1. Scope
This Privacy Notice explains how Konteks handles information when you visit konteks.io, use Zero, connect through Core MCP, or use related Konteks APIs and services. Customer agreements and data-processing addenda may provide additional terms.
2. Information we process
We process account and workspace identity, contact details, authentication records, organization membership, billing and transaction records, support communications, service configuration, audit events, and technical telemetry. When you connect repositories, catalogs, VCS providers, MCP servers, or model providers, Konteks processes the content and metadata needed to provide the requested capability.
3. Software and agent data
Depending on your configuration, Konteks may process repository URLs and content, branches, commits, pull requests, catalog entities, Software Systems, Components, session messages, prompts, tool calls, plans, validation evidence, logs, model telemetry, and usage records. Customer code and private organizational context remain customer data.
4. Model providers and BYOK
Every published Konteks plan is bring-your-own-key. When you select an external model provider, relevant prompts and context are sent to that provider under your provider account and its terms. Konteks does not treat model-provider charges as Konteks Story Points. You are responsible for choosing providers and configuring their retention or privacy controls.
5. How we use information
We use information to authenticate users, enforce tenant isolation and permissions, preserve System and Component context, orchestrate and validate agent work, operate billing and approvals, provide evidence and support, protect the service, prevent abuse, improve reliability, and comply with law. We do not train general-purpose models on private customer code or commercial history without explicit agreement.
6. Service providers and transfers
Konteks may rely on hosting, storage, observability, authentication, payment, email, version-control, and model-provider services. Data may be processed in countries where those providers operate. We limit access by purpose and use contractual, technical, and organizational safeguards appropriate to the service.
7. Security
We use tenant-scoped authorization, encryption in transit, protected secret storage, audit logging, credential rotation and revocation, and scoped execution environments. No service can guarantee absolute security. Please report suspected vulnerabilities to hello@konteks.io.
8. Retention and deletion
We retain information for as long as needed to provide the service, maintain security and audit integrity, settle billing, satisfy legal obligations, and resolve disputes. Workspace deletion and cleanup are designed to remove tenant-owned sessions, plans, runs, catalog state, credentials, and related resources while preserving records we must legally or contractually retain.
9. Your choices and rights
Subject to applicable law and your organization’s administration, you may request access, correction, export, restriction, or deletion of personal information. Workspace owners control most product data and connected systems. Contact hello@konteks.io for privacy requests.
10. Updates
We may update this notice as Konteks reaches general availability, adds providers, or changes legal requirements. Material changes will be posted on konteks.io with an updated effective date.