Skip to main content

Privacy Policy

Last updated: October 1, 2026

This Privacy Policy explains how PEDRO MACHADO CONSULTORIA (CNPJ 36.196.031/0001-07), which operates Contextra (“Contextra”, “we”, “us”), collects and processes personal data when you use our website, account dashboard, and desktop application. We process personal data in accordance with Brazil’s Lei Geral de Proteção de Dados (LGPD).

Where your data goes

Your Library, Translation Memories, Term Bases and the API keys you enter in the app are stored on your computer. Document text leaves it to reach an AI provider when an AI step runs, when you share work with your team on the Team plan, and in copies you choose to make, such as backups to a synced folder. Your Contextra account also receives records about your use, such as the file name of each document you export. This summary is a guide; the numbered sections below are the policy itself.

Kept on your computer

Your work

What
Stored on your computer, not with Contextra (apart from what you share with your team): your Library (the original files and your translations), memories, Term Bases, glossaries, instructions, your Usage history and the API keys you enter in the app.
Where it goes
A folder on your computer that belongs to your Contextra account, not Contextra’s servers, unless you share work on the Team plan (below). Accounts on the same computer are kept apart, except for a few files the whole computer shares, such as the list of documents exported from it, file names included (section 6); the files aren’t encrypted. On Windows, this folder is in your roaming profile, so an organization that syncs roaming profiles may copy it to its servers. Contextra doesn’t sync it between your computers.
How long
Until you delete it. Deleted documents wait 30 days in Recently deleted first.

Backups

What
A zip of your Translation Memories, Term Bases and Library, made on each day you open Contextra and sign in, without your API keys or usage log.
Where it goes
On your computer, and also in a folder you choose if you pick one; a Dropbox, iCloud Drive or OneDrive folder puts that copy with that service. Never uploaded to Contextra, and not encrypted.
How long
The last 7, plus up to 3 “Before restore” snapshots.

Sent to an AI provider when an AI step runs

Analyze sends all of a document’s translatable text, including text the document hides, in batches, with the Term Base terms already found in it. Translate sends the segments being translated with the document’s field, country and register, the glossary terms each batch needs, your instructions and similar passages from your memories. For a 101% or 102% match with mixed formatting, such as bold words or a link, Translate also sends the source and your memory’s translation, so the AI can place the formatting. Analyze term and AI suggestions send the term or row you ask about. Adding or changing a glossary term sends the text of the document, and of other open documents that contain the term, so the AI can find where it occurs; this starts on its own when you save the term.

On your own API key

Where it goes
On your own API key, straight from your computer to Anthropic, OpenAI or Google, under your own account with them, never through Contextra’s servers.
How long
As your provider’s API terms say.

On AI Credits

Where it goes
Through Contextra’s gateway to the AI provider that runs the model you picked, on Contextra’s account with that provider.
How long
The gateway doesn’t keep the text of your requests. Our gateway keeps the AI’s reply, encrypted, so that a retry within ten minutes isn’t charged twice; routine clean-up then erases it. Clean-up runs as later requests arrive, so a reply can be kept longer than ten minutes. A billing record of each request is kept while your account exists; once the reply is erased, it holds no text from your documents. On AI Credits, the repeated part of a request, such as the document’s context and your instructions, can also stay briefly in the AI provider’s cache on our account (section 5).

Sent to Contextra

Account and computers

What
Your email address, your name if you give one, your password as a secure hash, your plan, payments and AI Credits balance, and a name for each signed-in computer taken from its hostname, which often includes your name. Also any API keys you saved on this website: the app doesn’t use them, and you can delete them in Settings.
When
When you create your account on this website, and when the app signs in on a computer (that’s when the computer’s name is sent). After that, while it’s open, the app checks your license about every ten minutes using that computer’s sign-in key; the check doesn’t resend your account details.
How long
While your account exists.

Delivered documents

What
The record holds the document’s original file name, its source and target languages, its page count (source words ÷ 250, rounded up), token totals, whether the AI ran on your own key or on AI Credits, and which of your computers sent it. The record never contains the document’s text or your translations. File names often identify a client or a case.
When
The first time you export a document from the desktop app’s editor on a computer, the app sends one record to your account, so your dashboard can list your delivered documents. Exporting it again from that computer sends no new record unless its page count has changed; exporting it on another computer sends another. If you’re offline, it waits on your computer and is sent later.
How long
While your account exists.

