BaseFrame← Back to Home

Privacy Policy

Effective Date: May 15, 2026

Last Updated: May 15, 2026

This Privacy Policy (“Policy”) describes how BaseFrame Inc. (“BaseFrame,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with your use of the BaseFrame platform, website (https://baseframe.co), communications between you and us, use of artificial intelligence and machine learning software, and related services (collectively, the “Services”). In this Policy, “Personal Information” means any information relating to an identified or identifiable individual.

By using the Services, you agree to the collection and use of information in accordance with this Policy. If you do not agree with this Policy, please do not use the Services.

IMPORTANT NOTICE REGARDING AI AGENTS: The Services enable you to connect third-party services (such as email, messaging, productivity, and other applications) to AI-powered agents operating in virtual machines. When you connect such services, the AI agents will access and process data from those services on your behalf. This may include personal data of you and others. You are responsible for ensuring that your use of the Services complies with applicable privacy laws and that you have obtained any necessary consents. BaseFrame does not control the actions taken by AI agents and is not responsible for how AI agents access, use, or disclose data from connected services.

1. Personal Information We Collect

We may collect Personal Information about you directly from you and from third parties, as well as automatically through your use of the Services.

Information Provided by You

Contact Information: We may collect professional contact details such as first and last name, email address, phone number, company name, title and department, and other relevant information necessary for us to manage your account and business relationship.

Profile Data: We may collect information such as the username and password that you may set to establish an online account with us, biographical information, and any other information that you add or is associated with your account.

Payment Information: If you subscribe to our Services, we will ask you to provide your payment information, such as your credit card number and billing address, to process your payment. Payment processing is handled by our third-party payment processor, and we do not store complete credit card numbers.

User-Generated Content: Such as photos, images, music, videos, comments, questions, messages, correspondence, and other content or information that you generate, transmit, or otherwise make available on the Service to us or other persons, as well as associated metadata.

Communication Information: When you contact us via a contact form, email, or other means, you may provide us with communication information, such as your name, email address, company, and the content, date, and time of your message.

Support Information: When you request technical support services, we will process your contact information, communication information, as well as information on the reasons for your support request, and any additional information you may provide.

API Keys and Credentials: You may provide API keys for third-party services (such as Glyphic or Granola). These are stored encrypted on your local device and are not accessible to BaseFrame. Authentication tokens used by the Desktop Application are stored in your operating system's secure keychain (macOS Keychain or Windows Credential Manager) and are never transmitted to BaseFrame.

Information from Connected Services

Third-Party Service Data: When you authorize connections to third-party services (such as email, messaging, calendars, file storage, development tools, or other applications), data from those services may be accessed and processed by the Desktop Application to enrich workflow analysis. This data may include: email and calendar metadata; contacts and address books; calendar events and scheduling information; files and documents; usage data from connected applications; and any other data accessible through the APIs of those services.

Note: Third-party service connections are brokered through Composio, an integration infrastructure provider. A per-user entity is created in Composio on your behalf when you connect a service. All Composio operations are proxied through BaseFrame's servers, so your credentials are never exposed to Composio directly.

Microsoft Account: When you connect a Microsoft account, an OAuth access token is stored encrypted in BaseFrame's cloud database to enable persistent access to Microsoft services (Outlook, Teams, OneDrive, etc.). This token is used only to fetch data for workflow analysis on your behalf.

Information Collected via Automated Means

Website Usage Information: When you use our website (baseframe.co), we may automatically collect information about your visit, including via cookies and similar technologies. This may include your IP address, web browser, device type, and the pages you visit. The Desktop Application does not send analytics events or usage telemetry. No product analytics data leaves your device from the Desktop Application.

Device and Log Information: We collect information about the devices you use to access the Services, including: IP address; browser type and version; operating system; device identifiers; and log data including access times and referring URLs. This applies to website and API usage; the Desktop Application does not generate server-side logs beyond what is required to authenticate requests.

