PRIVACY
Privacy Policy
Effective date: July 21, 2026
This Privacy Policy explains how NeatContext handles information when you use the NeatContext website, desktop application, downloads, updates, support channels, checkout flows, and related services.
1. Local-First Commitment
NeatContext is a local-first desktop application that organizes user-selected domain profiles, local knowledge folders, and read-only extensions into Contexts for a connected AI client. NeatContext does not run an AI model, store model credentials, host conversations, or write the connected client's answers.
Your local files, profiles, Context definitions, runtime configuration, and Context Activity logs stay on your device by default. NeatContext-hosted services do not receive incident requests, profiles, local paths, source queries, evidence, or tool logs through the ordinary Context handoff. We receive local content only when you deliberately send it to us, such as in a support request.
When you connect a supported AI client, the local NeatContext MCP service supplies analysis instructions and the selected Context's absolute profile paths, knowledge folder paths, and available extension tools. The client may then read and process those files under its own permissions, settings, terms, and privacy policy.
2. Scope of This Policy
NeatContext is operated by XT SOFTWARE LABS LLC, a Washington limited liability company, which is the controller responsible for the information described in this Policy. This Policy applies to the NeatContext public website, desktop application, downloads, update flows, account or checkout experiences, support communications, and other online services that link to this Policy.
We generally act as controller for account, website, billing-support, and direct support information that we receive. The local Context handoff does not by itself send your organization's incident content to us. If we later offer a separate hosted feature that processes customer content on an organization's behalf, the parties' roles and any data processing addendum will be addressed for that feature.
Connected AI clients and their model providers, Paddle, hosting and email providers, extensions, MCP servers, operational systems, operating systems, browsers, and other services you use with NeatContext have their own privacy practices. Their handling of information is governed by their own terms and privacy policies.
3. Information Processed Locally
The desktop application may process information on your device, including user-selected local files and folders, Markdown domain profiles, Context definitions, linked resource paths, Team Library settings, managed extension snapshots and tool catalogs, nonsecret runtime configuration, app and client-connection settings, Context Activity logs, extension diagnostic logs, and retained historical audit artifacts.
NeatContext does not store conversation history, model configuration, or model credentials. Account session tokens, extension API keys, extension bearer tokens, and extension OAuth tokens saved by the desktop app are encrypted using operating-system-provided protection before ciphertext is written to local application data. On Windows, the ciphertext protection uses the Data Protection API (DPAPI); on macOS, it uses Keychain. For use by the connected local runtime, NeatContext also places the configured extension connection in the operating system's credential store. Connection fields that an extension identifies as nonsecret, such as a service site or base URL, are stored as local configuration rather than encrypted secret values.
The desktop and native runtime handle the decrypted connection locally so that, when an enabled extension runs, the native runtime can retrieve and supply its credentials to that extension process. NeatContext does not intentionally write plaintext credentials to the host-visible runtime file or add them to the tool result returned to the connected AI client. The extension necessarily receives its credentials and can use or transmit them according to its code and the service connection you configure, so you should install extensions only from sources you trust.
Personal profiles and knowledge folders are linked at their existing locations rather than uploaded or copied into a hosted service. NeatContext edits a personal profile file only when you use an explicit editing action. Team Library profiles and folders are read-only in NeatContext. Removing a link or Context does not delete the linked source file or folder.
4. Information We May Collect
We may collect information you provide directly, such as your email address, password for hashing and authentication, account and email-verification information, acceptance of the Terms and Privacy Policy, support messages, feedback, and files or logs you voluntarily send to us for support.
Our website, API, download, update, security, and hosting infrastructure may process IP address, browser type, device or operating-system information, requested pages or API routes, referring URLs, timestamps, request and error logs, download activity, app version, and approximate location derived from network information.
