Privacy Policy

Last updated: April 6, 2026 | GDPR-Compliant | Your Rights Protected

GDPR Compliance: This privacy policy complies with the EU General Data Protection Regulation (GDPR). If you have questions about your rights or how we process your data, contact us at privacy@contextium.io.

Introduction

Welcome to Contextium. We respect your privacy and are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. This privacy policy will inform you about how we handle your personal data when you use our documentation platform and tell you about your privacy rights under GDPR.

Data Controller

Contextium [Legal Entity Name] is the data controller responsible for your personal data. You can contact us at:

Legal Basis for Processing

We process your personal data under the following legal bases (GDPR Article 6):

  • Contract Performance (6.1.b): To provide our services as outlined in our Terms of Service
  • Legitimate Interests (6.1.f): To improve our services, prevent fraud, and ensure security
  • Consent (6.1.a): For optional features like marketing communications (you can withdraw consent at any time)
  • Legal Obligation (6.1.c): To comply with legal requirements like tax and accounting laws

Information We Collect

Account Information

When you create an account, we collect:

  • Name and email address
  • Password (encrypted and never stored in plain text)
  • Profile information you choose to provide

Content Data

We store the content you create and upload:

  • Documents, files, and projects you create
  • Complete version history for all files (content snapshots, timestamps, authors, change summaries)
  • Comments, suggestions, and collaboration data
  • Workspace and team settings
  • Agent configurations (name, instructions, selected skills)
  • Skill definitions and custom instructions
  • Workflow configurations and tag-based collections
  • Inline tags used for file organization
  • Feedback submissions (bug reports and feature requests)
  • Integration data (e.g., Slack workspace connections, MCP authorizations)

AI Chat Data

When you use AI Chat, we process:

  • Your messages and conversation history, which are transmitted to the AI provider configured for your workspace (Anthropic or OpenAI) in order to generate responses
  • Workspace content you share during a session (files, skills, agents, tags) which may be sent to the AI provider as context
  • Your encrypted AI provider API key, stored in our database on your behalf to facilitate requests

Contextium does not store your chat conversation history on its servers. Conversations are stored in your browser's local storage only. Clearing your browser data will permanently remove your chat history and it cannot be recovered.

Marketplace Data

When you use the Marketplace, we collect and may publicly display:

  • Publishers: Your display name and account creation date (month and year) are shown publicly on your publisher profile page alongside all listings you have published
  • Install records: Every installation is recorded (your user ID, the listing ID, and timestamp). Aggregate install counts are displayed publicly on listing pages
  • Reviews and ratings: Review text, star rating, and your user ID are stored and displayed publicly on the listing page. Publisher responses are also stored and publicly visible
  • Imported listings: For listings sourced from external platforms (e.g. skills.sh), the original author's handle may be displayed publicly with a link to their profile on that platform

Usage Information

  • Log data (IP address, browser type, pages visited)
  • Device information
  • Usage patterns and interactions with our service
  • Session activity and last active timestamps
  • Collaboration activity (who you collaborate with via mentions, comments, and suggestions)
  • File access and editing activity timestamps
  • Workspace member activity logs
  • Search queries within your workspace (retained for 90 days for debugging)
  • MCP client access logs (timestamps, operations, files accessed)

This data is used for activity feeds, notifications, workspace analytics, and service improvement. Your collaboration patterns are only visible to members of your workspace.

Billing Information

For paid subscriptions, we collect:

  • Billing name and email address
  • Subscription plan and payment history
  • Payment information is processed and stored securely by Stripe - we do not store credit card numbers

How We Use Your Information

We use your information to:

  • Provide and maintain our service
  • Process your transactions and manage your subscription
  • Send you service updates and important notifications
  • Improve our platform and develop new features based on user feedback
  • Respond to bug reports and feature requests you submit
  • Detect and prevent fraud and abuse
  • Provide customer support
  • Enable team collaboration and workspace features

Search Functionality

Your file content is indexed by our search service (Elasticsearch) to enable full-text search across your workspace. Search indexes are encrypted and access-controlled. Search queries are logged for debugging and service improvement and retained for 90 days.