Crash Reports: If the Desktop Application crashes, a report is saved locally containing an error stack trace and recent log data. File paths and other identifiable information are anonymized before saving. On the next launch, you will be explicitly asked for consent before any crash report is transmitted to BaseFrame. We use crash reports solely to identify and fix software defects. You may decline to submit them at any time.

Information Collected from Third Parties

Information from Other Sources: We may obtain information, including Personal Information, from third parties and sources other than our Services, such as our business customers and partners. If we combine or associate information from other sources with Personal Information that we collect through our Services, we will treat the combined information as Personal Information in accordance with this Policy.

Local Data Sources Read by the Desktop App

The BaseFrame desktop app reads on-device data to find the workflows worth automating. The exact sources depend on which operating system you run.

macOS. We read passively from sources Apple already maintains: app-focus events from the Biome stream (Library/Biome), historical app usage from Screen Time (knowledgeC.db), Apple Mail / Calendar / Reminders / Contacts, browser history (Safari, Chrome, Arc, Brave, Edge, Firefox), and per-app SQLite caches (Slack, Notion, Microsoft Office, Linear, etc.). We never read message bodies. macOS Full Disk Access is required for these reads.

Windows.Windows has no equivalent passive app-focus stream, so we run a small background process that records the foreground window’s application name and title once per second. Window titles are scrubbed for emails, phone numbers, file paths, and other PII patterns before they are stored locally. You can disable title capture in Settings. We additionally read browser history (Edge, Chrome, Firefox), Outlook mail headers (subject, sender, recipients) and calendar entries via MAPI, and Microsoft Teams channel activity. We never read message bodies.

All raw local data stays on your device. To generate workflow recommendations, the Desktop Application constructs prompts from scrubbed activity metadata (app names, timestamps, and PII-scrubbed window titles) and sends them to BaseFrame's servers, which forward them to an AI provider for processing. No message bodies, file contents, email text, or unredacted personal data are included in these prompts. Activity data that has already been summarized into a workflow fingerprint is cached locally and is not re-sent.

2. How We Use Personal Information

We may use Personal Information for the following purposes:

Providing the Services: We may use your Personal Information to provide and personalize the Services, process payments, provide customer service, maintain or service accounts, verify customer information, operate the Desktop Application, facilitate AI workflow analysis, enable connections to third-party services, and undertake similar services.

Support: We use Personal Information to provide technical support, including diagnosing and resolving any issues you report.

Customer Relationship Management: We may process your Personal Information for customer relationship management purposes.

Communicating with You: We may use your email address and other Personal Information as necessary to contact you for administrative purposes, to manage your account, provide information you request, send service-related notices, updates, security alerts, and respond to your comments and questions.

Understanding Usage and Improving the Services: We use the information that we collect on the Services to understand and analyze usage trends and preferences, improve the Services, and develop new products, services, features, and functionality.

Marketing: We may use your email address and other Personal Information to send marketing communications, including updates on promotions and events relating to our products and services. You have the ability to opt out of receiving promotional communications as described below under Your Rights and Choices.

Crash Diagnostics: We use crash reports you consent to submit to identify, diagnose, and fix software defects in the Desktop Application.

Security and Fraud Prevention: We may use your Personal Information to detect, prevent, and respond to fraud, abuse, security incidents, and other harmful activities.

Administrative and Legal Purposes: We may use your Personal Information to address administrative or legal issues, including but not limited to intellectual property infringements, defamation, or privacy rights, and to comply with applicable laws, regulations, legal processes, and governmental requests.

Aggregation:We may aggregate or otherwise de-identify Personal Information and use the resulting information (“De-identified Information”) for any lawful purpose. We will maintain and use De-identified Information in de-identified form and will not attempt to re-identify the information, except to verify our de-identification processes.

Important: We do not use Customer Content (including data from Connected Services) to train AI models or for any purpose other than providing the Services to you.

3. When We Disclose Information

We may disclose information to third parties in the following circumstances:

Service Providers: We may engage third-party service providers to assist in providing hosting services or other services necessary for the operation of the Services. These service providers may have access to or process your information as part of providing those services for us. They are contractually obligated to protect your information. Key service providers include:

Clerk: account authentication and identity management.

