Contexter
Features Security Developers Help Sign in Get started

Contexter Privacy Policy

EN · RU — русская версия

Effective date: 31 July 2026
Last updated: 30 July 2026
Version: 0.9

Contexter is a workspace for keeping personal and shared project contexts available across Telegram, ChatGPT, Claude, the Contexter web workspace, and other compatible clients. This Privacy Policy explains what personal data Contexter processes, why it is processed, who can receive it, how long it is kept, and what choices you have.

This Policy applies to contexterai.com, the Contexter web workspace, the @ai_contexter_bot Telegram bot, the Contexter MCP server, and related integrations (together, the Service).

1. Who is responsible for your data

The data controller is:

Individual Entrepreneur Maksim Shirokov (Georgia), operating as Contexter
Address: 4a Tamarashvili Street, Tbilisi, Georgia
Privacy contact: privacy@contexterai.com

In this Policy, "Contexter", "we", "us", and "our" refer to this controller.

Third-party services you choose to connect—such as Telegram, ChatGPT/OpenAI, Claude/Anthropic, or another MCP-compatible client—process data under their own terms and privacy policies. Contexter does not control how those services handle data in your account with them.

2. Data we process

We process only the data needed to operate the features you use.

Account and connection data

  • your Telegram numeric user ID and, when Telegram provides them, your display name and username;
  • your internal Contexter user ID, selected language, access-approval status, onboarding state, and preferences;
  • information about connected clients, OAuth grants and scopes, access and refresh tokens, connection status, and revocation events;
  • shared-context membership, invitations, permissions, and confirmation records. In a shared context, other participants (and the AI surfaces they use) can see your display name, the surface a record came from, and your internal Contexter member identifier — a service ID used for access management; your Telegram ID is never exposed to them.

Telegram does not give the bot your phone number by default. Contexter never asks for the password to your Telegram, ChatGPT, Claude, or other third-party account.

Content you choose to provide

  • messages and files that you send to the Contexter bot after activation;
  • context names, descriptions, notes, source messages, attachments, and other records;
  • AI-generated results or files that you explicitly ask a connected client to save;
  • edits, deletion and restoration requests, sharing choices, and other actions;
  • authorship, source surface, timestamps, and audience information attached to records.

Content may include personal data about you or other people. Do not submit another person's data unless you have a lawful reason and the right to share it. The Service is not intended for passwords, authentication secrets, complete payment-card data, official medical records, biometric templates, or copies of government identity documents.

Telegram group data

When group functionality is available, Contexter is designed so that:

  • a participant must opt in before their contributions can be stored;
  • only eligible messages deliberately sent to or in reply to the bot are stored as context content;
  • ordinary group conversation is not stored as context content;
  • limited service events, commands, opt-in or opt-out events, and membership changes may be processed to operate consent and access controls.

Telegram may technically deliver additional group messages to a bot if the bot is made a group administrator or if Telegram Privacy Mode is disabled. Contexter's application layer is designed to reject non-eligible messages without storing their content or writing it to application logs. Group administrators should not disable Privacy Mode or grant unnecessary administrator rights.

Technical and support data

  • IP address, browser or client type, request time, session and authentication events, requested method or tool name, response status, and error information;
  • support requests and any information you include in them.

Application logs record operational events such as method and tool names but are designed not to contain the content of your records, messages, or files.

3. What Contexter does not collect automatically

Connecting an AI client does not import your AI chat history. Contexter receives a tool request only when you or your client invokes a Contexter action. We do not automatically copy entire ChatGPT, Claude, or Telegram conversations into Contexter.

In a private Telegram chat, messages you send to the activated bot are treated as content submitted to the Service. In a connected AI client, a new record, file, edit, deletion, or share is created only through an explicit tool action under the permissions you granted.

