Ctxia · Privacy Policy

Your AI knowledge stays under your control.

Last updated: August 13, 2026 · Applies to the Ctxia browser extension and its backend services

Ctxia ("we", "the extension") helps you turn conversations from AI platforms (ChatGPT, Claude, Gemini, DeepSeek) into reusable knowledge cards. This policy describes exactly what data is processed, where it lives, who it is shared with, and the controls you have. The guiding principle is data minimization: nothing is collected automatically, and nothing leaves your device except through actions you explicitly take.

One-minute summary: Cards and Inbox items are stored locally in your browser. Conversation content is only transmitted when you click AI refinement or email export, and our servers do not retain that content after processing your request. Usage analytics never carry card content and can be turned off in one click.

1. Data we process

DataWhere it livesWhy
Inbox items (conversations you collect)Your browser (chrome.storage.local)So your Inbox survives page navigation; removed when you remove items, clear the Inbox, or uninstall
Knowledge cards you createYour browser (IndexedDB)Your personal library; exportable anytime via Backup
Account email & bearer tokenYour browser (chrome.storage.local)Your email is your passwordless account identity; the token authenticates quota and email delivery
Usage quota & email-delivery metadataOur server (e.g., daily counts, delivered/bounced status)Fair-use limits and delivery health; never conversation content
Usage-analytics eventsPostHog (see §4)Understanding feature usage; no content, opt-out available
Compatibility telemetryOur server (aggregate statistics, ≤ 30 days)Technical metrics only when a Ctxia capability fails on a page (see §2); never conversation content, never your identity

2. When content leaves your device

Conversation content is transmitted only in these two explicit cases:

We never sell data, and we never use your content to train AI models.

Compatibility telemetry (technical metrics, not content): when one of Ctxia's capabilities fails on a page (an AI platform changed its interface), the extension sends an anonymous technical event: the platform name, the affected capability, rule/extension/browser versions and a machine-readable failure reason. It carries no conversation content and no user identity, is deduplicated per page session, and exists solely to alert us that a platform's interface changed. Statistics are reviewed manually by our developers; no alert emails are sent.

Page-structure fingerprint (still not content): to repair compatibility for page variants we cannot reproduce ourselves, a failed self-check may additionally attach a sanitized structural skeleton of the page — element tag names, class names and attribute names only. All text and attribute values are stripped before the skeleton leaves your device (a small allow-list of platform identifiers such as role/data-testid may keep their values, which are platform-defined labels, never user data). Each distinct structure is identified by a SHA-256 fingerprint and uploaded at most once every 7 days — one sample per changed layout rather than one per user — and only while product analytics is enabled. Turning analytics off in Settings stops this entirely.

3. Third-party processors

ProviderPurposeData shared
DeepSeek (current AI processing provider)AI refinement (only when you request it)The conversation items you selected
ResendEmail delivery (only when you export)Your card content + your email address
CloudflareAPI hosting (api.ctxia.io) and analytics proxy (p.ctxia.io)Requests you initiate (account token, submitted content); analytics events relayed to PostHog
PostHogProduct analytics (via our p.ctxia.io proxy)Usage events; account email linked when you register (see §4)

Depending on provider routing, processing may occur outside your country of residence. We select providers with industry-standard security, and the scope of shared data is limited as described above.

4. Usage analytics

We use PostHog to understand which features help you. Events contain action names and coarse properties only (e.g., "a card was created", platform name, error type) — never card content, conversation text, or search queries. Events reach PostHog through our own reverse proxy (p.ctxia.io). Identity is a random per-install ID; if you register an account, your account email is linked to these events (PostHog's identify mechanism) so we can connect your usage over time and provide support.

Control: analytics are enabled by default and can be disabled at any time in the extension's settings panel ("Share usage data"). When disabled, no analytics events are sent — including the email linkage and the page-structure fingerprint described in §2. You may disable analytics before using AI refinement features if you prefer.

5. Retention & deletion

6. Security

Requests to our API require your bearer token; transport is TLS-encrypted. All card content is escaped before rendering into emails. Analytics and networking failures can never block the product. We continuously review and improve our security practices, but no method of electronic storage or transmission over the Internet can be guaranteed to be 100% secure. If you discover a vulnerability, please contact us.

7. Children's data

Ctxia is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect data from them.

8. Legal basis for processing

We process personal data only as necessary to provide the services you request, fulfill our contractual obligations, comply with legal obligations, protect against abuse, and, where applicable, based on your consent (such as product analytics).

9. Changes to this policy

If we make material changes, we will update the "Last updated" date above and surface the change in the extension where practical. Continued use after the effective date constitutes acceptance.

10. Contact

Questions, deletion requests, or feedback: support@ctxia.io

Privacy inquiries: support@ctxia.io