BaseFrame
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
“Important: We do not use Customer Content (including data from Connected Services) to train AI models or for any purpose other than providing the Services to you.”
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Watch: subprocessors data sharing
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Identifies categories of third-party service providers (hosting, authentication, payment, integration infrastructure) that may access or process user information, and states that these providers are contractually obligated to protect user information — establishes disclosure obligations and protective contractual requirements for subprocessors.
Discloses that prompts may be processed by third-party AI providers selected by the user pursuant to the user's own API key, states that BaseFrame does not control how those providers process data, and notes such processing is governed by the AI provider's own terms — disclaimer of BaseFrame's responsibility for third-party AI provider processing.
Expressly prohibits using Customer Content (including data from Connected Services) to train AI models or for any purpose other than providing the Services — user-favorable restriction that forbids training use of customer data.
How to read this page: Overall risk rates what BaseFrame's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 35 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
Blocked core document: Privacy Policy
- Privacy PolicyVerified - read in full - 35 citationsLast captured 2026-07-19
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Enumerates specific categories of Personal Information BaseFrame may collect directly from users (contact details, profile data, payment information), establishing the operative scope of data collection practices and creating an obligation of transparency about those practices.
" Contact Information: We may collect professional contact details such as first and last name, email address, phone number, company name, title and department, and other relevant information necessary for us to manage your account and busin..."
Restricts BaseFrame's access to user-provided API keys and authentication tokens by stating they are stored encrypted locally on the device, are never transmitted to BaseFrame, and are not accessible to BaseFrame — user-favorable restriction limiting the company's data access.
" API Keys and Credentials: You may provide API keys for third-party services (such as Glyphic or Granola). These are stored encrypted on your local device and are not accessible to BaseFrame. Authentication tokens used by the Desktop Applic..."
Describes automated collection of website usage data (IP address, browser, device type, pages visited) via cookies, and expressly states that the Desktop Application sends no analytics or usage telemetry — the latter is a user-favorable restriction on data collection from the application.
" Website Usage Information: When you use our website (baseframe.co), we may automatically collect information about your visit, including via cookies and similar technologies. This may include your IP address, web browser, device type, and ..."
Prohibits discrimination against users for exercising their privacy rights, while noting that withdrawal of consent may limit service delivery — user-favorable non-discrimination restriction, with a service-impact caveat. Also grants users the right to opt out of marketing communications.
" You will not be discriminated against in any way by virtue of your exercise of the rights listed in this Policy. However, should you withdraw your consent or object to the processing of your Personal Information, or if you choose not to pr..."
States that Personal Information may be obtained from third-party sources and partners, and that any combined information will be treated as Personal Information in accordance with the policy — imposes an obligation to apply policy protections to third-party-sourced data.
" Information from Other Sources: We may obtain information, including Personal Information, from third parties and sources other than our Services, such as our business customers and partners. If we combine or associate information from oth..."
Establishes the procedure for California residents to exercise their privacy rights by directing them to contact the provider at a specified email address.
" To exercise your California privacy rights, contact us at team@baseframe.co ."
Disclaims any guarantee of security system integrity, placing the risk of information disclosure on the user, and assigns responsibility for maintaining account credentials and API key security to the user.
" However, no security system is impenetrable, and we cannot guarantee the security of your information. You acknowledge that you provide information at your own risk. You are responsible for maintaining the security of your account credenti..."
Identifies categories of third-party service providers (hosting, authentication, payment, integration infrastructure) that may access or process user information, and states that these providers are contractually obligated to protect user information — establishes disclosure obligations and protective contractual requirements for subprocessors.
" We may disclose information to third parties in the following circumstances: Service Providers: We may engage third-party service providers to assist in providing hosting services or other services necessary for the operation of the Servi..."
Clause A implies consent to data disclosure by simply using the services, while Clause B states that all data sharing requires an explicit opt-in, creating conflicting mechanisms for user consent.