4. Why we process data and our legal bases

PurposeData usedLegal basis, where required
Create and maintain your account, connect clients, authenticate requests, and keep sessions active Account, connection, session, and technical data Performance of the Service you requested or steps taken at your request; legitimate interests in operating the Service
Store, retrieve, organize, edit, share, restore, export, and delete your contexts and records Content, provenance, permissions, and action history Performance of the Service you requested; your consent or explicit action where consent is required
Operate shared contexts and Telegram groups Membership, audience, consent events, eligible contributions, and service events Performance of the Service; consent for optional contribution and sharing features where required
Protect accounts, enforce permissions, prevent abuse, investigate errors, and maintain reliability Authentication, security, technical, and limited usage data Our legitimate interests in securing and operating the Service; compliance with legal obligations
Respond to support and privacy requests Contact information, request contents, and relevant account records Performance of the Service; compliance with legal obligations
Comply with law and defend legal claims Relevant account, content, and technical data Legal obligation and legitimate interests in establishing, exercising, or defending legal claims

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that was lawful before withdrawal. Some core processing is necessary to provide the Service; if you do not provide the necessary data, the relevant feature may not work.

This Privacy Policy is a notice, not a consent form. When the law requires consent, Contexter asks for it separately and in context.

5. AI clients and other third-party services

Connected AI clients

When you ask ChatGPT, Claude, or another connected client to read from Contexter, Contexter returns the requested content to that client. The AI provider may then process it under your account, plan, settings, and its own privacy policy. When you save from an AI client, Contexter receives only the tool payload submitted to the Service, not the whole surrounding chat unless the client explicitly includes it.

Review the policies of the services you connect:

  • Telegram Privacy Policy
  • OpenAI Privacy Policies
  • Anthropic Privacy Center

Telegram assistant

If you use an AI-powered assistant feature inside the Contexter Telegram bot, the prompt and the limited context needed to answer it may be sent to the AI model provider identified on our Subprocessors page. We do not send unrelated contexts to answer a request.

Contexter does not use your content to train a proprietary AI model. A third-party AI provider's own handling of data is governed by the applicable service agreement and privacy terms described on the Subprocessors page or in your own account with that provider.

6. When data is disclosed

We may disclose personal data only as needed:

  • to people you choose: members of a shared context can see the full contents of that context, its contributors, and its provenance information;
  • to connected services you choose: when you invoke a connector or authorize a client to act for you;
  • to service providers: hosting, storage, AI, security, and other infrastructure providers that process data to help us operate the Service;
  • for legal and safety reasons: where reasonably necessary to comply with law, a valid legal request, protect rights or safety, investigate abuse, or defend legal claims;
  • if the operator changes: as part of a merger, acquisition, financing, reorganization, or sale of the Service, subject to appropriate safeguards and notice where required.

The current service-provider list, processing purpose, and hosting region must be published at https://contexterai.com/subprocessors.

We do not sell personal data. We do not use your content for third-party advertising.

7. Shared contexts and audience controls

A shared context is not private to one person. Everyone shown in its audience can read all records placed in it, including records created before they joined. Record cards may show the contributor's display name, source surface, and time.

Before an action widens the audience for existing content or adds new content to a context that other people can see, Contexter is designed to show the intended audience and require an explicit confirmation. The owner can revoke a member's future access. Revocation does not erase:

  • records that the member authored and that remain lawfully stored;
  • copies the member already downloaded or exported;
  • information already sent, at a user's request, to an external AI client or other third-party service.

Removing a record from one context is not the same as deleting the underlying record. It may remain in its owner's personal record pool or in another context.

8. Retention and deletion

  • Active account and content: kept while your account is active and until you delete it or request account deletion, unless a longer period is required by law.
  • Deleted records: the "Delete record" action removes a record everywhere and places it in a recoverable state for 7 days. During this period the author can restore it. After the recovery window, the content and stored attachments are permanently removed from active storage, subject to legal retention requirements.
  • Removed records: "Remove from context" only removes the link from that context; it does not delete the underlying record.
  • Deleted contexts: deleting a context deletes the collection and its access list after the 7-day recovery window, but does not automatically delete the underlying records from their owners' pools.
  • Web sessions: the protected web session cookie lasts for up to 30 days and ends earlier if you sign out, the session expires, or the linked access is revoked.
  • OAuth connections: grants and tokens are retained until they expire, are revoked, or are no longer needed for the connection.
  • Operational and security logs: retained for 30 days and then deleted or aggregated.
  • Support and legal records: kept only as long as needed to resolve the request and meet legal or limitation-period requirements.
  • Backups and infrastructure snapshots: automatic server backups are taken by the hosting provider (DigitalOcean) in the same hosting region (Amsterdam, the Netherlands), encrypted at rest, and rotated on a rolling basis so that no backup is kept longer than about four weeks.