Stripe: payment processing and subscription billing.

Composio: integration infrastructure that brokers connections to third-party services (Gmail, Slack, Linear, and 46+ others). When you connect a third-party service, a per-user entity is created in Composio on your behalf. All Composio API requests are routed through BaseFrame's servers.

Google Cloud Platform: cloud infrastructure, database, and serverless compute hosting.

Meta Platforms, Inc.: advertising measurement and audience building via the Meta Pixel (browser-side) and Meta Conversions API (server-side). On our public website only. Server-side events are sent for signup, demo requests, downloads, and subscription billing milestones, and include hashed email, IP address, user agent, and the Meta browser cookies (_fbp, _fbc) when present. See Section 5 for details and the opt-out path.

RB2B, Maverick, and Delivr AI: marketing analytics and visitor identification on our public website only (subject to your cookie consent). See Section 5 for details.

Rewardful: affiliate-program attribution on our public website only (subject to your cookie consent).

PostHog: product analytics, session recording (with inputs masked), and feature-flag delivery (subject to your cookie consent).

Clerk: identity, authentication, and user management for signed-in users. Clerk stores email, hashed passwords (if used), and basic profile information.

AI Providers:When you use AI agents, your prompts and instructions may be processed by third-party AI providers (such as Anthropic, OpenAI, or other providers you select) pursuant to your API key and their terms of service. BaseFrame does not control how AI providers process this data, and such processing is governed by the applicable AI provider’s terms and privacy policy.

Connected Services: When you connect third-party services, information is shared with those services as necessary to enable the integration. Such sharing is governed by the terms and privacy policies of those services.

Business Purposes: We may make certain information available to third parties for various purposes, including compliance with reporting obligations or for our business purposes. Any such disclosure will be in accordance with applicable laws and regulations.

Legal Requirements: We may disclose your information if required to do so by law or in the good-faith belief that such action is necessary to comply with applicable laws, respond to a court order, judicial or other government subpoena or warrant, or to cooperate with law enforcement or other governmental agencies.

Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, we may transfer your information to the acquiring entity as part of the transaction.

Affiliates: We may share Personal Information with our affiliates, subsidiaries, and branch offices to which it is reasonably necessary or desirable for us to disclose Personal Information for the purposes mentioned above.

With Your Consent: We may share information with your consent or at your direction.

4. AI Processing and Workflow Discovery

The Desktop Application analyzes your local work activity to identify recurring workflows and surface automation suggestions. You should be aware of how AI processing works:

Local Analysis: The Desktop Application reads activity metadata from your device (app usage, browser history, calendar entries, etc.) as described in Section 1. This data is processed locally first to construct anonymized activity summaries.

AI Provider Processing: Activity summaries and workflow discovery prompts are transmitted to BaseFrame's servers and forwarded to a third-party AI provider (currently routed via OpenRouter) for analysis. No raw message bodies or file contents are included. Processing by the AI provider is governed by that provider's terms of service and privacy policy. BaseFrame does not control how AI providers handle data once transmitted, and different providers have different data retention policies.

Connected Service Data: When you connect third-party services (such as Gmail, Slack, or Linear), the Desktop Application may fetch metadata from those services (subject lines, event titles, channel names, record titles) to enrich workflow analysis. This metadata may be included in AI prompts. We do not include message bodies or file contents.

Workflow Sharing: You may choose to publish a workflow snapshot to a public URL. When you do, the workflow name, description, automation suggestion, and app list are stored on BaseFrame's servers and accessible to anyone with the link. Sharing is entirely opt-in.

Your Responsibility: You are responsible for ensuring you have authority to connect third-party services; obtaining any necessary consents from individuals whose data may appear in your activity; and complying with the privacy policies of any AI providers or connected services you use.

