1. Introduction
CONTEXTFORCE LLC, a California limited liability company (“we”, “us”), operates Forty Pirates — the mobile app, the website at fortypirates.com, and related services (the Service). We turn travel content you already watch into real places you can save, map, and act on.
This policy explains what we collect, who receives it, how long we keep it, and how to make us delete it. Using the Service means you accept it.
2. Information we collect
A. Information you give us
- Account data — email, display name, username, and profile image. Sign in with Google or Apple and we receive your email and name from them, never your password.
- Password — if you sign up with email, stored only as a salted hash.
- Your content — trips, boards, lists, saved places, captures, notes, and images you upload.
- Links you submit — the YouTube, TikTok, Instagram, and web URLs you paste in.
- Prompts and queries — what you type into search, extraction, and planning features.
B. Information processed through integrations
- Social content — when you submit a link, we retrieve publicly accessible material from platforms such as YouTube, TikTok, and Instagram: transcripts, captions, post text, titles, thumbnails, and creator handles. We never access private accounts, messages, or anything behind a login, and we never ask for your credentials to those platforms.
- Place data — we resolve the places we find against mapping and place-data sources to get addresses, coordinates, hours, and photos. Extracted content is cached so the same video is not re-processed for every user.
C. Information collected automatically
- Technical data — IP address, device type, and app version.
- Usage events — which features you use, recorded in our own server logs to run the Service, fix breakage, and prevent abuse.
- Location, if you permit it — used to center the map and sort places by distance. Most of that happens on your device. The one exception: when you search for a place to add, your approximate coordinates go with the search so results near you rank first. We do not keep a history of where you have been, and we never share your location with advertisers or data brokers.
- Product analytics — we use PostHog to understand how the app is used. It receives your account ID, email, and display name, along with events like opening a place, running an extraction, or saving to a list. Events carry context such as a place category or city, the platform a link came from — never the link itself — and counts. The SDK also records app opens, screen taps, device model, OS version, and IP address. You can turn this off: see section 9.
No advertising identifiers (including Apple's IDFA), no advertising profiles, no crash-reporting SDKs, and no payment card details. We do not track you across other companies' apps or websites, and we do not sell or share your data for advertising. Our one analytics provider is named above and in section 4.F, and you can switch it off.
3. How we use AI
- What we send — submitted content and your prompts go to third-party AI providers to identify places, write summaries, and build itineraries.
- Who receives it — a small number of third-party AI providers under contract. We never send them your email, password, or payment details.
- No training — they act as our processors under terms prohibiting them from training their models on your data.
Hours, prices, and itinerary details can be wrong. Confirm anything that matters with the venue or an official source before you rely on it.
4. Service providers
We do not sell your personal information or share it for cross-context behavioural advertising. These providers are contractually bound to process your data only on our instructions, and each receives only what it needs:
A. AI processing
- AI model providers — content extraction and itinerary generation. See section 3.
B. Infrastructure and storage
- Cloud hosting, object storage, and CDN (United States) — running the Service and storing your content and uploaded images.
- Managed database (United States) — holding your account and its records.
C. Mapping and place data
- Mapping and place-data providers — resolving place names to real locations and drawing the map. These receive the place or area being looked up, not your identity.
D. Identity
- Google and Apple — optional social sign-in, if you choose it. They tell us your email and name; we never see your password.
E. Booking partners
- Travel booking partners, reached through an affiliate network — hotel and flight availability, and the hand-off when you book. See section 5.
F. Analytics and error tracking
- PostHog — product analytics, so we can see which features are used and where people get stuck. It receives the account and event data described in section 2.C. It is contractually bound to process that data only on our instructions, it does not sell it, and it does not use it for advertising. Turn it off in the app at any time.
- No crash reporting — we run no third-party crash or error-reporting service. Everything else in section 2.C comes from our own server logs.
We will name the specific companies behind any category on request. We may also disclose data where the law requires it, to investigate fraud or abuse, to protect someone's safety, or to a buyer in a merger or acquisition.
5. Affiliate booking links
Hotel and flight links may carry an affiliate code, and we may earn a commission at no extra cost to you. We strip third-party tracking parameters before adding our own, and commission never affects the order in which we show you places. Once you reach a partner's site, their privacy policy governs, not ours.
7. Payments
The Service is free and we collect no payment card details. If we introduce paid features, in-app purchases will be processed by Apple under Apple's terms — we would receive confirmation of a purchase, never your card number — and we will update this policy first.
8. Data retention
- Account and content — kept while your account is open.
- After deletion — removed from live systems within 30 days, and from encrypted backups within 90 days.
- Place data — information about real-world places is not personal to you and stays in our public catalog with your identifiers removed.
- Legal records — limited records kept longer where the law requires.
9. Your choices and controls
- Your details — edit your display name, email, and bio in your profile at any time.
- Location — revoke the permission in your device settings.
- Analytics — turn PostHog off in the app under Settings → Privacy → Share usage data. Switch it off and the app stops sending events and forgets the identifier it was using. Everything else keeps working; nothing is withheld for opting out.
- Visibility — un-share anything you made public, whenever you want.
- Your rights — depending on where you live, you may access, correct, delete, or export your data, object to or restrict processing, and withdraw consent. Email us to exercise any of these; we may need to verify your identity, and you may also complain to your local data protection authority.
Go to Profile → Settings → your name → Delete account, or email support@contextforce.com from your registered address. This removes your account, trips, boards, lists, saved places, sign-in methods, and your public storefront. It is permanent.
In the EEA, UK, and Switzerland we rely on performance of our contract, our legitimate interests in securing and improving the Service, your consent for location, and legal obligations. In California, we do not sell or share personal information as the CCPA defines those terms, and we will not discriminate against you for exercising your rights.
10. Security
Traffic is encrypted with TLS, data at rest is encrypted, passwords are stored only as salted hashes, and production access is limited to those who need it. No system is perfect — use a strong, unique password and tell us if you suspect your account has been compromised.
11. Children's privacy
The Service is not intended for children under 13, and we do not knowingly collect their data. In the European Economic Area, the United Kingdom, and Switzerland the minimum is 16, or your country's age of digital consent if that is lower. If we learn we have collected data from a child below the applicable age, we delete it promptly. Parents and guardians can reach us at support@contextforce.com.
12. International users
We store and process data in the United States, where data protection law may differ from your own. For transfers out of the EEA, UK, or Switzerland we rely on the Standard Contractual Clauses or another lawful mechanism.
13. Changes
We will revise the date above when this policy changes, and give notice in the app or by email before material changes take effect. Continued use means you accept the update.
14. Contact us
Questions about this policy, or any request about your data, go to support@contextforce.com.