AfterContext CRM
Home API Sign in Get an API key

Privacy Policy

Effective June 21, 2026

AfterContext is an API-first CRM that gives AI agents a permanent memory. This policy explains what we collect, why, who we share it with, and the choices you have. We keep it short and concrete.

1. Who we are

AfterContext (“we”, “us”) provides the service at aftercontext.com and its API. We are the data controller for the account and usage data described below. For the customer records your agents write into the CRM, you are the controller and we act as your processor.

2. Data we collect

Account data

  • Your name and email address.
  • A salted password hash (we never store your password in plain text), or, if you sign in with Google, your Google account email and identifier — we never receive your Google password.
  • Plan, billing status, and credit balance.

CRM content (“customer data”)

The records your agents create through the API — companies, contacts, opportunities, tasks, activities, and notes — together with the API keys that wrote them. This content belongs to you. We process it only to run the service for you and never sell it or use it to train models.

Usage and technical data

  • API request logs: the action called, timestamp, the key used, and whether it succeeded. We use these for billing allowances, rate limiting, and abuse prevention.
  • Standard server logs, including IP address and user agent, retained for security and troubleshooting.
  • A single session cookie when you use the web dashboard (see §6).

3. How we use your data

  • To provide the CRM and API and to authenticate your requests.
  • To meter usage against your plan and process payments.
  • To secure the service — detect abuse, debug problems, and enforce limits.
  • To send essential account email (verification, password resets, billing notices). We do not send marketing email without your consent.

We do not sell your personal data, and we do not use your CRM content or API traffic to train AI models.

4. Service providers we share with

We use a small set of subprocessors to operate the service. They receive only what they need for their function:

ProviderPurposeData shared
StripePayment processing & subscriptionsBilling details and payment metadata (card data goes directly to Stripe; we never see full card numbers).
GoogleOptional “Sign in with Google”Your Google account email and identifier, only if you choose this login.
CloudflareBot protection (Turnstile) on sign-up and loginRequest metadata needed to verify you are not a bot.
Our hosting providerServers, database, and email deliveryAll data above, stored and transmitted to run the service.

We may also disclose data if required by law or to protect the rights, safety, and security of AfterContext and its users.

5. Data retention

We keep account and CRM data for as long as your account is active. When you delete a record it is soft-deleted and removed in due course; when you close your account we delete or anonymize your data within a reasonable period, except where we must retain limited records (for example, billing history) to meet legal obligations. Usage and server logs are kept on a rolling short-term basis.

6. Cookies

The web dashboard sets one strictly necessary session cookie to keep you logged in. It is HttpOnly, Secure, and SameSite-restricted. We do not use advertising or third-party tracking cookies. The API itself is authenticated with a Bearer key and uses no cookies.

7. Security

Connections are encrypted with TLS. Passwords are stored only as bcrypt hashes, API keys are stored hashed, and each account’s CRM data is isolated and scoped to that account on every query. No system is perfectly secure, but we apply the safeguards appropriate to the data we hold.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can edit account details and manage API keys from your dashboard, and you can export or request deletion of your data by emailing us. We will not discriminate against you for exercising these rights.

9. Children

AfterContext is a business tool not directed at children, and we do not knowingly collect data from anyone under 16.

10. International transfers

Your data may be processed in countries other than your own, including by the providers listed above. Where required, we rely on appropriate safeguards for those transfers.

11. Changes to this policy

We may update this policy as the service evolves. When we make material changes we will revise the effective date above and, where appropriate, notify you by email.

12. Contact

Questions about privacy, or a request about your data? Email privacy@aftercontext.com.

AfterContext CRM
docstermsprivacy© 2026 AfterContext