Update checks

What
Your operating system, processor type and app version, with no account details.
When
About once an hour, and when you come back to the app.
How long
Not added to your account.

Only if your team uses the Team plan

Team projects

What
The Word files a manager uploads, the working file your app sends when you export or complete, the translated file you hand back, due dates, progress counts and a timeline.
Where it goes
Contextra’s servers. Readable by the assigned translator, the team’s owner and managers, and Contextra: team files aren’t end-to-end encrypted. Every member of your team can see document names, assignees and statuses.
How long
The current and previous working file and the latest translated file, until the document, project or team is deleted. Copies a translator opened stay in the Library on their computer.

Shared memories

What
Every entry of a Translation Memory or Term Base someone shares: source, translation, the sentences around it and the contributor’s email address.
Where it goes
Contextra’s servers, then copied to the computer of every teammate who subscribes to it, syncing every few minutes while their app is open; their app consults it for documents in the same language pair. Their app can send matching entries to the AI as references, in readable form even on an encrypted team, and on AI Credits through Contextra’s gateway. Contextra can read the entries unless your team turned on end-to-end encryption before they were sent. Encryption is optional, turned on by an owner or manager, and can’t be undone; memory names, language pairs and owners stay readable, and passing the key to teammates’ computers relies on the member and device list Contextra keeps, which the app doesn’t yet let you check.
How long
Until the memory stops being shared or the team is deleted. Copies that subscribers already received stay on their computers, and we have no way to reach them.

Never used

No analytics, advertising or tracking, in the app or on this website.

Removing your data

From your Contextra account

Delete your account in your dashboard’s Settings (section 13). Deleting your account is immediate and can’t be undone. It ends your plan or license at once, a Perpetual license included, cancels any subscription at once and deletes any unspent AI Credits. Contextra opens the work on your computers only while you’re signed in, so export what you need before you delete your account. If you own a team, contact us first: the team has to be deleted or handed to another member before your account can be deleted, and neither can yet be done from the dashboard.

From a computer

Signing out doesn’t erase anything, and removing the app can leave its data behind. Sign out of the app first, or sign the computer out under Devices in your dashboard, so its sign-in key stops working. Quit Contextra and delete these folders. On a Mac, in Finder choose Go ▸ Go to Folder… and paste each path; on Windows, paste each path into File Explorer’s address bar.

  • On a Mac: ~/Library/Application Support/pro.contextra.app, ~/Library/WebKit/pro.contextra.app, ~/Library/Caches/pro.contextra.app and ~/.contextra, and the file ~/Library/Preferences/pro.contextra.app.plist (it remembers the last folder you opened files from).
  • On Windows: %APPDATA%\pro.contextra.app, %LOCALAPPDATA%\pro.contextra.app and %USERPROFILE%\.contextra.

This removes the data of every Contextra account on that computer, including its local backups. If your team uses end-to-end encryption, it also removes that computer’s copy of the team key; if no other computer holds it, your team loses access to its encrypted entries. Copies in a backup folder you chose, files you exported or saved elsewhere, and copies made by other backup or sync software stay until you delete them. Section 6 has the details (Removing Contextra’s data from a computer).

Signing a computer out

Use Devices in your dashboard. The computer is signed out the next time it checks in, within about ten minutes while it’s online.

1. Who we are & scope

The data controller is PEDRO MACHADO CONSULTORIA (CNPJ 36.196.031/0001-07). You can reach us at support@contextra.pro. Contextra has a desktop app, a website where your account lives and, on the Team plan, features you share with your team. They handle your data very differently:

