Privacy and Security

How ContextCrux handles your data, in plain English.

The short version: You own your data. We never sell it, share it, or train on it. You can delete everything at any time. We are transparent about what we store and why.

Your rights under GDPR

RightHow to exercise itResponse time
Right to accessExport your data from the You tab or request via privacy@contextcrux.ioWithin 30 days
Right to rectificationEdit any decision or context answer in the app directlyImmediate
Right to erasureDelete individual decisions or your entire account from SettingsImmediate (permanent within 30 days)
Right to data portabilityExport as JSON via the API or Data Room exportWithin 30 days
Right to objectDisable any integration or delete your accountImmediate
Right to withdraw consentRevoke any integration or delete your accountImmediate

What we store

What we do NOT do

Data retention

Security measures

Where your data lives

Data typeLocationProvider
DatabaseUS East (AWS us-east-2)Neon Postgres
Application hostingGlobal edgeVercel
Agent computeUS West (AWS us-west-2)Self-hosted
File storageYour own Google DriveGoogle (your account)

Intellectual property

You own every decision, document, and artifact you create in IncOS. We claim no IP rights over your content. Our systems process your data to provide the service; that processing does not transfer ownership. Your data is yours, full stop.

Contact

Data Protection Officer: privacy@contextcrux.io
Security reports: security@contextcrux.io
Response time: within 30 days (GDPR requirement: 72 hours for data breach notification)