" This Privacy Policy ( “Policy” ) describes how BaseFrame Inc. ( “BaseFrame,” “we,” “us,” or “our” ) collects, uses, discloses, and protects information in connection with your use of the BaseFrame platform, website (https://baseframe.co), communications between you and us, use of artificial intelligence and machine learning software, and related services (collectively, the “Services” ). In this Policy, “Personal Information” means any information relating to an identified or identifiable individual. By using the Services, you agree to the collection and use of information in accordance with this Policy. If you do not agree with this Policy, please do not use the Services. IMPORTANT NOTICE REGARDING AI AGENTS: The Services enable you to connect third-party services (such as email, messaging, productivity, and other applications) to AI-powered agents operating in virtual machines. When you connect such services, the AI agents will access and process data from those services on your behalf. This may include personal data of you and others. You are responsible for ensuring that your use of the Services complies with applicable privacy laws and that you have obtained any necessary consents. BaseFrame does not control the actions taken by AI agents and is not responsible for how AI agents access, use, or disclose data from connected services."
"Sharing is entirely opt-in. Your Responsibility: You are responsible for ensuring you have authority to connect third-party services; obtaining any necessary consents from individuals whose data may appear in your activity; and complying with the privacy policies of any AI providers or connected services you use."
Within one document
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" We may disclose information to third parties in the following circumstances: Service Providers: We may engage third-party service providers to assist in providing hosting services or other services necessary for the operation of the Services. These service providers may have access to or process your information as part of providing those services for us. They are contractually obligated to protect your information. Key service providers include: Clerk : account authentication and identity management. Stripe : payment processing and subscription billing. Composio : integration infrastructure that brokers connections to third-party services (Gmail, Slack, Linear, and 46+ others). When you connect a third-party service, a per-user entity is created in Composio on your behalf. All Composio API requests are routed through BaseFrame's servers. Google Cloud Platform : cloud infrastructure, database, and serverless compute hosting. Meta Platforms, Inc. : advertising measurement and audience building via the Meta Pixel (browser-side) and Meta Conversions API (server-side). On our public website only. Server-side events are sent for signup, demo requests, downloads, and subscription billing milestones, and include hashed email, IP address, user agent, and the Meta browser cookies (_fbp, _fbc) when present. See Section 5 for details and the opt-out path. RB2B, Maverick, and Delivr AI : marketing analytics and visitor identification on our public website only (subject to your cookie consent). "
Identifies categories of third-party service providers (hosting, authentication, payment, integration infrastructure) that may access or process user information, and states that these providers are contractually obligated to protect user information — establishes disclosure obligations and protective contractual requirements for subprocessors.
AI-generated interpretation, not legal advice.
" AI Providers: When you use AI agents, your prompts and instructions may be processed by third-party AI providers (such as Anthropic, OpenAI, or other providers you select) pursuant to your API key and their terms of service. BaseFrame does not control how AI providers process this data, and such processing is governed by the applicable AI provider’s terms and privacy policy. Connected Services: When you connect third-party services, information is shared with those services as necessary to enable the integration. Such sharing is governed by the terms and privacy policies of those services. Business Purposes: We may make certain information available to third parties for various purposes, including compliance with reporting obligations or for our business purposes. Any such disclosure will be in accordance with applicable laws and regulations. Legal Requirements: We may disclose your information if required to do so by law or in the good-faith belief that such action is necessary to comply with applicable laws, respond to a court order, judicial or other government subpoena or warrant, or to cooperate with law enforcement or other governmental agencies. Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, we may transfer your information to the acquiring entity as part of the transaction. Affiliates: We may share Personal Information with our affiliates, subsidiaries, and branch offices to which it is reasonably necessary or desirable for us to disclose Personal Information for the purposes mentioned above. With Your Consent: We may share information with your consent or at your direction."
Discloses that prompts may be processed by third-party AI providers selected by the user pursuant to the user's own API key, states that BaseFrame does not control how those providers process data, and notes such processing is governed by the AI provider's own terms — disclaimer of BaseFrame's responsibility for third-party AI provider processing.
AI-generated interpretation, not legal advice.
" Important: We do not use Customer Content (including data from Connected Services) to train AI models or for any purpose other than providing the Services to you."
Expressly prohibits using Customer Content (including data from Connected Services) to train AI models or for any purpose other than providing the Services — user-favorable restriction that forbids training use of customer data.
AI-generated interpretation, not legal advice.
" API Keys and Credentials: You may provide API keys for third-party services (such as Glyphic or Granola). These are stored encrypted on your local device and are not accessible to BaseFrame. Authentication tokens used by the Desktop Application are stored in your operating system's secure keychain (macOS Keychain or Windows Credential Manager) and are never transmitted to BaseFrame."
