Privacy Policy
Effective June 21, 2026
AfterContext is an API-first CRM that gives AI agents a permanent memory. This policy explains what we collect, why, who we share it with, and the choices you have. We keep it short and concrete.
1. Who we are
AfterContext (“we”, “us”) provides the service at
aftercontext.com and its API. We are the data controller for the account
and usage data described below. For the customer records your agents write into the CRM,
you are the controller and we act as your processor.
2. Data we collect
Account data
- Your name and email address.
- A salted password hash (we never store your password in plain text), or, if you sign in with Google, your Google account email and identifier — we never receive your Google password.
- Plan, billing status, and credit balance.
CRM content (“customer data”)
The records your agents create through the API — companies, contacts, opportunities, tasks, activities, and notes — together with the API keys that wrote them. This content belongs to you. We process it only to run the service for you and never sell it or use it to train models.
Usage and technical data
- API request logs: the action called, timestamp, the key used, and whether it succeeded. We use these for billing allowances, rate limiting, and abuse prevention.
- Standard server logs, including IP address and user agent, retained for security and troubleshooting.
- A single session cookie when you use the web dashboard (see §6).
3. How we use your data
- To provide the CRM and API and to authenticate your requests.
- To meter usage against your plan and process payments.
- To secure the service — detect abuse, debug problems, and enforce limits.
- To send essential account email (verification, password resets, billing notices). We do not send marketing email without your consent.
We do not sell your personal data, and we do not use your CRM content or API traffic to train AI models.
4. Service providers we share with
We use a small set of subprocessors to operate the service. They receive only what they need for their function:
| Provider | Purpose | Data shared |
|---|---|---|
| Stripe | Payment processing & subscriptions | Billing details and payment metadata (card data goes directly to Stripe; we never see full card numbers). |
| Optional “Sign in with Google” | Your Google account email and identifier, only if you choose this login. | |
| Cloudflare | Bot protection (Turnstile) on sign-up and login | Request metadata needed to verify you are not a bot. |
| Our hosting provider | Servers, database, and email delivery | All data above, stored and transmitted to run the service. |
We may also disclose data if required by law or to protect the rights, safety, and security of AfterContext and its users.
5. Data retention
We keep account and CRM data for as long as your account is active. When you delete a record it is soft-deleted and removed in due course; when you close your account we delete or anonymize your data within a reasonable period, except where we must retain limited records (for example, billing history) to meet legal obligations. Usage and server logs are kept on a rolling short-term basis.
6. Cookies
The web dashboard sets one strictly necessary session cookie to keep you logged in. It is
HttpOnly, Secure, and SameSite-restricted. We do not
use advertising or third-party tracking cookies. The API itself is authenticated with a
Bearer key and uses no cookies.
7. Security
Connections are encrypted with TLS. Passwords are stored only as bcrypt hashes, API keys are stored hashed, and each account’s CRM data is isolated and scoped to that account on every query. No system is perfectly secure, but we apply the safeguards appropriate to the data we hold.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can edit account details and manage API keys from your dashboard, and you can export or request deletion of your data by emailing us. We will not discriminate against you for exercising these rights.
9. Children
AfterContext is a business tool not directed at children, and we do not knowingly collect data from anyone under 16.
10. International transfers
Your data may be processed in countries other than your own, including by the providers listed above. Where required, we rely on appropriate safeguards for those transfers.
11. Changes to this policy
We may update this policy as the service evolves. When we make material changes we will revise the effective date above and, where appropriate, notify you by email.
12. Contact
Questions about privacy, or a request about your data? Email privacy@aftercontext.com.