Skip to main content
The Context Company processes production agent interactions, which can include sensitive user content, tool arguments, and results. This page summarizes what is collected, how it is protected, and where to find deeper detail.

What is collected

For every run you send, the platform stores the fields listed on the What TCC captures page: prompts, responses, model calls, tool calls, arguments and results, errors, latency, tokens, cost, user and organization identifiers you attach, feedback, and any custom metadata. Sensitive fields you don’t want stored can be redacted at ingest (see PII redaction) or excluded from the metadata you send in the first place.

Data security

  • Encryption in transit. All ingest and API traffic is served over TLS.
  • Encryption at rest. Stored data is encrypted at rest.
  • Tenant isolation. Data is isolated per organization. Your traces are never mixed with other customers’ data.
  • Access control. Access is scoped by API key (dev / prod / dev+prod) and by dashboard membership.
For anything not covered here or in the linked pages, see our Privacy Policy or contact support@thecontextcompany.com.

PII redaction

PII redaction runs at ingest, before data reaches storage or search indexes. Detected values are replaced with category placeholders ([EMAIL], [SSN], [CREDIT_CARD], [IP_ADDRESS], [PHONE], [API_KEY]). Available on the Enterprise plan. See PII redaction for the full list of categories, examples, and limitations.

Data export and deletion

For data export or deletion requests, contact support@thecontextcompany.com. See Data privacy for policy links. Users located in the EU, EEA, or UK see a cookie consent banner on their first visit. Analytics tracking is disabled by default for these users until they explicitly accept.

What TCC captures

The full list of fields stored per run.

PII redaction

Redact sensitive fields at ingest.

Data privacy

Policy, export, and deletion.

Contact

Ask us about anything else.