Restricts BaseFrame's access to user-provided API keys and authentication tokens by stating they are stored encrypted locally on the device, are never transmitted to BaseFrame, and are not accessible to BaseFrame — user-favorable restriction limiting the company's data access.
AI-generated interpretation, not legal advice.
" We and our service providers may use cookies and similar technologies to collect usage and browser information about how you use our Services. The technologies we use for this automatic data collection may include cookies and web beacons that permit us to verify system and server integrity and generate statistics around the popularity of certain content. Essential Cookies: Necessary for the operation of the Services, including authentication and security. Analytics Cookies: Help us understand how visitors interact with our website (baseframe.co). We use PostHog to collect and analyze website usage data. The Desktop Application does not use PostHog or any analytics service. No telemetry or usage events are collected from the Desktop Application. Advertising and Marketing Pixels: On our website (baseframe.co), we use the following third-party advertising and marketing technologies. These are loaded by default and may be opted out of via the “Do Not Sell or Share My Personal Information” link in the footer or by enabling the Global Privacy Control signal in your browser. None of these technologies operate inside the Desktop Application. Meta (Facebook) Pixel: We use the Meta Pixel, a browser-side tracking technology from Meta Platforms, Inc., to measure the effectiveness of our advertising on Facebook and Instagram, to build custom and lookalike audiences, and to track conversions (such as page views, leads, signups, downloads, and subscription purchases). "
Describes the use of cookies and similar technologies by BaseFrame and its service providers to collect usage and browser information, categorizes them as essential cookies (necessary for authentication and security) and analytics cookies (for website interaction analysis via a named analytics provider), establishing the operative basis for automated data collection.
AI-generated interpretation, not legal advice.
" You can decline all of the above marketing and analytics technologies by using the “Do Not Sell or Share My Personal Information” link in the footer or by enabling Global Privacy Control in your browser. When you opt out, we stop loading the Meta Pixel, RB2B, Maverick, Delivr AI, Rewardful, and PostHog; we clear the Meta browser cookies (_fbp, _fbc) and any stored marketing attribution from your device. Preference Cookies: Remember your settings and preferences. Cookie Choices: You can manage cookie preferences by customizing your browser settings to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable certain cookies, please note that some parts of our Services may not function properly. Interest-Based Advertising: We may allow third parties to collect Personal Information to provide interest-based advertising. You can opt out of interest-based advertising through the Digital Advertising Alliance (optout.aboutads.info) or Network Advertising Initiative (optout.networkadvertising.org). Selling Personal Information: While we do not sell Personal Information in exchange for monetary consideration, we do disclose Personal Information for other benefits that could be deemed a “sale” under various data protection laws. You may opt out as described in Section 6."
Grants users the right to opt out of all marketing and analytics tracking technologies via a named link or browser signal, and specifies the effect of opting out (stopping loading of named third-party scripts and clearing stored marketing cookies) — user-favorable right to withdraw consent and restrict data collection.
AI-generated interpretation, not legal advice.
" You will not be discriminated against in any way by virtue of your exercise of the rights listed in this Policy. However, should you withdraw your consent or object to the processing of your Personal Information, or if you choose not to provide certain Personal Information, we may be unable to provide some, or all, of our Services to you. Marketing Communications: You have the right to opt out of receiving promotional communications from us. You can do so by following the instructions included in the communication or by contacting us using the contact details provided at the end of this Policy. To exercise these rights, please contact us at team@baseframe.co . We will respond within the timeframes required by applicable law."
Prohibits discrimination against users for exercising their privacy rights, while noting that withdrawal of consent may limit service delivery — user-favorable non-discrimination restriction, with a service-impact caveat. Also grants users the right to opt out of marketing communications.
AI-generated interpretation, not legal advice.
" We do not intend to collect any Special Category Data, which is any data that reveals your racial or ethnic origin, political opinions, religious, moral or philosophical beliefs, trade union membership, political views, the processing of genetic data, biometric data for the purpose of identifying a person, and data concerning health or a person’s sex life and/or sexual orientation. Please refrain from sending us any Special Category Data."
Restricts the provider from intentionally collecting special category data and instructs users to refrain from submitting such data, defining special category data as information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric identity data, health data, or data about sex life or sexual orientation.
AI-generated interpretation, not legal advice.
" The Services are not intended for children under the age of 18. We do not knowingly collect Personal Information from children under the age of 18 without parental consent. If you believe we have collected information from a child under the age of 18, please contact us using the contact details provided at the end of this Policy, and we will take steps to delete such information."
