Effective 27 August 2026

Privacy policy

This policy explains how Context Passport collects, uses and protects information when you use contextpassport.cloud.

What we collect

Account identifiers, profile attributes you enter, preferences, constraints, goals, confirmed memories, proposed memories, integration permissions and a limited activity history. Context-request logs use item identifiers and categories by default rather than storing full prompts.

Why we use it

To maintain your personal context vault, select context relevant to a request, show a sharing preview, provide approved context to connected clients, suggest memories when you explicitly ask, secure the service and support account operations.

What is sent to AI websites

Only the context items you leave checked in the preview are added to the prompt on the supported AI website. The destination AI provider processes that text under its own terms and privacy policy.

Chrome extension data use

The extension stores scoped authentication information on your device. It processes your account identifier and approved profile context, detects whether a supported AI composer is available and reads the current prompt only after you click Personalize. The prompt is sent securely to the Context Passport service to select relevant approved context. Only context you leave checked is inserted or copied, and the extension never clicks Submit.

Context Passport's use of information received through Chrome extension APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

What we do not collect by default

We do not collect browsing history, continuously upload AI conversations, sell personal profile data, use profile data for advertising or use it to train unrelated models.

Processors

We use Supabase for database and authentication services and Vercel for web and API hosting. If you enable optional AI-assisted ranking, selected query and candidate context may be processed server-side by OpenAI. Product analytics and third-party error reporting are disabled at launch.

Retention

You control an activity-retention setting from 0 to 730 days. Account data remains until you delete individual records, personalization data or the account, subject to any legally required minimal records disclosed at launch.

Your choices

You can inspect, edit, archive, reject, export and delete profile data. You can disable personalization or memory suggestions, revoke integrations and request account deletion from settings.

Security

We apply access control, Row Level Security, scoped tokens, transport encryption provided by production hosting, secret separation and audit logging. No service can promise absolute security.

Contact and updates

For privacy questions or requests, email andreivisan82@gmail.com. Material policy changes will be dated and communicated through the service.