Legal
Acceptable Use Policy
What CiteTrue may and may not be used for. Most of it is the usual — do not resell it, do not scrape it, do not break the law with it. The section that is worth your time is the one about using results responsibly, because a failed check is far more often bad metadata than a fabricated citation.
01What this covers
This policy is part of the Terms of Service at /terms and applies to everything CiteTrue offers: the website, the browser extension, the macOS app, the API and the MCP server. Breaking it is breaking the terms.
02What CiteTrue is for
- Checking the references in your own writing before you submit or publish it
- Checking references in work you are supervising, reviewing, editing or marking
- Screening material you suspect was generated by an AI system, where fabricated citations are the thing you are looking for
- Teaching — showing students what a fabricated reference looks like and how to check one
- Building on the API or MCP server, within your plan’s limits, for your own or your institution’s work
03What is not allowed
- Using the service to make fabricated or plagiarised work look legitimate — for instance, iterating on invented references until they stop being flagged
- Reselling, white-labelling or redistributing verification as your own service without a written agreement
- Scraping the service, circumventing credit limits, or spreading work across multiple free accounts to avoid paying
- Reverse-engineering the verification pipeline, or using our results as training data to build an equivalent service
- Sharing an account or API key across people or institutions that should hold their own
- Uploading material you have no right to submit — documents under confidentiality obligations you would be breaking, or personal data you have no lawful basis to process
- Deliberately overloading the service, probing it for vulnerabilities without permission, or interfering with other users
- Anything illegal, and anything designed to harass a specific person
04Using results responsibly
This section matters more than the rest of the page, because the most likely harm this service can cause is not abuse of our servers — it is someone being accused on the strength of a result they never got to see.
A reference we could not verify usually means the record is missing, the metadata is wrong at the source, or the citation was typed badly. Fabrication is one explanation among several, and it is not the most common one. Treat a flagged reference as a question to ask, not an answer to act on.
- Check the underlying source yourself before you act on a finding, especially one that could affect a grade, a job, or a publication
- Show the person the finding and let them respond, rather than presenting a report as a verdict
- Do not present CiteTrue output as proof of misconduct — it is evidence that something needs looking at, and we will say exactly that if anyone asks us
- Follow your institution’s own integrity procedure; this service does not replace it
05Automated access
The API and MCP server are meant to be used by software — that is the point. What is not welcome is traffic engineered to get around what you are paying for: parallel free accounts, key sharing across an institution that should buy a team plan, or hammering endpoints past the documented rate limits.
If you need more headroom than your plan allows, ask. We would rather size a plan for you than play cat and mouse with rate limits.
06What happens if you break this policy
For accidental or borderline cases — an integration gone wrong, a script that ran away — we will normally contact you first and give you a chance to fix it.
For deliberate abuse, fraud, or anything that puts other users or the service at risk, we may suspend or close the account immediately and without notice. Where a paid account is closed for a serious breach, we do not refund the remaining period.
07Reporting a problem
If you believe someone is using CiteTrue against this policy, or you have found a security issue, write to [email protected] with enough detail to reproduce it. Security reports made in good faith are welcome and will not be met with legal threats.