Restricts the provider from knowingly collecting personal information from individuals under 18 without parental consent, and establishes a procedure whereby the provider will delete such information upon notice, protecting minors from data collection.
AI-generated interpretation, not legal advice.
" This section provides additional information regarding our processing of Personal Information of people located in the European Union (EU), European Economic Area (EEA), Switzerland, and the United Kingdom (UK) in accordance with the EU General Data Protection Regulation (GDPR), UK Data Protection Regulation, and the Swiss Federal Data Protection Act. For transfers from the EEA, United Kingdom, or Switzerland, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses, adequacy decisions, or other lawful bases."
Incorporates by reference specific regional data protection regulations and designates lawful cross-border transfer mechanisms such as standard contractual clauses, adequacy decisions, or other lawful bases for transfers from the named jurisdictions.
AI-generated interpretation, not legal advice.
" We may collect Personal Information about you directly from you and from third parties, as well as automatically through your use of the Services."
Identifies the three collection channels — directly from the user, from third parties, and automatically — serving as a definitional framing for the data collection practices described below.
AI-generated interpretation, not legal advice.
" Contact Information: We may collect professional contact details such as first and last name, email address, phone number, company name, title and department, and other relevant information necessary for us to manage your account and business relationship. Profile Data: We may collect information such as the username and password that you may set to establish an online account with us, biographical information, and any other information that you add or is associated with your account. Payment Information: If you subscribe to our Services, we will ask you to provide your payment information, such as your credit card number and billing address, to process your payment. Payment processing is handled by our third-party payment processor, and we do not store complete credit card numbers. User-Generated Content: Such as photos, images, music, videos, comments, questions, messages, correspondence, and other content or information that you generate, transmit, or otherwise make available on the Service to us or other persons, as well as associated metadata. Communication Information: When you contact us via a contact form, email, or other means, you may provide us with communication information, such as your name, email address, company, and the content, date, and time of your message. Support Information: When you request technical support services, we will process your contact information, communication information, as well as information on the reasons for your support request, and any additional information you may provide. "
Enumerates specific categories of Personal Information BaseFrame may collect directly from users (contact details, profile data, payment information), establishing the operative scope of data collection practices and creating an obligation of transparency about those practices.
AI-generated interpretation, not legal advice.
" Website Usage Information: When you use our website (baseframe.co), we may automatically collect information about your visit, including via cookies and similar technologies. This may include your IP address, web browser, device type, and the pages you visit. The Desktop Application does not send analytics events or usage telemetry. No product analytics data leaves your device from the Desktop Application. Device and Log Information: We collect information about the devices you use to access the Services, including: IP address; browser type and version; operating system; device identifiers; and log data including access times and referring URLs. This applies to website and API usage; the Desktop Application does not generate server-side logs beyond what is required to authenticate requests. Crash Reports: If the Desktop Application crashes, a report is saved locally containing an error stack trace and recent log data. File paths and other identifiable information are anonymized before saving. On the next launch, you will be explicitly asked for consent before any crash report is transmitted to BaseFrame. We use crash reports solely to identify and fix software defects. You may decline to submit them at any time."
Describes automated collection of website usage data (IP address, browser, device type, pages visited) via cookies, and expressly states that the Desktop Application sends no analytics or usage telemetry — the latter is a user-favorable restriction on data collection from the application.
AI-generated interpretation, not legal advice.
" Depending on your location, you may have certain rights regarding your Personal Information under applicable data protection laws. To exercise any of the privacy rights afforded to you, please see the How to Contact Us section below. Access: The right to request access to and obtain a copy of any Personal Information we may have about you. Deletion: The right to delete your Personal Information that we have collected or obtained, subject to certain exceptions. Correction: The right to request that we correct any inaccuracies in your Personal Information, subject to certain exceptions. Opt Out of Certain Processing: The right to opt out of the processing of your Personal Information for purposes of targeted or cross-context behavioral advertising and/or the sale of your Personal Information. Objection/Restriction of Processing: The right to object to or restrict us from processing your Personal Information in certain circumstances. Withdraw Consent: The right to withdraw your consent where we are relying on your consent to process your Personal Information. Portability: The right to receive your Personal Information in a structured, commonly used, and machine-readable format. Automated Decision-Making and Profiling: We do not, at this time, use Personal Information for automated decision making or for profiling in furtherance of decisions that produce legal or similarly significant effects. Thus, we do not fulfill requests to opt out of these uses. "
Enumerates specific user rights regarding Personal Information (access, deletion subject to exceptions, correction subject to exceptions, opt-out of sale or sharing) conditioned on the user's location and applicable data protection laws, and directs users to the contact section to exercise those rights.
