Privacy Policy

Last updated: August 24, 2026

This Privacy Policy explains how PEDRO MACHADO CONSULTORIA (CNPJ 36.196.031/0001-07), which operates Contextra (“Contextra”, “we”, “us”), collects and processes personal data when you use our website, account dashboard, and desktop application. We process personal data in accordance with Brazil’s Lei Geral de Proteção de Dados (LGPD).

1. Who we are & scope

The data controller is PEDRO MACHADO CONSULTORIA (CNPJ 36.196.031/0001-07). You can reach us at support@contextra.pro. Contextra has two parts, and they handle your data very differently:

  • The desktop app is local-first. Your documents are opened and processed on your own computer. Your document content, your translations, and your translation memories, term bases, and projects stay on your device, unless you use one of the two Team-plan features below. When you translate in the default bring-your-own-key mode, the text of the segment being translated goes directly from the app to the AI provider you chose (Gemini, GPT, or Claude) using your own API key — it never passes through our servers. If you translate on managed AI credits instead, that same text is relayed through our AI gateway to reach the provider on our key: we use it only to perform that call and debit your credits, and we do not store it.
  • The Team plan has two exceptions, and only if you use them. A manager can upload a document to a cloud project so a colleague can pick it up; those files, and the translation state saved back to them, are stored on our servers so the assigned translator can download them (see section 3). And anyone on a team can share a translation memory or term base, which uploads its entries — source text and translation — so teammates who subscribe receive a copy (see section 4). Neither happens unless someone on your team deliberately does it; solo use and ordinary local work are unchanged.
  • The account and website give you an account, a license, and a usage dashboard. To do that, our servers collect and store the data described below. This policy is mainly about that data.

2. Data we collect

  • Account data: your email address, your name (optional), and a password — the password is stored only as a secure hash (Argon2), never in plain text. If you verify your email, we store the time of verification.
  • Social login: if you sign in with Google or Microsoft, we receive your email address, your name, and a stable account identifier from that provider. We request only basic profile and email.
  • Authentication & security: we set httpOnly session cookies to keep you signed in — a short-lived access cookie (about 15 minutes) and a rotating refresh cookie (about 30 days); the sign-in-with Google/Microsoft flow uses two temporary cookies (about 10 minutes). Refresh tokens and desktop app keys are stored only as hashes.
  • Desktop app keys: when the desktop app signs in we issue an API key so it can sync. We store only a short prefix and a hash of that key — never the key itself.
  • Your AI provider keys (BYOK): if you save a Gemini, GPT, or Claude API key in your dashboard, we store it encrypted at rest and only ever display its last four characters. We do not use your key ourselves — it is stored so the desktop app can use it on your behalf.
  • Document metadata: the desktop app syncs metadata about documents you process — the file name, the source and target language names, the page count, and whether it completed. Outside the two Team-plan features below, it never sends the document’s content or your translations, and we never store them.
  • Team cloud project files (Team plan only): when someone on your team uploads a document to a shared project, we store that file and the translation state saved back to it, plus its name, assignee, status and progress. This content may contain personal data belonging to your clients — see section 3.
  • Shared memory & term base entries (Team plan only): when someone on your team shares a translation memory or term base, its entries are uploaded so subscribing teammates receive a copy. Each entry contains the source text and its translation (or the source and target term), the sentences immediately before and after it in the original document, content hashes, the language pair, any domain or jurisdiction label, the email of whoever created it, and timestamps. This is client text — see section 4.
  • Usage data: counts of pages and documents processed, and token counts, with timestamps, so your dashboard can show your activity.
  • Billing data: your plan and subscription status, and — if you buy AI credits — your credit balance and a ledger of purchases and per-call debits (amounts and timestamps only, never the text you translated). Card payments are handled by our payment processor; we do not store card numbers.

3. Team cloud projects

This section applies only to the Team plan’s shared projects, and only to documents someone on your team chooses to upload. If you don’t use them, nothing here applies to you. Shared translation memories are a separate feature with a different shape — see section 4.

  • What is stored: the uploaded document, the translation state saved back to it, and its name, assignee, status and progress. We keep the current version and the one before it, so a mistaken upload can be recovered; older versions are deleted automatically.
  • Who can read it: the translator the document is assigned to, plus your team’s owner and managers. Other members of your team cannot download it. Every download is recorded with the account and the time.
  • Security: files are stored encrypted at rest and are never publicly accessible. Uploads and downloads use links that are unique to a single file and expire within minutes.
  • Your clients’ data: a document you upload may contain personal data belonging to your clients. For that content your team is the controller and we act as an operator (processor) on your instructions — we store it to provide the service and use it for nothing else. If you need a data processing agreement, contact us.
  • Deletion: deleting a document, a project, or your team removes the stored files themselves, not just the entries pointing at them. Files are never used to train any AI model, by us or by anyone else.

