Ctxia ("we", "the extension") helps you turn conversations from AI platforms (ChatGPT, Claude, Gemini, DeepSeek) into reusable knowledge cards. This policy describes exactly what data is processed, where it lives, who it is shared with, and the controls you have. The guiding principle is data minimization: nothing is collected automatically, and nothing leaves your device except through actions you explicitly take.
| Data | Where it lives | Why |
|---|---|---|
| Inbox items (conversations you collect) | Your browser (chrome.storage.local) | So your Inbox survives page navigation; removed when you remove items, clear the Inbox, or uninstall |
| Knowledge cards you create | Your browser (IndexedDB) | Your personal library; exportable anytime via Backup |
| Account email & bearer token | Your browser (chrome.storage.local) | Your email is your passwordless account identity; the token authenticates quota and email delivery |
| Usage quota & email-delivery metadata | Our server (e.g., daily counts, delivered/bounced status) | Fair-use limits and delivery health; never conversation content |
| Usage-analytics events | PostHog (see §4) | Understanding feature usage; no content, opt-out available |
| Compatibility telemetry | Our server (aggregate statistics, ≤ 30 days) | Technical metrics only when a Ctxia capability fails on a page (see §2); never conversation content, never your identity |
Conversation content is transmitted only in these two explicit cases:
We never sell data, and we never use your content to train AI models.
Compatibility telemetry (technical metrics, not content): when one of Ctxia's capabilities fails on a page (an AI platform changed its interface), the extension sends an anonymous technical event: the platform name, the affected capability, rule/extension/browser versions and a machine-readable failure reason. It carries no conversation content and no user identity, is deduplicated per page session, and exists solely to alert us that a platform's interface changed. Statistics are reviewed manually by our developers; no alert emails are sent.
Page-structure fingerprint (still not content): to repair compatibility for page variants we cannot reproduce ourselves, a failed self-check may additionally attach a sanitized structural skeleton of the page — element tag names, class names and attribute names only. All text and attribute values are stripped before the skeleton leaves your device (a small allow-list of platform identifiers such as role/data-testid may keep their values, which are platform-defined labels, never user data). Each distinct structure is identified by a SHA-256 fingerprint and uploaded at most once every 7 days — one sample per changed layout rather than one per user — and only while product analytics is enabled. Turning analytics off in Settings stops this entirely.
| Provider | Purpose | Data shared |
|---|---|---|
| DeepSeek (current AI processing provider) | AI refinement (only when you request it) | The conversation items you selected |
| Resend | Email delivery (only when you export) | Your card content + your email address |
| Cloudflare | API hosting (api.ctxia.io) and analytics proxy (p.ctxia.io) | Requests you initiate (account token, submitted content); analytics events relayed to PostHog |
| PostHog | Product analytics (via our p.ctxia.io proxy) | Usage events; account email linked when you register (see §4) |
Depending on provider routing, processing may occur outside your country of residence. We select providers with industry-standard security, and the scope of shared data is limited as described above.
We use PostHog to understand which features help you. Events contain action names and coarse properties only (e.g., "a card was created", platform name, error type) — never card content, conversation text, or search queries. Events reach PostHog through our own reverse proxy (p.ctxia.io). Identity is a random per-install ID; if you register an account, your account email is linked to these events (PostHog's identify mechanism) so we can connect your usage over time and provide support.
Control: analytics are enabled by default and can be disabled at any time in the extension's settings panel ("Share usage data"). When disabled, no analytics events are sent — including the email linkage and the page-structure fingerprint described in §2. You may disable analytics before using AI refinement features if you prefer.
Requests to our API require your bearer token; transport is TLS-encrypted. All card content is escaped before rendering into emails. Analytics and networking failures can never block the product. We continuously review and improve our security practices, but no method of electronic storage or transmission over the Internet can be guaranteed to be 100% secure. If you discover a vulnerability, please contact us.
Ctxia is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect data from them.
We process personal data only as necessary to provide the services you request, fulfill our contractual obligations, comply with legal obligations, protect against abuse, and, where applicable, based on your consent (such as product analytics).
If we make material changes, we will update the "Last updated" date above and surface the change in the extension where practical. Continued use after the effective date constitutes acceptance.
Questions, deletion requests, or feedback: support@ctxia.io
Privacy inquiries: support@ctxia.io