AI-generated interpretation, not legal advice.
" We implement reasonable security measures to protect the Personal Information we collect and maintain, including: Encryption in Transit: Data transmitted between the Desktop Application (or your browser) and BaseFrame's servers is encrypted using industry-standard TLS/SSL. Local Data Encryption: Activity data cached by the Desktop Application on your device is encrypted at rest using AES-256-GCM. The encryption key is stored in a user-only file on your device and is never transmitted to BaseFrame. Cloud Data Encryption: Sensitive data stored on BaseFrame's servers (such as Microsoft OAuth tokens) is encrypted at rest. Access Controls: We maintain access controls to limit access to information to authorized personnel. Security Monitoring: We monitor our systems for potential security threats and vulnerabilities."
Imposes an obligation on the provider to implement reasonable security measures including TLS/SSL encryption in transit, AES-256-GCM local encryption at rest with device-stored keys never transmitted to the provider, and cloud-side encryption of sensitive stored data.
AI-generated interpretation, not legal advice.
" This Privacy Policy ( “Policy” ) describes how BaseFrame Inc. ( “BaseFrame,” “we,” “us,” or “our” ) collects, uses, discloses, and protects information in connection with your use of the BaseFrame platform, website (https://baseframe.co), communications between you and us, use of artificial intelligence and machine learning software, and related services (collectively, the “Services” ). In this Policy, “Personal Information” means any information relating to an identified or identifiable individual. By using the Services, you agree to the collection and use of information in accordance with this Policy. If you do not agree with this Policy, please do not use the Services. IMPORTANT NOTICE REGARDING AI AGENTS: The Services enable you to connect third-party services (such as email, messaging, productivity, and other applications) to AI-powered agents operating in virtual machines. When you connect such services, the AI agents will access and process data from those services on your behalf. This may include personal data of you and others. You are responsible for ensuring that your use of the Services complies with applicable privacy laws and that you have obtained any necessary consents. BaseFrame does not control the actions taken by AI agents and is not responsible for how AI agents access, use, or disclose data from connected services."
Defines the scope and subject matter of the policy, identifies the controller entity ('BaseFrame Inc.'), defines 'Personal Information' as information relating to an identified or identifiable individual, and establishes user consent to data collection and use by using the Services — foundational definitions and consent incorporation operative throughout the document.
AI-generated interpretation, not legal advice.
" Information from Other Sources: We may obtain information, including Personal Information, from third parties and sources other than our Services, such as our business customers and partners. If we combine or associate information from other sources with Personal Information that we collect through our Services, we will treat the combined information as Personal Information in accordance with this Policy."
States that Personal Information may be obtained from third-party sources and partners, and that any combined information will be treated as Personal Information in accordance with the policy — imposes an obligation to apply policy protections to third-party-sourced data.
AI-generated interpretation, not legal advice.
" The BaseFrame desktop app reads on-device data to find the workflows worth automating. The exact sources depend on which operating system you run. macOS. We read passively from sources Apple already maintains: app-focus events from the Biome stream (Library/Biome), historical app usage from Screen Time (knowledgeC.db), Apple Mail / Calendar / Reminders / Contacts, browser history (Safari, Chrome, Arc, Brave, Edge, Firefox), and per-app SQLite caches (Slack, Notion, Microsoft Office, Linear, etc.). We never read message bodies. macOS Full Disk Access is required for these reads. Windows. Windows has no equivalent passive app-focus stream, so we run a small background process that records the foreground window’s application name and title once per second. Window titles are scrubbed for emails, phone numbers, file paths, and other PII patterns before they are stored locally. You can disable title capture in Settings. We additionally read browser history (Edge, Chrome, Firefox), Outlook mail headers (subject, sender, recipients) and calendar entries via MAPI, and Microsoft Teams channel activity. We never read message bodies. All raw local data stays on your device. To generate workflow recommendations, the Desktop Application constructs prompts from scrubbed activity metadata (app names, timestamps, and PII-scrubbed window titles) and sends them to BaseFrame's servers, which forward them to an AI provider for processing. No message bodies, file contents, email text, or unredacted personal data are included in these prompts. Activity data that has already been summarized into a workflow fingerprint is cached locally and is not re-sent."
