Privacy Policy
Last updated: September 30, 2026
This Privacy Policy explains how Basebright Inc., a Delaware corporation (“Basebright,” “we,” “us”), collects, uses, shares and protects personal data. It covers our website basebright.ai, the web application at app.basebright.ai (the “Service”), our emails, and demo and support requests.
Basebright is a business-to-business service. The people whose data we handle are mostly employees and contractors of our customers, and people who contact us.
This Policy does not cover data that we process on behalf of our customers, such as data about visitors to a customer’s website collected through our tracking code. For that data, the customer is responsible, and our Terms of Service and Data Processing Addendum apply (see Section 9).
In short:
- We do not sell personal data, and we do not use advertising or analytics cookies.
- We send the content you ask us to analyze to AI providers (OpenAI, Anthropic, Google, Perplexity, xAI). We do not send them your account details; the one exception is described in Section 2.5.
- You can ask us to access, correct, export or delete your data by writing to [email protected].
Table of Contents
- Who We Are
- Personal Data We Collect
- How We Use Personal Data and Our Legal Bases
- How We Share Personal Data
- Cookies and Browser Storage
- Data Retention
- Security
- Your Rights and Choices
- Data We Process on Behalf of Customers
- International Data Transfers
- U.S. State Privacy Rights
- Children
- Changes to This Policy
- Contact Us
1. Who We Are
Basebright Inc. is the controller of the personal data described in this Policy.
Basebright Inc., 2810 N Church St, Wilmington, Delaware 19802, USA. Email: [email protected]
2. Personal Data We Collect
2.1 Account Data
You sign in with a link that we email to you, or with Google. We do not ask for passwords or usernames.
- Email address.
- If you sign in with Google: your name, profile picture and Google account identifier, as provided by Google. We never receive your Google password.
- Sign-in records kept by our authentication provider, such as sign-in times, and the IP address and browser used.
2.2 Organization and Team Data
- Organization details you enter: company name, website, whether you are an agency, and the business positioning (“brand profile”), products, competitors and prompts you set up.
- Membership: your role in each organization (owner or member), when you joined, and your onboarding status.
- Invitations: the invitee’s email address, who sent the invitation, the role offered, and the invitation’s expiry. The invitation email shows the inviter’s email address to the invitee. When an invitation is sent by email, our authentication provider may create an account record for the invitee’s address before the invitation is accepted.
- Other members of your organization can see your email address and the analyses and settings in the organization.
2.3 Billing Data
Payments are processed by Stripe. We do not receive or store full card numbers.
We store:
- Your Stripe customer and subscription identifiers.
- Your plan and subscription status.
- Payment amounts, invoices and their status.
- Automatic top-up settings.
- Event data that Stripe sends us. This can include the billing name, email address and billing address, and the card brand, last four digits and expiry date.
2.4 Content You Submit and AI Assistant Chats
- Content you submit to the Service, such as prompts, brand descriptions and competitor lists, and the AI responses we collect for you. This is mostly business information. If it includes personal data (for example, a person’s name in a prompt), Section 9 applies.
- Conversations with the in-product AI assistant: your messages, the assistant’s answers and the data it looked up. They are stored as chat history until you delete the chat or the organization is deleted.
2.5 Free-Trial Eligibility Check
When a new organization is created, we check whether the sign-up email address belongs to a business:
- We compare its domain against lists of personal and disposable email providers.
- We then send only the domain (for example, “example.com”, never the full address) to an AI model from OpenAI to assess whether it is a business domain.
The result decides only whether free trial credits are granted. It does not affect your ability to use or pay for the Service. You can ask a person to review the decision by writing to [email protected].
2.6 Communications and Demo Requests
- Support emails: your name, email address and what you write.
- Demo requests on our website: your name and work email address, and the page you sent the form from.