5. Cookies and Other Tracking Technologies

We and our service providers may use cookies and similar technologies to collect usage and browser information about how you use our Services. The technologies we use for this automatic data collection may include cookies and web beacons that permit us to verify system and server integrity and generate statistics around the popularity of certain content.

Essential Cookies: Necessary for the operation of the Services, including authentication and security.

Analytics Cookies: Help us understand how visitors interact with our website (baseframe.co). We use PostHog to collect and analyze website usage data. The Desktop Application does not use PostHog or any analytics service. No telemetry or usage events are collected from the Desktop Application.

Advertising and Marketing Pixels:On our website (baseframe.co), we use the following third-party advertising and marketing technologies. These are loaded by default and may be opted out of via the “Do Not Sell or Share My Personal Information” link in the footer or by enabling the Global Privacy Control signal in your browser. None of these technologies operate inside the Desktop Application.

Meta (Facebook) Pixel:We use the Meta Pixel, a browser-side tracking technology from Meta Platforms, Inc., to measure the effectiveness of our advertising on Facebook and Instagram, to build custom and lookalike audiences, and to track conversions (such as page views, leads, signups, downloads, and subscription purchases). The Meta Pixel may share your IP address, browser information, page URL, interaction events, and the Meta browser cookies (_fbp, _fbc) with Meta. Meta may combine this information with other data they collect about you. We also pass your Clerk user identifier (after sign-in) as an “external_id” to help Meta match events across devices. You can manage your Meta ad preferences at facebook.com/settings?tab=ads.

Meta Conversions API (CAPI):In addition to the browser-side Pixel, we send certain conversion events to Meta server-side via the Meta Conversions API. This includes event types such as Lead (demo request), CompleteRegistration (signup), DownloadStarted (desktop app download), Subscribe (subscription started), and Purchase (subscription payment). For each event, we send the event name, a unique event identifier (used for de-duplication with the browser Pixel), the page URL, an action source, and user-data fields that we hash with SHA-256 before transmission: email address, phone number (when provided), first and last name (when provided), Clerk user identifier (“external_id”), country code, and the Meta browser cookies (_fbp, _fbc) when they exist. We also include the request IP address and user agent. Meta uses these events for ad delivery optimization, conversion measurement, and audience building.

Limited Data Use (LDU):For visitors whose IP indicates California or another applicable jurisdiction, we instruct Meta to process events under their Limited Data Use mode, which restricts Meta’s secondary use of the data per CCPA/CPRA requirements.

RB2B: We use RB2B to identify anonymous business visitors to our website. RB2B may match website visitors against a third-party business contact database and share identifying information (such as company name and professional contact details) with us. RB2B operates only within the United States and only on visitors associated with a business context. You may request opt-out at rb2b.com/privacy.

Maverick: We use Maverick (Maverick Intelligence) to personalize website content and analyze visitor intent. Maverick may collect browsing behavior and device information to power its personalization features.

Delivr AI / Sitelytics: We use a Delivr AI tracking pixel served via sitelytics.tech to attribute traffic and measure the effectiveness of marketing channels.

Rewardful: We use Rewardful to attribute affiliate-program referrals. Rewardful sets first-party cookies to identify the referring affiliate when a visitor lands on our site via an affiliate link, and records that attribution when the visitor signs up or pays.

Marketing Attribution Storage (first-party):When you arrive at our site from an advertising campaign, we store the URL parameters identifying that campaign (UTM tags and click identifiers such as fbclid, gclid, msclkid, ttclid) in your browser’s local storage so that we can correctly attribute a later signup to its original source. These values stay on your device until you opt out, sign up (at which point they are sent to our servers to be associated with your account), or clear your browser data.

You can decline all of the above marketing and analytics technologies by using the “Do Not Sell or Share My Personal Information” link in the footer or by enabling Global Privacy Control in your browser. When you opt out, we stop loading the Meta Pixel, RB2B, Maverick, Delivr AI, Rewardful, and PostHog; we clear the Meta browser cookies (_fbp, _fbc) and any stored marketing attribution from your device.

Preference Cookies: Remember your settings and preferences.

