ctx / privacy
Privacy
This notice covers the free public ctx website and remote MCP service. You choose sources and their destination. Installing or signing in does not authorize full-library reading, automatic organization, or sharing personal data with an enterprise.
Data we process
Identity and access: GitHub and Supabase Auth verify account identifiers, login sessions and workspace membership. ctx does not ask you to send passwords or login tokens through chat.
Selected materials: saving, searching and reading sources may process conversations, documents, skills, memories, and necessary source, version and workspace metadata that you are authorized to provide. The remote version does not scan local files or automatically read entire host chats.
Enterprise invitations: enterprise names, roles, invitation status and expiry are checked. Accepting an invitation does not automatically move personal data.
AI submissions: records include the authorizing human, agent, workspace, operation, run identifier, state, time and necessary target identifiers. They exclude submission arguments and original content. They are not cryptographic signatures or proof of correctness; an unverified model remains unknown.
Support: requests you choose to submit and their handling status are saved. You can read your own requests; authorized maintainers can handle them. Include only necessary, redacted diagnostics.
Retention
Selected materials are persistent until an authorized deletion operation is completed; there is no automatic expiry. Signing out, revoking a connection, removing a member and deleting data are separate operations.
AI audits are long-term, access-controlled, append-only records. Users cannot directly delete them, and deleting a workspace is not promised to delete its audits.
Support requests are stored persistently, with no verified automatic disposal period. Submit handling or deletion requests through account support and complete the necessary identity and permission checks.
MCP OAuth grants last at most 30 days and access tokens at most one hour. The authorization-flow cookie lasts 15 minutes and a website session lasts one hour. Grant storage, revocation and expiry follow the OAuth Provider’s mechanisms. Revocation does not erase saved materials.
Providers and access
Cloudflare hosts the website and MCP endpoint, Supabase provides identity and data services, and GitHub provides sign-in. Your host handles search results and inputs you explicitly send under its own terms and data settings.
Workspace materials are accessible only to members with the relevant current permissions. Enterprise membership management is separate from sharing private sources.
ctx adds no ads, analytics trackers or content console logs, and Worker observability is disabled. Cloudflare, Supabase, GitHub and your host may independently retain infrastructure logs, security data and backups. This notice does not promise universal zero retention or a uniform backup disposal period.
This is not a promise of end-to-end encryption, storage in one country, or a universal exclusion from model training. Do not submit authentication secrets or unnecessary sensitive personal data.
Your choices and contact
Check the identity, workspace and requested scopes; choose which sources to provide. You can decline invitations or revoke applicable connection authorization. Changing a workspace requires new authorization, without silently expanding access.
Use signed-in account support for privacy, access and deletion requests. Handling requires identity and workspace-permission verification. Copies held by third parties follow their own rules; ctx does not promise to delete every copy.
Policy updates show a new effective date. There is currently no automatic policy notification mechanism; review this page before using the service again.