openContext

Privacy policy

Last updated .

This policy explains what is collected when you visit this website and when you run the OpenContext beta software on your own machine, and what you can do about it. The website has no publisher analytics or tracking. The local software keeps a vault on your computer and sends content to model providers when you enable and use AI; integrations, linked assistants, sharing and browser features create additional data flows described below.

The principle: only what is necessary

The local app processes only the data needed for the features you choose, with retention described below. The publisher does not collect local vault contents, prompts, usage telemetry or crash reports through this application, sell that content, or use it for advertising or model training. Local files are retained for the app features described below, in some cases until you delete them. Provider and integration data practices are governed by their own agreements. When a feature needs new data, this policy changes first, and the date at the top of the page changes with it.

This website

What the site itself collects: nothing. The pages and their interactive assets are static files. They set no cookies, use no browser storage, load nothing from another origin, run no analytics, and carry no tracking pixels. The landing page's example graph and example answers run entirely in your browser; questions typed into that demo are not sent to a model or server. The savings calculator also runs locally. Choosing "Open workspace and ask" carries your question to the configured workspace in the URL fragment, which is not included in the HTTP request. The workspace places it in a draft; sending that draft uses the app's normal model and privacy settings. Code-copy buttons write to your clipboard only when you use them. The site's test suite checks that its scripts make no network requests and use no cookies or browser storage.

What the host may log. The site is served by Vercel, under its privacy policy. Like every web server, the host receives your IP address, the page you requested, the time, and the browser's user-agent string when it serves a page, and may keep that in its ordinary server logs for security and operations under its own policy. The publisher has not enabled visitor analytics or advertising trackers. Hosting diagnostics may be reviewed to resolve availability or security problems. The legal basis, where one is required, is the host's and the publisher's legitimate interest in serving the site securely.

Links that leave the site. Links to GitHub, and to the documentation of other products, take you to sites with their own policies.

The software, on your machine

The OpenContext app runs on your computer. It has no publisher telemetry or analytics collection endpoint. Optional app sign-in protects access to the local server; it does not upload your vault to the publisher or create a multi-tenant service. The privacy page is the full description of where your data lives and every outbound call the local server can make; the points that matter for this policy are:

  • AI is enabled by default. For a supported, configured model destination, running AI sends questions, conversation context, documents and graph text needed for that run to that provider. Privacy shows the destination and lets you pause AI; existing saved pauses are preserved. OpenRouter forwards requests to model providers. API keys and consumer Claude Code logins have different data practices. This policy cannot promise zero retention or no training by those providers. Pausing AI blocks new model calls and requests cancellation of active work; it cannot recall content already sent.
  • Integrations run on your own credentials. Google Drive, Gmail, GitHub, GitLab, and X are read with your own OAuth client (the sign-in grant you register with the service yourself) or personal token, read-only, only when you press sync. Their terms and privacy policies apply to that access.
  • Additional data flows. Captured pages are fetched from the computer running the app. Entity scans may search the web and fetch public pages. Browser dictation may send microphone audio to a speech service, with a separate disclosure before use. Linked assistants can send graph evidence under their own settings. A Git push, export or synced folder can also share content. Pausing AI does not disconnect integrations, link fetching, browser dictation, or linked apps.
  • Conversation retention. New conversations default to Temporary: transcript memory expires after one hour without activity, on server restart, or a vault switch. Closing the browser tab alone does not erase server memory. Temporary chats do not save transcripts/comparisons to app files or write to the graph. Saved conversations retain questions, answers and tool activity locally until deletion. Deleting one also removes its saved comparisons, but preserves knowledge already written, checkpoint copies, logs and Git history. Local token/cost records can remain.
  • Local storage. Originals, extracted text, graph files, history, caches, privacy findings, job activity, credentials and settings remain on the computer running the app. Some contain personal data. OpenContext does not encrypt the vault. The operating system, local account permissions, backup services and storage devices also affect protection and retention. The app disables software development kit (SDK) session history and optional diagnostic telemetry for app-run agents; historical sessions and independently run clients are separate.
  • Nothing is sent to the publisher. No usage data, no crash reports, no vault content, no keys.
  • Data you ingest about other people (a colleague named in a meeting note, an email thread) is stored on your machine, under your control, and you are the one responsible for it. The software screens documents for specific sensitive patterns before a model reads them, but that screening is a safeguard, not a promise of completeness.

Children

This site and the software are not directed at children under 16, and no data is knowingly collected from them.

Your rights

Because the site collects nothing and the software sends nothing to the publisher, there is normally nothing for the publisher to access, correct, export, or delete on your behalf: your vault is a folder on your own machine. Removing it removes that local copy, not exports, older SDK sessions, upload staging, remote copies, backups, or records held by model and integration providers. Those require separate review and deletion. Filesystem deletion is not a secure-erasure guarantee. If you believe the publisher holds personal data about you (for example, because you wrote to them, or opened an issue on the repository), you can ask what it is, ask for it to be corrected or deleted, or object to its use, through the contact routes below. Where the General Data Protection Regulation or a similar law applies to you, you also have the right to complain to your supervisory authority.

Contact

Changes

When this policy changes, the date at the top changes with it, the page's markdown twin shows the exact wording, and the repository's history records every edit.