2.7 Technical Data
- Server and security logs. When you visit our website or use the Service, our servers and our network provider, Cloudflare, process technical data:
- your IP address
- browser and device type (user agent)
- the page requested, including any URL parameters
- the referring page
- time and status of the request
- Application logs. Our application logs record internal user and organization identifiers, the pages and actions requested, and your user agent. Email addresses are masked in these logs, and access tokens are removed.
- We do not use product analytics, session recording or advertising tools, and we do not derive your location from your IP address.
2.8 Information from Third Parties and Public Sources
- Google: profile data, if you sign in with Google.
- Stripe: payment status and the billing details described in Section 2.3.
- Public websites: when you use the Service, we fetch publicly available web pages of your company, your competitors and the sources that AI responses cite. We do this from our own servers and through the data providers listed in Section 4. These pages are business information, but they may contain names of people.
3. How We Use Personal Data and Our Legal Bases
If the EU or UK General Data Protection Regulation (“GDPR”) applies to you, we rely on the legal bases below:
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and operating accounts, sign-in, organizations and team features | Account, organization and team data | Contract (Art. 6(1)(b)). For people invited by a customer: legitimate interests of the customer and of Basebright in providing the service the customer chose (Art. 6(1)(f)) |
| Providing the Service: analyses, the AI assistant and reports | Content you submit, account data | Contract; legitimate interests |
| Billing, automatic top-ups and receipts | Billing data | Contract; legal obligation for tax and accounting records (Art. 6(1)(c)) |
| Free-trial eligibility | Email domain | Legitimate interests in preventing abuse of free credits |
| Service emails: sign-in links, invitations and billing notices | Email address, account data | Contract; legitimate interests |
| Internal notifications to our team about sign-ups, analysis runs and demo requests | Organization and product names and run statistics; no email addresses or names | Legitimate interests in running and supporting the Service |
| Answering demo requests and support messages | Name, email address, message | Steps before entering into a contract; legitimate interests |
| Security, abuse prevention and debugging | Technical data, logs | Legitimate interests |
| Improving the Service, including reviewing AI assistant conversations to fix errors | Usage and log data, AI assistant conversations | Legitimate interests |
| Complying with law and handling legal claims | Any relevant data | Legal obligation; legitimate interests |
Where we rely on legitimate interests, you can object (see Section 8).
We do not make decisions based solely on automated processing that have legal or similarly significant effects on you. We do not sell personal data, and we do not use it for cross-context behavioral advertising. We do not use your personal data to train AI models.
4. How We Share Personal Data
4.1 Service Providers
We use the following providers to run the Service. They process personal data on our behalf, under contracts that limit how they may use it. Stripe and Google also act as independent controllers for some processing, such as fraud prevention and your Google account.
| Provider | What it does for us | Personal data involved | Location |
|---|---|---|---|
| DigitalOcean | Hosts our application servers | All data processed by the Service; server logs | USA (Virginia) |
| Supabase (on Amazon Web Services) | Database and sign-in (authentication) | All account and Service data; sign-in records | USA (Virginia) |
| Cloudflare | DNS, content delivery, encryption and security for our websites | IP addresses and the content of requests passing through its network | Global network |
| Stripe | Payments and invoices; fraud prevention through Stripe.js | Billing data; device and IP data | USA and other countries |
| Resend | Sends our emails (invitations, billing receipts and alerts) and notifies our team of demo requests | Email addresses and email content | USA |
| OpenAI, Anthropic, Google (Gemini), Perplexity, xAI | AI Providers: run your analyses; extract brand mentions and sources; suggest prompts; summarize web pages; power the AI assistant | Content you submit and AI assistant conversations. OpenAI also receives the email domain for the trial check (Section 2.5) | USA |
| Exa | Web search and page retrieval for content features and the AI assistant | Web addresses and search queries, which may reflect what you ask the assistant | USA |
| DataForSEO | Search, keyword and website traffic data | Domains, web addresses and keywords (normally no personal data) | Estonia; servers in Germany and the USA |
| Telegram | Internal notifications to our team | Organization and product names and run statistics; no email addresses or names | Global |
| Sign-in with Google; website icons (favicons), which our servers fetch from Google by domain name | Google account data if you use Google sign-in; for icons, only website domain names (no personal data) | USA |
We also run two tools on our own servers at DigitalOcean (USA):
- Grafana Loki stores application logs (see Section 2.7).
