Back to home

Privacy Policy

Last updated: September 30, 2026

This Privacy Policy explains how Basebright Inc., a Delaware corporation (“Basebright,” “we,” “us”), collects, uses, shares and protects personal data. It covers our website basebright.ai, the web application at app.basebright.ai (the “Service”), our emails, and demo and support requests.

Basebright is a business-to-business service. The people whose data we handle are mostly employees and contractors of our customers, and people who contact us.

This Policy does not cover data that we process on behalf of our customers, such as data about visitors to a customer’s website collected through our tracking code. For that data, the customer is responsible, and our Terms of Service and Data Processing Addendum apply (see Section 9).

In short:

  • We do not sell personal data, and we do not use advertising or analytics cookies.
  • We send the content you ask us to analyze to AI providers (OpenAI, Anthropic, Google, Perplexity, xAI). We do not send them your account details; the one exception is described in Section 2.5.
  • You can ask us to access, correct, export or delete your data by writing to [email protected].

Table of Contents

  1. Who We Are
  2. Personal Data We Collect
  3. How We Use Personal Data and Our Legal Bases
  4. How We Share Personal Data
  5. Cookies and Browser Storage
  6. Data Retention
  7. Security
  8. Your Rights and Choices
  9. Data We Process on Behalf of Customers
  10. International Data Transfers
  11. U.S. State Privacy Rights
  12. Children
  13. Changes to This Policy
  14. Contact Us

1. Who We Are

Basebright Inc. is the controller of the personal data described in this Policy.

Basebright Inc., 2810 N Church St, Wilmington, Delaware 19802, USA. Email: [email protected]


2. Personal Data We Collect

2.1 Account Data

You sign in with a link that we email to you, or with Google. We do not ask for passwords or usernames.

  • Email address.
  • If you sign in with Google: your name, profile picture and Google account identifier, as provided by Google. We never receive your Google password.
  • Sign-in records kept by our authentication provider, such as sign-in times, and the IP address and browser used.

2.2 Organization and Team Data

  • Organization details you enter: company name, website, whether you are an agency, and the business positioning (“brand profile”), products, competitors and prompts you set up.
  • Membership: your role in each organization (owner or member), when you joined, and your onboarding status.
  • Invitations: the invitee’s email address, who sent the invitation, the role offered, and the invitation’s expiry. The invitation email shows the inviter’s email address to the invitee. When an invitation is sent by email, our authentication provider may create an account record for the invitee’s address before the invitation is accepted.
  • Other members of your organization can see your email address and the analyses and settings in the organization.

2.3 Billing Data

Payments are processed by Stripe. We do not receive or store full card numbers.

We store:

  • Your Stripe customer and subscription identifiers.
  • Your plan and subscription status.
  • Payment amounts, invoices and their status.
  • Automatic top-up settings.
  • Event data that Stripe sends us. This can include the billing name, email address and billing address, and the card brand, last four digits and expiry date.

2.4 Content You Submit and AI Assistant Chats

  • Content you submit to the Service, such as prompts, brand descriptions and competitor lists, and the AI responses we collect for you. This is mostly business information. If it includes personal data (for example, a person’s name in a prompt), Section 9 applies.
  • Conversations with the in-product AI assistant: your messages, the assistant’s answers and the data it looked up. They are stored as chat history until you delete the chat or the organization is deleted.

2.5 Free-Trial Eligibility Check

When a new organization is created, we check whether the sign-up email address belongs to a business:

  1. We compare its domain against lists of personal and disposable email providers.
  2. We then send only the domain (for example, “example.com”, never the full address) to an AI model from OpenAI to assess whether it is a business domain.

The result decides only whether free trial credits are granted. It does not affect your ability to use or pay for the Service. You can ask a person to review the decision by writing to [email protected].

2.6 Communications and Demo Requests

  • Support emails: your name, email address and what you write.
  • Demo requests on our website: your name and work email address, and the page you sent the form from.

