Legal

Privacy Policy

Effective . This Privacy Policy explains how ctxhub handles your personal data when you use the ctxhub service.

Introduction

ctxhub (“ctxhub”, “we”, “our”, or “us”) takes privacy seriously and works to keep any information you share with us secure. This Privacy Policy (the “Policy”) describes how we collect, use, disclose, and otherwise process personal data when you use ctxhub’s software, websites, command-line tools, APIs, documentation, integrations, and the related services we make available to build, share, and operate persistent agent context (collectively, the “Service”), including at ctxhubs.app.

This Policy also describes the data-protection rights that may be available to you depending on where you live and how you can exercise them. Please read it carefully. By accessing or using the Service, you acknowledge that you have been informed of and consent to ctxhub’s practices with respect to your personal data.

This Policy does not apply where ctxhub processes personal data on behalf of a commercial customer — for example, where your employer has provisioned a ctxhub workspace for you to use at work. In those cases, ctxhub acts as a data processor (or service provider) on behalf of that customer, and the customer’s own privacy notice and our customer agreement covering the Service govern that processing.

1. Personal data we collect

We collect the following categories of personal data.

A. Information you provide directly

We collect personal data when you create a ctxhub account, configure the Service, or communicate with us:

  • Account information. Identifiers such as your name, email address, profile image, and the workspace or organization name you supply when you sign up for ctxhub or request information about the Service.
  • Authentication data. If you sign in through a third-party identity provider (such as Google or GitHub), we receive the identifiers and basic profile information that provider releases to us under your authorization, plus access and refresh tokens scoped to permissions you grant.
  • Payment information. If you subscribe to a paid ctxhub plan, our payment processor collects your billing details. ctxhub receives a redacted summary (last four digits, card brand, billing country, invoice metadata) but does not store your full card number.
  • Context, inputs, and outputs.The Service is designed to store the context you share with your agents — notes, snippets, files, knowledge views, prompts, agent definitions, flows, skills, and the messages exchanged between you and an agent (collectively, “Content”). If your Content contains personal data, we will receive and store it so we can render the Service back to you, and it may appear in agent outputs you or your teammates request.
  • Integration data. When you connect an integration (such as a code host, calendar, ticketing system, drive, CRM, or chat tool), we receive the data the integration is configured to share with ctxhub under the scopes you authorize. You can disconnect integrations at any time from the Service settings.
  • Communications.If you contact us directly — for support, sales, or a feedback exchange — we receive your name, contact information, and the contents of your messages, including any attachments.
  • Feedback. If you rate an agent response, report a problem, or otherwise send us feedback, we may retain the surrounding exchange to understand context and improve the Service.

B. Information we receive automatically

When you use the Service, we automatically receive technical information:

  • Device information. Information about how you install, access, or use the Service, including device type, browser, operating system, language, and (for mobile) mobile network or ISP.
  • Log information. Information about Service performance and reliability, including IP address, timestamps, request paths, response codes, user-agent strings, and error traces.
  • Usage data. Information about how you use the Service, such as dates and times of access, pages and views you load, features you interact with, search queries inside the Service, agent runs you trigger, and tools the agent invoked on your behalf.
  • Cookies and similar technologies. We and our service providers use cookies, local storage, pixels, scripts, and similar technologies to operate the Service (for example, to keep you signed in), to remember your preferences, and to measure performance and reliability. Where required by law, we ask for your consent before setting non-essential cookies.
  • Approximate location. For security and abuse-prevention purposes (for example, to flag unusual sign-in activity) and for regional routing, we may derive an approximate location from your IP address. We do not collect precise GPS-level location.

C. Information we do not knowingly collect

ctxhub does not knowingly collect sensitive or special-category personal data — including genetic data, biometric data used to uniquely identify a natural person, health information, or information about religious or philosophical beliefs. Do not paste this kind of information into the Service. If you do, we will treat it under this Policy but ask that you delete it. ctxhub is not directed to children under the age of 18; see “Children” below.

