Privacy Policy
Last updated: February 17, 2025
1. Introduction
ContextForge ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our Service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Name (if provided)
- Profile picture (if using OAuth providers like Google or GitHub)
- Authentication data from third-party OAuth providers
2.2 Your Content
We store the knowledge items, spaces, projects, tasks, and other content you create in the Service. This content is stored in our database infrastructure hosted on Supabase and is only accessible to you and the collaborators you explicitly invite.
2.3 Usage Data
We automatically collect usage data to operate and improve the Service, including:
- API usage counts (queries, ingestions, deletions) for plan limit enforcement
- Feature usage patterns (via Vercel Analytics)
- Error logs for debugging and service improvement
2.4 Payment Information
Payment processing is handled entirely by Stripe. We do not store credit card numbers, bank account details, or other payment credentials on our servers. We only store your Stripe customer ID and subscription status to manage your plan.
3. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Service
- Process transactions and manage subscriptions
- Send service-related communications (billing confirmations, security alerts)
- Enforce usage limits based on your subscription plan
- Detect and prevent fraud, abuse, or security incidents
- Respond to your support requests
4. What We Do NOT Do
- We do NOT sell your personal information or content to third parties
- We do NOT use your content to train AI or machine learning models
- We do NOT share your content with other users unless you explicitly invite them as collaborators
- We do NOT send marketing emails without your consent
- We do NOT track you across other websites
5. Data Storage and Security
We take security seriously and implement the following measures:
- All data is encrypted in transit (TLS/HTTPS) and at rest
- API keys are hashed using SHA-256 before storage
- Row-Level Security (RLS) policies ensure data isolation between organizations
- Database infrastructure is hosted on Supabase with enterprise-grade security
- The web application is deployed on Vercel with automatic security updates
6. Third-Party Services
We use the following third-party services to operate ContextForge:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database, authentication | Account data, content |
| Stripe | Payment processing | Email, payment details |
| Vercel | Hosting, analytics | Usage metrics, IP address |
| GitHub | OAuth, git integration | Email, repository data (when connected) |
7. Data Retention
- Your content is retained as long as your account is active
- Upon account deletion, your data will be permanently removed within 30 days
- You can export your data at any time using the Export feature in the dashboard or MCP tools
- Usage event logs are retained for billing and rate limiting purposes for the duration of the billing cycle
8. Your Rights
You have the right to:
- Access your personal data and content stored in the Service
- Export your data at any time through the dashboard
- Delete your account and all associated data
- Correct inaccurate personal information
- Object to processing of your data for specific purposes
To exercise any of these rights, contact us at support@contextforge.com.
9. Cookies
We use essential cookies only, required for authentication and session management. We do not use advertising cookies or third-party tracking cookies. Vercel Analytics collects anonymized usage data without cookies.
10. Children's Privacy
The Service is not intended for users under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. The "Last updated" date at the top of this page indicates when the policy was last revised.
12. Contact
If you have questions about this Privacy Policy or how we handle your data, please contact us at support@contextforge.com.