2.7 Technical Data

  • Server and security logs. When you visit our website or use the Service, our servers and our network provider, Cloudflare, process technical data:
    • your IP address
    • browser and device type (user agent)
    • the page requested, including any URL parameters
    • the referring page
    • time and status of the request
  • Application logs. Our application logs record internal user and organization identifiers, the pages and actions requested, and your user agent. Email addresses are masked in these logs, and access tokens are removed.
  • We do not use product analytics, session recording or advertising tools, and we do not derive your location from your IP address.

2.8 Information from Third Parties and Public Sources

  • Google: profile data, if you sign in with Google.
  • Stripe: payment status and the billing details described in Section 2.3.
  • Public websites: when you use the Service, we fetch publicly available web pages of your company, your competitors and the sources that AI responses cite. We do this from our own servers and through the data providers listed in Section 4. These pages are business information, but they may contain names of people.

If the EU or UK General Data Protection Regulation (“GDPR”) applies to you, we rely on the legal bases below:

PurposeDataLegal basis
Creating and operating accounts, sign-in, organizations and team featuresAccount, organization and team dataContract (Art. 6(1)(b)). For people invited by a customer: legitimate interests of the customer and of Basebright in providing the service the customer chose (Art. 6(1)(f))
Providing the Service: analyses, the AI assistant and reportsContent you submit, account dataContract; legitimate interests
Billing, automatic top-ups and receiptsBilling dataContract; legal obligation for tax and accounting records (Art. 6(1)(c))
Free-trial eligibilityEmail domainLegitimate interests in preventing abuse of free credits
Service emails: sign-in links, invitations and billing noticesEmail address, account dataContract; legitimate interests
Internal notifications to our team about sign-ups, analysis runs and demo requestsOrganization and product names and run statistics; no email addresses or namesLegitimate interests in running and supporting the Service
Answering demo requests and support messagesName, email address, messageSteps before entering into a contract; legitimate interests
Security, abuse prevention and debuggingTechnical data, logsLegitimate interests
Improving the Service, including reviewing AI assistant conversations to fix errorsUsage and log data, AI assistant conversationsLegitimate interests
Complying with law and handling legal claimsAny relevant dataLegal obligation; legitimate interests

Where we rely on legitimate interests, you can object (see Section 8).

We do not make decisions based solely on automated processing that have legal or similarly significant effects on you. We do not sell personal data, and we do not use it for cross-context behavioral advertising. We do not use your personal data to train AI models.


4. How We Share Personal Data

4.1 Service Providers

We use the following providers to run the Service. They process personal data on our behalf, under contracts that limit how they may use it. Stripe and Google also act as independent controllers for some processing, such as fraud prevention and your Google account.

ProviderWhat it does for usPersonal data involvedLocation
DigitalOceanHosts our application serversAll data processed by the Service; server logsUSA (Virginia)
Supabase (on Amazon Web Services)Database and sign-in (authentication)All account and Service data; sign-in recordsUSA (Virginia)
CloudflareDNS, content delivery, encryption and security for our websitesIP addresses and the content of requests passing through its networkGlobal network
StripePayments and invoices; fraud prevention through Stripe.jsBilling data; device and IP dataUSA and other countries
ResendSends our emails (invitations, billing receipts and alerts) and notifies our team of demo requestsEmail addresses and email contentUSA
OpenAI, Anthropic, Google (Gemini), Perplexity, xAIAI Providers: run your analyses; extract brand mentions and sources; suggest prompts; summarize web pages; power the AI assistantContent you submit and AI assistant conversations. OpenAI also receives the email domain for the trial check (Section 2.5)USA
ExaWeb search and page retrieval for content features and the AI assistantWeb addresses and search queries, which may reflect what you ask the assistantUSA
DataForSEOSearch, keyword and website traffic dataDomains, web addresses and keywords (normally no personal data)Estonia; servers in Germany and the USA
TelegramInternal notifications to our teamOrganization and product names and run statistics; no email addresses or namesGlobal
GoogleSign-in with Google; website icons (favicons), which our servers fetch from Google by domain nameGoogle account data if you use Google sign-in; for icons, only website domain names (no personal data)USA

We also run two tools on our own servers at DigitalOcean (USA):

  • Grafana Loki stores application logs (see Section 2.7).
  • Langfuse records the AI assistant’s conversations for debugging and quality review: your messages, the assistant’s answers, the data it looked up, your user identifier and your organization’s name.

