. They are not transmitted anywhere unless you save that citation while sync is turned on.

Public catalog lookups

When a page or PDF you are citing carries a DOI (the permanent ID printed on most journal articles and many reports) or an ISBN (the number printed on a published book), and CardCite could not find a detail such as the author, date, page numbers or edition on the document itself, CardCite looks that detail up in a free public catalog: Crossref (the publishers' DOI registry) for a DOI, then DataCite (the DOI registry for research data and reports) when Crossref has no record of it, and Open Library (a library catalog) for an ISBN.

A lookup works like searching a library catalog for a book. CardCite asks the catalog about the document, using the identifier printed on it (a DOI looks like 10.1234/abcd.5678), and puts the answer into your citation. The request carries nothing about you: no personal information, no account details, no browsing history, and nothing that identifies you or your device. CardCite keeps nothing from it, and the answer only ever fills a field that was left blank.

When you cite a PDF

CardCite downloads the PDF from the site you are already viewing it on, so that it can read the document's text and details.

Many PDFs are published with a page of their own on the same website, such as a report's page on a research institute's site, and that page usually lists the title, author, date and publisher. If you opened the PDF from a page like that and one of those details is missing from the PDF itself, CardCite reads the page and fills in only what is missing: a blank field, or a publisher that could only be guessed from the site's web address. A value found in the PDF itself is never replaced.

CardCite reads that page only when it is on the same site as the PDF, and never reads a page on a different site or a search results page. It knows which page you came from because your browser already tells the PDF's site, and it uses what it reads only when that page links to the PDF you are viewing. The page is requested the same way your browser would request it, so a site you are signed in to loads as you would normally see it.

All of this happens on your device. The page's address and contents are used only to fill in the missing details, and are not stored by CardCite or sent to the developer or anyone else.

Optional sign-in and cross-device sync

CardCite includes an optional feature, off unless you choose to enable it, that lets you sign in with your Google account to sync your citation library across devices and to insert citations into Google Docs using the CardCite Google Docs add-on.

You sign in with your Google account. Google shares your email address, a sign-in ID, your name and your profile picture with CardCite. CardCite uses your email address and that ID to connect you to your own library. Your name and picture are kept with your sign-in record and are not used.

With sync on, your citation library, including any notes you have added to citations, is stored in CardCite's database on Google Cloud (Firebase), so your other devices and the Google Docs add-on can read it. Each library is private to its own account, protected by per-user security rules, and is never sold, shared, or used for anything other than providing sync and the Google Docs feature to you.

The Google Docs add-on writes the citation you choose at your cursor and does nothing else. It never reads, collects, stores, or transmits anything in your document. The Google Docs add-on policy covers this in full.

You can turn sync off and sign out at any time. Signing out ends the extension's access to your Google account on that device.

No analytics or tracking

CardCite does not use analytics, advertising, or third-party tracking. Besides the page you are citing, the only services it contacts are the public catalogs Crossref, DataCite and Open Library, which receive only a document's DOI or ISBN; the website a PDF is on, as described above; and Google Cloud (Firebase), to store your library, if you turn on sync.

Data retention and deletion

Your preferences stay until you change them. Your library holds up to 250 citations: once it is full, saving a new citation removes the oldest one. You can also delete individual citations or clear your library from within the extension. If you have enabled sync, a citation removed in any of these ways is removed from your synced library as well.

If you have used sync and you want the backed-up copy removed entirely, email elliott7987@gmail.com and your account and all synced data will be deleted.

Limited Use disclosure

CardCite's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Questions about this policy?

Email elliott7987@gmail.com.