Context Crux
Privacy Policy
What we collect, who else can see it, and how long it stays.
What we collect
Three kinds of thing, for three different reasons.
- Content you give us: messages, uploaded documents, pages you ask us to read, and the decisions derived from them. We hold this to provide the service.
- Account data: your email address, your name if you give one, and billing identifiers held by Stripe. We hold this to identify you and to charge you.
- Technical data: a keyed hash of your IP address, which browser or app you used, and timestamps. We hold this to tell users apart, to enforce rate limits, and to keep an access record.
We do not store your IP address
We store a keyed hash of it. That is enough to tell two callers apart on a dashboard and to bind a session to whoever started it, and not enough to tell anyone where you were. Rotating the key makes every historical record unlinkable.
Who else sees your content
Providing this service means sending your content to companies that run language models. We instruct all of them that your content must not be retained for training, and for confidential sessions we prefer providers offering zero data retention.
The current list is maintained in our subprocessor register and reproduced on this page. We will update it before adding anyone new.
- OpenRouter, and the model providers it routes to — required for the product to function
- Amazon Web Services — hosting, database, logs
- Cloudflare — content delivery and protection
- Stripe — payments; receives no content
- Pangram, Google (speech synthesis), Cursor — optional features, never used on confidential sessions
What we never do
We do not train models on your content. We do not sell your data. We do not use your documents to improve the product for anyone else. We do not place advertising or tracking cookies; the only cookies we set are for signing in and for holding a session you created.
How long we keep it
Standard sessions for 365 days after last activity, confidential sessions for 180 days, and then automatic deletion. Access records are kept for two years and contain no content. Encrypted backups rotate within 7 days.
You can delete any session yourself at any time, and it goes immediately along with everything derived from it.
Your rights
If you are in the UK, the EU, or another place with comparable law, you have the right to see what we hold about you, correct it, delete it, take it elsewhere, and object to how we use it. Write to the address below and we will respond within 30 days.
We rely on our contract with you as the legal basis for handling your content, and on legitimate interests for security records and abuse prevention.
Where your data lives
In the United States, on Amazon Web Services. Model providers may process content in other countries. If you are in the UK or EU, transfers rely on the standard contractual clauses in our agreements with those providers.
Contact
Questions, requests, or complaints: privacy@crux.io. If you are in the UK or EU and are unhappy with our response, you may complain to your national data protection authority.