4.2 AI Providers

  • What they receive. AI Providers receive the prompts and content needed for each task. They do not receive your account details (except the email domain in Section 2.5).
  • Their terms. We use them under their commercial API terms, under which they do not use this data to train their models.
  • Their retention. They may keep it for a limited period, typically up to 30 days, to monitor abuse, as described in their own terms.
  • API, not consumer apps. We query their APIs, not their consumer apps.

4.3 Other Disclosures

  • Within your organization: other members can see your email address and the organization’s data. An invitee sees the email address of the person who invited them.
  • Legal reasons: to comply with law, legal process or requests from public authorities; to enforce our Terms; and to protect the rights, property or safety of Basebright, our users or others.
  • Business transfers: as part of a merger, acquisition, financing or sale of assets, subject to this Policy. We will notify you if your data becomes subject to a different privacy policy.
  • With your consent or at your direction.
  • Aggregated or de-identified information that cannot reasonably be used to identify you.

5. Cookies and Browser Storage

We do not use advertising or analytics cookies. We use only storage that is needed to provide the Service or to remember your settings.

NameWherePurposeHow long
sb-…-auth-token (browser storage)AppKeeps you signed inUntil you sign out or the session expires
sidebar:state (cookie)App; demo page on our websiteRemembers whether the sidebar is open7 days
Settings in browser storage (theme, selected organization, filters, panel sizes, onboarding progress, a pending invitation)AppRemembers your choicesUntil you clear them
theme (browser storage)WebsiteRemembers light or dark modeUntil you clear it
Stripe cookies such as __stripe_mid and __stripe_sidAppSet by Stripe.js to prevent payment fraudUp to 1 year

Stripe.js loads only when you open the form to add a payment card, and then stays active until you reload or close the browser tab.

Because we use only storage that is strictly necessary or that remembers settings you chose, we do not show a cookie banner. If we add analytics in the future, we will ask for your consent where the law requires it.

Emails. Our emails do not contain tracking pixels, and we do not track clicks.


6. Data Retention

DataHow long we keep it
Account, organization and Service data, including prompts, AI responses and settingsWhile the organization exists. After a verified deletion request or closure of the organization, we delete it within 30 days (see Terms, Section 8.7)
AI assistant chat historyUntil you delete the chat, or the organization is deleted
InvitationsUntil accepted or cancelled, or until the organization is deleted
Records of payments and credit purchases (amounts, dates, identifiers), including payment event data received from Stripe (which may include the billing name, email and address, and the card brand, last four digits and expiry date)While the organization exists; after it is deleted, only as long as tax and accounting law requires. Invoices and payment details themselves are held by Stripe
Web server logs (IP address, user agent)30 days
Application logs30 days
Copies of AI assistant conversations in our debugging tool (Langfuse)While the organization exists; deleted together with it
Demo requestsUntil we have handled the request and any follow-up, or earlier if you ask us to delete it
Database backups7 days

We may keep data longer where the law requires it, or to establish, exercise or defend legal claims.


7. Security

We use technical and organizational measures appropriate to the risk:

  • Encryption. Data is encrypted in transit (TLS) between your browser, our network provider and our servers. Our database provider encrypts data at rest.

  • Access control. Every request to the Service is authenticated. Our application checks on each request that you belong to the organization whose data you are accessing. Your browser does not access our database directly.

  • Staff access. Administrative access to production systems is limited to the people who need it to run the Service.

