Privacy policy for CiteKit - Citation Generator & Reference Library
CiteKit - Citation Generator & Reference Library by CiteKit
CiteKit – Reference Library: Privacy Policy
Effective September 17, 2026
This policy covers the CiteKit – Reference Library browser extension. The CiteKit website (citekit.com) and the CiteKit Reference Manager WordPress plugin have their own policies.
Summary
The extension stores your reference library in your browser. It sends references only to a WordPress site you connect, and only when you choose to send them. It sends nothing to CiteKit, and has no analytics, tracking or advertising.
When the extension reads a page
The extension has no access to the sites you visit until you click the CiteKit button or press its keyboard shortcut. At that moment it reads the current page's address, title and publicly published metadata: DOI, PMID, ISBN, authors, publication, dates and similar citation details. It also reads any text you have highlighted on the page, and if the page has no ISBN in its metadata, it scans the visible text for one. It does not read form fields, passwords, cookies or your browsing history, and it does not run in the background on other pages.
What the extension stores on your device
Your reference library: references, reference sets, notes, highlighted passages and reference ids.
Settings: how new ids are generated, and your active reference set.
If you connect a WordPress site: the site's address, the connection key from its connection code, your WordPress display name and role, and the reference count the site reports.
Send records: which references are on the connected site, the site's response to your most recent send, and progress while a send is running.
This data stays in your browser's extension storage. Removing the extension deletes it, which is why the extension offers an export. Clearing your browsing history does not remove it.
When data leaves your browser
Only in these cases, each started by you:
Connecting a WordPress site. The extension contacts the site you connect to confirm the connection code and read the site name, your display name and role, and its reference count. Your browser first asks your permission to access that one site.
Sending references. The extension sends the references you choose to your connected WordPress site: type, title, authors, publication, publisher, dates, volume, issue, pages, identifiers, page address and language. Your notes and highlighted passages are not sent.
Checking the connection, when you choose Check connection.
These requests go to the WordPress site you connected, which you or your organization operate. What happens to references stored there is governed by that site and its policies. The extension never sends data to CiteKit or any other third party.
Files you export or import
When you export, the extension creates a file on your device. When you import, it reads the file you choose. Neither is uploaded anywhere.
What we don't do
We don't collect, receive, sell, rent or share your data.
We don't track the pages you visit.
We don't use analytics, advertising or third-party tracking.
We don't require a CiteKit account.
Permissions
activeTab and scripting: read the current page's metadata, only after you click CiteKit.
storage and unlimitedStorage: keep your reference library in your browser without a size cap.
Optional access to websites: requested only when you connect a WordPress site, and only for that site. You can remove it in your browser's extension settings. Sending then stops until you allow it again.
Disconnecting
Disconnect in the extension's Settings to remove the stored connection key from your browser. To stop a connection completely, also revoke it in WordPress under CiteKit Library → Browser extension, or Profile → CiteKit extension. References already sent stay on your site.
Changes
If a future version changes how data is handled, we will update this policy and the extension's store listing before that version is released.
Contact
support@citekit.com