ContextFlow Privacy Policy
1. What ContextFlow is
ContextFlow is a Mac app, with a companion Chrome extension, that builds a private picture of your world from your own data: the people you are close to, arranged in relationship rings with short summaries, and a shopping assistant that knows your preferences, what you have bought, and what you are running low on. When you approve a purchase, it can prepare the checkout for you, and you place the order yourself.
2. What we collect
We collect data only from sources you choose to connect. Once a source is connected, every conversation in it is included.
| Category | Source | What |
|---|---|---|
| Account | Sign-up | Your email address and sign-in records |
| Messages | iMessage, WhatsApp, Gmail | Message and email bodies, senders and recipients, timestamps, conversation structure |
| Calls | iPhone calls and FaceTime, WhatsApp calls | Who, when, how long, direction. Never audio. |
| Contacts | macOS Contacts | Names, phone numbers, email addresses |
| Browsing | Browser history and open tabs on your Mac; the Chrome extension | Page titles, URLs with credentials removed, time on page; product details on product pages; during a purchase or seller contact you approve, an outline of the store or seller page, which for a seller can include your existing conversation with them (see §3) |
| Purchases | Order receipts in Gmail; purchases made through ContextFlow | Merchant, items, price, order date and status |
| Your profile | Your own profile card in Settings | Your company, role, location and school, filled in automatically from your email address the first time you open it, or from your LinkedIn profile if you import it. You can edit or clear it. |
Derived data. From the above we compute classifications, relationship summaries and ring positions, facts about your preferences and needs as a buyer (for example sizes, brands, dietary constraints and devices you own), purchase history, and restock suggestions. Derived data is stored with your account and is covered by the same deletion rights.
Controls. Disconnecting a source stops future collection and removes its credentials. It does not erase data already collected; deleting your account does. Muting a person or hiding them from the graph changes what you see, not what is stored.
3. The Chrome extension
The extension records no browsing until you sign in, read its disclosure, press Start capturing, and grant Chrome website access. The shopping agent (below) is separate: it works only on a purchase you approve in the ContextFlow app on your Mac, whether or not capture is on.
What it records
For each page you visit: the site, the page title, a sanitized URL (sign-in tokens, codes and other credentials removed), time actively spent on the page, the linking site and the navigation type. On a product page it also records the product’s name, brand, price, currency, availability, SKU and GTIN, read from the page’s structured data (schema.org and OpenGraph). While you browse it does not record page text, form entries, text selections or incognito browsing.
Major banks and brokerages, some patient portals, password managers, identity providers and sign-in pages are blocked by default, and you can block more sites in the extension’s Settings. You can pause capture from the toolbar.
The shopping agent
When you approve a purchase in the ContextFlow app, the extension opens the store in a new tab and moves through the product, cart and checkout pages using Chrome’s debugger. Chrome shows a “debugging this browser” bar the whole time, and cancelling it, pausing the extension or signing out stops it. While it works it sends us an outline of the store page it is on: before the cart, the page’s headings, text, buttons and field names; from the cart on, only the buttons and field names, plus the page type, the order’s subtotal, total and currency, whether it has a recurring charge and, on an order confirmation, the order number. It never sends what is typed into a field. Our server passes that outline to our AI provider (OpenAI) to choose the next step from a fixed list, and does not store it. The extension can fill your saved shipping address and the purchase’s one-time card from the ContextFlow app on your Mac. The card is never sent to our servers. It stops before placing the order: you press the final button yourself. When you ask ContextFlow to contact a seller, the extension types a draft message, and you press Send yourself; the outline of that page can include your existing conversation with that seller.
Deleting extension data
Delete any recent visit from the extension’s toolbar popup, and it is deleted on our servers too. Signing out clears your sign-in, recorded visits and upload queue on this device. Excluded sites and your account identifier remain; pending deletion requests keep account and visit IDs until our server confirms them. Deleting your account erases everything.
4. Purchases and payments
Purchases require your approval each time. Payment uses your own Link account (by Stripe), connected from the ContextFlow app on your Mac. For each purchase you approve, Link issues a one-time card for the approved amount, and it is used only on your Mac and in your browser. We store the purchase record (merchant, item, amount, status and order number), never your card number.