  • Sign-in without passwords. Sign-in uses email links or Google; we do not ask for passwords.

  • Log hygiene. Email addresses are masked in application logs, and tokens are removed.

No method of transmission or storage is completely secure. If a personal data breach occurs, we will notify you and the authorities where the law requires it.


8. Your Rights and Choices

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you, and receive a copy in a portable format.
  • Correct inaccurate data.
  • Delete your data.
  • Restrict or object to our processing, including processing based on legitimate interests.
  • Withdraw consent at any time, where we rely on consent.

How to make a request. Write to [email protected]. We will reply within 30 days. We may need to verify your identity, and we may refer you to your organization’s owner if the request concerns data the organization controls.

Deleting your account or organization. There is no self-service deletion yet, so please write to us. We will delete the data within 30 days of verifying the request. Owners of an organization can also remove members themselves.

Emails.

  • Service emails, such as sign-in links, invitations and billing notices, are part of the Service.
  • We do not send marketing newsletters. If we start, we will offer an opt-out, or ask for consent where the law requires it.

Complaints. If the GDPR applies, you can complain to the data protection authority where you live or work. In the UK, that is the Information Commissioner’s Office. We would appreciate the chance to address your concern first.


9. Data We Process on Behalf of Customers

9.1 Visitor Data from the Tracking Code

Customers can install our tracking code on their websites to measure visits by AI crawlers and AI-referred visitors.

What the code sends us for each measured request:

  • the page path and URL parameters
  • the referring page
  • the visitor’s browser (user agent) and IP address

What we do with it:

  • We combine the IP address and user agent with the date to create a pseudonymous daily visitor code.
  • We do not store the IP address itself.
  • We classify the user agent to recognize AI crawlers.
  • We store the page path, URL parameters, referring page, visitor type and the pseudonymous code.

The customer who operates the website is the controller of this data, and we process it under their instructions and our Data Processing Addendum. We keep Visitor Data while the customer’s organization exists, unless the customer asks us to delete it earlier, and delete it together with the organization. If you visited a website that uses our tracking code, please contact that website’s operator.

9.2 Personal Data in Customer Content

Prompts, AI responses and fetched web pages can contain personal data, such as the names of people mentioned in them. We process such data on behalf of the customer and under the Data Processing Addendum.


10. International Data Transfers

Basebright Inc. is incorporated in the United States. Our servers and database are in the United States (Virginia). Some providers, such as Cloudflare and Telegram, operate globally.

When we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to service providers in other countries, we rely on one of the following:

  • The provider’s certification under the EU-U.S. Data Privacy Framework, including the UK Extension and the Swiss-U.S. framework, where the provider is certified.
  • The European Commission’s Standard Contractual Clauses (with the UK Addendum) included in the provider’s data processing terms.

You can ask us for more information about these safeguards.


11. U.S. State Privacy Rights

Residents of California and other U.S. states with comprehensive privacy laws may have the right to:

  • know what personal data we collect, use and disclose;
  • access, correct and delete it; and
  • not be discriminated against for exercising these rights.

We do not sell or share personal data for cross-context behavioral advertising, and we do not use sensitive personal information for purposes that require an opt-out.

In the past 12 months we collected the categories below, for the purposes in Section 3, and disclosed them to the service providers in Section 4:

  • Identifiers: name, email address and IP address.
  • Commercial information: plans, payments and credit purchases.
  • Internet activity: logs and use of the Service.
  • Professional information: company name, website and role in an organization.

To make a request, write to [email protected]. You may use an authorized agent. We will verify requests before acting on them.


12. Children

The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.


13. Changes to This Policy

We may update this Policy to reflect changes in our practices or the law.

  • We will change the “Last updated” date at the top of this page.
  • For material changes, we will notify account owners by email or in the Service before the changes take effect.

14. Contact Us

Basebright Inc. 2810 N Church St Wilmington, Delaware 19802, USA Email: [email protected]