- Langfuse records the AI assistant’s conversations for debugging and quality review: your messages, the assistant’s answers, the data it looked up, your user identifier and your organization’s name.
4.2 AI Providers
- What they receive. AI Providers receive the prompts and content needed for each task. They do not receive your account details (except the email domain in Section 2.5).
- Their terms. We use them under their commercial API terms, under which they do not use this data to train their models.
- Their retention. They may keep it for a limited period, typically up to 30 days, to monitor abuse, as described in their own terms.
- API, not consumer apps. We query their APIs, not their consumer apps.
4.3 Other Disclosures
- Within your organization: other members can see your email address and the organization’s data. An invitee sees the email address of the person who invited them.
- Legal reasons: to comply with law, legal process or requests from public authorities; to enforce our Terms; and to protect the rights, property or safety of Basebright, our users or others.
- Business transfers: as part of a merger, acquisition, financing or sale of assets, subject to this Policy. We will notify you if your data becomes subject to a different privacy policy.
- With your consent or at your direction.
- Aggregated or de-identified information that cannot reasonably be used to identify you.
5. Cookies and Browser Storage
We do not use advertising or analytics cookies. We use only storage that is needed to provide the Service or to remember your settings.
| Name | Where | Purpose | How long |
|---|---|---|---|
sb-…-auth-token (browser storage) | App | Keeps you signed in | Until you sign out or the session expires |
sidebar:state (cookie) | App; demo page on our website | Remembers whether the sidebar is open | 7 days |
| Settings in browser storage (theme, selected organization, filters, panel sizes, onboarding progress, a pending invitation) | App | Remembers your choices | Until you clear them |
theme (browser storage) | Website | Remembers light or dark mode | Until you clear it |
Stripe cookies such as __stripe_mid and __stripe_sid | App | Set by Stripe.js to prevent payment fraud | Up to 1 year |
Stripe.js loads only when you open the form to add a payment card, and then stays active until you reload or close the browser tab.
Because we use only storage that is strictly necessary or that remembers settings you chose, we do not show a cookie banner. If we add analytics in the future, we will ask for your consent where the law requires it.
Emails. Our emails do not contain tracking pixels, and we do not track clicks.
6. Data Retention
| Data | How long we keep it |
|---|---|
| Account, organization and Service data, including prompts, AI responses and settings | While the organization exists. After a verified deletion request or closure of the organization, we delete it within 30 days (see Terms, Section 8.7) |
| AI assistant chat history | Until you delete the chat, or the organization is deleted |
| Invitations | Until accepted or cancelled, or until the organization is deleted |
| Records of payments and credit purchases (amounts, dates, identifiers), including payment event data received from Stripe (which may include the billing name, email and address, and the card brand, last four digits and expiry date) | While the organization exists; after it is deleted, only as long as tax and accounting law requires. Invoices and payment details themselves are held by Stripe |
| Web server logs (IP address, user agent) | 30 days |
| Application logs | 30 days |
| Copies of AI assistant conversations in our debugging tool (Langfuse) | While the organization exists; deleted together with it |
| Demo requests | Until we have handled the request and any follow-up, or earlier if you ask us to delete it |
| Database backups | 7 days |
We may keep data longer where the law requires it, or to establish, exercise or defend legal claims.
7. Security
We use technical and organizational measures appropriate to the risk:
-
Encryption. Data is encrypted in transit (TLS) between your browser, our network provider and our servers. Our database provider encrypts data at rest.
-
Access control. Every request to the Service is authenticated. Our application checks on each request that you belong to the organization whose data you are accessing. Your browser does not access our database directly.
-
Staff access. Administrative access to production systems is limited to the people who need it to run the Service.
