Privacy & terms · v2026.04

Privacy and terms, in plain language.

What we collect, what we don't, what we let you do, and how we keep boundaries enforced. Effective April 1, 2026.

01 Section 01

What ContextStream collects

We collect: workspace name and members, source connection metadata (repo URL, doc workspace ID), Stream events you capture (decisions, lessons, preferences), Atlas nodes and edges derived from those events, citations back to source artefacts, and product telemetry needed to operate and improve the service.

We do not, by default, store the contents of your source repos, docs, or threads. Source contents are read transiently to derive structure and candidates, then discarded. Local-only mode (Enterprise) keeps even that derivation inside your boundary.

02 Section 02

What you control

You can export your workspace at any time as JSON. You can delete an event, a Capsule, a scope, or the entire workspace. Deletion is hard-deletion within 30 days; backups roll off within 60 days. We confirm both in writing on Enterprise.

03 Section 03

Scopes and visibility

Personal scopes are visible only to you. Project, team, and client scopes are visible only to the members you authorise. Cross-scope promotion requires explicit, redacted action by the author. Agents see only the scope explicitly granted to the agent identity.

04 Section 04

Subprocessors

We use subprocessors for cloud hosting, object storage, transactional email, error reporting, and payment processing. The full list lives on the Trust page and is updated when it changes. Material additions trigger advance notice for Enterprise customers.

05 Section 05

Security commitments

Encryption in transit and at rest. Per-workspace KMS keys for Enterprise. Access reviews quarterly. Vulnerability disclosure at [email protected] with a 90-day coordinated disclosure window.

06 Section 06

AI training and your data

We do not train foundation models on your project data. We do not share your project data with model providers beyond the per-request context required to fulfil your queries. You can disable third-party model providers entirely on Enterprise.

07 Section 07

Terms of service

Acceptable use, fair-use limits on Context Credits, indemnification, warranty disclaimers, and dispute resolution are described in our Master Subscription Agreement (Enterprise) and Standard Terms (Solo and Team). Both are written in plain language and available on request.

08 Section 08

Contact

Questions about this policy: [email protected]. Security disclosures: [email protected]. Data subject requests: [email protected].

Want a fuller policy or DPA?

We send the Master Subscription Agreement and DPA on request — usually within one business day.