Privacy
Contexto is a second brain for a business. It reads the tools you connect, keeps the shape of your work, and fetches the words only at the moment you ask a question. This page says exactly what that means.
Last updated 19 September 2026. Contexto is operated by Superhyre (superhyre.com).
The one rule everything else follows
Contexto stores the shape of your work and not its words. Who wrote to whom, when, in which thread, which file, which spreadsheet column — that is kept. Subject lines, message bodies, filenames, document text and cell values are not. They stay in the tool they came from — Google, Microsoft, Slack, Notion, GitHub, your CRM, your own database — and Contexto fetches them per request, as you, holds them in memory for at most sixty seconds, and never writes them to disk or to a database.
What Contexto asks Google for
Permission to read, and permission to act: to send and draft mail, and to create and edit files, sheets, documents and calendar events. Contexto reads, and does one thing more: when you ask it for an email, it writes a draft and shows it to you, and it sends that email from your Gmail only when you press Send on it. It sends to the addresses you typed, or the ones you put on the draft yourself, and to nobody else.
It does one other thing, and only when you ask for it in a message you typed: when you tell it to fetch your invoices into Drive, it looks in your Gmail for PDFs attached to mail about an invoice, receipt or bill and saves a copy of each new one into a Drive folder. It uses the folder you name, or an existing folder called Invoices, and if there is no such folder it asks you what to call one. That request is the go-ahead, so it does not ask again before it saves. It only ever adds files: it does not change, move, share or delete anything that is already in your Drive, and it does not save the same invoice twice. It reads each attachment for as long as it takes to decide whether it is an invoice, and keeps nothing of it. It has no code path that edits, deletes or shares anything, and anything more it does for you later will be written here first. It never asks for the permission that deletes mail outright.
- Gmail — message and thread identifiers, participants, timestamps, labels, sizes and attachment counts are stored. Message bodies, subject lines and the text of attached PDFs are read only when you ask a question they answer, or ask Contexto to file your invoices.
- Drive — file identifiers, types, owners, folder structure and modification times are stored. File names and file contents — including the text inside PDFs, Word documents, presentations and every tab of a spreadsheet — are read only on demand, and kept for no longer than the answer takes.
- Sheets — tab names and header rows are stored. Cell values are read only as a bounded range, on demand.
- Docs and Calendar — asked for now so that you are not asked again later. Nothing from either is read or stored today.
- Your email address and Google account identifier — to know who you are and which company you belong to.
Contexto reads as you. It can never see anything in Google that you could not already open yourself, and a colleague who has not connected their own account contributes nothing to what Contexto knows.
The other tools you can connect
Everything above is true of each of these too: read-only unless its line says otherwise, connected by each person for themselves, and the shape kept while the words stay where they are. You connect the ones you use and none of the others, and a tool nobody has connected is a tool Contexto cannot see.
- Microsoft 365 (read-only) — Outlook, OneDrive, SharePoint and Teams. Participants, timestamps, file and channel structure are stored; message bodies, file names and workbook cells are read on demand. Contexto declines the tenant-wide credential Microsoft offers and uses your own permission.
- Slack (read-only) — channels, membership and message shape from the day you connect. Searching is done with your own Slack permission, and direct messages are left out of answers.
- Notion (read-only) — exactly the pages and databases you tick on Notion's own screen. Database structure and page identifiers are stored; page content is read on demand.
- GitHub (read-only) — repositories, pull requests, issues and reviews. Diffs and comment text are read on demand.
- HubSpot (read-only) — the structure of contacts, companies and deals. No name and no deal amount out of your CRM is stored; a question mentioning a customer resolves that name at HubSpot, as you, at the moment you ask.
- Zoho (read-only) — CRM, Mail and Books, each narrowed by Zoho to what your own login can see.
- Stripe (read-only) — invoices, charges, subscriptions and disputes. Amounts and dates are stored; customer names and email addresses are not. Contexto cannot move money and has no code path that could.
- Razorpay (read-only) — payments, orders, invoices, subscriptions, refunds, disputes and settlements. Amounts, methods and dates are stored; customer names are not, and neither are UPI handles, mobile numbers or card numbers. Razorpay itself grants Contexto read-only access, so it cannot issue a refund or move money, and Contexto has no code path that could.
- Your own database — connected with a read-only role you create yourself. Contexto stores the catalogue (tables, columns, types) and never the rows; a credential that can write is refused.
- Railway — deployments, their outcomes and what they cost. Log lines are read on demand and passwords, tokens and keys in them are masked before anybody sees them. Railway lets only a member read logs, so that is the access Contexto asks for; it also allows deploying, restarting and changing variables, which Contexto does not do today, has no code path that could, and never reads a variable.
