# Privacy policy

Last changed 2026-09-05.

This policy explains what Relote collects when you use Context Engine, what we do with it, which other companies handle it, and how long we keep it. It is written to match what the service actually does; where the code changes, this page is updated with it.

The short version: **your engine's content is yours, it is stored on Cloudflare, it is sent to models only to answer you, it is not used to train anything, and you can export or delete all of it yourself.**

## What we collect

**Your account.** Your email address, which is how you sign in. A display name if you set one. If you sign in with Google or GitHub, the name and avatar from that profile, copied once when you first arrive.

**Sign-in records.** When you sign in, the IP address and browser of the session, kept with the session so you can see and end it. Recent sign-in attempts and email sends are counted by address and IP address to stop abuse. If you turn on two-step sign-in, the secret for it and your recovery codes are stored hashed.

**Your engine's content.** Everything you and your members put into an engine, and everything the engine captures on your instruction: notes, records, files and their extracted text, journal entries, tasks, conversations with the assistant, and audio you dictate, which is transcribed and then treated as text. Content that arrives through a service you connect is the same.

**Usage.** For each engine, how many messages were asked, how many model tokens were used and what they cost, how many web searches and page reads were made, and how much voice was used. This is what a plan's ceilings are measured against and what your bill is based on.

**Support.** What you write to us from the console, and a copy of a conversation if you choose to attach one.

**Connections.** When you connect another service, the authorisation for it is held by Composio, the broker we use, in an account that belongs to your engine. We store which services are connected and which tools they offer, not the credentials.

We do not collect payment card numbers in the product.

## What we use it for

- To run the service: storing your content, indexing it for search, and sending the relevant parts of it to a model when you ask a question or an agent acts for you.
- To sign you in, keep your session, and stop somebody else from signing in as you.
- To enforce plan limits, and to bill paid plans.
- To answer support requests.
- To find and fix faults. Our logs record what happened, which engine it happened to, and an error id; they never contain the content of a note, a message, a search or a model answer.

We do not use your content to train models. We do not sell it, and we do not use it for advertising.

## Who else handles it

Everything below is a company we have chosen to run part of the service on. Each receives only what its part needs.

| Who | What they do | What reaches them |
| --- | --- | --- |
| **Cloudflare** | Hosts the whole service: the database, the file store, the search index, the models that answer questions, the mail that sends sign-in codes, and the check that stops bots signing up. | Everything, because the service runs there. Model calls pass through Cloudflare's AI Gateway, which records the model, token counts and cost of each call and **not** the prompt or the answer. |
| **A web search provider** | Answers when the assistant searches the web. Serper by default, which resells Google's results, so a query reaches Serper and Google; or Brave where a deployment is configured for it. | The search query only. No engine name, no account, no conversation. |
| **Composio** | Brokers connections to other services such as Gmail or Drive, and holds the authorisations for them. | The authorisation, and a file when you ask the assistant to send one to a connected service, which is then a copy in Composio's storage on their retention. |
| **Google, GitHub** | Sign-in, if you choose it. | That you signed in, and to us your name, email and avatar. |
| **ElevenLabs** | Speech, only if an owner has put their own ElevenLabs key into an engine. | The text being spoken, under that owner's own account with them. |
| **The service you connect** | Whatever you connect, acting on your instruction. | What the assistant sends it when you ask, and what you tell it to fetch. |

Reading a web page sends nothing of yours anywhere: the page is fetched from its own site, which learns only that it was fetched.

## Where it is stored

Every engine's content and its record of changes are stored in Cloudflare's network. An owner who chooses **European Union** when creating an engine has that engine's database and stored files placed in the EU, and this cannot be changed afterwards.

That choice covers storage. It does not cover the search index built from the content, or the model that answers questions, because no region control is published for either. We say "database and stored files" rather than "residency" for exactly this reason, and we will not claim more than that until we can keep it.

Sending a file to a connected service copies it outside that boundary, whatever the engine's placement. The manual says so on the connections and files topics.

## How long we keep it

**Your engine's content** is kept until you delete it. Deleting a record or a file removes it from the engine; deleting the engine removes everything.

**Deleting an engine** is something an owner does in the console. It takes effect after a day, during which the engine stays open so you can change your mind or take an export. When it runs, it removes the engine's database, search index, stored files, its rows in every nightly backup, its account records, and any authorisations naming it. Nothing of the engine is kept afterwards except a log line saying that it was deleted.

**An engine that a subscription has lapsed on** is not deleted. It is frozen read-only, as the [terms](/terms) say, until its owner deletes it.

**Nightly backups** of the account database are kept for 30 days.

**Per-call usage events** are kept for 45 days. Monthly totals per engine are kept for as long as the engine exists, because they are what your bills are based on.

**Sign-in sessions** last 30 days unless you end them sooner. Sign-in codes and links expire in minutes.

**Support requests** are kept so we can answer them and so you can read the thread back.

**Your account** is kept until you ask us to close it. Closing it removes your email address, name and sign-in records; the content of engines you were a member of belongs to those engines and stays with them.

## Your rights

You can see and change your name on the Account page, and see which engines you belong to. An owner can **export a whole engine** at any time as a ZIP of Markdown and JSON, and can **delete it** as described above. For anything else, including a copy of the personal data we hold about you, correcting it, or closing your account, write to us from the console at [/help/write](/help/write) and we will do it.

If you are in the EU or the UK, you also have the right to complain to your data protection authority.

## Changes to this policy

When the service changes in a way that changes what this page says, this page changes with it. The date at the top is when it was last changed. For a change that reduces what we promise here, we email every owner before it takes effect.

## Contact

Relote operates Context Engine. Write to us from the console, or at [/help/write](/help/write).