MCP Server and AI Tool Access

When you authorize MCP clients (e.g., Claude Desktop, Cursor) to access your workspace:

  • We issue secure access tokens that allow the authorized application to access your workspace on your behalf
  • We log MCP access for security and debugging purposes (timestamp, operation type, files accessed)
  • You can view and revoke MCP authorizations from your account settings at any time
  • MCP tokens are encrypted and stored securely

Feedback Data

When you submit feedback (bug reports or feature requests), we collect the information you provide along with technical details like your browser information and the page you were on. This helps us diagnose issues and improve the platform. Feedback submissions are one-way and are reviewed by our team to prioritize improvements.

Data Security

We implement industry-standard security measures to protect your data:

  • All data is encrypted in transit using SSL/TLS (HTTPS)
  • Sensitive data at rest is encrypted using AES-256 encryption
  • Passwords are hashed using bcrypt with salt
  • Payment information is tokenized and encrypted via Stripe - we never store credit card details
  • JWT-based authentication with secure token refresh mechanisms
  • Role-based access control (RBAC) for workspace permissions
  • Regular security audits and updates
  • Secure cloud infrastructure with automatic backups
  • Database credentials and API keys are encrypted and never exposed

File Storage Infrastructure

  • Documents and files are stored in Cloudflare R2 (S3-compatible storage)
  • Database and metadata hosted on secure cloud infrastructure
  • Data stored in multiple geographic regions for redundancy
  • All storage encrypted at rest with AES-256 encryption

You can request specific data residency information by contacting privacy@contextium.io.

Staff Access to Your Content

We only access your workspace content in limited circumstances:

  • With your explicit consent (e.g., customer support requests)
  • To maintain service security and prevent abuse
  • To investigate violations of our Terms of Service
  • When required by law or legal process
  • To backup and restore data during technical operations

All staff access is logged and audited for security purposes.

Data Sharing

We do not sell your personal data. We may share your information only in these limited circumstances:

  • Within Your Workspace: Content you create is shared with workspace members you invite. You control who has access to your workspaces.
  • Service Providers: Third-party services that help us operate (payment processing, email delivery, hosting)
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • With Your Consent: When you explicitly authorize us to share your data

Important: When you invite team members to your workspace, they will have access to the content and data within that workspace according to their role permissions. You are responsible for managing workspace access and user permissions.

Externally Shared Content

When you create a share link for a file, the file’s content is served to viewers outside your workspace and is no longer protected by your workspace’s access permissions for as long as the link is active. Where a restricted (email-verified) link is used, we process the recipient’s email address to verify access and to record link activity (access time and email) for the link creator’s visibility; verification codes are stored only as hashes and expire shortly after issue. We cannot control the further use, storage, or redistribution of content once a recipient has viewed or downloaded it. Revoking a link stops future access but cannot recall content that has already been viewed or downloaded.

Third-Party Services

We use the following third-party services:

Stripe Payment Processing

We use Stripe to process all subscription payments. When you subscribe to a paid plan:

  • Data Shared with Stripe: Your name, email, billing address, and payment information
  • What Stripe Collects: Stripe collects payment method details, transaction data, device information, and fraud detection data
  • How Stripe Uses Data: To process payments, prevent fraud, and comply with financial regulations
  • Data Storage: We do NOT store credit card numbers - they are tokenized and stored securely by Stripe
  • Stripe's Policies: Review Stripe's Privacy Policy and Services Agreement
  • GDPR Compliance: Stripe is GDPR-compliant and has a Data Processing Agreement (DPA) in place

Authentication Providers

Anthropic (Claude AI)

If your workspace is configured to use Claude, your chat messages, conversation history, and any workspace context shared during a session are sent to Anthropic's API to generate responses. Anthropic processes this data under their own privacy policy. We store your Anthropic API key encrypted (AES-256) in our database on your behalf solely to facilitate requests.

OpenAI

If your workspace is configured to use OpenAI, your chat messages, conversation history, and any workspace context shared during a session are sent to OpenAI's API to generate responses. OpenAI processes this data under their own privacy policy. We store your OpenAI API key encrypted (AES-256) in our database on your behalf solely to facilitate requests.

