Legal
Privacy Policy
Last updated: August 29, 2026
Overview
UserContext (“we”, “our”, “us”) helps product teams understand user friction. We correlate what users say, through voice and text feedback, with what they do on our customers' websites. This policy explains what data we collect, how we use it, and the rights you have over it.
We play two roles. For the account data of our customers, we are the data controller. For end-user data collected on a customer's site, the customer is the controller and we process that data on their behalf.
1. Data We Collect
a) Account Data (from you, our customer)
- Email address and name (during registration)
- Role and team size (during onboarding)
- Project configuration and API keys
- Billing information (processed by our payment provider)
b) End-User Interaction Data (from your users' browsers)
- Pageviews and navigation: page URL changes within your site
- Clicks: element tag, visible text, and CSS selector
- Frustration signals: rage clicks and dead clicks
- Page errors: JavaScript errors surfaced on the page
- Performance metrics: Core Web Vitals (LCP, INP, CLS)
- Environment metadata: browser name and version, operating system, viewport size, and connection type
- Feedback: what your users choose to tell you, by voice or text
Voice feedback is transcribed and the audio is then discarded. We do not store recordings. When a screenshot accompanies voice feedback, input fields are masked in the browser before upload, so typed values never leave the page.
We do not capture keystrokes or form input values. Session recording exists only as an explicit, operator-armed flow for a specific journey, with an opt-out that persists in the visitor's browser. There is no ambient session replay.
2. Identity, Cookies, and Consent
The tracker sets one cookie, _uc_aid, used to recognize a returning anonymous visitor. It is consent-gated by default: it is not written until the site signals that consent was given. Session identity for a single visit lives in sessionStorage. localStorage holds a small configuration cache plus the opt-out and consent flags themselves.
Visitors can opt out programmatically, and the tracker honors that flag everywhere. Logged-in identity is attached only when the customer calls our identify API for their own authenticated users, and trait keys pass a server-side whitelist. As controller, the customer decides which consent mechanism their site uses.
The UserContext dashboard uses essential session cookies for authentication only. We do not use advertising cookies or third-party analytics cookies.
3. How We Use Data
- Identify friction and product issues in your application
- Correlate user feedback with the behavior around it
- Deliver the resulting insights to your dashboard, Slack, and development tools
- Measure whether fixes worked, using statistical checks against real behavior
We use data to improve our own service only in aggregate, de-identified form.
4. AI Processing
We use Groq to transcribe voice feedback, Anthropic to analyze signals, and Voyage AI to compute embeddings for search. Feedback transcripts contain whatever the user chose to say. Our agreements with these providers do not permit them to train their models on this data.
5. Retention and Deletion
Behavioral events are retained per site for a configurable window, 90 days by default, and purged nightly by scheduled database jobs. Screenshots past retention are purged nightly as well, both records and files. Our internal access logs are retention-limited and purged on the same schedule.
Deletion requests are executed by a subject-scoped purge that removes a person's events, contributions, derived facts, trait history, and identity links. Where an identifier is shared across people, for example a family device, the case is routed to manual review rather than deleting someone else's data.
After an account deletion request, project data is removed within 30 days. Billing records are kept only as long as the law requires.
6. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: request a copy of the data we hold about you
- Correction: request that we correct inaccurate data
- Deletion: request that we delete your data (“right to be forgotten”)
- Portability: request your data in a machine-readable format
- Opt-out: opt out of data processing for marketing purposes
To exercise any of these rights, contact us at privacy@usercontext.com. We will respond within 30 days. If you are an end user of a site that uses UserContext, direct your request to that site; we support them in executing it.
7. Subprocessors
We use the following services to operate UserContext:
- Supabase: database and authentication, hosted on AWS
- Railway: application hosting
- Vercel: website hosting
- Anthropic, Groq, and Voyage AI: AI processing as described in section 4
- Slack: only when a customer connects their workspace
- Resend: emails from this website's forms
We do not sell, rent, or trade any data to third parties.
8. Data Storage and Security
Data lives in PostgreSQL hosted by Supabase on AWS, with provider-managed encryption at rest and TLS in transit. Row-level security scopes every query to the owning project. For more detail, see our Security page.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or a prominent notice in the dashboard. Your continued use of UserContext after changes constitutes acceptance of the updated policy.
10. Contact
If you have questions about this Privacy Policy or our data practices, contact us at:
UserContext, Inc.
Email: privacy@usercontext.com