- PostHog (read-only) — the events and properties your product sends, so a question can be turned into a query. The query runs against your PostHog, not against a copy here.
- Trello — the boards in the workspace you connect: their lists, their labels, who is on each card and every move a card makes between lists. Card titles, descriptions, comments and checklists are read only when a question needs them, as you, and are never stored. The permission you give on Trello's screen also allows commenting on and changing cards. Contexto does not use that today, and has no code path that could.
What is stored, in plain terms
| Stored | Never stored |
|---|---|
| Message, thread and file identifiers; participants as email addresses; timestamps; label names; MIME types; folder structure; spreadsheet tab names and column headers; sizes, counts and links back to the original. | Subject lines; message bodies; snippets; file names; attachment names; document text; cell values; display names. |
Contexto also stores what it works out for you — a commitment, a decision, a task — each pointing back at the record it came from. That is Contexto's own output about your work, not a copy of your work.
What Contexto remembers from what you tell it
When you type a question into Contexto's panel, the last few questions and answers of that conversation go with it, so that "and the second one?" can be answered. They are held for the length of that one request and are not stored. Starting a new thread starts the conversation over.
When you tell Contexto something to keep — "from now on, keep answers short", "when I say deploys I mean the API", "Priya is our CFO" — it keeps it, as one sentence, so that later conversations are answered with it in mind. What it keeps is only what you typed: never an answer, never anything read from your tools, never a word of a call. A note is yours: it shapes your answers and nobody else's. The answer that keeps or forgets a note shows you the sentence, and a note it keeps has a Forget button beside it; asking it to forget something works too. If that answer fails, the note is not kept. Contexto is told never to keep a password, a key or an account number, and it turns away the ones it recognises. A question asked out loud to Contexto on your computer never leaves a note. A linked Echo is the one exception, and the section on Alexa below says so and why.
Favourites are the same thing for the people you reach by name. Tell Contexto "Punith is punith@superhyre.com", or type them into Favourites on this site, and it keeps that name with that address and phone number, so that "mail Punith the numbers" goes where you meant and a question about what somebody said on WhatsApp knows whose number to look for. Only what you typed is kept: an address Contexto read in your mail or your CRM never becomes a favourite, and nor does one said out loud to an Echo, because an address misheard is mail to a stranger. Your favourites are yours — they address your drafts and nobody else's — and removing one on the Favourites page deletes it. Contexto never sends an email on its own: a draft is shown to you first, and you press Send, or say so.
Meetings
If you use Contexto's meeting transcription, audio from the call is streamed to Deepgram, a speech-to-text provider, to be turned into text. The audio goes straight from your machine to Deepgram on a credential that expires in a minute; it never passes through Contexto's servers and Contexto never stores it.
The transcript is written on your own device and stays there. It is not uploaded, not backed up, and not readable by anyone but you — with one exception, and it is worth reading twice.
When a call ends, the words of that call are sent to Contexto's service so that a model can write your card — what was decided, what was promised, by whom, by when, in English whatever language the call was in. They are held for the length of that one request, are never written to disk or to a database, and are gone when it answers. If you rejoin the same call within half an hour before answering its card, the card is written again from the whole call when it ends, which sends the words again. The transcript itself stays on your device throughout; what leaves is a copy that nothing keeps.
The card is yours until you answer it. Only once you approve it does it reach Contexto's servers — automatically after two hours if nobody answers sooner — and from then on it is what Contexto knows about that meeting: the decisions with their reasons, and the promises as tasks. The transcript is still not uploaded. Delete a meeting on your device and its card, its tasks and its decisions are deleted from Contexto's servers too.
Contexto never joins your meeting as a participant, and nothing is announced to the other people in the call.
Asking out loud
You can ask Contexto a question by saying "Contexto" and then asking it. There are two situations, and they are not the same, so they are written out separately.
In a call, nothing changes and nothing extra is captured. The call is already being transcribed, so Contexto simply reads its own name in the words your microphone has already produced. No additional audio is recorded and no additional audio is sent anywhere.
Outside a call, this is off until you turn it on, in Settings, on each computer. While it is on, your microphone is open and a small model on your computer listens for the single word "Contexto". That model recognises nothing else. It does not transcribe, it does not record, it does not reach the network, and nothing it hears is written to disk or sent to Contexto, to Deepgram, or to anyone else.
Audio leaves your computer only after you have said "Contexto", and only until your question ends — in practice a few seconds. To catch the start of a question you began before your laptop was ready for it, Contexto keeps the last two seconds of audio in memory; that buffer overwrites itself continuously, is never written to disk, and is discarded when listening stops. Once your question has been transcribed the microphone is closed again, before the question is even sent for an answer.
