Community Preview Privacy Policy
Effective date and version: 2026-07-30
Context Engine App Ltd is the data controller. We are registered in England and Wales under company number 17357482, with a registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. Our operations include directors working from the United Kingdom and Italy.
Contact us about privacy at legal@context-engine.app.
1. Who this Policy applies to
The Community Preview is available only to people aged 18 or older. We do not knowingly offer it to children and do not collect a date of birth, identity document, or other age-verification data.
2. GitHub sign-in data
GitHub sign-in requests the read:user and user:email scopes. It does not request repository access. We may receive your GitHub user ID, username, email when available, display name, avatar URL, and authentication and security information needed to sign you in.
Our application database copies only the account fields needed to operate the Preview. It does not copy GitHub access tokens or the complete GitHub metadata record into the public user profile table.
3. Account and API-key data
We process:
- Your internal user ID and account details.
- Role, tier, entitlement status, and expiry.
- The agreement version and time you accepted it.
- API-key ID, name, prefix, SHA-256 hash, status, expiry, creation, last-use, and last-verification times.
A new raw API key is displayed once. The database stores its hash and prefix, not the raw key. The website does not put it in local storage or session storage. Licence validation sends the key over HTTPS; the service hashes it before lookup and does not persist or intentionally log it.
4. Licence-verification data
The executable sends a random installation or machine UUID, Context Engine version, operating-system name, API key, and an aggregate telemetry object that is currently empty. It does not currently send the operating-system version.
The service records the machine UUID, version, operating-system fields, result, denial reason where applicable, related API-key ID when known, and timestamp. Local licence files contain pseudonymous identifiers and entitlement details, not the raw API key.
5. Source code and product telemetry
The licence-verification flow does not transmit repository source code, file contents, prompts, MCP query arguments, repository names, file paths, symbol names, or repository credentials.
The protocol reserves aggregate telemetry fields, but the current executable sends empty tool counts, zero estimated token savings, and an empty language list. We will update this Policy before activating non-empty product-usage telemetry.
6. Network, security, and logs
Providers process network information, including IP addresses, to deliver and protect the Services. For licence rate limiting, the application hashes the client IP in memory and stores only the hash-derived bucket key. We do not use it to determine your country, verify age, or perform sanctions screening.
Application logs may contain versions, pseudonymous API-key IDs, GitHub username, tier, licence expiry, request outcome, and errors. HTTP tracing does not include request headers or bodies, and the application does not intentionally log raw API keys.
7. Cookies and browser storage
The portal uses Supabase authentication cookies and a signed, Secure, HttpOnly, SameSite=Lax agreement-intent cookie lasting no more than 10 minutes. They are used for authentication, security, and recording agreement acceptance. The website currently uses no advertising or analytics cookies and no browser local storage or session storage.
8. Why we process data
- Contract: account creation, authentication, agreement acceptance, API-key administration, and licence validation.
- Legitimate interests: securing the Services, preventing abuse, proving applicable agreements, and establishing or defending legal claims.
- Legal obligation: responding where law requires processing or disclosure.
We do not rely on consent for processing necessary to provide or secure the Services.
9. Automated licence decisions
The Services automatically reject invalid, inactive, revoked, expired, or unsupported licences; apply rate limits; deactivate keys when entitlements become inactive; and require the current agreements before key rotation. Contact us for human review if you believe a result is wrong. We do not profile users for advertising, credit, employment, or insurance.
10. Providers and sharing
- GitHub provides sign-in and identity information.
- Supabase provides authentication and database services.
- Render hosts the website and licence-validation service.
The production Supabase project is hosted primarily in London. The Render web and licence services are hosted in Frankfurt. Providers and their subprocessors may process data in other countries.
We may also disclose data to advisers under confidentiality, where law requires it, to investigate abuse or security incidents, to protect rights and safety, or in a corporate transaction subject to applicable law. We do not sell personal data, use it for third-party advertising, or collect payment-card data during the Preview.
11. International transfers
Where data is transferred to a country without an applicable adequacy decision, provider contractual safeguards apply, including the European Commission Standard Contractual Clauses and UK International Data Transfer Addendum where relevant. GitHub also states that it participates in the EU-US Data Privacy Framework and UK Extension. Contact us for information about applicable safeguards.
12. Retention and deletion
- Account, entitlement, and API-key records: while the account is open and up to 30 days after verified closure.
- Licence-verification records: 90 days, then removed during the next verification or maintenance run.
- Rate-limit buckets: 24 hours after their window, then removed during the next verification or maintenance run.
- Authentication sessions: until expiry, sign-out, or account closure.
- Support, rights-request, and agreement records: up to six years where needed for compliance or legal claims.
- Application and provider logs: according to operational need and the configured provider retention period.
Deleted data may remain in restricted provider backups until normal backup rotation. To close an account or request deletion, email legal@context-engine.app from the address associated with your account. We may ask you to verify the request.
13. Security
Safeguards include one-time raw-key display, hash-only key storage, scoped database roles and row-level security, secure cookies, signed agreement intent and licence responses, separate production secrets, and request-size and rate limits. No safeguard can guarantee absolute security.
14. Your rights
Depending on applicable law, you may have rights to information, access, correction, erasure, restriction, portability, objection, and human review of a qualifying solely automated decision.
Right to object
You may object to processing based on our legitimate interests. We will stop unless compelling legitimate grounds override your rights or the processing is needed for legal claims. Some rights are qualified, and we may need to verify your identity.
15. Complaints
Please contact us first so we can investigate. You may also complain to the UK Information Commissioner's Office, the Italian Data Protection Authority, or the competent authority where you live or work.
16. Changes
We may update this Policy when the Services, law, providers, or processing change. We will publish the updated effective date and provide notice or seek renewed agreement or consent where law requires it.
17. Contact
Context Engine App LtdCompany number 17357482
71-75 Shelton Street, Covent Garden
London WC2H 9JQ, United Kingdom
legal@context-engine.app