Data Handling and Privacy
What data Outercite collects, what it is used for, and how to request retention, sub-processor, and DPA documentation.
Outercite collects a narrow, well-defined set of data to do its job. This page explains what that data is, why it is collected, and how we handle the things we cannot answer here in a generic knowledge base article.
What you'll learn
- What data Outercite collects and stores
- How that data is used within the platform
- The principle of data minimisation and what it means in practice
- How to request specifics such as data retention periods, a data processing agreement, or a sub-processor list
What Outercite collects
Outercite stores three categories of data tied to your account:
1. The prompts you choose to track
These are the keywords and prompts you set up in the dashboard. Examples: "best accountant in Brisbane" or "project management software for small teams". You control which prompts are tracked. Outercite does not add prompts without your instruction.
2. The AI responses those prompts generate
When Outercite queries one of the six tracked AI engines with your prompt, it receives a text response. That response is stored so the verification pipeline can process it. It is also the source of the proof snippets you see on each citation in your dashboard.
3. The citation results from the verification pipeline
After the two-model verification process runs, the structured result is stored against your account. This includes the confidence score, citation tier, sentiment, position, and other per-citation fields that power your dashboard metrics.
Outercite does not access your website, your CRM, your product catalogue, or any other brand asset unless you explicitly connect an integration. The platform works entirely from the prompts you define and the AI responses those prompts return.
What the data is used for
Collected data is used for:
- Running the verification pipeline to produce citation results
- Displaying your citation history, trends, and metrics in the dashboard
- Powering features like surge alerts, lost citation tracking, share of voice, and predictions
- Generating reports you export or schedule
- For agency customers: populating the portfolio view across client workspaces
Data is not used to train external models or shared with other customers. Your citation data stays within your account and, for agencies, within the relevant client workspace.
Data minimisation
Outercite collects what it needs to run the pipeline and power the product. It does not speculatively collect additional data hoping it might be useful later. If you stop tracking a prompt, Outercite stops querying AI engines with that prompt.
This is a practical stance as much as a principled one. Tracking irrelevant prompts produces noise in your dashboard. The product works best when the prompt list reflects what your brand genuinely wants to understand about its AI search visibility.
What we cannot answer here
Some questions are specific to your organisation's requirements and cannot be answered accurately in a generic page. For the following, please contact the Outercite team directly:
- Data retention periods: how long citation data, AI responses, and prompts are stored
- Sub-processor list: the third-party services Outercite uses to process your data
- Data Processing Agreement (DPA): a signed agreement for customers with specific contractual requirements
- Data residency: where your data is processed and stored geographically
- Security documentation: architecture details, access controls, and related materials
To request any of the above, use the contact details in your dashboard or the help widget. Mention what you need and we will get the right documentation to you.
Try this in Outercite
To see exactly what Outercite is tracking on your behalf, go to your prompts list. Every prompt there is an active tracking instruction. Removing a prompt stops future checks.
Related
Trust Overview
The three pillars of Outercite's trust model: accurate data, controlled data, and isolated workspaces.
Data Isolation
How client workspaces are kept separate so one client can never see another's data.
How We Verify Citations
The two-model verification process that ensures the citation data in your dashboard is accurate.
