Privacy Notice

Last updated: 21 July 2026

Early access notice. This notice describes how the hosted Context Assistant service handles data today, during early access. It will be superseded by a full privacy policy and a Data Processing Addendum (DPA) before general availability.

1. Who this covers

This notice is for two audiences: workspace owners (whether they signed up themselves or we provisioned a workspace for them directly) and their end users (visitors who talk to an embedded assistant). We are a data processor for end-user conversation content on behalf of the workspace owner, who is the data controller for their own site's visitors.

2. What we collect

We do not receive the workspace owner's permanent API credentials in the browser at any point; those stay server-side.

3. What we don't do

4. Retention and deletion

Workspace owners can export a full workspace's conversation history (NDJSON) or delete an individual conversation at any time through their workspace. For the WordPress integration specifically, end users can also request export or erasure of their own conversations through the site's standard WordPress privacy tools, keyed to their account.

5. Sub-processors

Running the assistant involves at least one LLM provider (OpenAI or an OpenAI-compatible endpoint the workspace owner configures) to generate responses, and our own infrastructure to store conversations and serve the API. We don't add further sub-processors without updating this notice.

6. Self-hosting

If you self-host the open-core instead of using our hosted service, this notice doesn't apply to your deployment — you control where the data lives and who processes it.

7. Contact

Questions about this notice, or a request to exercise a data subject right: reach us through the contact form linked from the homepage footer.