2. How we use personal data

We use personal data for the following purposes:

  • To provide and operate the Service, including rendering your Content back to you and your teammates, running agents you trigger, and delivering optional features that enhance the experience.
  • To create, manage, and administer your account, including verifying your identity, processing payments, issuing invoices, and responding to inquiries.
  • To maintain, debug, and improve the Service, including diagnosing reliability issues, measuring performance, and evaluating new features.
  • To communicate with you, including service announcements, security notices, billing notices, product updates, and (where permitted) marketing about ctxhub features.
  • To prevent, detect, and investigate fraud, abuse, spam, security incidents, and violations of the ctxhub Terms of Service or our acceptable-use expectations.
  • To comply with legal obligations and to protect the rights, safety, privacy, and property of ctxhub, our users, and third parties.
  • To enforce our Terms of Service and other applicable agreements.

Use of your Content to train models. ctxhub does not use your Content to train AI models, and does not permit third-party model providers we use to deliver the Service to train their models on your Content, except where: (i) Content is flagged by automated safety systems for review, in which case we may analyze it to improve our enforcement of our Terms of Service; (ii) you explicitly opt in — for example, by submitting Content to us as Feedback or by enabling a clearly labelled training option in Settings; or (iii) we are required to do so by law.

We may aggregate or de-identify personal data so it no longer reasonably identifies you, and use that aggregated or de-identified data for any purpose consistent with this Policy — for example, to publish usage statistics or improve the Service. We maintain aggregated or de-identified data in that form and do not attempt to re-identify it except as permitted by law.

3. How we share personal data

We share personal data only in the following circumstances:

  • Service providers and business partners. We share personal data with third-party vendors that support our operations — including cloud hosting, database, model inference, observability, analytics, customer support, abuse monitoring, communications, payment processing, and compliance providers. These vendors process personal data only as needed to perform services on our behalf and subject to confidentiality obligations. For commercial uses of the Service where ctxhub acts as a data processor, the third-party subprocessors we engage are listed at /trust/subprocessors (sign-in required).
  • Integrations you connect. When you connect an integration to ctxhub, personal data and Content may flow to and from that integration under the scopes you authorize. The third party controls the data once it leaves the Service, and its own terms and privacy notice govern its use.
  • Workspace administrators. If your account is part of a ctxhub workspace or organization (for example, one created by your employer), administrators of that workspace may access account, audit, and Content data associated with your usage, and may exercise administrative controls over your account, including provisioning, deprovisioning, retention, and export.
  • Other users you share with. The Service offers features that let you share Content, invitations, and links with other users. Information you choose to share through those features is, by your action, disclosed to the recipients you designate.
  • Business transfers. If ctxhub is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal data may be disclosed to counterparties and their advisors as part of diligence or transferred as part of the transaction.
  • Legal compliance and protection of rights. We may disclose personal data to governmental authorities or other third parties when we believe in good faith that doing so is necessary to comply with applicable law or legal process; to respond to lawful requests or investigations; to protect the rights, property, or safety of ctxhub, our users, or the public; to prevent fraud or other unlawful activity; or to enforce our Terms of Service.
  • Affiliates. We may share personal data with our corporate affiliates, who will use it in a manner consistent with this Policy.
  • With your consent. We may share personal data for any other purpose disclosed to you at the time and with your consent.

ctxhub does not sell your personal data, and we do not “share” it for cross-context behavioural advertising, as those terms are defined under U.S. state privacy laws.

4. Retention

We retain personal data for as long as needed to provide the Service and to support legitimate business purposes, including legal compliance, safety, dispute resolution, and enforcement of our agreements. Appropriate retention periods depend on the type of data, the purpose it was collected for, its sensitivity, and any applicable legal requirements.

When personal data is no longer needed, ctxhub and its service providers will delete, erase, anonymize, or de-identify it in accordance with applicable law. Backups containing deleted data are overwritten on a rolling basis.

Some Service settings affect retention. For example, you can delete individual Content items, chats, or agent runs at any time; you can also delete your workspace or your account, which removes the associated Content from active systems on a defined schedule. Audit and security logs may be retained for a longer period as required for fraud prevention, abuse monitoring, and legal compliance.

5. Security

We implement commercially reasonable technical and organizational measures designed to protect personal data from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. These measures include encryption of data in transit and at rest using industry-standard ciphers, role-based access controls, audit logging, vulnerability management, secret management, employee training, and regular review of our security program.