Other Services

  • Resend: Transactional email delivery for notifications and service updates. Notification emails may include excerpts of comments, file titles, and user activity, but never full file content.
  • Slack: Optional workspace integration for notifications (see Slack Privacy Policy)

When you use these third-party authentication or integration services, they may collect and process your data according to their own privacy policies. We only receive the minimum information necessary to create and maintain your account or provide the integration functionality.

Your Rights Under GDPR

As a data subject under GDPR, you have the following rights regarding your personal data. These rights are subject to certain limitations and exemptions as provided by law.

Right of Access (Article 15)

You have the right to request a copy of your personal data and information about how we process it. We provide this free of charge and will respond within 30 days.

Right to Rectification (Article 16)

You can update or correct your personal information at any time through your account settings, or by contacting us.

Right to Erasure / "Right to be Forgotten" (Article 17)

You can request deletion of your account and personal data. We will comply within 30 days, subject to any legal obligations to retain certain data (such as billing records for tax purposes).

Right to Data Portability (Article 20)

You can export your data in a structured, machine-readable format (JSON) from your account settings, or request a full export by contacting us.

Right to Restriction of Processing (Article 18)

You can request that we limit how we process your data in certain circumstances, such as while we verify the accuracy of data you have contested.

Right to Object (Article 21)

You can object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we have compelling legitimate grounds.

Right to Withdraw Consent (Article 7.3)

Where we process data based on consent, you can withdraw that consent at any time. This does not affect the lawfulness of processing before withdrawal.

Right to Lodge a Complaint (Article 77)

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with your local data protection authority (DPA). You can find your DPA contact details at: https://edpb.europa.eu/about-edpb/about-edpb/members_en

How to Exercise Your Rights

To exercise any of these rights, contact us at: privacy@contextium.io

We will respond to your request within 30 days. If your request is complex or we receive multiple requests, we may extend this period by up to 60 additional days and will notify you of the extension.

We may need to verify your identity before processing certain requests to protect your personal data from unauthorized access.

Data Retention (GDPR Principle of Storage Limitation)

We retain your personal data only as long as necessary for the purposes outlined in this policy, in accordance with GDPR's principle of storage limitation.

Account Data

When you request account deletion:

  • 90-Day Grace Period: Your account is deactivated immediately, but data is retained for 90 days to allow reactivation if you change your mind
  • After 90 Days: All personal data and content is permanently deleted from our active systems
  • Backups: Data in encrypted backups may persist for up to an additional 90 days before being automatically purged
  • Immediate Deletion: You can request immediate deletion by contacting privacy@contextium.io, and we will complete it within 30 days

File Deletion and Trash Retention

When you delete files, folders, or projects:

  • Trash Period: Items moved to trash are retained for 30 days by default (configurable by workspace admins)
  • Restoration: You can restore items from trash during the retention period
  • Permanent Deletion: After the retention period, items are automatically and permanently deleted
  • Immediate Deletion: You can permanently delete items from trash at any time
  • Backups: Permanently deleted data may remain in encrypted backups for up to 90 additional days
  • Version History: All file versions are deleted when a file is permanently deleted

Other Data Types

  • Active Account Data: Retained while your account is active
  • Version History: Retained for the lifetime of the file
  • Collaboration Data: Comments and suggestions retained as part of file history
  • Billing Records: Retained for 7 years to comply with tax and accounting laws
  • Log Data: Retained for 90 days for security and debugging purposes
  • Search Queries: Retained for 90 days for debugging purposes
  • MCP Access Logs: Retained for 90 days for security auditing
  • AI Chat History: Stored in browser localStorage only — not retained on Contextium servers. Clearing your browser data permanently removes your chat history
  • Marketplace install records and reviews: Retained while your account is active and deleted when your account is permanently deleted
  • Legal Hold: Data may be retained longer if required by law, legal proceedings, or to establish/defend legal claims

This retention schedule complies with GDPR requirements while balancing the need to prevent accidental data loss and meet legal obligations.

Cookies and Tracking

We use cookies and similar technologies to provide our service. Under GDPR, we only use strictly necessary cookies that are essential for the service to function.