4. Shared translation memories & term bases

This section applies only to the Team plan, and only once someone on your team chooses to share a memory. A private translation memory or term base — which is what every solo translator has, and what a team member has until they share one — never leaves the computer it lives on.

If your team turns on end-to-end encryption, we cannot read these entries at all. They are encrypted on your own computer before they are sent, and we store only the result. That is the important thing about this section, so it is stated first — the rest explains what is stored either way, and what encryption does and does not cover.

  • End-to-end encryption (Team plan). A team can encrypt its shared memories from the desktop app. When it does, a key is generated on the device that turns it on and is never sent to us in a form we can read: we hold only copies sealed to each member’s device, which we have no way to open, and one sealed to a recovery code that is shown once on screen and never reaches us. From that point every entry is encrypted before it leaves the translator’s computer, and our servers refuse any entry that is not. What we store for each one is an identifier, a keyed index value, whether it has been deleted, and an opaque block of ciphertext.
  • What is stored inside that ciphertext. The entry itself: the source text and its translation (or, for a term base, the source and target term), the sentences immediately before and after it in the original document (which is how a match knows it fits the same context), the language pair, any domain or jurisdiction label, how the translation was produced, the email of whoever created the entry, and timestamps. On an encrypted team, all of that is unreadable to us. On a team that has not turned encryption on, it is stored as ordinary data that our systems can read.
  • What encryption does not cover. Some things have to stay readable for the feature to work at all, and we would rather list them than imply otherwise: the memory’s name, description, language pair, domain and publisher; how many entries it has and when it changed; who subscribes to it; and — within one team — the fact that two entries have the same source text. Encryption protects the content of the entries, not the existence or shape of the memory.
  • It is your clients’ text. A translation memory entry is a sentence from a real document and its translation, so it can contain personal data belonging to your clients. For that content your team is the controller and we act as an operator (processor) on your instructions — we store and relay it to provide the feature and use it for nothing else. It is never used to train any AI model, by us or by anyone else. If you need a data processing agreement, contact us. With encryption on, this is enforced by the system rather than by our undertaking: we could not use the entries for anything else even if we wanted to, because we cannot read them.
  • Who can read it. Every member of your team can see the shared memory in the catalogue and subscribe to it; subscribing downloads its entries onto that person’s computer. Sharing a memory is therefore a disclosure of client text to your colleagues, which is the point of the feature — but it is worth being deliberate about which memories you share. Encryption does not change this: it keeps us out, not your teammates, who are exactly who the memory is for.
  • Losing the key. Because we do not hold a key, we cannot restore access if every member’s device is lost — the recovery code shown when encryption is switched on is the only way back. Keep it somewhere safe. This is the unavoidable cost of the guarantee: a provider who could recover your data for you is a provider who could read it.
  • Stopping sharing does not recall what was already sent. Retiring a memory removes it and its entries from our servers and stops any further updates reaching your team. Copies that subscribers already downloaded are on their own computers and we have no way to reach them. The same is true of a member who leaves: they keep what they had already received.
  • Deleting an entry. When you delete an entry in the app, we record the deletion and pass it on, so subscribers remove their copy too. The entry’s text is retained on our side for a period while that deletion reaches every subscriber, and is then purged.
  • Teams that have not turned encryption on. Encryption is opt-in, and a team that has not enabled it has its entries stored as readable data, protected by access control rather than by cryptography. The app shows which state your team is in, and turning encryption on takes one click in the Memory panel.

5. What we don’t collect

  • Outside the Team plan’s cloud projects (section 3) and shared memories (section 4), we never store the contents of your documents or your translations — they stay on your device and go only to the AI provider you chose. When you translate on managed AI credits, the segment text does transit our gateway to reach that provider (section 1), but it is not stored; in the default bring-your-own-key mode we never receive it at all.
  • We don’t run advertising, analytics, or third-party tracking in our app or on our site, and we don’t use tracking cookies.

6. Cookies

We use only essential cookies needed to sign you in and keep your session secure (the session and sign-in cookies listed above). We do not use advertising or analytics cookies. Because these cookies are strictly necessary to provide the service, they are set when you use your account.