No method of transmission over the Internet and no method of electronic storage is fully secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential, using strong and unique passwords, and enabling available security features such as two-factor authentication.

6. Your rights and choices

Depending on where you live, you may have certain rights with respect to your personal data, including the rights described below. To exercise any of these, you or an authorized agent may contact us at privacy@ctxhub.com. We may need information to verify your identity before responding. ctxhub will not discriminate against you for exercising any privacy right available under applicable law.

  • Right to know. You may request information about the categories of personal data we collect, the purposes for which we use it, and the categories of third parties with whom we share it.
  • Access and portability. You may request a copy of the personal data we hold about you and, where applicable, ask us to provide it in a portable, machine-readable format.
  • Deletion. You may request that we delete personal data we collected from you in connection with your use of the Service, subject to certain exceptions (for example, to comply with law or to detect fraud).
  • Correction. You may request that we correct inaccurate personal data we maintain about you. Because AI models can produce unpredictable outputs, we cannot guarantee the factual accuracy of agent responses generated by the Service.
  • Objection and restriction. Where applicable, you may object to or ask us to restrict certain processing of your personal data. We will honor those requests unless we have a legitimate overriding ground to continue.
  • Withdraw consent. Where we rely on your consent as the legal basis for processing, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.
  • Complaint. You may lodge a complaint with your local data-protection authority.

No solely-automated decisions with legal effect. ctxhub does not make decisions about you that produce legal or similarly significant effects (such as decisions about credit, insurance, housing, or employment) based solely on automated processing of your personal data.

No sale or targeted advertising. We do not “sell” personal data, do not “share” it for cross-context behavioural advertising, and do not process personal data for “targeted advertising” (as those terms are defined under applicable U.S. state privacy laws). We do not process sensitive personal data to infer characteristics about you.

7. International transfers

ctxhub operates servers in multiple jurisdictions, including the United States. When you use the Service, your personal data may be transferred to, stored in, and processed in countries other than the one you live in, including countries that may have data-protection laws different from those in your country.

Where personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, ctxhub relies on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) and applies additional safeguards as required by law. We apply the protections described in this Policy to your personal data regardless of where it is processed.

8. Jurisdiction-specific disclosures

Some jurisdictions require additional disclosures. The following supplement, but do not replace, the rest of this Policy.

European Economic Area, United Kingdom, and Switzerland

Where the EU General Data Protection Regulation, the UK GDPR, or the Swiss Federal Act on Data Protection apply, ctxhub is the controller of personal data described in this Policy unless we tell you otherwise. Our legal bases for processing your personal data are:

  • Performance of a contract, where processing is necessary to provide the Service or to take steps at your request before entering into a contract.
  • Legitimate interests, where processing is necessary for our legitimate interests — such as operating, securing, and improving the Service — and those interests are not overridden by your rights.
  • Consent, where you have given us consent for a specific purpose (such as setting non-essential cookies or receiving marketing messages).
  • Legal obligation, where we are required to process personal data to comply with law.

California

The California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives California residents the rights described under “Your rights and choices” above. In the preceding 12 months, we have collected, used, and disclosed the categories of personal data described in “ Personal data we collect” for the purposes described in “How we use personal data” and disclosed them to the categories of recipients described in “How we share personal data”. ctxhub does not sell personal data and does not share it for cross-context behavioural advertising as those terms are defined under California law.

Other U.S. states

Residents of other U.S. states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana) may have rights similar to those described under “Your rights and choices” above. You may exercise those rights by contacting privacy@ctxhub.com.

9. Children

The Service is not directed to children under the age of 18, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact privacy@ctxhub.com and we will investigate and, where appropriate, delete the information and close the associated account.

10. Changes to this policy

We may update this Policy from time to time. When we do, we will publish the updated version on this page and revise the “Effective” date at the top. If the changes are material, we will provide additional notice (for example, by email or via an in-Service banner) before they take effect. Your continued use of the Service after the updated Policy takes effect constitutes your acceptance of the updated Policy.

11. Contacting ctxhub

If you have questions about this Policy or ctxhub’s privacy practices, contact our privacy team at privacy@ctxhub.com. For general inquiries, write to hi@ctxhub.com.