Last updated 2026-08-15
Digital Empire Holdings LLC ("PixelProof", "we", "us") built this policy to explain, in plain language, what data PixelProof collects when you run a free scan, sign up for the waitlist, or become a paying customer — and what we do with it.
We use a small set of vetted subprocessors, all US-region:
We do not sell your data, and we do not share it with data brokers or ad networks. California residents: PixelProof does not sell personal information, so there is nothing to opt out of under CCPA's "Do Not Sell" provision -- this section is provided in response to your "Your California Privacy Choices" footer link.
You can request a full export of your data or full deletion of your account at any time. Email hello@citationsafe.com with the subject line "Data Request" from the email address on file. A self-serve export/delete page is planned for /meta-monitor/account/delete — until it ships, every request is handled manually: exports within 30 days, deletion within 30 days (45 days for CCPA requests, per the California statute's timeline). EU/UK residents also have the right to lodge a complaint with their local data protection authority.
PixelProof uses essential cookies only — the session cookie that keeps you signed in and CSRF protection on forms. We do not use third-party advertising or tracking cookies. PostHog analytics runs cookie-light (device/session ID, no cross-site tracking).
Data is encrypted in transit (TLS) and at rest (Supabase-managed encryption). Access to production data is limited to the founder and service-role API credentials; row-level security is enabled on every table.
If we materially change what we collect or how we use it, we'll update the "Last updated" date above and, for material changes, notify active customers by email.
If we discover a security incident that affects your personal data, we will notify you without unreasonable delay. For users in the EU/UK, we will notify affected users within 72 hours of becoming aware of the breach in accordance with GDPR Art. 33 and, where applicable, the corresponding supervisory authority. For California residents, we will notify you in the most expedient time possible and without unreasonable delay in accordance with Cal. Civ. Code §1798.82. State-law notice requirements for other U.S. residents will be honored as applicable.
How we notify: primary channel is email to the address on file; we may also post an in-app notice at /meta-monitor/accountand a public update on our status page at /meta-monitor/status.
What we will include: a description of the nature of the incident, the categories and approximate number of records/users affected, the likely consequences of the incident, and the mitigation and remediation steps we are taking (or that you can take, such as password rotation).
Breach concerns: hello@citationsafe.com. This mailbox is monitored on the same rotation as our security-disclosure inbox described at /security.
v0 — attorney-review-pending. This breach-notification commitment is authored in-house and has not yet been reviewed by outside counsel; it is offered as a good-faith statement of practice and does not waive any statutory rights you may have.
Questions about this policy or a data request: hello@citationsafe.com (fallback: hello@citationsafe.com).
Digital Empire Holdings LLC, 30 N Gould St Ste N, Sheridan WY 82801