Strictly Necessary Cookies

These cookies are essential for the service to function and cannot be disabled. We store them for up to 7 days and they are automatically renewed when you use the service:

  • session_token: A secure session identifier to keep you logged in. This cookie is HTTP-only and cannot be accessed by JavaScript.

These cookies are set with the Secure and SameSite=Lax flags for security, and are scoped to the .contextium.io domain to enable cross-subdomain authentication.

Analytics

We use Cloudflare Web Analytics to understand how visitors use our website. This service is privacy-focused and:

  • Does not use cookies or local storage
  • Does not track users across websites
  • Does not collect personally identifiable information
  • Is fully GDPR-compliant without requiring consent
  • Uses the browser's Beacon API for privacy-preserving analytics

Learn more about Cloudflare Web Analytics privacy: https://www.cloudflare.com/web-analytics/

What We Don't Use

We do not use:

  • Third-party tracking cookies
  • Advertising cookies or pixels
  • Social media tracking widgets
  • Cross-site tracking or profiling
  • Any cookies that require consent under GDPR

International Data Transfers (GDPR Chapter V)

Your data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place as required by GDPR:

Safeguards for Data Transfers

  • Adequacy Decisions: Transfers to countries recognized by the EU Commission as providing adequate data protection
  • Standard Contractual Clauses (SCCs): EU-approved contract terms that require recipients to protect your data to EU standards
  • Service Provider Commitments: Third-party processors (like Stripe, Resend) have implemented appropriate safeguards

Specific Transfers

  • Cloud Infrastructure: [Specify your cloud provider and data centers - e.g., "AWS EU regions"]
  • Stripe (Payments): Processes payments globally with GDPR-compliant safeguards
  • Resend (Emails): Email service provider with appropriate data protection measures

You can request more information about the specific safeguards used for data transfers by contacting privacy@contextium.io.

California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) give you specific rights regarding your personal information.

Your California Rights

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, our business purpose, and the categories of third parties we share it with.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions (e.g. data needed to complete a transaction or comply with legal obligations).
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing: We do not sell or share your personal information for cross-context behavioural advertising. No opt-out is required.
  • Right to Limit Use of Sensitive Personal Information: We do not collect sensitive personal information as defined by the CPRA.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
  • Right to Data Portability: You may request a copy of your personal information in a portable format via your account settings.

How to Submit a Request

To exercise any of the above rights, contact us at privacy@contextium.io or use the account deletion and data export features in your account settings. We will respond within 45 days. We may need to verify your identity before processing your request.

Categories of Personal Information Collected

In the past 12 months we have collected: identifiers (name, email, account ID); internet or electronic network activity (usage data, log data); and professional or employment-related information (workspace and team data). We do not sell this information.

AI Features and Transparency (EU AI Act)

Contextium uses artificial intelligence to power features including AI Chat and context-aware suggestions. In accordance with the EU Artificial Intelligence Act (Regulation 2024/1689), we disclose the following:

  • AI systems used: Contextium integrates with large language models provided by Anthropic (Claude) and OpenAI (GPT-4 and successors), depending on your workspace configuration.
  • Purpose: These models generate responses to your chat messages and assist with documentation tasks. They are not used for automated decision-making that produces legal effects.
  • AI-generated content: Where content is generated by an AI model, this is indicated within the interface.
  • Human oversight: All AI outputs are advisory. You retain full control and can disregard, edit, or delete any AI-generated content.
  • Your data and AI providers: Content you send to AI features is transmitted to the relevant AI provider (Anthropic or OpenAI) under their respective terms. See the Third Parties section above for details.

Children's Privacy

Our service is not intended for children under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

Automated Decision-Making and Profiling

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you. Any analytics we perform are for service improvement and do not result in automated decisions about you.

If this changes in the future, we will update this policy and provide information about the logic involved, as well as the significance and envisaged consequences, as required by GDPR Article 13(2)(f).

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach
  • Notify affected individuals without undue delay if the breach poses a high risk
  • Provide information about the nature of the breach, likely consequences, and measures taken
  • Document all data breaches and our response, even if notification is not required

We maintain robust security measures and incident response procedures to minimize the likelihood and impact of data breaches.

Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by email or through our service. Continued use of Contextium after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this privacy policy or our data practices, please contact us: