ContextFlow Privacy Policy

Effective 30 September 2026 · ContextFlow is made by Finaimo (“we”, “us”) · Contact: team@finaimo.com

The short version. ContextFlow reads only the sources you connect, to build your own relationship rings and a shopping assistant that knows you. Your data is encrypted in transit and your message content is encrypted at rest with a key specific to you. We don’t sell your data, use it for advertising, or use it to train AI models. Payment cards never reach our servers. You can delete your account and everything in it at any time.

1. What ContextFlow is

ContextFlow is a Mac app, with a companion Chrome extension, that builds a private picture of your world from your own data: the people you are close to, arranged in relationship rings with short summaries, and a shopping assistant that knows your preferences, what you have bought, and what you are running low on. When you approve a purchase, it can prepare the checkout for you, and you place the order yourself.

2. What we collect

We collect data only from sources you choose to connect. Once a source is connected, every conversation in it is included.

CategorySourceWhat
AccountSign-upYour email address and sign-in records
MessagesiMessage, WhatsApp, GmailMessage and email bodies, senders and recipients, timestamps, conversation structure
CallsiPhone calls and FaceTime, WhatsApp callsWho, when, how long, direction. Never audio.
ContactsmacOS ContactsNames, phone numbers, email addresses
BrowsingBrowser history and open tabs on your Mac; the Chrome extensionPage titles, URLs with credentials removed, time on page; product details on product pages; during a purchase or seller contact you approve, an outline of the store or seller page, which for a seller can include your existing conversation with them (see §3)
PurchasesOrder receipts in Gmail; purchases made through ContextFlowMerchant, items, price, order date and status
Your profileYour own profile card in SettingsYour company, role, location and school, filled in automatically from your email address the first time you open it, or from your LinkedIn profile if you import it. You can edit or clear it.

Derived data. From the above we compute classifications, relationship summaries and ring positions, facts about your preferences and needs as a buyer (for example sizes, brands, dietary constraints and devices you own), purchase history, and restock suggestions. Derived data is stored with your account and is covered by the same deletion rights.

Controls. Disconnecting a source stops future collection and removes its credentials. It does not erase data already collected; deleting your account does. Muting a person or hiding them from the graph changes what you see, not what is stored.

3. The Chrome extension

The extension records no browsing until you sign in, read its disclosure, press Start capturing, and grant Chrome website access. The shopping agent (below) is separate: it works only on a purchase you approve in the ContextFlow app on your Mac, whether or not capture is on.

What it records

For each page you visit: the site, the page title, a sanitized URL (sign-in tokens, codes and other credentials removed), time actively spent on the page, the linking site and the navigation type. On a product page it also records the product’s name, brand, price, currency, availability, SKU and GTIN, read from the page’s structured data (schema.org and OpenGraph). While you browse it does not record page text, form entries, text selections or incognito browsing.

Major banks and brokerages, some patient portals, password managers, identity providers and sign-in pages are blocked by default, and you can block more sites in the extension’s Settings. You can pause capture from the toolbar.

The shopping agent

When you approve a purchase in the ContextFlow app, the extension opens the store in a new tab and moves through the product, cart and checkout pages using Chrome’s debugger. Chrome shows a “debugging this browser” bar the whole time, and cancelling it, pausing the extension or signing out stops it. While it works it sends us an outline of the store page it is on: before the cart, the page’s headings, text, buttons and field names; from the cart on, only the buttons and field names, plus the page type, the order’s subtotal, total and currency, whether it has a recurring charge and, on an order confirmation, the order number. It never sends what is typed into a field. Our server passes that outline to our AI provider (OpenAI) to choose the next step from a fixed list, and does not store it. The extension can fill your saved shipping address and the purchase’s one-time card from the ContextFlow app on your Mac. The card is never sent to our servers. It stops before placing the order: you press the final button yourself. When you ask ContextFlow to contact a seller, the extension types a draft message, and you press Send yourself; the outline of that page can include your existing conversation with that seller.

Deleting extension data

Delete any recent visit from the extension’s toolbar popup, and it is deleted on our servers too. Signing out clears your sign-in, recorded visits and upload queue on this device. Excluded sites and your account identifier remain; pending deletion requests keep account and visit IDs until our server confirms them. Deleting your account erases everything.

4. Purchases and payments

Purchases require your approval each time. Payment uses your own Link account (by Stripe), connected from the ContextFlow app on your Mac. For each purchase you approve, Link issues a one-time card for the approved amount, and it is used only on your Mac and in your browser. We store the purchase record (merchant, item, amount, status and order number), never your card number.

5. How we use data

We do not sell your data, use it for advertising or share it with data brokers, use it to decide creditworthiness or for lending, or use it to train our own or anyone else’s general-purpose AI models.

6. Information about people you communicate with

Your messages, calls and contacts include information about other people. We process it only to provide ContextFlow to you. We never contact those people, never build profiles of them for anyone else, and never sell or advertise with their information.

7. Security

Report a security issue to team@finaimo.com.

8. Who at Finaimo can see your data

No person at Finaimo reads your data except: with your explicit permission (for example, when you ask us to fix a problem you are seeing), when needed to investigate a security incident or abuse, or when required by law.

9. Service providers

We share the minimum each provider needs to run ContextFlow for you. None may use your data for its own purposes.

ProviderPurposeData
OpenAIAI processing: classification, extraction, summaries, shopping-agent stepsMessage content and context needed for each request; the store-page outline during a checkout you approved. Governed by our API data controls; not used to train OpenAI’s models.
Amazon Web Services (US)Servers, database, encryption keysAll stored app data (our database has run on AWS since 29 September 2026)
Supabase (US)Sign-in; our previous databaseEmail address and sign-in records. Supabase also holds a read-only copy of app data as it stood when we moved our database to AWS on 29 September 2026, kept until we delete it after the move.
CloudflareNetwork security and deliveryTraffic in transit
PostHog (US)Product analytics and AI cost monitoringUsage events keyed to your account ID. No message content.
GoogleGmail access, if you connect GmailRead access to your mailbox under your authorization
Link (Stripe)Payment, only for purchases you approveHandled between your Mac and your Link account
People Data LabsFilling in your own profile cardYour email address, and your LinkedIn URL if you import it
MerchantsOrders you placeOrder, shipping and payment details, entered in the merchant’s own checkout

We may disclose data if required by law, or as part of a merger or acquisition, in which case this policy continues to apply to it.

10. Retention and deletion

We keep your data while your account is active, so ContextFlow can remember long-term context. There is no automatic expiry. You control deletion:

Operational logs. To run and secure the service we keep technical logs: request IDs, your account ID, the API route called, status codes, timings, error types, and security events such as sign-ins (with IP address). From late September 2026 these logs are designed not to contain message content or the names, email addresses or phone numbers of the people you talk to. Log lines written before then can contain contact names and short summary previews, and they are deleted when their retention window below ends. The system journal on our server is kept for up to 30 days, and a tamper-resistant copy is kept in AWS for up to 400 days for security and audit purposes. The Mac app keeps diagnostic logs on your own computer, and we see them only if you send them to us.

11. Google user data

ContextFlow’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

12. Your rights

You can ask to access, correct or delete your data, or ask a question about it, by emailing team@finaimo.com. We answer within 30 days. Account deletion is self-serve in the app. Depending on where you live, you may have further rights under local law, and you can complain to your data protection authority.

Your data is processed and stored in the United States.

13. Children

ContextFlow is not directed to children under 16, and we do not knowingly create accounts for them.

14. Changes

If we make a material change to this policy, we will email account holders before it takes effect and update the date at the top.