Privacy Policy

Effective August 6, 2026 · Last updated August 6, 2026

Draft — pending legal review. This document describes how the product actually works, but it has not yet been reviewed by a qualified lawyer and the bracketed placeholders below are not filled in. Do not rely on it as a final legal agreement.

This policy explains what [LEGAL ENTITY] ("ContextHive", "we") does with personal data when you use ContextHive.

Two different groups of people appear in this document, and the distinction matters:

  • Customers — people who sign up and use the dashboard. For their data, we are the controller.
  • End customers — the people who write in to a customer's support inbox. For their data, we are a processor acting on our customer's instructions. If you contacted a business that uses ContextHive and want your data removed, ask that business; they control it, not us.

What we collect

Account data. Name, email address, hashed password or the identifier from your chosen sign-in provider, workspace name and slug, your role, and the avatar you upload.

Support conversation data. The content of messages sent through the inbox, including anything typed by end customers, file attachments, email headers needed for threading, and any contact record we build from them — typically name, email address, and the company they belong to.

Billing data. Subscription status, plan, seat count, and invoice history. Card numbers are handled by Stripe and never reach our servers.

Operational data. Server logs containing timestamps, IP addresses, request paths and error traces. We log identifiers and counts rather than message content.

Waitlist data. If you join the pre-launch waitlist, we store your email address and which page you submitted it from, and nothing else.

Why we process it

To run the product you asked us to run: delivering messages, threading replies, generating AI answers, keeping your team's access correct, taking payment, and diagnosing failures. We also use aggregate, non-identifying usage information to decide what to build.

We do not sell personal data. We do not use your conversation content to train our own models, and we do not permit our model providers to train on it.

AI processing, specifically

This is the part worth reading closely.

When the AI agent handles a conversation, message content and the relevant passages from your knowledge base are sent to a large language model provider, routed through OpenRouter. That means conversation text leaves our infrastructure to be answered.

We select providers that contractually agree not to train on submitted content. We cannot make that guarantee stronger than the one they give us.

If your workspace sets the agent mode to off, no conversation content is sent to any model provider for reply generation.

Where the data lives

Our database and application servers are hosted in [HOSTING REGION]. Attachments are stored in Cloudflare R2. Realtime message delivery runs through Cloudflare Workers and Durable Objects.

Some of our subprocessors operate outside your country, so using ContextHive involves international transfers of personal data. Where required, these rely on Standard Contractual Clauses or an equivalent transfer mechanism.

The current list of subprocessors is published at /legal/subprocessors.

How long we keep it

Account and conversation data is retained while your workspace is active. If you delete your workspace, we delete the associated data within [RETENTION WINDOW] days, except where we are legally required to keep records — invoices, most commonly.

Server logs are retained for [LOG RETENTION] days and then rotated out.

Waitlist entries are deleted once we launch, or on request, whichever comes first.

Security

Access to production data is limited to the people who need it to operate the service. Traffic is served over TLS. Sensitive credentials stored on our side — such as workspace integration secrets — are encrypted at rest with application-level encryption.

We are not currently SOC 2 or ISO 27001 certified, and we would rather tell you that than imply otherwise.

Your rights

Depending on where you live, you may have the right to access, correct, export, delete or restrict processing of your personal data, and to object to it. Contact [CONTACT EMAIL] and we will respond within the period the applicable law requires.

If you are an end customer of a business using ContextHive, please direct these requests to that business.

You can also complain to your local data protection authority.

Cookies

We use cookies to keep you signed in and to keep the sign-in process secure. Details are at /legal/cookies.

Changes

If we change this policy materially, we will update the date at the top and notify workspace owners by email before the change takes effect.

Contact

[LEGAL ENTITY] [ADDRESS] [CONTACT EMAIL]

Data protection contact: [DPO OR PRIVACY CONTACT]