CONTENTS
- 01Information We Collect
- 02Data We Process for Our Customers
- 03How We Use Your Information
- 04AI Processing
- 05Third-Party Services
- 06Account Integrations You Connect
- 07Advertising & Conversion Tracking
- 08Cookies & Similar Technologies
- 09Data Retention
- 10Your Rights
- 11Data Security
- 12International Data Transfers
- 13Children's Privacy
- 14Changes to This Policy
- 15Contact
Context Memo ("we," "us," or "our") operates the website at contextmemo.com and the associated platform. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.
Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Name (if provided)
- Company name and domain
- Password (stored as a cryptographic hash — we never store plaintext passwords)
Brand and Content Data
When you use the platform, we collect information you provide about your brand, including website URLs, company descriptions, product information, and any context you submit for memo generation or landing pages. If you connect an optional content source such as a meeting-notes tool, we store the notes or transcripts you choose to import, encrypted at rest.
Usage Data
We automatically collect:
- Pages visited, features used, and actions taken within the platform
- Browser type, operating system, and device information
- IP address and approximate geographic location (city/country level)
- Referring URLs and search terms that led you to our site
Payment Information
Payment processing is handled by Stripe. We do not store credit card numbers or full payment details on our servers. Stripe's privacy policy is available at stripe.com/privacy.
Data We Process for Our Customers
Context Memo publishes memos and landing pages for our customers. When you visit one of those pages, we process data as a service provider for the customer whose page you are viewing:
- Lead form submissions — if you fill out a form on a customer's page, we collect the fields in that form (typically name, email, phone, and company) and deliver them to that customer, along with the referring URL and any campaign identifiers (such as UTM parameters or ad click IDs) attached to your visit.
- Page analytics — page views, referrer, approximate location (city/country), device and browser information, and a first-party visitor identifier stored in your browser. IP addresses used for traffic analytics are stored only as truncated hashes.
- AI and bot traffic detection — we identify visits from AI assistants and crawlers by user agent and network operator so customers can see how AI systems use their content. Customers may optionally install a lightweight edge script on their own site that forwards the same bot-visit metadata to us; it does not forward raw visitor IP addresses.
For this data, the customer is the data controller and we act on their instructions. Requests about data collected on a customer's page should be directed to that customer; we will assist them in responding.
How We Use Your Information
- Provide and operate the Context Memo platform
- Generate, verify, and maintain factual reference memos and landing pages for your brand
- Run and measure advertising campaigns you create through the platform
- Process payments and manage subscriptions
- Send transactional emails and notifications (account verification, password resets, memo status updates, lead alerts)
- Analyze usage patterns to improve the product
- Detect and prevent fraud, abuse, or security incidents
- Comply with legal obligations
AI Processing
Context Memo uses artificial intelligence to generate and verify reference content and to run visibility scans. When we process your brand information, it may be sent to the following AI providers:
- OpenAI — memo generation and content analysis
- Anthropic — content generation, verification, and search-grounded scans
- Google (Gemini) — search-grounded content analysis and scans
- Perplexity — research and fact-checking
- OpenRouter — a routing layer that sends requests to models from multiple providers
These providers process data according to their respective privacy policies and data processing agreements. Brand information sent to AI providers through our API calls is used solely for generating and verifying your content and running your scans; we do not submit your account data, private brand context, or platform data for model training.
A distinction worth being clear about: content you choose to publish (memos and landing pages) is public reference material. Public content can be crawled by AI systems, including crawlers that collect training data, and being discoverable by AI engines is the purpose of the product. Everything you do not publish (your account, your brand context, your analytics, and the API requests we make on your behalf) stays private and is never used for training.
Third-Party Services
We use the following third-party services that may collect or process data:
| SERVICE | PURPOSE | DATA SHARED |
|---|---|---|
| Supabase | Database and authentication | Account data, application data |
| Stripe | Payment processing | Email, payment details |
| Vercel | Hosting and edge analytics | Request data, performance metrics |
| Google Analytics | Website analytics | Usage data, device info, IP address (consent-gated) |
| PostHog | Product analytics | Usage data, device info |
| Sentry | Error monitoring | Error data, device info |
| Resend | Transactional email | Email address, email content |
| Inngest | Background job processing | Job payloads (brand and content data) |
| Upstash | Rate limiting on public endpoints | IP address (transient) |
| IPInfo | IP geolocation and network lookup | IP address |
| SerpAPI | Search result analysis | Brand-related search queries |
| ScreenshotOne | Page screenshot capture | Public page URLs |
| OpenAI Ads | Ad campaigns and conversion measurement | See Section 07 |
Account Integrations You Connect
You can optionally connect third-party accounts to your brand. We access only the data needed for the feature, only after you connect, and you can disconnect at any time from your dashboard settings. Access credentials are stored in our encrypted database and used only to provide the features described below.