  • The desktop app works on your computer. Your Library (the files you add and your translations), your Translation Memories, Term Bases, glossaries and instructions, and the API keys you enter in the app are stored on your computer, not with us (section 6). The Team plan features below are the exception, and only for what your team shares. Document text leaves your computer to reach an AI provider when an AI step runs. On your own API key, each AI request goes straight from your computer to your provider, never through Contextra’s servers; what the provider keeps follows its API terms. On AI Credits it goes through our gateway. The gateway doesn’t keep the text of your requests. Our gateway keeps the AI’s reply, encrypted, so that a retry within ten minutes isn’t charged twice; routine clean-up then erases it. Clean-up runs as later requests arrive, so a reply can be kept longer than ten minutes. Section 5 explains what each AI step sends and how long that reply can be kept.
  • The Team plan adds two features that store content with us, and only if someone on your team uses them. A manager can upload a Word document to a team project so a colleague can translate it; that file, the working files the translator’s app sends back and the translated file handed back are stored on our servers (section 3). And a team member can share a Translation Memory or Term Base, which uploads its entries, source text and translation, so teammates who subscribe receive a copy (section 4). Neither starts unless someone on your team chooses it; after that, uploads happen on their own: each export of a team document made while you’re online sends a checkpoint, and shared memories sync every few minutes. Solo use is unaffected.
  • The website and your account give you your license, billing and AI Credits, your list of signed-in computers, a dashboard of your delivered documents and usage, the Team plan’s management pages, and app downloads and updates. To do that, our servers collect and store the data in section 2, and the app sends us what section 7 lists.

2. Data we collect

  • Account data: your email address, your name (optional), and a password, stored only as a secure hash (Argon2), never in plain text.
  • Social login: if you sign in with Google or Microsoft, we receive your email address, your name, and a stable account identifier from that provider. We request only basic profile and email.
  • Authentication & security: we set httpOnly session cookies to keep you signed in — a short-lived access cookie (about 15 minutes) and a rotating refresh cookie (about 30 days); the sign-in-with Google/Microsoft flow uses two temporary cookies (about 10 minutes). Refresh tokens and desktop app keys are stored only as hashes.
  • Desktop app sign-ins: when the desktop app signs in, we issue it a key so it can reach your account. We store only a short prefix and a hash of that key, never the key itself. With it we store a name for the computer made from its hostname, which often includes your name, for example “Contextra Desktop (your-computer-name)”, and when it first signed in, last signed in and was last active; your dashboard’s Devices page shows them.
  • AI provider keys: the API keys you enter in the desktop app stay on your computer: the app never sends them to us (section 6). Separately, the Settings page of the website dashboard has a panel called “API keys saved on this website”. If you save a key there, we store it encrypted, show only its last four characters, and you can delete it at any time; the desktop app doesn’t use keys saved there.
  • Delivered documents: the first time you export a document from the desktop app’s editor on a computer, the app sends one record to your account, so your dashboard can list your delivered documents. The record holds the document’s original file name, its source and target languages, its page count (source words ÷ 250, rounded up), token totals, whether the AI ran on your own key or on AI Credits, and which of your computers sent it. Exporting it again from that computer sends no new record unless its page count has changed; exporting it on another computer sends another. The record never contains the document’s text or your translations. File names often identify a client or a case.
  • Team project files (Team plan only): when someone on your team uploads a Word document to a team project, we store that file, the working files the translator’s app sends back and the translated file handed back with Complete, plus the document’s name, assignee, status, due date, language pair, word and segment counts, progress counts, and a timeline of what happened to it and who did it. This content may contain personal data belonging to your clients — see section 3.
  • Team invitations (Team plan only): when a manager invites someone, we store the invitee’s email address, the role offered, who sent the invitation and whether it was accepted or withdrawn, and we send the invitation email through our email provider.
  • Encryption keys (Team plan, only if your team turns on end-to-end encryption): each member’s computer registers an encryption public key with us, labeled with the computer’s hostname, and we store copies of the team key sealed to those computers and to the recovery code. We can’t open any of them (section 4). Your teammates’ apps receive each computer’s label, with its member’s name and email address, so they can pass the team key to it.
  • Shared Translation Memory & Term Base entries (Team plan only): when someone on your team shares a Translation Memory or Term Base, its entries are uploaded so subscribing teammates receive a copy. Each entry contains the source text and its translation (or the source and target term), the sentences immediately before and after it in the original document, content hashes, the language pair, any domain or jurisdiction label, the email of whoever created it, and timestamps. This is client text — see section 4.
  • Usage data: counts of the pages and documents you export, and token counts, with timestamps and, if you belong to a team when a record arrives, that team, so your dashboard can show your activity.
  • Billing data: your plan and subscription status and your payment processor’s customer reference; if you buy AI Credits, your credit balance and a ledger of purchases and debits; and, for each AI Credits request, a billing record: the provider and model, the step it was for, token counts, the provider’s cost, the credits debited, which computer sent it, how long it took and whether it succeeded. Until routine clean-up erases it after the ten-minute retry window, the AI’s reply is kept with that record, encrypted (section 5); apart from that reply, the billing record contains no text from your documents. Card payments are handled by our payment processor; we do not store card numbers.

