Privacy
What we collect, and what we deliberately do not.
Short, because there is not much to describe. This site runs privacy-first analytics in consent-denied mode, so it sets no cookies of its own and holds no identifier for you, and it stores nothing about you unless you send us something. Where that is not the whole story, the whole story is below.
Short answer
What data does the Citon website collect?
The Citon website runs Google Analytics 4 through Google Tag Manager in consent-denied mode, so it sets no cookies of its own and holds no identifier for you; the analytics beacon shares only your IP address and the page path with Google, in aggregate. The only data we store ourselves is what you type into the Gap Report form and send deliberately: a work email, a company domain, and your answers to two questions. Third-party requests are listed in full below.
In effect from 30 August 2026
01Who this is about
This page covers the Citon website and the Gap Report request that runs from it. The operating entity is not yet named here, and will be before this site is public.
02What you send us on purpose
There is one way to reach us and it posts to this site. The Gap Report form is the whole of it: no embedded scheduler, no third-party widget, nothing that hands what you type to another company before it reaches us. Clause 4 lists every host your browser does contact and says exactly when.
The Gap Report form asks four questions, and it is worth listing all four rather than summarising them:
- Your work email. Where the report and the call invite go.
- Your company domain. The measurement is anchored to it.
- The company an AI assistant names first in your category. This one asks you to name a third party, and often that party is a competitor. We use the name as an input to the measurement, which is the only reason it is asked for. We do not tell them, and we do not publish it.
- Your category and the questions your buyers ask. These become the queries we run.
We use those four things to run the report and to talk to you about it. Nothing else.
We do not sell it, rent it, or pass it to a data broker, an enrichment service or an advertising network. We do not add you to a list you did not ask to be on.
03What the site collects by itself
Privacy-first analytics. This site runs Google Analytics 4 through Google Tag Manager, and it runs in consent-denied mode: analytics storage is defaulted off and nothing on this site turns it on, so the tag sets no cookie and holds no identifier for you. Google receives an aggregate measurement carrying your IP address and the page you viewed, and nothing you typed. It is how we count how many people read a page, and no more than that.
No cookies from us. This site sets no cookies of its own, which is why you were not asked to accept any.
04Third parties your browser contacts
Being honest about this is the point of the section. An HTTP request necessarily carries your IP address to whoever answers it, so every host your browser reaches is worth naming. They split into two groups, and the split is the part that matters: some you cannot avoid, and some are reached only if you choose to do something.
Reached on every page load, whether you act or not.
- fonts.googleapis.com, which serves the stylesheet that describes two of the typefaces this site renders in.
- fonts.gstatic.com, which serves the font files for those two typefaces, and is reached because the stylesheet above points at it rather than because this site names it.
- stijndv.com, which serves the display typeface this site renders headings in.
- img.logo.dev, which serves the company logos shown in the diagrams, requested by domain name.
- www.googletagmanager.com, which loads Google Tag Manager and Google Analytics 4 in consent-denied cookieless mode, so Google sees your IP address and the page path in aggregate but sets no cookie and receives nothing you typed.
- www.google-analytics.com, which receives the Google Analytics 4 measurement beacon that Tag Manager fires, in aggregate and with no cookie or identifier we created, so Google sees your IP address and the page path but nothing you typed.
Most of those are a font or an image request. The two Google hosts are the analytics tag described above, which runs consent-denied so it sets no cookie. None of these receives anything you typed, and none is given an identifier we created for you. They are on the list because they see your request, which is enough to be worth telling you.
Reached only when you do something. Never on load.
- slack.com, which receives the four answers submitted through the Gap Report form, so the request reaches our own team.
- www.wikidata.org, which linked from the Organization schema's sameAs field as our verified entity record; a visitor following that link reaches Wikidata, not us.
- twitter.com, which is where the share button on a blog post sends a visitor who chooses to post the link, and is contacted only on that click.
- t.me, which is where the share button on a blog post sends a visitor who chooses to post the link, and is contacted only on that click.
- www.linkedin.com, which is where the share button on a blog post sends a visitor who chooses to post the link, and is contacted only on that click.
- news.ycombinator.com, which is where the submit button on a blog post sends a visitor who chooses to post the link, and is contacted only on that click.
- claude.ai, which opens a new chat prefilled with a prompt naming this post, if a visitor chooses Open in Claude, so that prompt and the fact they were reading this post reach Anthropic.
- chatgpt.com, which opens a new chat prefilled with a prompt naming this post, if a visitor chooses Open in ChatGPT, so that prompt and the fact they were reading this post reach OpenAI.
Nothing on this site is embedded from any of those, and your browser reaches none of them unless you act. Most are plain links out: the share destinations on a blog post header, and the Wikidata entry our structured data points at. Following one hands you to that company exactly as any link would, and staying put hands them nothing.
Slack is the one worth reading twice, because it is the only entry there that receives something you typed, and it is not a fetch your browser makes at all. When you submit the Gap Report form, this site posts your answers to our own Slack from our server, so they reach our team while your browser never contacts slack.com. It is listed because a privacy page that names only what a browser fetches would omit a real recipient of your data, and that omission is the kind that matters.
There is no embedded scheduler on this site and no third-party frame of any kind. A booking calendar was embedded here until 2026-08-30, which is why this clause is written to separate hosts you cannot avoid from hosts you reach only by acting. If anything embedded ever returns, that split is where it has to be declared.
05How long we keep it
A Gap Report request and the report produced from it are kept while we are working with you and for twelve months afterwards, so that a later measurement can be compared against the baseline we took. After that we delete it. You can ask us to delete it sooner and we will, including the baseline, which means we lose the ability to prove a later result.
06Your rights over it
Ask and we will tell you what we hold, correct it, send you a copy of it, or delete it. We will not ask you to justify the request or route you through a form designed to make you give up.
If you are in the UK or the EU, the UK GDPR and the GDPR give you those rights as a matter of law rather than as a courtesy, and they also give you the right to complain to your data protection authority. Our lawful basis for handling a Gap Report request is the legitimate interest of responding to someone who contacted us about buying something.
07Reaching a person about this
A contact address for privacy requests is not published on this page yet. Until it is, use the Gap Report request on the home page and say what you need; it reaches the same people.
08Changes to this page
If we start collecting something we do not collect today, this page changes before that happens rather than after, and the date at the top changes with it. A privacy page updated in arrears is a disclosure that arrived too late to be one.