Privacy Policy

Last updated: February 17, 2025

1. Introduction

ContextForge ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address
  • Name (if provided)
  • Profile picture (if using OAuth providers like Google or GitHub)
  • Authentication data from third-party OAuth providers

2.2 Your Content

We store the knowledge items, spaces, projects, tasks, and other content you create in the Service. This content is stored in our database infrastructure hosted on Supabase and is only accessible to you and the collaborators you explicitly invite.

2.3 Usage Data

We automatically collect usage data to operate and improve the Service, including:

  • API usage counts (queries, ingestions, deletions) for plan limit enforcement
  • Feature usage patterns (via Vercel Analytics)
  • Error logs for debugging and service improvement

2.4 Payment Information

Payment processing is handled entirely by Stripe. We do not store credit card numbers, bank account details, or other payment credentials on our servers. We only store your Stripe customer ID and subscription status to manage your plan.

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Service
  • Process transactions and manage subscriptions
  • Send service-related communications (billing confirmations, security alerts)
  • Enforce usage limits based on your subscription plan
  • Detect and prevent fraud, abuse, or security incidents
  • Respond to your support requests

4. What We Do NOT Do

  • We do NOT sell your personal information or content to third parties
  • We do NOT use your content to train AI or machine learning models
  • We do NOT share your content with other users unless you explicitly invite them as collaborators
  • We do NOT send marketing emails without your consent
  • We do NOT track you across other websites

5. Data Storage and Security

We take security seriously and implement the following measures:

  • All data is encrypted in transit (TLS/HTTPS) and at rest
  • API keys are hashed using SHA-256 before storage
  • Row-Level Security (RLS) policies ensure data isolation between organizations
  • Database infrastructure is hosted on Supabase with enterprise-grade security
  • The web application is deployed on Vercel with automatic security updates

6. Third-Party Services

We use the following third-party services to operate ContextForge:

ServicePurposeData Shared
SupabaseDatabase, authenticationAccount data, content
StripePayment processingEmail, payment details
VercelHosting, analyticsUsage metrics, IP address
GitHubOAuth, git integrationEmail, repository data (when connected)

7. Data Retention

  • Your content is retained as long as your account is active
  • Upon account deletion, your data will be permanently removed within 30 days
  • You can export your data at any time using the Export feature in the dashboard or MCP tools
  • Usage event logs are retained for billing and rate limiting purposes for the duration of the billing cycle

8. Your Rights

You have the right to:

  • Access your personal data and content stored in the Service
  • Export your data at any time through the dashboard
  • Delete your account and all associated data
  • Correct inaccurate personal information
  • Object to processing of your data for specific purposes

To exercise any of these rights, contact us at support@contextforge.com.

9. Cookies

We use essential cookies only, required for authentication and session management. We do not use advertising cookies or third-party tracking cookies. Vercel Analytics collects anonymized usage data without cookies.

10. Children's Privacy

The Service is not intended for users under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. The "Last updated" date at the top of this page indicates when the policy was last revised.

12. Contact

If you have questions about this Privacy Policy or how we handle your data, please contact us at support@contextforge.com.