Cookie Choices: You can manage cookie preferences by customizing your browser settings to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable certain cookies, please note that some parts of our Services may not function properly.

Interest-Based Advertising: We may allow third parties to collect Personal Information to provide interest-based advertising. You can opt out of interest-based advertising through the Digital Advertising Alliance (optout.aboutads.info) or Network Advertising Initiative (optout.networkadvertising.org).

Selling Personal Information:While we do not sell Personal Information in exchange for monetary consideration, we do disclose Personal Information for other benefits that could be deemed a “sale” under various data protection laws. You may opt out as described in Section 6.

6. Your Rights and Choices

Depending on your location, you may have certain rights regarding your Personal Information under applicable data protection laws. To exercise any of the privacy rights afforded to you, please see the How to Contact Us section below.

Access: The right to request access to and obtain a copy of any Personal Information we may have about you.

Deletion: The right to delete your Personal Information that we have collected or obtained, subject to certain exceptions.

Correction: The right to request that we correct any inaccuracies in your Personal Information, subject to certain exceptions.

Opt Out of Certain Processing: The right to opt out of the processing of your Personal Information for purposes of targeted or cross-context behavioral advertising and/or the sale of your Personal Information.

Objection/Restriction of Processing: The right to object to or restrict us from processing your Personal Information in certain circumstances.

Withdraw Consent: The right to withdraw your consent where we are relying on your consent to process your Personal Information.

Portability: The right to receive your Personal Information in a structured, commonly used, and machine-readable format.

Automated Decision-Making and Profiling: We do not, at this time, use Personal Information for automated decision making or for profiling in furtherance of decisions that produce legal or similarly significant effects. Thus, we do not fulfill requests to opt out of these uses.

Lodge a Complaint: The right to lodge a complaint with a supervisory authority or other regulatory agency if you believe we have violated any of the rights afforded to you under applicable data protection laws. We encourage you to first reach out to us so we have an opportunity to address your concerns directly before you do so.

Global Privacy Control (GPC): You may also exercise your opt-out rights by broadcasting an Opt-Out Preference Signal, such as the Global Privacy Control (GPC). We honor Opt-Out Preference Signals, including GPC. If you choose to use an Opt-Out Preference Signal, you will need to turn it on for each supported browser or browser extension you use.

You will not be discriminated against in any way by virtue of your exercise of the rights listed in this Policy. However, should you withdraw your consent or object to the processing of your Personal Information, or if you choose not to provide certain Personal Information, we may be unable to provide some, or all, of our Services to you.

Marketing Communications: You have the right to opt out of receiving promotional communications from us. You can do so by following the instructions included in the communication or by contacting us using the contact details provided at the end of this Policy.

To exercise these rights, please contact us at team@baseframe.co. We will respond within the timeframes required by applicable law.

7. Data Retention

We retain Personal Information for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required or permitted by law. We take reasonable steps to ensure that Personal Information is securely deleted or anonymized when no longer needed.

Account Information: Retained for the duration of your account and for a reasonable period thereafter for legal, tax, and audit purposes.

Local Device Data: Activity data cached by the Desktop Application is stored encrypted on your device and is under your control. It can be removed by deleting the application's data directory or uninstalling the Desktop Application.

Cloud Account Data: Account-associated data stored on BaseFrame's servers (such as subscription status, connected service tokens, and shared workflow snapshots) is retained while your account is active. Following account closure, this data may be deleted within thirty (30) days.

Usage and Log Data: Server-side log data is retained for up to 1 month for security and debugging purposes.

Communication Records: Support communications may be retained for quality assurance and legal purposes.

8. Information Security

We implement reasonable security measures to protect the Personal Information we collect and maintain, including:

Encryption in Transit: Data transmitted between the Desktop Application (or your browser) and BaseFrame's servers is encrypted using industry-standard TLS/SSL.

Local Data Encryption: Activity data cached by the Desktop Application on your device is encrypted at rest using AES-256-GCM. The encryption key is stored in a user-only file on your device and is never transmitted to BaseFrame.

