Citation verification · Courts of Australia
True·Cite

Privacy Policy

Last updated: 15 September 2026

This policy explains what TrueCite does with personal information. TrueCite (ABN 37 688 027 367) is in Sydney, New South Wales, Australia, and can be reached at info@truecite.com.au.

What we collect

When a firm registers, we collect the firm name, the ABN, the name of the contact person, and the firm email address. Barristers register in their own name with their own ABN.

When citations are checked, we receive the citation strings, an optional party name, a document fingerprint, and an optional report label.

When you check a document in your browser, extraction happens in your browser. The text of that document does not leave the browser and is not sent to us. The one exception is the Clio integration described below, where a document your firm selects in Clio is sent to us to be read.

We do not collect or retain submission text, quoted passages, judgment text or card details.

A report label is retained with the report it belongs to, and a report URL can be read by anyone who holds the link. Do not put confidential information in a report label.

Why we collect it

How we handle it

We handle personal information consistently with the Australian Privacy Principles.

Cookies and sessions

Signing in sets one session cookie, named tc_session. It identifies your session; it is HttpOnly and SameSite=Lax, it is Secure when served over the internet, and it lasts up to 30 days. There are no advertising and no analytics cookies.

Payment

Reports are paid for through Revolut's hosted checkout page. Card details are entered on Revolut's page and do not pass through TrueCite. We store the Revolut order number and the payment status, not the card.

When a payment is confirmed we issue an invoice for it and email that invoice to the firm email address on the account. The invoice carries the firm name, the registration number and the contact email held on the account, the date, what was bought and the amount, and for an Australian sale the GST included in it. It does not carry the citations that were checked or anything from a document you submitted. A copy is stored so you can open it again while signed in, and only your own account can open it.

Where your information is held

The website is hosted on Render, and the data centre region is Singapore. Personal information — contact names, email addresses and ABNs — is therefore stored outside Australia.

Email is sent through Zoho Mail. Payment is handled through Revolut. If your firm connects Clio, Clio is involved as well.

Our hosting provider's operational logs may contain IP addresses and timestamps.

Analytics and other parties

These pages carry no third-party analytics, advertising or tracking scripts. The pages do load their typefaces from Google Fonts, which is a request your browser makes directly.

Our servers do make requests to other parties while checking a citation, and those are set out in the two sections below rather than hidden here.

Checking a citation our index does not hold

Our index does not hold every judgment, and no index ever will. When a citation in your document is not in it and external search is enabled, TrueCite looks for official case metadata or a record on a reviewed court or law library website. The following describes what can leave our servers during that lookup.

The citation goes to the configured search provider. When external search is enabled, we use Google Programmable Search or Brave Search to turn a citation into candidate web addresses. What is sent is the citation and any supplied case name — for example Smith v Jones [2020] HCA 1. We do not send the surrounding document text, file, matter details, or your firm's account information. The provider handles that query under its own terms and privacy policy: Google or Brave Search API. If a citation or party name is itself confidential, treat sending it to us as sending it to a search engine. The coverage API identifies the provider when this feature is configured; an unavailable search does not establish that a judgment is absent.

We then either use accepted search metadata or read the page ourselves. For a reviewed official individual case route, Brave-indexed title metadata can be accepted as identity evidence without a request to that court site; its observation time is the search retrieval time. The separate live-page fallback follows a result only when its address is on a list of court and law library sites we have reviewed and named in our code. That site sees an ordinary web request from our server: our address, and a user agent that says plainly that it is TrueCite and gives this domain. We ask the site's own robots file first and do not fetch where it tells automated clients not to. We do not send it your document, your firm, or the citation as a search term.

What we keep is the source address, citation, extracted case name, observation time and an evidence digest, with the provider and available source dates. For search-index evidence, the observation time records the search response; it does not mean we read the court page. For a fetched record, it records the page request. We do not retain search snippets or judgment text.

This happens only for citations the index could not answer. A citation the index holds is answered on our own servers and never reaches a search engine.

Australian Business Numbers

If your document states an ABN, TrueCite checks it. Most of that check happens on our own servers and asks nobody anything: an ABN carries a check digit, and a number that was invented almost always fails the arithmetic without leaving this building.

To find out whether a valid number is registered, still active, and whose it is, we ask ABN Lookup, the Australian Business Register's own published web service. The number is what we send. Nothing else from your document goes with it.

Partner API (pilot)

Partner credentials are issued to a partner for a stated scope, and usage is metered. A partner pilot is a separate arrangement from an individual firm account.

Clio

The Clio integration is not switched on for this service today; this section describes how it works when it is. If your firm connects Clio Manage (Australia), TrueCite stores the OAuth access token and refresh token in a restricted file on our servers, used only for the functions your firm calls. If your firm disconnects the integration in Clio, or writes asking us to, the stored tokens are deleted or invalidated. Clio data is not sold and is not shared with third parties.

Documents your firm sends us from Clio. When a person signed in to your firm chooses a matter and a document in Clio and asks for a check, we ask Clio for that document and receive its contents. We receive the document's bytes, and from them the citation identifiers it contains and a fingerprint of its text. That is all we read it for.

The document's text is held in memory only while the request is being answered. It is not written to our database, our logs or any file, and it does not appear in any response we send and in no error message. What is retained afterwards is the same thing a browser check retains: the citation identifiers, the source metadata we judged them against, and a fingerprint of the text. The document itself, its wording, its quotations and its propositions are not retained. A report label carries the Clio document's name, so do not check a document whose name is itself confidential.

Writing the report back into Clio is a separate step that a person must ask for. It creates a new document in the matter and never alters or removes a document that is already there.

Reading a document from Clio is a request made from our servers in Singapore to Clio's Australia region; it is not the same as a check made in your browser against our local index, which sends nothing to Clio and nothing about your document off this service.

How long we keep it

Verification runs retain citation strings, compact findings and provenance, document fingerprints and optional report labels. Issued reports and payment events are retained for replay and accounting records. Your records (check history, saved reports, developer keys and usage) are kept until you ask us to delete them. To delete them, email info@truecite.com.au from your account email address, and we delete the records stored for that account, except any that Australian law requires us to keep for longer. Checks run on the Try page without an account are not linked to any account; to ask us to delete one, email info@truecite.com.au with the citation you checked and the approximate date and time of the check.

What a fingerprint means

A document fingerprint is a hash. It detects whether the stored payload has been altered. It does not establish judicial authenticity and it is not court endorsement.

Access, correction and deletion

Write to info@truecite.com.au to ask what we hold about you, to correct it, or to ask us to delete it.

Complaints

Raise a complaint with us first, at info@truecite.com.au. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Data breaches

If a data breach occurs, we notify the people affected and the regulator as Australian law requires.

Changes to this policy

We publish changes on this website with a new version number and date.

Contact

info@truecite.com.au

Version 1