3. Team projects

This section applies only to the Team plan’s team projects, and only to documents someone on your team chooses to upload. If you don’t use them, nothing here applies to you. Shared Translation Memories are a separate feature with a different shape — see section 4.

  • What is stored: the Word document a manager uploads; the working file the translator’s app sends each time they export the document or hand it back with Complete; the translated Word file delivered with Complete; and the document’s name, assignee, status, due date, language pair, counts and progress, and its timeline. We keep the current working file and the one before it as a safety copy; older versions are deleted automatically. Only the latest translated file is kept.
  • Who can read it: the translator the document is assigned to, plus your team’s owner and managers. Other members of your team cannot download it, although every member can see document names, assignees and statuses. Your team’s records keep only who last downloaded the working file and when: there is no download history, and downloads of the translated file aren’t included.
  • Security: team project files are not publicly accessible: uploads and downloads use links that are unique to a single file and expire within minutes. Uploads are checked against their checksum before they’re published, and the desktop app verifies every file it downloads. The files are not end-to-end encrypted, so our systems can read them.
  • Your clients’ data: a document you upload may contain personal data belonging to your clients. For that content your team is the controller and we act as an operator (processor) on your instructions — we store it to provide the service and use it for nothing else. If you need a data processing agreement, contact us.
  • Deletion: deleting a document, a project, or your team removes the stored files themselves, not just the entries pointing at them. Copies a translator has already opened stay in the Library on their computer, and files already downloaded stay where they were saved; we have no way to reach them. We never use these files to train AI models.

4. Shared Translation Memories & Term Bases

This section applies only to the Team plan, and only once someone on your team chooses to share a memory. A Translation Memory or Term Base you haven’t shared (which is what every solo translator has) is stored on your computer and never uploaded to us. Its entries leave your computer only inside AI requests, as memory references or Term Base terms, which on AI Credits pass through our gateway (section 5), and in copies you make yourself, such as backups to a folder you choose or TMX and TBX exports.

If your team turns on end-to-end encryption, we hold no key that can read the entries shared from then on, provided the member and device list we keep is accurate (see “How far it protects you” below). They are encrypted on the sending computer before they are sent, and we store only the result. Entries shared before encryption was turned on stay as they were, readable to us, until they change. That is the important thing about this section, so it is stated first — the rest explains what is stored either way, and what encryption does and does not cover.