Enumerates specific on-device data sources read by the Desktop Application on each operating system (activity streams, usage databases, mail, calendar, browser history, app caches), and includes a restriction that message bodies are never read — defines the scope of local data access and user-favorably restricts reading of message body content.
AI-generated interpretation, not legal advice.
Common questions about BaseFrame's policies
- Does BaseFrame train its AI models on your data?
- No training on your content by default — based on 1 verified finding from BaseFrame's published policy. Informational only, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from BaseFrame's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in BaseFrame's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in BaseFrame's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat BaseFrame requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in BaseFrame's published policies yet.
What the policies actually cover
0 topicsNone of BaseFrame's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause permits sale of personal data or information.
“We and our service providers may use cookies and similar technologies to collect usage and browser information about how you use our Services. The technologies we use for this automatic data collection may include cookies and web beacons that permit us to verify system and server integrity and generate statistics around the popularity of certain content. Essential Cookies: Necessary for the operation of the Servic...”Open source citation
The clause permits sale of personal data or information.
“You can decline all of the above marketing and analytics technologies by using the “Do Not Sell or Share My Personal Information” link in the footer or by enabling Global Privacy Control in your browser. When you opt out, we stop loading the Meta Pixel, RB2B, Maverick, Delivr AI, Rewardful, and PostHog; we clear the Meta browser cookies (_fbp, _fbc) and any stored marketing attribution from your device. Preference...”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“We may disclose information to third parties in the following circumstances: Service Providers: We may engage third-party service providers to assist in providing hosting services or other services necessary for the operation of the Services. These service providers may have access to or process your information as part of providing those services for us. They are contractually obligated to protect your informatio...”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“AI Providers: When you use AI agents, your prompts and instructions may be processed by third-party AI providers (such as Anthropic, OpenAI, or other providers you select) pursuant to your API key and their terms of service. BaseFrame does not control how AI providers process this data, and such processing is governed by the applicable AI provider’s terms and privacy policy. Connected Services: When you connect th...”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“We and our service providers may use cookies and similar technologies to collect usage and browser information about how you use our Services. The technologies we use for this automatic data collection may include cookies and web beacons that permit us to verify system and server integrity and generate statistics around the popularity of certain content. Essential Cookies: Necessary for the operation of the Servic...”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | privacy data use | worsens | HIGH | 3 |
| All applicable tiers | training use | improves | LOW | 1 |
| Api | subprocessors data sharing | conditional | MEDIUM | 2 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: third party or vendor sharing on subprocessors data sharing
“We may disclose information to third parties in the following circumstances: Service Providers: We may engage third-party service providers to assist in providing hosting services or other services necessary for the operation of the Services. These service providers may have access to or process your information as part of providing those services for us. They are contractually obligated to protect your information. Key service providers include: Clerk : account authentication and identity management. Stripe : payment processing and subscription billing. Composio : integration infrastructure that brokers connections to third-party services (Gmail, Slack, Linear, and 46+ others). When you connect a third-party service, a per-user entity is created in Composio on your behalf. All Composio API requests are routed through BaseFrame's servers. Google Cloud Platform : cloud infrastructure, database, and serverless compute hosting. Meta Platforms, Inc. : advertising measurement and audience building via the Meta Pixel (browser-side) and Meta Conversions API (server-side). On our public website only. Server-side events are sent for signup, demo requests, downloads, and subscription billing milestones, and include hashed email, IP address, user agent, and the Meta browser cookies (_fbp, _fbc) when present. See Section 5 for details and the opt-out path. RB2B, Maverick, and Delivr AI : marketing analytics and visitor identification on our public website only (subject to your cookie consent).”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“AI Providers: When you use AI agents, your prompts and instructions may be processed by third-party AI providers (such as Anthropic, OpenAI, or other providers you select) pursuant to your API key and their terms of service. BaseFrame does not control how AI providers process this data, and such processing is governed by the applicable AI provider’s terms and privacy policy. Connected Services: When you connect third-party services, information is shared with those services as necessary to enable the integration. Such sharing is governed by the terms and privacy policies of those services. Business Purposes: We may make certain information available to third parties for various purposes, including compliance with reporting obligations or for our business purposes. Any such disclosure will be in accordance with applicable laws and regulations. Legal Requirements: We may disclose your information if required to do so by law or in the good-faith belief that such action is necessary to comply with applicable laws, respond to a court order, judicial or other government subpoena or warrant, or to cooperate with law enforcement or other governmental agencies. Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, we may transfer your information to the acquiring entity as part of the transaction. Affiliates: We may share Personal Information with our affiliates, subsidiaries, and branch offices to which it is reasonably necessary or desirable for us to disclose Personal Information for the purposes mentioned above. With Your Consent: We may share information with your consent or at your direction.”Open timeline citation
Latest stance: sale or sell on privacy data use
“We and our service providers may use cookies and similar technologies to collect usage and browser information about how you use our Services. The technologies we use for this automatic data collection may include cookies and web beacons that permit us to verify system and server integrity and generate statistics around the popularity of certain content. Essential Cookies: Necessary for the operation of the Services, including authentication and security. Analytics Cookies: Help us understand how visitors interact with our website (baseframe.co). We use PostHog to collect and analyze website usage data. The Desktop Application does not use PostHog or any analytics service. No telemetry or usage events are collected from the Desktop Application. Advertising and Marketing Pixels: On our website (baseframe.co), we use the following third-party advertising and marketing technologies. These are loaded by default and may be opted out of via the “Do Not Sell or Share My Personal Information” link in the footer or by enabling the Global Privacy Control signal in your browser. None of these technologies operate inside the Desktop Application. Meta (Facebook) Pixel: We use the Meta Pixel, a browser-side tracking technology from Meta Platforms, Inc., to measure the effectiveness of our advertising on Facebook and Instagram, to build custom and lookalike audiences, and to track conversions (such as page views, leads, signups, downloads, and subscription purchases).”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“We and our service providers may use cookies and similar technologies to collect usage and browser information about how you use our Services. The technologies we use for this automatic data collection may include cookies and web beacons that permit us to verify system and server integrity and generate statistics around the popularity of certain content. Essential Cookies: Necessary for the operation of the Services, including authentication and security. Analytics Cookies: Help us understand how visitors interact with our website (baseframe.co). We use PostHog to collect and analyze website usage data. The Desktop Application does not use PostHog or any analytics service. No telemetry or usage events are collected from the Desktop Application. Advertising and Marketing Pixels: On our website (baseframe.co), we use the following third-party advertising and marketing technologies. These are loaded by default and may be opted out of via the “Do Not Sell or Share My Personal Information” link in the footer or by enabling the Global Privacy Control signal in your browser. None of these technologies operate inside the Desktop Application. Meta (Facebook) Pixel: We use the Meta Pixel, a browser-side tracking technology from Meta Platforms, Inc., to measure the effectiveness of our advertising on Facebook and Instagram, to build custom and lookalike audiences, and to track conversions (such as page views, leads, signups, downloads, and subscription purchases).”Open timeline citation
Latest stance: sale or sell on privacy data use
“You can decline all of the above marketing and analytics technologies by using the “Do Not Sell or Share My Personal Information” link in the footer or by enabling Global Privacy Control in your browser. When you opt out, we stop loading the Meta Pixel, RB2B, Maverick, Delivr AI, Rewardful, and PostHog; we clear the Meta browser cookies (_fbp, _fbc) and any stored marketing attribution from your device. Preference Cookies: Remember your settings and preferences. Cookie Choices: You can manage cookie preferences by customizing your browser settings to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable certain cookies, please note that some parts of our Services may not function properly. Interest-Based Advertising: We may allow third parties to collect Personal Information to provide interest-based advertising. You can opt out of interest-based advertising through the Digital Advertising Alliance (optout.aboutads.info) or Network Advertising Initiative (optout.networkadvertising.org). Selling Personal Information: While we do not sell Personal Information in exchange for monetary consideration, we do disclose Personal Information for other benefits that could be deemed a “sale” under various data protection laws. You may opt out as described in Section 6.”Open timeline citation
Latest stance: no training claim on training use
“Important: We do not use Customer Content (including data from Connected Services) to train AI models or for any purpose other than providing the Services to you.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-19· verified 2026-07-19verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
37 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of BaseFrame's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified BaseFrame's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from BaseFrame's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.