ContextBoard

Privacy policy

Last updated: 2026-08-14

This Privacy Policy describes how ContextBoard collects, uses, and shares information in connection with the Service. It applies to account holders and workspace members ("users"), and separately describes how we handle Customer Content uploaded to a workspace.

1. Information we collect

  • Account information: name, email address, and password (stored as a salted hash, never in plaintext).
  • Usage data: API and application requests, timestamps, and event types, used for rate limiting, dashboards, and abuse prevention.
  • Customer Content: documents, extracted data, and configurations you upload or create, described further below.
  • Cookies: as described in our Cookie policy.

2. How we use information

We use account and usage information to operate, secure, and improve the Service, including authenticating requests, enforcing rate limits, computing usage shown on your dashboard, and providing support. We do not sell personal information.

3. Customer Content

Customer Content is processed to provide the Service -- parsing, extraction, search indexing, and context pack generation -- and is accessible only to authorized members of the workspace it belongs to, enforced by row-level access controls at the database layer. We do not access Customer Content except to provide the Service, to investigate abuse or security incidents, or as required by law.

4. Sharing

We share information with subprocessors who help us operate the Service (see the Subprocessor list), and, for extraction, with the language model provider used to process your request. We do not share Customer Content with other customers or with third parties for their own marketing purposes.

5. Data retention

Account information and Customer Content are retained for as long as your organization's account is active, and for a reasonable period afterward to allow export, unless a shorter or longer period is agreed in a Data Processing Agreement. Usage event logs are retained for a rolling window sufficient for billing and abuse investigation.

6. Your rights

Depending on your location, you may have rights to access, correct, export, or delete personal information we hold about you. Workspace administrators can export or delete Customer Content directly from the application; for account-level requests, contact us through contact sales.

7. Security

We use encryption in transit and at rest, row-level access controls, and scoped, revocable API keys. See our security page for more detail.

8. International transfers

Information may be processed in countries other than your own. Where required, we rely on appropriate transfer mechanisms with our subprocessors.

9. Changes to this policy

We will post material changes to this page and update the "Last updated" date above.

10. Contact

For privacy questions, contact us through contact sales.