  • End-to-end encryption (Team plan). An owner or manager can turn on encryption for the team’s shared memories from the desktop app; it applies to the whole team and can’t be turned off. When they do, a key is generated on their computer and is never sent to us in a form we can read: we hold only copies sealed to each member’s computer, which we have no way to open, and one sealed to a recovery code that is shown once on screen and never reaches us. New teammates’ computers receive the key from a teammate’s app the next time it syncs. From then on every entry is encrypted before it leaves the sender’s computer, and our servers refuse any entry that is not. What we store for each one is an identifier, a keyed index value, whether it has been deleted, and an opaque block of ciphertext.
  • How far it protects you. Your teammates’ apps pass the team key to every computer our servers list for a member of your team, and the app doesn’t yet let you check that list. The protection therefore relies on the member and device list we keep being accurate. To make that possible, each computer on an encrypted team registers an encryption public key with us, labeled with its hostname, and your teammates’ apps receive that label with the member’s name and email address so they can pass the key on.
  • What is stored inside that ciphertext. The entry itself: the source text and its translation (or, for a Term Base, the source and target term), the sentences immediately before and after it in the original document (which is how a match knows it fits the same context), the language pair, any domain or jurisdiction label, how the translation was produced, the email of whoever created the entry, and timestamps. On an encrypted team, all of that is unreadable to us for entries sent after encryption was turned on. On a team that has not turned encryption on, and for entries shared before it was, it is stored as ordinary data that our systems can read.
  • What encryption does not cover. Some things have to stay readable for the feature to work at all, and we would rather list them than imply otherwise: the memory’s name, description, language pair, domain and publisher; how many entries it has and when it changed; who subscribes to it; and, within one team, the fact that two entries have the same source text. It also doesn’t cover entries shared before encryption was turned on, until they change; team project files (section 3); or an entry’s text once a teammate’s app uses it as a reference in an AI request, which on AI Credits passes through our gateway (section 5). Encryption protects the content of the entries, not the existence or shape of the memory.
  • It is your clients’ text. A Translation Memory entry is a sentence from a real document and its translation, so it can contain personal data belonging to your clients. For that content your team is the controller and we act as an operator (processor) on your instructions — we store and relay it to provide the feature and use it for nothing else. We never use it to train AI models. When a subscriber translates, their app puts matching entries into their AI requests as references, in readable form even on an encrypted team. On AI Credits those requests pass through our gateway, and the AI provider handles them under the terms that apply to that request (section 5). If you need a data processing agreement, contact us. With encryption on, entries sent from then on are protected by cryptography rather than only by our undertaking, within the limits described above.
  • Who can read it. Every member of your team can see the shared memory in the catalog and subscribe to it; subscribing downloads its entries onto that person’s computer. Sharing a memory is therefore a disclosure of client text to your colleagues, which is the point of the feature — but it is worth being deliberate about which memories you share. Encryption does not change this: it keeps us out, not your teammates, who are exactly who the memory is for.
  • Losing the key. Because we do not hold a key we can use, we cannot restore access to encrypted entries if every computer that holds your team’s key is lost. The recovery code is generated on the computer that turns encryption on, shown once, and never stored by us. The app can’t yet use it to restore access, so keep at least one computer that holds the key; removing Contextra’s data from a computer also removes that computer’s copy (section 6). This is the unavoidable cost of end-to-end encryption: a provider who could recover your data for you is a provider who could read it.
  • Stopping sharing does not recall what was already sent. When a memory stops being shared, by the member who shared it or by one of your team’s managers, we remove it and its entries from our servers, and no further updates reach your team. Copies that subscribers already received stay on their computers, and we have no way to reach them. The same is true of a member who leaves: they keep what they had already received.
  • Deleting an entry. When you delete an entry in the app, we record the deletion and pass it on, so subscribers remove their copy too. The deleted entry’s text currently stays on our servers until the memory stops being shared or the team is deleted.
  • Teams that have not turned encryption on. Encryption is optional, and a team that has not turned it on has its entries stored as readable data, protected by access control rather than by cryptography. The app shows which state your team is in; an owner or manager turns encryption on from the Team library on the app’s Memory page, and it can’t be turned off.

5. Text sent to AI providers

Contextra’s AI steps send document text to an AI provider. Each one runs on your own API key or on AI Credits and needs an internet connection; section 3 of our Terms says when a plan is also needed. Everything else (editing, review, accepting into your memory, filling rows from your memory, the Quality check and export) runs on your computer without the AI.

What each AI step sends:

  • Analyze:all of the document’s translatable text, in batches, with the Term Base terms already found in it, so the AI can work out its field, jurisdiction and register and propose glossary terms. It runs when you choose Analyze, or Analyze & translate in your Library.
  • Translate: the segments being translated, in batches, with the document’s field, country and register, the glossary terms each batch needs, your instructions, and similar passages from your Translation Memories (including memories you subscribe to on a team) as references. Segments your memory already confirms (101%, 102% and human-approved 100%) aren’t sent to the AI for translation. But a 101% or 102% match whose formatting has to be carried over, such as bold words or a link, is sent with your memory’s translation in a small request that only places the formatting.
  • Analyze term and AI suggestions: the term or segment you ask about, with the document’s context.
  • Adding or changing a glossary term: the term and all of the document’s translatable text, in batches, so the AI can find the rows where it occurs; the same can happen for each other open document in the same language pair whose text contains the term. Then the linked rows go for re-translation, except rows you accepted, typed yourself or filled from a 101%, 102% or human 100% memory match. This starts on its own when you save the term.

Text a document hides (for example Word hidden text, or hidden Excel sheets, rows and columns) is read and sent like any other text.

On your own API key, the requests go straight from your computer to the provider you chose (Anthropic, OpenAI or Google), under your account with that provider and its API terms. Requests on your own key never pass through our servers, and we never see them.

