Privacy and Security
How ContextCrux handles your data, in plain English.
The short version: You own your data. We never sell it, share it, or train on it. You can delete everything at any time. We are transparent about what we store and why.
Your rights under GDPR
| Right | How to exercise it | Response time |
|---|
| Right to access | Export your data from the You tab or request via privacy@contextcrux.io | Within 30 days |
| Right to rectification | Edit any decision or context answer in the app directly | Immediate |
| Right to erasure | Delete individual decisions or your entire account from Settings | Immediate (permanent within 30 days) |
| Right to data portability | Export as JSON via the API or Data Room export | Within 30 days |
| Right to object | Disable any integration or delete your account | Immediate |
| Right to withdraw consent | Revoke any integration or delete your account | Immediate |
What we store
- Your decisions: Questions, options, evidence, and outcomes. Stored in our database. You own the IP. Deletable per-decision.
- Your context answers: The onboarding questions about your company. Stored so agents can personalize. Deletable per-answer.
- Agent outputs: Briefs, memos, and drafts produced by your agents. Stored in the Data Room. Deletable per-artifact.
- Integration tokens: OAuth tokens for Google Drive, GitHub, and Calendar. Stored encrypted. Revocable at any time.
- Device tokens: Authentication tokens for your mobile devices. Stored hashed. Revocable per-device.
What we do NOT do
- NEVER Sell your data to third parties
- NEVER Train models on your data
- NEVER Share your decisions with other users
- NEVER Use your data for marketing
- NEVER Send your data to analytics providers
Data retention
- Active account: Data retained as long as your account exists
- Deleted account: All data permanently deleted within 30 days
- Individual deletion: Immediate and permanent
Security measures
- All traffic encrypted with TLS 1.3
- Device tokens stored hashed (SHA-256), never plaintext
- OAuth tokens encrypted at rest
- Database access restricted to the application layer
- Agent actions gated behind explicit operator approval (SUPERVISED autonomy by default)
- Deploy signals monitored for anomalies
- Infrastructure health monitored 24/7 with automated alerts
Where your data lives
| Data type | Location | Provider |
|---|
| Database | US East (AWS us-east-2) | Neon Postgres |
| Application hosting | Global edge | Vercel |
| Agent compute | US West (AWS us-west-2) | Self-hosted |
| File storage | Your own Google Drive | Google (your account) |
Intellectual property
You own every decision, document, and artifact you create in IncOS. We claim no IP rights over your content. Our systems process your data to provide the service; that processing does not transfer ownership. Your data is yours, full stop.
Contact
Data Protection Officer: privacy@contextcrux.io
Security reports: security@contextcrux.io
Response time: within 30 days (GDPR requirement: 72 hours for data breach notification)