Privacy notice

How FreshContext handles your information.

What we collect, why, where it is kept and when it is deleted. Written to match what our systems actually do.

Effective 28 September 2026.

Who is responsible

Immanuel Gabriel, trading as FreshContext, Erf 1447, Linekela Kalenga Street, Tsumeb, Namibia (postal: P.O. Box 938, Tsumeb 14002). Privacy contact: immanuel@freshcontext.dev.

For the records a customer sends us to audit, the customer decides how they are used, and we process them on the customer's instructions under the signed Order. For the contact, billing and delivery information described below, we decide.

What we collect, why, and for how long

InformationWhyHow long
Snapshot requests and enquiries: name, work email, company, role, the help-centre URL or description you typeTo assess and answer your requestDeleted automatically 90 days after receipt (a job runs every six hours). If it becomes an engagement, a copy is kept with the engagement record
Engagement records: approvals, dates, notes, invoices, deliveries, email logTo perform the contract, keep accounts, and show what was agreed and delivered5 years after the end of the tax year in which the engagement's last invoice was paid, then deleted
Files you upload (such as bot exports), with names, sizes and fingerprintsTo perform the auditFile contents and names are erased 30 days after the engagement closes, or sooner on request. A receipt (fingerprint, size, sender, dates) stays with the engagement record
Portal sign-in: your email address and sign-in timesSo only you see your requests, invoices and deliveriesSessions last 24 hours. Access is removed once nothing is open or owed
Encrypted backups of the aboveTo recover from lossDaily copies 35 days, monthly copies about 13 months. A backup copy of an erased file goes when the last backup holding it expires

We do not store your IP address, browser user agent or request headers with a request. The IP address is used for a moment to limit abusive submissions and then discarded. When a request arrives, we receive an email alert with only its reference, the kind of request, and the company name.

We do not sell personal data, use it for advertising, or train AI models on it.

AI tools

Audits use rule-based checks, and a person reviews every finding. An optional AI review step exists for answers the rules cannot settle. It is off by default and runs only for an engagement whose signed Order allows it.

When it is allowed, it uses Anthropic's Claude models only, through Anthropic's commercial API. For each answer the rules could not settle, we send: the question, the bot's answer and the value at issue, with email addresses and phone numbers masked; the source page's address; and up to three excerpts of that page, at most 600 characters each. Names written in free text are not removed automatically, so tell us if your answers contain personal data and we will prepare or leave out those items. Anthropic processes the data in the United States; under its commercial terms it does not train on it and deletes it within 30 days by default. We keep each call's result, not the text sent, with the engagement record.

The AI step can only mark an answer as changed, with a quote we check against the page; it can never mark one as fine. No other AI provider receives customer data, and we never paste customer records into consumer chat apps.

Who else processes it, and where

  • Cloudflare, Inc. hosts this website, the request service, the console, the customer portal and the databases. It runs portal sign-in (Cloudflare Access), sends our email, protects forms from abuse (Turnstile) and stores the encrypted backups. The request database and backups are in Cloudflare's eastern United States region. Engagement records are in a Cloudflare data centre outside Namibia (Cloudflare does not offer this storage in Africa). Requests pass through Cloudflare's global network.
  • Google provides the operators' sign-in to our internal console. Email you send us may be kept in the founder's Google mailbox.
  • GitHub stores our source code only, never customer data.

Backups are encrypted with a key held only by FreshContext, so Cloudflare cannot read them.

Cookies

This website sets no cookies of its own and runs no analytics. The Turnstile check on our forms is run by Cloudflare to keep automated submissions out, under Cloudflare's own privacy policy.

The customer portal uses only strictly necessary sign-in cookies set by Cloudflare Access: CF_Authorization (your session, 24 hours), CF_AppSession (protects sign-in against forged requests, 24 hours), CF_Session (the same on the sign-in page, 4 hours) and CF_Device (stops abuse of one-time codes, 30 days).

Security

The portal requires a one-time-code sign-in, and customers see only their own records. Files are checked by fingerprint on every download. Operators sign in through Cloudflare Access, and every change is logged with the person who made it. Only the owner can change payment details or backup keys, or erase files.

Your rights

You can ask to see, correct or delete your personal data, to object to or restrict our use of it, or for a copy to take elsewhere. Email immanuel@freshcontext.dev; a person answers within 30 days. We may keep what the law or an open contract requires, such as invoices.

If something goes wrong

If a security incident affects your personal data, we will tell you without undue delay, say what happened and what we are doing, and notify any regulator the law requires.

The legacy open-source service

The frozen open-source package and its hosted endpoint at api.freshcontext.dev run on Cloudflare. Its request logs may hold route, timing, status, network metadata and user agent. Its verdict records hold identifiers, the source URL, the decision, timestamps, a signature and a SHA-256 hash of the content, not the content itself. These records have no automatic deletion date; to ask for one to be removed, email us with its verdict identifier or source URL.

Changes

We post changes here with a new date, and tell active customers by email about significant ones.