On AI Credits, the requests go through our gateway to the AI provider that runs the model you picked, on our account with that provider. The gateway doesn’t keep the text of your requests. Our gateway keeps the AI’s reply, encrypted, so that a retry within ten minutes isn’t charged twice; routine clean-up then erases it. Clean-up runs as later requests arrive, so a reply can be kept longer than ten minutes. For each request we keep a billing record: your account, the computer, the model, the step, token counts, the provider’s cost, the credits debited, timing and status. It never holds the text you send, and until clean-up it also holds the encrypted reply described above. These records are kept while your account exists. For the text you send on AI Credits, we act as an operator (processor) on your instructions: we use it only to run the request, and we keep the AI’s reply only to answer a retry without a second charge.

Provider caches. Contextra builds its prompts so providers can reuse the repeated part of a request, such as the document’s context and your instructions, from a short-lived cache, which makes later requests cheaper. On your own key that cache belongs to your provider account; on AI Credits it belongs to ours. Either way, the cached part stays with the provider while a run keeps reusing it and for a short time after the last request that used it, as that provider’s caching rules set.

What providers do with it. Each AI provider handles the text it receives under its own API terms: on your own key, the terms between you and that provider; on AI Credits, the terms between us and that provider. We never use your text to train AI models.

6. Data on your computer

Most of what you create in Contextra is stored on the computer where you create it, and you control it there.

  • What is stored: your Library (the original files you add and your translations), Translation Memories, Term Bases, glossaries, instructions, your detailed usage log (each AI request with its document name and cost estimate) and the API keys you enter in the app, in a folder on your computer that belongs to your Contextra account. It isn’t synced between your computers.
  • Accounts on one computer: on a shared computer, each Contextra account keeps its own documents, memories and API keys inside the app — separation, not encryption: anyone using the same computer login can still reach the files. On Windows, the data folder is in your roaming profile, so on a company network with roaming profiles it can be copied to the company’s server. A few files serve the whole computer rather than one account, among them the sign-in file and the list of exported documents the app reports to your account, file names included, which is kept after it has been sent.
  • API keys: the keys you enter are kept in an unencrypted file in your account’s folder, not in your system’s keychain. The app never sends them to us and never includes them in backups.
  • Backups: on each day you open Contextra and sign in, it backs up your memories, Term Bases and Library on your computer as plain, unencrypted zips, never uploading them to Contextra. It can also copy each backup to a folder you choose; a cloud-synced folder puts that copy in that cloud. Your API keys and the usage log aren’t in them. Backups include archived documents and Recently deleted. The last 7 are kept, plus up to 3 “Before restore” snapshots. A copy in a cloud-synced folder, such as Dropbox, iCloud Drive or OneDrive, is held by that service under its terms.
  • Deleting documents: documents you delete wait 30 days in Recently deleted and are then removed the next time you use Contextra; “Delete now” and “Empty Recently deleted” remove them at once. A removed document can remain inside backups made before it was removed, until those backups are replaced.

Removing Contextra’s data from a computer

Signing out doesn’t erase anything, and removing the app can leave its data behind. To remove it:

  1. Sign out of the app first, or sign the computer out under Devices in your dashboard, so its sign-in key stops working.
  2. Quit Contextra and delete these folders. On a Mac, in Finder choose Go ▸ Go to Folder… and paste each path; on Windows, paste each path into File Explorer’s address bar.
    • On a Mac: ~/Library/Application Support/pro.contextra.app, ~/Library/WebKit/pro.contextra.app, ~/Library/Caches/pro.contextra.app and ~/.contextra, and the file ~/Library/Preferences/pro.contextra.app.plist (it remembers the last folder you opened files from).
    • On Windows: %APPDATA%\pro.contextra.app, %LOCALAPPDATA%\pro.contextra.app and %USERPROFILE%\.contextra.

This removes the data of every Contextra account on that computer, including its local backups. If your team uses end-to-end encryption, it also removes that computer’s copy of the team key; if no other computer holds it, your team loses access to its encrypted entries. Copies in a backup folder you chose, files you exported or saved elsewhere, and copies made by other backup or sync software stay until you delete them.

7. What the app sends to Contextra

Besides the AI requests in section 5, the desktop app contacts contextra.pro for the following.