7. How & why we use your data

Under the LGPD, we rely on the following legal bases:

  • To provide the service — create and manage your account, issue your license, check your entitlement, and power your dashboard (performance of our contract with you).
  • To keep the service secure — authentication and preventing abuse (our legitimate interest).
  • To process payments and manage subscriptions (performance of contract).
  • To send you service and account messages, such as security, billing, or important changes (performance of contract / legitimate interest).
  • To comply with our legal obligations.

Where the law requires your consent, we ask for it, and you can withdraw it at any time.

8. Sharing & sub-processors

We don’t sell your personal data. We share it only with providers that help us run the service:

  • Railway — cloud hosting and our database (servers located in the United States).
  • Google and Microsoft — only if you choose to sign in with them, to authenticate you.
  • Our payment processor (Stripe) — to process payments.

Separately, the AI provider you choose (Google, OpenAI, or Anthropic) receives the text you translate. In the default bring-your-own-key mode that happens directly from the desktop app using your own key, under that provider’s own terms, and never through our servers; when you translate on managed AI credits, the text is relayed through our gateway to the provider on our key, and we do not store it. Please review your provider’s privacy terms for how they handle that text.

Within your own team, two features disclose content to your colleagues rather than to a third party: a document in a cloud project can be downloaded by its assignee and by your team’s owner and managers, and the entries of a shared memory are copied onto the computer of every teammate who subscribes to it.

9. International data transfer

Our servers are located in the United States (Railway, US East). If you are in Brazil or elsewhere, your account data is processed in the United States. We rely on the appropriate safeguards for international transfers required by the LGPD and, where applicable, other data-protection laws.

10. Data retention

We keep your account data for as long as your account is active, and your document metadata and usage history so your dashboard stays complete. You can delete your account and all of this data at any time from your dashboard Settings — deletion is immediate and permanent (you can also request it by email; see your rights below). We don’t otherwise run automated purging of account data; if that changes, we’ll update this policy.

Team cloud project files are different, because they can contain your clients’ personal data. For those we keep only the current version of each document and the one immediately before it; older versions are deleted as soon as a newer one is saved. Deleting a document, a project, or a team deletes its files straight away. Servers are located in the United States (Railway, US East), and the files are stored there too.

A memory you shared with a team stays with that team when you leave or delete your account, no longer attributed to you — it is terminology your colleagues are relying on, and withdrawing it silently would break their work. Its entries live until the publisher or one of your team’s managers retires the memory, or the team itself is deleted, at which point they are removed from our servers. As section 4 explains, none of that reaches copies already downloaded by subscribers. If you want a shared memory gone before you close your account, retire it first.

11. Your rights (LGPD)

Under Article 18 of the LGPD, you may request:

  • confirmation that we process your data, and access to it;
  • correction of incomplete, inaccurate, or out-of-date data;
  • anonymization, blocking, or deletion of unnecessary data;
  • portability of your data;
  • deletion of data processed with your consent;
  • information about the entities we share your data with;
  • to withdraw your consent.

To exercise any of these rights, email support@contextra.pro. We’ll respond within the timeframes set by the LGPD (generally up to 15 days). You can also delete your account and all its data yourself at any time from your dashboard Settings.

12. Security

We protect your data with encryption in transit (HTTPS/TLS), hashed passwords and tokens, and httpOnly session cookies. Saved AI provider keys are additionally encrypted by us before they are stored, and team cloud project files are stored encrypted at rest in object storage.

Shared translation memories and term bases can be end-to-end encrypted, which is a stronger guarantee than the rest of this section describes: the key is generated on your own device and we never receive it in a form we can read, so we hold ciphertext and no means of opening it. See section 4 for exactly what that covers and what it does not. A team that has not turned it on has those entries stored as readable data instead.

Team cloud project files (section 3) are not end-to-end encrypted: they are encrypted at rest in storage, which protects them from disclosure of the underlying disks but not from us. We would rather draw that line clearly than let one feature’s guarantee imply another’s.

No method of storage or transmission is completely secure, but we work to protect your information and to keep these measures current.

13. Children

Contextra is intended for professional use by adults (18+). We don’t knowingly collect personal data from children or adolescents. If you believe a minor has provided us data, contact us and we’ll delete it.

14. Changes to this policy

We may update this policy from time to time. We’ll change the “Last updated” date above and, for significant changes, notify you by email or in the app.

15. Contact

For any privacy question or to exercise your rights, contact our data protection officer (encarregado) at support@contextra.pro. Controller: PEDRO MACHADO CONSULTORIA, CNPJ 36.196.031/0001-07.