5. How we use data
- To build your relationship rings and summaries.
- To power your shopping assistant: your buyer facts, purchase history, restock and product suggestions, and preparing checkouts for purchases you approve.
- To operate, secure and debug the service, and to prevent abuse.
We do not sell your data, use it for advertising or share it with data brokers, use it to decide creditworthiness or for lending, or use it to train our own or anyone else’s general-purpose AI models.
6. Information about people you communicate with
Your messages, calls and contacts include information about other people. We process it only to provide ContextFlow to you. We never contact those people, never build profiles of them for anyone else, and never sell or advertise with their information.
7. Security
- All data travels over encrypted (TLS) connections.
- Message content is encrypted at rest with a per-user key managed by AWS Key Management Service. Some fields derived from content are not yet encrypted at rest, and closing that gap is ongoing work.
- Every request is scoped to your account by our application code. Connected-account tokens are stored encrypted, and our secrets are held in AWS Secrets Manager.
- Our servers must read your content in order to process it, for example to classify a message or summarize a relationship. That processing is automated.
Report a security issue to team@finaimo.com.
8. Who at Finaimo can see your data
No person at Finaimo reads your data except: with your explicit permission (for example, when you ask us to fix a problem you are seeing), when needed to investigate a security incident or abuse, or when required by law.
9. Service providers
We share the minimum each provider needs to run ContextFlow for you. None may use your data for its own purposes.
| Provider | Purpose | Data |
|---|---|---|
| OpenAI | AI processing: classification, extraction, summaries, shopping-agent steps | Message content and context needed for each request; the store-page outline during a checkout you approved. Governed by our API data controls; not used to train OpenAI’s models. |
| Amazon Web Services (US) | Servers, database, encryption keys | All stored app data (our database has run on AWS since 29 September 2026) |
| Supabase (US) | Sign-in; our previous database | Email address and sign-in records. Supabase also holds a read-only copy of app data as it stood when we moved our database to AWS on 29 September 2026, kept until we delete it after the move. |
| Cloudflare | Network security and delivery | Traffic in transit |
| PostHog (US) | Product analytics and AI cost monitoring | Usage events keyed to your account ID. No message content. |
| Gmail access, if you connect Gmail | Read access to your mailbox under your authorization | |
| Link (Stripe) | Payment, only for purchases you approve | Handled between your Mac and your Link account |
| People Data Labs | Filling in your own profile card | Your email address, and your LinkedIn URL if you import it |
| Merchants | Orders you place | Order, shipping and payment details, entered in the merchant’s own checkout |
We may disclose data if required by law, or as part of a merger or acquisition, in which case this policy continues to apply to it.
10. Retention and deletion
We keep your data while your account is active, so ContextFlow can remember long-term context. There is no automatic expiry. You control deletion:
- Delete your account in the ContextFlow app’s Settings. This permanently erases your messages, derived data, relationship graph, shopping data and credentials. We keep a minimal record that the deletion happened, for security audit.
- Delete a visit from the Chrome extension’s popup.
- Disconnect a source to stop collection and remove its credentials.
Operational logs. To run and secure the service we keep technical logs: request IDs, your account ID, the API route called, status codes, timings, error types, and security events such as sign-ins (with IP address). From late September 2026 these logs are designed not to contain message content or the names, email addresses or phone numbers of the people you talk to. Log lines written before then can contain contact names and short summary previews, and they are deleted when their retention window below ends. The system journal on our server is kept for up to 30 days, and a tamper-resistant copy is kept in AWS for up to 400 days for security and audit purposes. The Mac app keeps diagnostic logs on your own computer, and we see them only if you send them to us.
11. Google user data
ContextFlow’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
12. Your rights
You can ask to access, correct or delete your data, or ask a question about it, by emailing team@finaimo.com. We answer within 30 days. Account deletion is self-serve in the app. Depending on where you live, you may have further rights under local law, and you can complain to your data protection authority.
Your data is processed and stored in the United States.
13. Children
ContextFlow is not directed to children under 16, and we do not knowingly create accounts for them.
14. Changes
If we make a material change to this policy, we will email account holders before it takes effect and update the date at the top.