Google User Data (Google Analytics and Search Console)
Context Memo lets you optionally connect your Google account so we can display your own website performance data inside your dashboard. When you connect, we access Google user data through Google APIs using the following read-only scopes:
- Google Analytics (analytics.readonly) — we read report data from the GA4 property you select, such as sessions, traffic sources, and AI-referral traffic, to show it in your Context Memo dashboard.
- Google Search Console (webmasters.readonly) — we read search performance data (impressions, clicks, and queries) for the site you select, to show it in your Context Memo dashboard.
We use this data solely to provide you with reporting and insights within Context Memo. We do not sell Google user data, do not use it for advertising, do not use it to train AI models, and do not share it with third parties except as necessary to provide the service (for example, secure storage with our database provider). Only the account that connected the Google integration, and members of the same workspace, can see this data. OAuth tokens are used only to retrieve the data described above. You can disconnect the integration at any time from your dashboard settings or by revoking access at myaccount.google.com/permissions, after which we stop accessing your Google data and delete the stored tokens.
Context Memo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Other Integrations
- Bing Webmaster Tools — you provide an API key; we read search and AI performance statistics for your site.
- HubSpot — OAuth connection used to publish memos to your HubSpot CMS and to read contact data for revenue attribution reporting.
- Slack — OAuth connection used to send lead and activity notifications to a channel you choose.
- Cloudflare — OAuth connection used to deploy an optional bot-tracking script to your own site, as described in Section 02.
- Granola and Fathom — you provide an API key; we import the meeting notes or call transcripts you select as brand context. Keys and imported content are encrypted at rest.
Advertising & Conversion Tracking
Customers can create and measure OpenAI ad campaigns through Context Memo. Two kinds of data flow to OpenAI as part of this feature:
- On contextmemo.com — our own marketing pages load an OpenAI ads measurement pixel, subject to your cookie consent choice, which may set an attribution cookie.
- On customer landing pages — when a visitor who arrived from an OpenAI ad submits a lead form for a customer with conversion tracking enabled, we send a conversion event to OpenAI's Conversions API containing the page URL, ad attribution identifiers, a SHA-256 hash of the submitted email address, and the visitor's IP address, user agent, and approximate location. This lets the customer measure which ads produced leads. Conversion API keys are encrypted at rest.
Data Retention
- Account data — retained while your account is active, deleted upon request
- Brand and memo data — retained while your account is active; published memos may persist as public reference documents after account deletion
- Lead and page analytics data — retained while the customer's account is active, deleted on the customer's request
- Usage and analytics data — retained for up to 26 months
- Payment records — retained as required by tax and financial regulations
Your Rights
Depending on your jurisdiction, you may have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate data
- Deletion — request deletion of your personal data
- Export — receive your data in a portable format
- Restriction — request we limit processing of your data
- Objection — object to processing based on legitimate interests
We provide self-service data export and account deletion through your dashboard settings. You can also email us at stephen@contextmemo.com to exercise any of these rights. We respond to requests within 30 days.
Data Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, AES-256 application-level encryption for sensitive API keys and imported content, hashing of IP addresses used in traffic analytics, access controls, and continuous error and security monitoring. While no system is 100% secure, we take reasonable steps to protect your information.
International Data Transfers
Your data may be processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place for international transfers in compliance with applicable data protection laws.
Children's Privacy
Context Memo is a business-to-business platform and is not intended for use by individuals under the age of 18. We do not knowingly collect data from children.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on our website. Continued use of the platform after changes constitutes acceptance of the updated policy.
Contact
For privacy-related questions or requests, contact us at: stephen@contextmemo.com
LAST UPDATED AUGUST 28, 2026