Your documents stay tied to your choices.
This policy explains what Base processes, why we process it, which service providers help us operate, and the controls available to you.
1. Who we are
Base is a document knowledge and sharing service operated by Solimar Group LLC (“Base,” “we,” “us,” or “our”). This policy applies to createbases.com, the Base web application, and Base connections used from ChatGPT, Codex, Claude, and other compatible AI clients.
Questions or privacy requests can be sent to privacy@createbases.com.
2. Information we process
Account and workspace information
We process your email address, display name if provided, workspace membership and role, account settings, and the authentication records needed to sign you in and keep your account secure.
Documents and knowledge content
When you upload files, we process the files, filenames, extracted text, tables, images, and the knowledge Base derives from them, including entities, claims, events, relationships, summaries, citations, and review decisions. This content may include personal data that you or another authorized user chose to upload.
Sharing and connection information
We process sharing settings, invite or recipient email addresses, access permissions, link status, and records showing which shared Bases you follow. When you connect an AI client, we process the client name, approved scopes, selected Base accounts, authorization grants, and security events such as connection, revocation, and denied-access attempts.
Billing and support information
If you purchase a plan on the Base website, we receive subscription, customer, plan, and payment-status information from Stripe. Base does not store complete payment-card numbers. We also process the information you include in support or privacy correspondence.
Technical information
We process limited technical information needed to operate and secure the service, such as IP addresses used for rate limiting, session identifiers, browser user-agent information, timestamps, and security or audit events. We do not use this information for third-party advertising or cross-service behavioral profiling.
3. How we use information
- Provide, secure, troubleshoot, and improve Base.
- Extract and organize information from documents and return cited results.
- Apply permissions, sharing controls, revocation, and workspace boundaries.
- Authenticate users and authorize AI-client connections.
- Send sign-in, sharing, and processing-status emails you request.
- Administer subscriptions purchased through the Base website.
- Prevent abuse, investigate security incidents, and comply with law.
We do not sell personal data or use customer documents to serve advertisements.
4. AI clients and model providers
Base only exposes content through an AI connection after you authorize the connection and select the Base accounts it may use. Tool results are limited to the specific, permissioned Base content needed for the request. You can revoke a connection at any time from Base’s AI connection settings.
Information that an AI client receives is also handled under that client provider’s terms and privacy policy. For document extraction, summarization, optical character recognition, or semantic search, Base may send the relevant document text or image content to model, embedding, and OCR providers acting as service providers, currently Anthropic, Voyage AI, and Mistral. Do not upload credentials, payment-card data, government identifiers, protected health information, or other data you are not authorized to process.
5. Service providers and disclosures
We disclose information only as needed to operate Base, including to:
- Railway for application, database, and storage infrastructure.
- Anthropic and Voyage AI for optional document intelligence and semantic retrieval.
- Mistral for optical character recognition when a document is scanned or image-only and its text cannot be read directly.
- Resend for transactional email delivery.
- Stripe for website subscription billing and payment administration.
- OpenAI or another AI-client provider when you authorize that client and ask it to use Base.
- Professional advisers, authorities, or counterparties when reasonably necessary to comply with law, protect rights and safety, or complete a corporate transaction.
These providers may process information in countries other than your own, subject to their contractual and legal safeguards.
Business transfers
If Base is reorganized, merged, acquired, or moved to a different entity, information held in Base may transfer with the service as part of that business. The receiving entity remains bound by this policy until it posts a replacement, and we will post notice here before a replacement policy takes effect. A transfer does not by itself change who can see a Base: access, sharing, and revocation controls carry over unchanged.
6. Retention
- Uploaded content and derived knowledge are retained while the Base exists. Deleting a Base removes its active content, sharing records, and associated audit history.
- Account and workspace records are retained while the account is active. We aim to complete a verified account-deletion request within 30 days.
- Magic sign-in links expire after 15 minutes. Browser sessions expire after 30 days.
- AI access tokens expire after one hour and refresh tokens after 30 days, unless revoked sooner.
- Security, billing, and support records may be retained longer when reasonably necessary for fraud prevention, accounting, dispute resolution, or legal compliance.
- Residual encrypted backups, if any, are isolated from ordinary use and overwritten through the normal backup cycle.
7. Your choices and controls
Depending on your role and location, you may access, correct, export, or delete personal data; object to or restrict certain processing; or request a portable copy. Base also lets authorized users delete Bases, revoke share access, disable downloads or external-AI access, and disconnect AI clients.
Send requests to privacy@createbases.com. We may need to verify your identity and authority before completing a request. You may also have the right to complain to your local data-protection authority.
8. Security
We use access controls, scoped OAuth permissions, hashed authentication tokens, encrypted network transport, tenant isolation, and revocable sharing controls. No security program can eliminate all risk, so you should use Base only for information you are authorized to process and share.
9. Children
Base is not directed to children under 13, and we do not knowingly collect their personal data.
10. Changes
We may update this policy as Base changes. We will post the updated version here, revise the effective date, and provide additional notice when required by law.