Cloud Data Encryption: Sensitive data stored on BaseFrame's servers (such as Microsoft OAuth tokens) is encrypted at rest.

Access Controls: We maintain access controls to limit access to information to authorized personnel.

Security Monitoring: We monitor our systems for potential security threats and vulnerabilities.

However, no security system is impenetrable, and we cannot guarantee the security of your information. You acknowledge that you provide information at your own risk. You are responsible for maintaining the security of your account credentials and API keys.

9. International Data Transfers

Our Services are hosted in the United States of America. If you choose to use our Services from a different jurisdiction, please note that your Personal Information may be transferred to and stored in the United States of America. By providing your Personal Information, you consent to the transfer and processing of your information in accordance with this Policy.

Individuals in the European Union, European Economic Area, Switzerland, and the United Kingdom

This section provides additional information regarding our processing of Personal Information of people located in the European Union (EU), European Economic Area (EEA), Switzerland, and the United Kingdom (UK) in accordance with the EU General Data Protection Regulation (GDPR), UK Data Protection Regulation, and the Swiss Federal Data Protection Act.

For transfers from the EEA, United Kingdom, or Switzerland, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses, adequacy decisions, or other lawful bases.

10. Legal Bases for Processing

Our legal basis for processing Personal Information depends on the Personal Information involved and the context in which we process it. Where we act as a controller, we process your Personal Information:

With your consent: Where you have given us consent to process your Personal Information for specific purposes.

Where necessary to perform a contract: To provide the Services you have requested.

To comply with our legal obligations: Where we are legally required to process your data.

Where doing so is in our legitimate interests: Including the purposes described in this Policy, such as analytics, security, fraud prevention, and improvement of our Services, and such interests are not outweighed by your rights and freedoms.

11. Special Category Data

We do not intend to collect any Special Category Data, which is any data that reveals your racial or ethnic origin, political opinions, religious, moral or philosophical beliefs, trade union membership, political views, the processing of genetic data, biometric data for the purpose of identifying a person, and data concerning health or a person’s sex life and/or sexual orientation. Please refrain from sending us any Special Category Data.

12. Children’s Privacy

The Services are not intended for children under the age of 18. We do not knowingly collect Personal Information from children under the age of 18 without parental consent. If you believe we have collected information from a child under the age of 18, please contact us using the contact details provided at the end of this Policy, and we will take steps to delete such information.

13. California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including:

Right to Know: The right to know what personal information we collect, use, disclose, and sell.

Right to Delete: The right to request deletion of personal information.

Right to Correct: The right to correct inaccurate personal information.

Right to Opt-Out: The right to opt out of the sale or sharing of personal information.

Right to Non-Discrimination: The right not to be discriminated against for exercising your privacy rights.

To exercise your California privacy rights, contact us at team@baseframe.co.

14. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) or equivalent laws:

Data Controller: BaseFrame Inc. is the data controller for Personal Information processed in connection with the Services.

Data Protection Officer: Not applicable.

Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority if you believe we have violated your privacy rights. We encourage you to contact us first so we can address your concerns.

15. Third-Party Services

The Services may contain features or links to websites and services provided by third parties. Any information you provide on third-party sites or services is subject to those operators’ privacy and security policies. We encourage you to review the privacy policies of those third parties before providing them with any information. We are not responsible for the privacy practices of third parties.

16. Changes to This Privacy Policy

We may update this Policy from time to time. The “Last Updated” date at the beginning of this Policy indicates when the latest revisions were made. Changes are effective when published on our website. For material changes, we will provide notice through the Services or by email. Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Policy.

We encourage you to periodically review this Policy to stay informed of how we collect, use, and disclose your Personal Information.

17. How to Contact Us

If you have any questions or concerns about this Privacy Policy or our privacy practices, please contact us at:

BaseFrame Inc.

2261 Market Street, Suite 69210

San Francisco, CA 94114

Email: team@baseframe.co

Website: https://baseframe.co

Please allow a reasonable time for us to respond to your inquiry.