basemode
Privacy
What we collect, what never leaves your machine, who else touches it, and how long we keep it.
Last updated 24 August 2026
This page covers three different things, and they collect very different amounts of information: the website you are reading now, the account portal at app.basemode.ai, and the base program that runs on your own machine. Each one is set out separately below, because lumping them together is how privacy pages end up saying nothing.
1. This website
basemode.ai is a static site. It sets no cookies, runs no analytics, and has no tracking of any kind. We do not know you were here.
One thing on this page comes from somewhere else: the typefaces are served by Google Fonts, so your browser fetches them from fonts.googleapis.com and fonts.gstatic.com, and Google receives your IP address when it does. That is the only third-party request the site makes.
The site is hosted on Railway, which keeps standard server logs including IP addresses for a short period as part of running the servers.
2. Your account
When you create an account we store your name, your email address, and your password as a hash we cannot reverse. If your organisation invites you, we store the invitation until it is used or it expires.
While you are signed in we store a session record that includes your IP address and your browser's user agent, so we can keep you signed in and spot a session that should not be there. We store the API tokens you or your agents create, which parts of the organisation you have been granted, and your role in it.
We keep an audit record of writes and administrative changes, with whoever made them attached. That record cannot be edited or removed, including by us. It is what lets your organisation answer what changed and who changed it, and it is the one part of the system that is deliberately not deletable.
We also count usage, meaning how much was written and how much is stored, because that is what the plans are billed on.
3. What your team writes into basemode
This is the content: the decisions, rules, corrections and notes your team records, whatever we read out of the systems you connect, and the structure parsed out of your code.
It is yours. We hold it so the service can work, and for nothing else. We do not read it except when you ask us to help with a specific problem and we need to, or where the law requires it. We do not use it to train machine learning models. We do not sell it and we do not share it with anyone for their own purposes.
Inside your organisation, who can read what is decided by the grants your owner sets. A query runs inside a grant and stops at its edge.
4. What stays on your machine
Every machine running base holds its own copy of your organisation's content, and reads are served out of that copy. They do not travel over the network and they do not reach us, which is why we cannot count them and why we have no record of what anyone looked up. Writes are sent to us so the other machines can receive them.
The program also writes to a small set of files on your machine when it installs and records what it touched. Removing it puts them back.
5. Accounts you connect
You can connect basemode to Notion, Google Drive, Google Calendar, Gmail, Slack, GitHub, Monday, HighLevel and Atlassian. Connections are set up through Nango, which handles the sign-in with each provider and holds the access tokens.
When you connect one, you choose what basemode is allowed to reach, and we read only what is needed for the job you connected it for. Disconnecting it stops any further reading immediately. Anything already read stays in your content until you delete it.
6. Email
We send account email, meaning verification, invitations, password resets, service notices and any digest you turn on, through Postmark. Postmark receives the email address it is going to and the contents of the message.
We do not send marketing email to people who have not asked for it. If we ever do send any, every message will carry an unsubscribe link and it will work.
7. Who else touches your data
| Who | What they do | What they see |
|---|---|---|
| Railway | hosts the site, the portal and its database | everything the portal stores, as its host |
| Postmark | sends account email | email addresses and message contents |
| Nango | brokers connections to other systems | access tokens for the accounts you connect |
| Stripe | takes payments for paid plans | your billing details and your card, which never reach us |
| Google Fonts | serves the typefaces on basemode.ai | your IP address when the page loads |
Card numbers never reach us. Paying happens on Stripe's own pages, and what comes back to us is a reference number, never a card.
Each company above is under a contract that limits it to working for us. We will update this table before we add anyone to it.
Beyond that, we share information only when the law requires it, and if somebody buys the business, your data moves with it under this same policy.
8. Where it is processed
The portal and its database run on Railway in the United States, in the us-west2 region. Email goes through Postmark and connections through Nango, both of which operate in the United States. If you are in the UK or the EU, that means your data is transferred outside it, and those transfers rely on the standard contractual clauses in our agreements with those companies.
9. How long we keep it
Your content stays until you delete it or close the account. Delete something and it stops appearing for every reader on every machine.
When you close an account we delete the live data within 30 days, and it clears our backups within 90 days. We keep the audit record and what we need for tax and accounting for as long as the law requires, and nothing more.
Server logs are kept for a short period and then rotated out.
10. What you can ask us for
You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, or ask us to stop processing it. Write tohello@basemode.ai and we will answer within 30 days.
If your organisation is your employer's, the content belongs to them, and we will point a request about that content back to them. Your own account details are yours and we deal with those directly.
If you are in the UK or the EU, you have these rights under the GDPR and you can complain to your data protection authority. If you are in California, you have the rights the CCPA gives you, and we do not sell personal information as that law defines it.
11. Keeping it safe
Traffic is encrypted in transit. Passwords are stored as hashes. Access inside your organisation is limited to the grants your owner sets, and every write is recorded.
No system is perfect. If we have a breach that affects you, we will tell the affected account owners and the regulators the law says we must, and we will say what happened rather than manage it.
12. Children
basemode is for work and is not for anyone under 16. We do not knowingly collect anything about children, and if we find we have, we delete it.
13. Changes
When this policy changes, the date at the top changes with it. If a change materially affects what we do with your information, we will email account owners before it takes effect.
14. Contact
BASEMODE LLC, address on request.
hello@basemode.ai