Skip to content
WhyCited

Privacy

Privacy notice

WhyCited is built for researchers and is deliberately incurious about you. This notice explains exactly what the extension captures, when, where it goes, and how long it is kept.

The short version

  • Nothing leaves your browser until you explicitly right-click a link and ask for an analysis.
  • When you do, only the citation context is sent — never your browsing history, cookies, credentials, or anything from other tabs.
  • AI provider API keys live only on our servers, never in the extension.
  • Analysis requests are transient on our servers: no paper archives, no PDF storage.
  • WhyCited never bypasses paywalls to fetch content.

What is captured, and when

The extension collects and sends nothing until you right-click a link and choose “Explain why this research is relevant”. At that moment it captures and sends to our backend:

  • the current page URL and the clicked link URL;
  • the link text;
  • the citation sentence, its paragraph, the neighbouring paragraphs, and the nearest section heading;
  • paper metadata visible on the page — title, DOI, authors, abstract meta tags.

The content script runs on pages only so it can capture the exact element you right-clicked. It transmits nothing on its own.

What is never collected

Full page contents beyond the citation context, browsing history, cookies, credentials, form input, or anything from other tabs. There is no analytics beacon in the extension and no tracking of what you read.

Where your data goes

Analysis requests go over HTTPS to our backend at api.whycited.com. To retrieve the linked paper, the backend consults openly accessible pages and public scholarly services such as Crossref and arXiv. To produce the explanation, the citation context and any openly retrieved content are processed by our AI providers — Google for standard analyses, Anthropic for deep analyses — acting as processors on our behalf.

Provider API keys are held only in our server environment. They are never present in extension code, extension storage, or any request your browser makes.

Retention

  • In your browser:your settings, and the in-flight analysis record, which is cleared when the browser closes. A local history of past analyses is opt-in and can be cleared at any time from the extension’s options page. Uninstalling the extension removes all of it.
  • On our servers: analysis jobs are transient — held briefly to serve the result (on the order of an hour), then discarded. We do not build archives of papers, store PDFs, or keep copies of what you read.
  • Feedback: if you rate a result or leave a comment, we keep that feedback to improve the product.
  • Accounts: when accounts launch, we will hold your email address, plan, and usage counts — the minimum needed to operate quotas and billing. Billing itself is handled by Stripe; we never see your card details.

No paywall circumvention

Retrieval uses only openly accessible pages and public metadata APIs. Where content cannot be accessed legitimately, the analysis says so and downgrades its confidence, rather than fetching what it should not.

Security measures

  • All traffic between the extension and backend uses HTTPS.
  • Backend fetches validate every URL and refuse private, loopback and reserved addresses (SSRF protection), with size and time limits.
  • Retrieved paper text is treated as untrusted evidence: models are instructed to ignore instructions embedded in documents, and model output is schema-validated and rendered as plain text only.
  • The backend accepts requests only from the extension’s origin and applies rate limiting.

Your choices

  • Local history is opt-in, and clearable in one click.
  • Uninstalling the extension removes everything stored in your browser.
  • For questions, or to ask us to delete feedback or account data, write to hello@whycited.com.

Changes to this notice

If what we collect or how we process it changes, this page will be updated and the date below revised before the change takes effect.

Last updated 3 August 2026