The question itself is then answered the way a typed one is, from what Contexto can already see, and the answer says what it was built from. In a call, the answer is also given the transcript of that call so far, so that a question asked in a meeting can be about the meeting. Neither the question nor the transcript is stored by Contexto's service; both are held for the length of one request, as the meeting card is.
Turning this off in Settings closes the microphone immediately. If we ever change what this section says, it switches itself off on every computer until the new wording has been accepted.
Alexa
If you link Contexto to Alexa, you can say "Alexa, open Contexto" and ask out loud. This is a different arrangement from the section above and the difference is worth being plain about.
The microphone is Amazon's, not Contexto's. Amazon's wake word, Amazon's microphone, Amazon's speech-to-text. Contexto receives the text of your question from Amazon and never receives audio at all. What Amazon itself keeps of what you said to Alexa is Amazon's, held under your Amazon account and managed in Amazon's own settings, not in Contexto's.
Your conversation with Alexa is stored, and this is the one place Contexto keeps what you said out loud. Each question and the answer Contexto gave are written down so that a follow-up — "and the second one?", "send that to her instead" — is understood as part of the same conversation rather than met as the first thing you have ever said. A question more than two hours after the last one starts a new conversation.
You end it by saying "close Contexto", which deletes that conversation rather than marking it finished. Anything you do not close is deleted after thirty days, and removing the Echo from your tools takes its conversations with it. The conversation you have with Contexto on your desktop is still stored nowhere.
Alexa can do everything the app can. Telling it to remember something keeps a note, exactly as typing it would, and it says back what it kept so a misheard sentence can be corrected on the spot — say "forget that" and it is gone. Asking it to file your invoices saves them into your Drive on the same terms as the app: it only ever adds files, it never changes, moves, shares or deletes anything already there, and the answer names each one it saved. One thing it does not do is add somebody to your favourites. It will mail a favourite you already keep — that is what makes "mail Punith the numbers" work out loud — but an address said to a microphone is one letter away from a stranger's, so favourites are written by typing and never by speaking.
Answers come from the tools connected by the person who linked the Echo, read with that person's own credentials, and from no one else's. Anyone who can speak to your Echo can ask Contexto, in the same way that anyone sitting at your unlocked laptop can open it.
Alexa can also write an email and send it. It reads the recipient and the subject back to you first, and sends nothing until you say so. You can take the link away at any time from your tools, where a linked Echo appears as a device called "Alexa"; removing it there stops Alexa reaching Contexto immediately.
Who else touches your data
- The tools you connect — Google, Microsoft, Slack, Notion, GitHub, HubSpot, Zoho, Stripe, Razorpay, Railway, PostHog, Trello and your own database are sources rather than recipients. Contexto reads from the ones you connect and writes nothing back to any of them.
- Supabase — the database holding the shape of your work, hosted in Mumbai (ap-south-1).
- Railway — hosting for Contexto's own service.
- Anthropic — the model that turns your question into an answer. What reaches it is the handful of records your question needed, the conversation you asked it in and the notes you asked Contexto to keep. The records and the conversation are not retained by Contexto afterwards.
- Deepgram — speech-to-text, and only if you use meeting transcription.
- Amazon — only if you link Alexa. Amazon hears the question and sends Contexto its text; Contexto sends Amazon back the answer to be spoken. Amazon never receives your connected tools or anything Contexto has stored.
Contexto does not sell your data, does not use it for advertising, and does not train any model on it.
Google API Services User Data Policy
Contexto's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular: data from Google APIs is used only to provide and improve the features you can see in Contexto; it is not transferred to anyone except as needed to provide those features, for security, or where the law requires it; it is not used for advertising; and no human reads it except with your explicit permission, for security purposes, or where the law requires it.
Keeping it
What Contexto stores lives for as long as your organisation uses Contexto, and is deleted 30 days after your subscription ends. When something is deleted in Google, Contexto removes its record within 24 hours of noticing. Nothing you wrote in Google is retained, because none of it is stored. Contexto keeps three bodies of text. One is the meeting cards you approved, which are its own words about your calls rather than a copy of them, and deleting the meeting on your device deletes them here. The second is the notes you asked it to keep, which are your own words to it, and Forget deletes them. The third is your favourites — the names, addresses and numbers of the people you reach by name — which you typed, and Remove on the Favourites page deletes them.
Stopping it
You can disconnect Google from Contexto's tools page at any time. Doing so hands Contexto's permissions back to Google immediately and stops all reading. You can also revoke Contexto yourself at myaccount.google.com/permissions. An administrator disconnecting the organisation removes everyone's access and schedules the deletion of everything stored.
Every record Contexto reads on your behalf is written to an audit trail your administrators can see: who read what, and when.
Asking us
For access, correction or deletion of your data, or any question about this policy, write to sudhanshu@superhyre.com.