Paddle is the merchant of record and processes payment-method and transaction information under its own Privacy Notice. We may receive billing metadata such as Paddle customer and subscription identifiers, plan, amount, subscription status, current-period end, scheduled cancellation date, renewal date, invoice information, and limited payment-method details needed for entitlement, billing support, tax, accounting, and fraud prevention.
5. Connected AI Clients and External Workflows
NeatContext does not submit prompts, conversation history, local files, or incident content to an AI model provider and does not operate a model of its own. You separately choose and configure the AI client that connects to the local NeatContext MCP service.
The connected client receives NeatContext's analysis instructions and the selected Context's absolute profile paths, knowledge folder paths, and available extension tools. It may read profiles and files, search folders, call extensions, and transmit resulting content, prompts, conversation history, metadata, or tool results to its own model provider depending on that client's architecture and your settings. The client owns the conversation and final response. We do not control how it or its provider processes information.
6. Extensions, Connected Tools, and Permissions
The outward NeatContext MCP boundary exposes only explicitly allowlisted read capabilities. It does not expose tools that write, modify, delete, acknowledge, remediate, publish, or perform other operational mutations. A connected AI client may have separate capabilities outside NeatContext; those are governed by that client and are not granted through the NeatContext connection.
Extensions are executable local software and may contact incidents, repositories, tickets, logs, services, or other systems according to their code, configured connection, allowlisted tools, and source-system permissions. Tool arguments are passed to the local extension process and tool results are returned to the connected client. Context Activity records stay local by default and contain tool names, status, timing, client identifiers, and bounded diagnostic details rather than full successful tool payloads. NeatContext cannot guarantee that third-party extension code will not include a credential or other sensitive value in a tool result, so extensions should be treated as trusted local software.
7. How We Use Information
We use information to:
- provide, operate, secure, and improve the website, downloads, and services;
- deliver updates, checkout flows, account functions, and service communications;
- respond to support, contact, feedback, and troubleshooting requests;
- diagnose errors, protect against abuse, fraud, malware, and unauthorized access;
- process payments, taxes, renewals, refunds, and billing support;
- comply with legal obligations and enforce our Terms of Service.
We do not use local Context content to train an AI model, and the ordinary local Context handoff does not make that content available to us for analytics or product improvement.
8. How Information Is Shared
We may share information with service providers that help operate NeatContext, such as hosting, CDN, security, email, support, payment, download, update, and infrastructure providers. They may process information on our behalf under appropriate contractual or technical controls.
The local desktop app supplies selected nonsecret Context pointers and tool access to the AI client you direct it to connect, without first sending that information to our hosted services. We may otherwise share information we possess with authorities or other parties when required by law or necessary to protect rights, safety, security, or prevent fraud; as part of a merger, financing, acquisition, reorganization, or sale of assets; and with your consent or direction.
We do not sell personal information for money, and we do not currently share personal information for cross-context behavioral advertising. If future website advertising or analytics practices are considered a "sale" or "sharing" under applicable privacy law, we will provide required notices and choices. You can exercise your choices at any time through our Do Not Sell or Share My Personal Information page.
9. Website Technologies and Online Connections
We do not currently use advertising cookies or cross-context behavioral advertising on the NeatContext public website. Hosting, CDN, and security providers may process request logs and similar technical information needed to deliver and protect the site. The public website currently requests web fonts from Google Fonts, so Google may receive network and browser request information under its own privacy practices. Paddle may use cookies or similar technologies in its hosted or overlay checkout and buyer portal under its own privacy notice.
The desktop application may contact NeatContext-hosted services for account, entitlement, billing-portal, release, and update functions; release hosting for update downloads; the connected AI client you choose; and external systems through extensions you enable. Sending files or logs to us for support is voluntary.
10. Retention
Local desktop data remains under your control and may be deleted from your device by deleting the relevant links, settings, profiles, Contexts, logs, installed extension snapshots, or application data, subject to operating-system and backup behavior. Deleting a NeatContext link or Context does not delete the linked source file or folder. Context Activity defaults to age- and size-bounded local retention that you can change in the app. Disconnecting an extension is designed to remove its current local connection file and runtime credential entry, but copies retained by operating-system backups or other backups remain subject to those systems' behavior.
