Privacy Policy

Last updated: September 13, 2026

Scope

This policy covers the SecureContext public website, customer accounts, licensing and access requests, and our handling of information in connection with Gateway and Platform. Data handling depends on the service and deployment you use. A self-hosted Gateway does not mean that website, billing or support information remains inside your infrastructure.

Website, account and commercial information

We handle information you provide when creating an account, buying a license, requesting a demo or Platform access, or contacting us. This can include your name, work email, organization, account identity, messages, license details and transaction references. We use it to authenticate users, manage accounts and licenses, process purchases, respond to requests and support the service.

Gateway and Platform deployment data

Gateway processes requests to the tools and systems configured by your organization. Where processing occurs depends on its deployment and the upstream tools and AI clients you choose. Your organization manages its self-hosted infrastructure, permissions and logging. Platform additionally handles tenant application and setup records, user and agent identities, connection settings, policy decisions, approvals and audit activity. In a hosted deployment, this information is processed in the environment arranged for that service. We do not describe hosted processing as taking place solely inside your own infrastructure.

Tool content and operational records

Connected tools may receive request arguments and return content to authorized clients. Audit and operational records can include identities, tool activity, timestamps and other request metadata; their contents depend on product configuration. Your organization should review logging and connector settings before processing sensitive information. Contact the administrator of your deployment for information about the data it retains.

Service providers and third-party connections

The public website uses Vercel for hosting and web analytics, Supabase for account authentication and application records, Stripe for payment processing, and EmailJS for contact and access-request messages. The website also loads the LinkedIn Insight Tag for advertising measurement. Integration icons may load from Google and jsDelivr. These providers receive information needed for their functions, such as submitted form details, browser/network information or payment details. Separately, customer-configured MCP servers, identity providers and AI clients handle data according to their own terms and your configuration.

Website analytics and browser storage

Website analytics and advertising measurement are separate from product runtime telemetry. The current website includes Vercel Analytics and the LinkedIn Insight Tag. Depending on the provider and browser, these services may use cookies or similar technologies and process page visits, browser/device details and network identifiers. Account sign-in also uses browser storage to maintain sessions. You can manage cookies and site storage through your browser; blocking them may affect sign-in or other functionality.

Retention and deployment location

Retention depends on the information and the service: account and license records support service access and renewal, transaction records support accounting, and contact messages support request handling. Customer-controlled runtime data follows the customer’s configured retention and backup practices. Hosted runtime retention and location should be confirmed for the applicable deployment. Website and service providers may process information in countries other than your own; contact us for deployment-specific handling and any applicable contractual arrangements.

Security and customer responsibilities

We use the security mechanisms available in the relevant product and service configuration, including identity controls and access restrictions. Customers are responsible for selecting appropriate tools, granting permissions and configuring their own infrastructure. Product capabilities are not a guarantee of compliance or a substitute for reviewing the chosen deployment and third-party services.

Your requests

For questions about website, account, billing or contact information, or to request access, correction or deletion, email contact@securecontext.org. Applicable rights depend on your jurisdiction and the circumstances; we may need to verify your identity. For information controlled by your employer or another customer organization in a Gateway or Platform deployment, contact that organization’s administrator. We will help identify the appropriate contact where possible.

Changes and contact

We may update this policy to reflect changes in the products or data handling. The date above identifies the latest update. For privacy and security questions, contact contact@securecontext.org.