Privacy

Last updated 9 August 2026

What we collect

Your account. An email address, which comes from the provider you sign in with; a handle; and, if you set them, a display name and a short bio.

What you write. The tacos and entities you create, and their history — each checkpoint you commit keeps the version of the content it committed, so history survives later edits.

What you keep track of. Which tacos you star and which accounts you follow.

How the service is used. Request counts, used to enforce rate limits and storage quotas; error reports; and the name an agent reports when it connects, so you can see which tools have access. We also record each request your agent or browser makes — which action it was, whether it succeeded, how long it took, and what was sent and returned — so we can find where the product is confusing or broken. Because a request to write a taco carries what you are writing, that record can include your content, including from private tacos. Only we can read it; it is never shown to anyone else and never used to train anything.

Visits to this website. Which page was viewed, roughly which country it was viewed from, and what kind of browser and device — counted so we can tell whether people who arrive here find what they came for. No cookies are set, nothing is linked to your account, and you are not tracked across other websites. This is the website only: an agent connected over MCP runs no page and is never counted here.

Sign-in credentials. Agents connect over OAuth and your client keeps the access token it is issued; we do not store an API key for you, and there is none to create. What we hold is the record that a client registered — its name and version — so you can see which tools have access.

What is public, and what never is

Tacos are private by default. Making one public is a deliberate action you take. An agent connected to your account can also make a taco public on your instruction, which is why the connect screen states that plainly.

Public. Your handle, display name, bio and follower count, and any taco you have chosen to publish — including its entities and its history.

Never public. Your email address, your private tacos, which tacos you have starred, and who you follow.

Once something has been public, treat it as public permanently: other people and search engines may have copied or indexed it, and making it private again does not reach those copies.

How we use it

To run the service and show you your own work; to enforce rate limits and storage quotas; to send email you have asked for; to diagnose errors; to count visits to this website so we can tell whether people who arrive find what they came for; and to bill you if you are on a paid plan. We do not sell your data, we do not serve advertising, and we do not use the contents of your tacos to train models.

Who else processes it

We use a small number of providers to run the service. They process data on our instructions only:

  • Supabase — Database and authentication
  • Vercel — Application hosting, edge protection and website visit counts
  • Cloudflare — DNS and TLS
  • Sentry — Error diagnostics
  • Resend — Email you have asked us to send
  • Polar — Billing, if you are on a paid plan

How long we keep it

We keep your account and its contents until you ask us to close it, and delete them within 30 days of that request.

What you can do

You can make any taco private again, and delete individual entities or a whole taco. To cut an agent off, remove the Contextaco connector in that client — it holds the credential, not us.

Deleting an entity that already has committed history hides it from the taco while its history is preserved, so a checkpoint you took stays intact.

There is no self-serve account deletion yet. Email us at hello@contextaco.com and we will delete your account and its contents for you.

Contact

Questions about this policy, or a request about your data: email hello@contextaco.com.

Ready AI Pte Ltd, 50 Everton Rd, Singapore 089396