  • Signing in: your email address and password, and a name for the computer made from its hostname (which often includes your name), for example “Contextra Desktop (your-computer-name)”, which appears on your dashboard’s Devices page. Once you’ve signed in, the app can open without reaching us.
  • License and account checks: when the app starts, about every ten minutes while it’s open, when you come back to its window and when you open Settings, to refresh your license, plan and AI Credits balance. Each check sends only that computer’s sign-in key.
  • Update checks: about once an hour and when you come back to the app, sending your operating system, processor type and app version, with no account details.
  • Delivered documents: the first time you export a document from the desktop app’s editor on a computer, the app sends one record to your account, so your dashboard can list your delivered documents. What it holds is listed in section 2. If you’re offline, it waits on your computer and is sent later.
  • On AI Credits: your AI requests go through our gateway, which keeps a billing record of each one (section 5).
  • On the Team plan, if your team uses it: progress counts for the documents assigned to you while you work, a checkpoint of the working file whenever you export a team document while online, the translated file when you Complete, and shared-memory syncs when you sign in, every five minutes, after an export and when you press Sync now.

8. What we don’t collect

  • Outside the Team plan features in sections 3 and 4, we don’t keep the contents of your documents or your translations, with two short-lived exceptions, both on AI Credits. Our gateway keeps the AI’s reply, encrypted, so that a retry within ten minutes isn’t charged twice; routine clean-up then erases it. Clean-up runs as later requests arrive, so a reply can be kept longer than ten minutes. On AI Credits, the repeated part of a request, such as the document’s context and your instructions, can also stay briefly in the AI provider’s cache on our account (section 5). The file names of documents you export do reach your account (section 2). On your own API key, AI requests never pass through our servers.
  • We don’t run advertising, analytics, or third-party tracking in our app or on our site, and we don’t use tracking cookies.

9. Cookies

We use essential cookies to sign you in and keep your session secure (the session and sign-in cookies listed above), and one preference cookie: cx_locale, which remembers the language you chose for this site, or the language of an account link you opened (English, Português (Brasil) or Español), for one year. We do not use advertising or analytics cookies. Your Light or Dark choice for this site is kept in your browser’s local storage, not in a cookie, and is never sent to us. Because the session and sign-in cookies are strictly necessary to provide the service, they are set when you use your account.

10. How & why we use your data

Under the LGPD, we rely on the following legal bases:

  • To provide the service — create and manage your account, issue your license, check your entitlement, and power your dashboard (performance of our contract with you).
  • To keep the service secure — authentication and preventing abuse (our legitimate interest).
  • To process payments and manage subscriptions (performance of contract).
  • To send you service and account messages, such as security, billing, or important changes (performance of contract / legitimate interest).
  • To comply with our legal obligations.

Where the law requires your consent, we ask for it, and you can withdraw it at any time.

11. Sharing & sub-processors

We don’t sell your personal data. We share it only with providers that help us run the service:

  • Railway — cloud hosting, our database and the AI Credits gateway.
  • Our object-storage provider — stores team project files (section 3).
  • Google and Microsoft — only if you choose to sign in with them, to authenticate you.
  • Our payment processor (Stripe) — to process payments.
  • Resend — to send transactional email: team invitations and password-reset links.
  • The AI providers that run the models offered on AI Credits — they process the AI requests we relay for you, on our accounts with them (section 5). Contact us for the current list.

Separately, on your own API key, the AI provider you choose (Anthropic, OpenAI or Google) receives the text your AI steps send, directly from the desktop app, under your own agreement with that provider, never through our servers. Please review your provider’s privacy terms for how they handle that text, including whether your plan with them lets them use it to improve their models. What AI Credits requests send, and what our gateway keeps, is in section 5.

Within your own team, two features disclose content to your colleagues rather than to a third party: a document in a team project can be downloaded by its assignee and by your team’s owner and managers, and the entries of a shared memory are copied onto the computer of every teammate who subscribes to it.

12. International data transfer

If you are in Brazil or elsewhere, your account data is processed outside Brazil, by us and by the providers listed in section 11. On AI Credits, the AI provider that runs the model also processes the text relayed through our gateway, under the terms between us and that provider (section 5). We rely on the appropriate safeguards for international transfers required by the LGPD and, where applicable, other data-protection laws.

