Privacy
What Contextfork collects, what it makes public, and who else touches it. Written to describe what the service actually does rather than to cover every eventuality.
Effective 9 August 2026
What we collect
Your account. An email address, which comes from the provider you sign in with; a handle; and, if you set them, a display name and a short bio.
What you write. The contexts and notes you create, and their history — each checkpoint you commit keeps the version of the content it committed, so history survives later edits.
What you keep track of. Which contexts you star and which accounts you follow.
How the service is used. Request counts, used to enforce rate limits and storage quotas; error reports; and the name an agent reports when it connects, so you can see which tools have access.
Access tokens. When you create a token we store only a one-way SHA-256 hash of its secret half. The token itself is shown to you once and cannot be recovered from us afterwards — not by you, and not by anyone who obtains our database.
What is public, and what never is
Contexts are private by default. Making one public is a deliberate action you take. An agent connected to your account can also make a context public on your instruction, which is why the connect screen states that plainly.
Public. Your handle, display name, bio and follower count, and any context you have chosen to publish — including its notes and its history.
Never public. Your email address, your private contexts, which contexts you have starred, who you follow, and your tokens.
Once something has been public, treat it as public permanently: other people and search engines may have copied or indexed it, and making it private again does not reach those copies.
How we use it
To run the service and show you your own work; to enforce rate limits and storage quotas; to send email you have asked for; to diagnose errors; and to bill you if you are on a paid plan. We do not sell your data, we do not serve advertising, and we do not use the contents of your contexts to train models.
Who else processes it
We use a small number of providers to run the service. They process data on our instructions only:
- Supabase — Database and authentication
- Vercel — Application hosting and edge protection
- Cloudflare — DNS and TLS
- Sentry — Error diagnostics
- Resend — Email you have asked us to send
- Polar — Billing, if you are on a paid plan
How long we keep it
We keep your account and its contents for as long as your account is open. The specific period we hold data after an account is closed is stated in the banner above as still to be set — email us and we will tell you exactly what applies to your account today.
What you can do
You can make any context private again, delete individual notes or a whole context, and revoke any token at any time — revoking one takes effect immediately and does not affect your other tokens.
Deleting a note that already has committed history hides it from the context while its history is preserved, so a checkpoint you took stays intact.
There is no self-serve account deletion yet. Email us at hello@contextfork.com and we will delete your account and its contents for you.
Contact
Questions about this policy, or a request about your data: email hello@contextfork.com.