-
Sign-in without passwords. Sign-in uses email links or Google; we do not ask for passwords.
-
Log hygiene. Email addresses are masked in application logs, and tokens are removed.
No method of transmission or storage is completely secure. If a personal data breach occurs, we will notify you and the authorities where the law requires it.
8. Your Rights and Choices
Depending on where you live, you may have the right to:
- Access the personal data we hold about you, and receive a copy in a portable format.
- Correct inaccurate data.
- Delete your data.
- Restrict or object to our processing, including processing based on legitimate interests.
- Withdraw consent at any time, where we rely on consent.
How to make a request. Write to [email protected]. We will reply within 30 days. We may need to verify your identity, and we may refer you to your organization’s owner if the request concerns data the organization controls.
Deleting your account or organization. There is no self-service deletion yet, so please write to us. We will delete the data within 30 days of verifying the request. Owners of an organization can also remove members themselves.
Emails.
- Service emails, such as sign-in links, invitations and billing notices, are part of the Service.
- We do not send marketing newsletters. If we start, we will offer an opt-out, or ask for consent where the law requires it.
Complaints. If the GDPR applies, you can complain to the data protection authority where you live or work. In the UK, that is the Information Commissioner’s Office. We would appreciate the chance to address your concern first.
9. Data We Process on Behalf of Customers
9.1 Visitor Data from the Tracking Code
Customers can install our tracking code on their websites to measure visits by AI crawlers and AI-referred visitors.
What the code sends us for each measured request:
- the page path and URL parameters
- the referring page
- the visitor’s browser (user agent) and IP address
What we do with it:
- We combine the IP address and user agent with the date to create a pseudonymous daily visitor code.
- We do not store the IP address itself.
- We classify the user agent to recognize AI crawlers.
- We store the page path, URL parameters, referring page, visitor type and the pseudonymous code.
The customer who operates the website is the controller of this data, and we process it under their instructions and our Data Processing Addendum. We keep Visitor Data while the customer’s organization exists, unless the customer asks us to delete it earlier, and delete it together with the organization. If you visited a website that uses our tracking code, please contact that website’s operator.
9.2 Personal Data in Customer Content
Prompts, AI responses and fetched web pages can contain personal data, such as the names of people mentioned in them. We process such data on behalf of the customer and under the Data Processing Addendum.
10. International Data Transfers
Basebright Inc. is incorporated in the United States. Our servers and database are in the United States (Virginia). Some providers, such as Cloudflare and Telegram, operate globally.
When we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to service providers in other countries, we rely on one of the following:
- The provider’s certification under the EU-U.S. Data Privacy Framework, including the UK Extension and the Swiss-U.S. framework, where the provider is certified.
- The European Commission’s Standard Contractual Clauses (with the UK Addendum) included in the provider’s data processing terms.
You can ask us for more information about these safeguards.
11. U.S. State Privacy Rights
Residents of California and other U.S. states with comprehensive privacy laws may have the right to:
- know what personal data we collect, use and disclose;
- access, correct and delete it; and
- not be discriminated against for exercising these rights.
We do not sell or share personal data for cross-context behavioral advertising, and we do not use sensitive personal information for purposes that require an opt-out.
In the past 12 months we collected the categories below, for the purposes in Section 3, and disclosed them to the service providers in Section 4:
- Identifiers: name, email address and IP address.
- Commercial information: plans, payments and credit purchases.
- Internet activity: logs and use of the Service.
- Professional information: company name, website and role in an organization.
To make a request, write to [email protected]. You may use an authorized agent. We will verify requests before acting on them.
12. Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
13. Changes to This Policy
We may update this Policy to reflect changes in our practices or the law.
- We will change the “Last updated” date at the top of this page.
- For material changes, we will notify account owners by email or in the Service before the changes take effect.
14. Contact Us
Basebright Inc. 2810 N Church St Wilmington, Delaware 19802, USA Email: [email protected]