We retain website, account, billing, support, and security information for as long as needed for the purposes described in this Policy, including service operation, legal compliance, security, fraud prevention, accounting, dispute resolution, and enforcement of our agreements. We determine retention periods based on the type and sensitivity of the information, the purpose for which it is processed, whether the purpose can be achieved by other means, and applicable legal, tax, and accounting requirements. When information is no longer needed, we delete or de-identify it.
Account information is generally kept while the account exists and afterward as needed for security, disputes, and legal compliance. Billing and transaction records are kept as required for tax, accounting, fraud prevention, and merchant-of-record support. Support records are kept as needed to resolve and follow up on the request. Hosting and security logs are retained according to operational, security, and provider requirements.
11. Security
We use reasonable technical and organizational measures designed to protect information we process. No method of transmission or storage is completely secure, and no software, connected AI client, model provider, extension, local device, or networked system can be guaranteed secure.
You are responsible for securing your devices, operating-system accounts, backups, local folders, connected AI client accounts, extension tokens, MCP servers, and any third-party tools you configure. Operating-system-provided credential protection is not a substitute for device security; software running under your operating-system account or a malicious extension may be able to access or misuse a credential after it is decrypted for use.
If a security incident affecting your personal information occurs, we will notify affected individuals and regulators as and when required by applicable law.
12. Your Choices and Rights
You can choose which local folders, domain profiles, extensions, MCP servers, tools, and supported AI clients to connect. You can remove Context selections, disconnect extensions and clients, remove local application data from your device, manage browser settings, and choose what information to provide in support requests.
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or opt out of certain processing, sale, sharing, targeted advertising, or profiling. We will honor applicable privacy rights as required by law.
Residents of Virginia, Colorado, Connecticut, and other states with comprehensive privacy laws may have rights to confirm, access, correct, delete, and obtain a copy of their personal data, and to opt out of targeted advertising, the sale of personal data, or certain profiling. To exercise these rights, contact us using the details in Section 17. If we deny your request, you may appeal by replying to our decision or contacting us using the same details; we will respond to your appeal within the time required by applicable law, and if your appeal is denied you may contact your state attorney general.
NeatContext is a general productivity application and does not intentionally collect "consumer health data" as defined by the Washington My Health My Data Act. As described in Section 1, we do not receive your local files or knowledge content unless you deliberately send it to us, such as in a support request.
13. California Privacy Notice
If California privacy law applies, the categories of personal information we may collect include identifiers, commercial information, internet or other electronic network activity, geolocation approximated from network data, payment and transaction metadata, and support communications.
We collect this information from you, your device, your browser, service providers, payment processors, and configured services. We use and disclose it for the business and operational purposes described in this Policy. California residents may have rights to know, access, correct, delete, opt out of sale or sharing, limit certain sensitive personal information uses, and be free from discrimination for exercising privacy rights.
14. International Users
If you access NeatContext from outside the United States, your information may be processed in the United States and other countries where we or our service providers operate. These locations may have privacy laws different from those in your country.
Where European Economic Area, United Kingdom, or similar privacy laws apply, our legal bases may include performing a contract, our legitimate interests, compliance with law, consent, and protection of rights, safety, and security. You may have rights to access, correct, delete, restrict, object, port data, withdraw consent, or lodge a complaint with a supervisory authority.
15. Children
NeatContext is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us so we can take appropriate action.
16. Changes to This Policy
We may update this Privacy Policy from time to time. The updated Policy will be posted on this page with a new effective date. If changes are material, we will provide notice as required by law or through reasonable product, website, or account communications.
17. Contact
Questions or requests about this Privacy Policy should be sent to XT SOFTWARE LABS LLC at privacy@neatcontext.com, or through the support or contact channel listed in the NeatContext app or on the NeatContext website.