13. Data retention

We keep your account data for as long as your account exists, including your delivered-document records, usage history and AI Credits billing records, so your dashboard stays complete. Our gateway keeps the AI’s reply, encrypted, so that a retry within ten minutes isn’t charged twice; routine clean-up then erases it. Clean-up runs as later requests arrive, so a reply can be kept longer than ten minutes. You can delete your account at any time from your dashboard’s Settings (you can also request it by email; see your rights below). Deleting your account is immediate and can’t be undone. It deletes your account data on our servers, including your delivered-document history, your usage and any API keys saved on this website. It ends your plan or license at once, a Perpetual license included, cancels any subscription at once and deletes any unspent AI Credits. Deleting refunds nothing: if you think you’re owed a refund, write to support@contextra.pro before you delete. If you own a team, contact us first: the team has to be deleted or handed to another member before your account can be deleted, and neither can yet be done from the dashboard. Deleting your account doesn’t delete what belongs to your team (documents in its team projects and memories you shared stay with it; see below) or anything on your computers (section 6). Contextra opens the work on your computers only while you’re signed in, so export what you need before you delete your account. We don’t otherwise run automated purging of account data; if that changes, we’ll update this policy.

Team project files are different, because they can contain your clients’ personal data. For those we keep only the current working file of each document and the one immediately before it, plus the latest translated file; older versions are deleted as soon as a newer one is saved. Deleting a document, a project, or a team deletes its files straight away.

A memory you shared with a team stays with that team when you leave or delete your account. It is no longer linked to your account, but each entry still carries the email address of the member who created it, including in the copies subscribers hold. It is terminology your colleagues are relying on, and withdrawing it silently would break their work. Its entries live until the member who shared it or one of your team’s managers stops sharing the memory, or the team itself is deleted, at which point they are removed from our servers. Copies that subscribers already received stay on their computers, and we have no way to reach them. If you want a shared memory gone from our servers before you close your account, stop sharing it first (section 4).

14. Your rights (LGPD)

Under Article 18 of the LGPD, you may request:

  • confirmation that we process your data, and access to it;
  • correction of incomplete, inaccurate, or out-of-date data;
  • anonymization, blocking, or deletion of unnecessary data;
  • portability of your data;
  • deletion of data processed with your consent;
  • information about the entities we share your data with;
  • to withdraw your consent.

To exercise any of these rights, email support@contextra.pro. We’ll respond within the timeframes set by the LGPD (generally up to 15 days). You can also delete your account and its data yourself at any time from your dashboard’s Settings; if you own a team, contact us first (section 13). Data on your own computers is yours to remove (section 6).

15. Security

We protect your data with encryption in transit (HTTPS/TLS), hashed passwords and tokens, and httpOnly session cookies. Provider keys saved in the website’s “API keys saved on this website” panel are also encrypted before they are stored. The API keys you enter in the desktop app never reach us; they are kept on your computer, unencrypted, in your account’s folder (section 6).

Shared Translation Memories and Term Bases can be end-to-end encrypted, which is a stronger guarantee than the rest of this section describes. It is optional: an owner or manager turns it on, and it can’t be turned off. The key is generated on a team member’s computer and we never receive it in a form we can read, so from then on we hold the entries as ciphertext and no key that can open them. Section 4 explains exactly what that covers and what it does not, including its reliance on the member and device list we keep. A team that has not turned it on has those entries stored as readable data instead.

Team project files (section 3) are not end-to-end encrypted: our systems can read them. We would rather draw that line clearly than let one feature’s guarantee imply another’s.

If you think someone else knows your password, reset it from the sign-in page: a reset signs every computer out of your account. Changing your password in your dashboard’s Settings doesn’t sign computers out; to do that, use Devices. An account created with Google or Microsoft sign-in has no password to reset.

No method of storage or transmission is completely secure, but we work to protect your information and to keep these measures current.

16. Children

Contextra is intended for professional use by adults (18+). We don’t knowingly collect personal data from children or adolescents. If you believe a minor has provided us data, contact us and we’ll delete it.

17. Changes to this policy

We may update this policy from time to time. We’ll change the “Last updated” date above and, for significant changes, notify you by email or in the app.

18. Contact

For any privacy question or to exercise your rights, contact our data protection officer (encarregado) at support@contextra.pro. Controller: PEDRO MACHADO CONSULTORIA, CNPJ 36.196.031/0001-07.