Deleting a Telegram message does not delete the corresponding Contexter record because Telegram deletion events are not a reliable deletion instruction for the Service. Use Contexter's "Delete record" action or send a privacy request.

Until self-service account deletion and export are available everywhere, you can request them at privacy@contexterai.com. Privacy and deletion requests are not conditional on a paid plan.

9. Cookies

The web workspace uses a strictly necessary cookie to keep you signed in for up to 30 days. It is used for authentication and security, not advertising.

As of the last-updated date, Contexter does not use non-essential advertising or cross-site tracking cookies. If analytics or other non-essential cookies are introduced, this Policy and the cookie interface will be updated, and consent will be requested where required.

10. Security

Contexter uses technical and organizational safeguards appropriate to an early-access service, including:

  • HTTPS in transit and OAuth 2.1 for connected clients;
  • server-side permission checks and scoped access;
  • explicit confirmation for actions that widen an audience;
  • protected web sessions with revocation checks;
  • short-lived, single-use file download links;
  • minimization of content in application logs.

No online service can guarantee absolute security. Keep your connected accounts secure, review audiences before sharing, and do not store secrets that the Service is not designed to protect. If we identify a personal-data incident that requires notice, we will notify affected users and the competent authority as required by applicable law.

11. Your rights

Depending on applicable law, you may have the right to:

  • know whether and how we process your personal data;
  • access it and receive a copy;
  • correct, update, or complete inaccurate data;
  • delete data or terminate processing;
  • restrict or block processing;
  • withdraw consent;
  • object to processing based on legitimate interests;
  • receive data you provided in a structured, commonly used, machine-readable format where applicable;
  • complain to a data-protection authority or court.

Contexter does not make solely automated decisions that produce legal or similarly significant effects about users.

To exercise a right, contact privacy@contexterai.com. We may verify the request through your linked Telegram account or another proportionate method. We respond within the period required by applicable law. Under Georgian law, many access, correction, and deletion requests must generally be handled within 10 working days, subject to lawful exceptions and permitted extensions.

If you are in Georgia, you may also contact the State Audit Office of Georgia—Personal Data Protection. If you are in the EEA or another jurisdiction, you may contact your local supervisory authority.

12. International data transfers

Contexter is operated from Georgia and hosts primary data in the Netherlands (Amsterdam, DigitalOcean). Connected clients and service providers may process data in other countries. Contexter does not actively direct or offer the Service to persons in the EEA, and an EU representative under GDPR Article 27 has not been appointed.

Where applicable law requires safeguards for an international transfer, we use an available lawful mechanism, such as an adequacy decision, contractual safeguards, or the data subject's informed instruction or consent where appropriate. Details of current providers and regions are available on the Subprocessors page.

13. Children

The Service is not directed to children under 16, and they must not use it or submit personal data. If you believe a child has provided data without valid authorization, contact privacy@contexterai.com so we can investigate and delete it where appropriate.

14. Changes to this Policy

We may update this Policy when the Service, providers, or legal requirements change. The page will show the new effective date. If a change materially affects how we process existing data, we will provide additional notice through the Service where required.

15. Contact

Questions, complaints, access, export, or deletion requests:

Individual Entrepreneur Maksim Shirokov / Contexter
Email: privacy@contexterai.com
Address: 4a Tamarashvili Street, Tbilisi, Georgia

Contexter Features Security Developers Help Privacy Terms Subprocessors Early access — open to everyone @ai_contexter_bot Open in the app