Privacy Policy
Last updated: September 2026 · Compliant with GDPR, CCPA/CPRA, and SOC 2 Type II
ContextPulse never uses customer telemetry, tool parameters, schema metadata, prompt fragments, or session execution traces to train, fine-tune, or evaluate public or private AI models (neither our own nor third parties'). Your telemetry belongs solely to you and is strictly quarantined for your workspace analytics and observability.
1. Overview & Scope
ContextPulse Inc. (“ContextPulse”, “we”, “us”) provides real-time observability, tracing, and analytics for Model Context Protocol (MCP) servers. This Privacy Policy governs the collection, processing, storage, and rights associated with data collected via our website (contextpulse.online), developer portal, and telemetry ingestion APIs.
2. Data We Collect & Process
We practice strict data minimization. We only collect the minimal data necessary to fulfill observability services:
- Account & Billing Data: Name, work email address, company name, workspace configuration, and payment information processed securely via our PCI-DSS Level 1 compliant partner (Stripe). We do not store raw credit card numbers on our infrastructure.
- MCP Protocol Telemetry: Tool identifiers, tool execution durations, client type attribution (e.g. Claude Desktop, Cursor, Custom Agent), completion status, and structured error codes.
- In-Process Client Scrubbing: The ContextPulse SDK includes automated local scrubbing that sanitizes bearer tokens, API keys, basic credentials, and base64 strings before data leaves your process.
- Metadata-Only Mode: Customers can activate
metadataOnly: truein the SDK to discard arguments and return values entirely, transmitting only tool names, timing, and status codes.
3. Encryption Standards & Technical Safeguards
ContextPulse maintains enterprise-grade physical, technical, and administrative safeguards designed to protect telemetry against unauthorized access, loss, or alteration:
All telemetry transmissions require modern cipher suites with perfect forward secrecy.
All database volumes, time-series tables, and backups are encrypted with hardware-managed keys.
4. Data Retention & Automated Deletion
Telemetry records are strictly bounded by active tier retention limits and permanently purged via automated lifecycle policies:
- Starter Plan: 30 days rolling telemetry retention.
- Pro Plan: 90 days rolling telemetry retention.
- Enterprise Plan: Custom retention up to 36 months, with support for customer-owned AWS S3 / KMS export.
5. GDPR & CCPA/CPRA Privacy Rights
Regardless of your geographic location, ContextPulse affords comprehensive privacy rights to all account holders:
• Right to Access: You may request a complete export of personal and workspace data stored by ContextPulse.
• Right to Erasure (“Right to be Forgotten”): You may request permanent deletion of your account, workspace, and telemetry at any time.
• Right to Rectification: You may correct inaccurate profile or billing information directly via the dashboard.
• Right to Restrict or Object to Processing: You may limit how your data is processed or opt out of non-essential processing.
• No Sale of Data: We do not sell, rent, or trade personal data or telemetry to data brokers or advertising networks.
6. Cloud Sub-Processors
ContextPulse partners with tier-1 enterprise cloud providers under signed Data Protection Agreements (DPAs):
| Sub-processor | Purpose | Data Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud compute, VPC isolation, Aurora & S3 storage | USA (East / West) |
| Cloudflare | DDoS mitigation, edge routing & WAF security | Global Edge |
| Stripe Inc. | PCI-DSS Level 1 payment processing and subscription billing | USA |
7. Official Privacy & Support Contact
If you have any questions regarding this policy, wish to execute a Data Protection Addendum (DPA), or wish to submit a data erasure request, please contact our team: