Privacy & Terms
Last updated 24 August 2026
Privacy
Basin holds files you chose to put here and a log of who read them.
What we hold
- your files — the Markdown you and your agents write, and every earlier version
- your email — the account itself, and the thing grants are bound to
- the activity log — every write, and every file read by someone you shared with
- connections — which tools you connected, and when each last called
- usage counts — how often tools were called, and how large files tend to be. Never contents.
Improving Basin with your data
Improving Basin with your data. We may use de-identified, aggregated data derived from your files to improve Basin — never your files themselves, never anything that identifies you. This is on by default; you can turn it off in Settings at any time, which stops all future use immediately. What an improvement model has already learned cannot always be unlearned.
We never let anyone else train on your files — no AI vendor, no partner, no buyer — and we never sell your data. Your files never leave for a model provider on our initiative; your assistants read them under your authority, not ours.
Third parties
- hosting — Fly.io runs the service
- database — Neon stores it
- sign-in — WorkOS issues and verifies your sign-in codes
- email — Resend delivers invitations and notifications
- nobody else — no analytics vendor, no session recorder, no advertising pixel
We set the cookies needed to keep you signed in — our login provider uses them to know it's you. No analytics cookies, no ad cookies, nothing that follows you elsewhere.
How access works
- sign-in — A one-time six-digit code, emailed to you. There are no passwords: none to steal, none to reuse, none to leak.
- connections — Each tool you connect signs in separately over OAuth. There is no API key to paste into a config file.
- grants — Space-level, read or write, bound to the email address you name. They do not re-share by default. You can allow someone you invited to invite others — one level deep, never onward.
- revocation — Takes effect on the next request. Nothing is cached on our side to go stale.
- read volume — Not limited. Someone you shared with can read what you gave them, as fast as they like. What you get is the record, not a cap: every whole-file read of a shared space is in your log, with who and when.
What the activity log records
- Every write, in the same transaction as the write — a write that is not logged is not a write.
- Every whole-file read by someone you have shared with, collapsed to one row per person, per file, per hour.
- Your own reads of your own files are not logged, and neither are search-result snippets.
How it is stored
- in transit — TLS, 1.3 where your client supports it.
- at rest — Encrypted by our database platform. We can read your files while running the service; every read of a shared space is logged where you can see it.
Specified in: RFC 8446.
Note: Encrypted at rest is not the same as encrypted so that we cannot read it. End-to-end encryption would stop the server serving files to your agents, so Basin does not claim it.
The threat model
- A grantee reads too much — Nothing stops them. What you shared, they can read, at any pace. Every whole-file read is in your log with a timestamp, so you find out; revoking ends it on their next request.
- A grantee re-shares — Only if you allowed it, and only one level deep.
- A connected tool is compromised — Remove that connection. The others keep working, and the log shows what it read.
- Your email is compromised — Email is the account. An attacker with your inbox has your files.
- We are compromised — Assume your files are readable.
Reporting something
Email security@getbasin.co. No bug bounty yet. We credit you by name unless you ask us not to.
The same contact is published where an automated scanner looks for it, as a code block carrying three lines read from the served file:
Specified in: RFC 9116.
How long things persist
Deleting your whole account is a real delete: your files, their versions and your activity log leave the live database immediately, including the history that individual deletes had kept. Deleting a single file is not the same. It stops appearing and can no longer be read, but its earlier versions are kept — that is what lets you restore it — so a single delete hides content rather than erasing it. There is no per-file purge yet. Our database platform keeps a six-hour encrypted restore window, so deleted data can survive there for up to six hours before it is gone everywhere. Nobody reads it in the meantime.
Your rights
- access — Export. One click, no request, no waiting period. It contains the current version of every file you own; version history and the activity log are not in the archive yet.
- portability — the same export — Markdown, opens anywhere
- erasure — Delete your account, on the Account page. Immediate.
- correction — edit the file through any connected tool
Deleting your account removes your files, versions, and account from the live database immediately. If de-identified data derived from your files has been used to improve Basin, what a model has already learned cannot always be unlearned — turning off improvement use in Settings, or deleting your account, stops all future use.
Terms
Written to be read.
Who "we" is
Basin is run by its operator as a sole proprietorship — a small service run by one person. When these pages say "we," that's who they mean. For anything legal or privacy-related, email hello@getbasin.co — it reaches the person who runs the service, and it is answered by them.
What you agree to
- your content — is yours. You give us only the permission needed to store it, serve it to the tools and people you authorise, and run the automated processing described in the privacy section above.
- your account — is your email. Keep it secure; anyone with it has your files.
- your age — Basin isn't for children. You must be at least 13 to use it — 16 if you're in Europe.
- acceptable use — nothing illegal, nothing that attacks the service or other users, no regulated data.
- your agents — act as you. What they write is attributed to you, and you are responsible for it.
We can suspend or close an account that breaks these terms or attacks the service. If we ever do, you get your export first, unless the law forbids it.
What we agree to
- changes — material changes are emailed before they take effect, never applied quietly
- the service — Basin will change over time, and parts of it may eventually be retired. If a change removes something you rely on, we'll email you before it takes effect.
- your data on exit — export keeps working until you delete your account
Third-party software
Basin talks to AI assistants and clients we don't build. We're responsible for storing and serving your files faithfully; what third-party software does with them — or writes into them — is between you and it.
Copyright
If you own a copyright and believe a file shared through Basin infringes it, email hello@getbasin.co with what it is and where you saw it. We'll take it down or tell you why not. If your file was removed by mistake, reply and say so — we'll look again.
Money
Basin is free right now. When paid plans exist, payment will be handled by a processor — we will never see a card number — and these terms will be updated by email before anything changes.
The rest
Basin is a small service run by one person. There's no uptime guarantee and no service-level agreement — we do our best, and the as-is disclaimer below means what it says.
Provided as is, to the extent the law allows. Our liability is capped at what you paid us in the twelve months before the claim. Nothing on this page limits rights the law says can't be limited; if a court cuts part of this section, the rest stands, and if any clause is unenforceable, the rest still stands.
Questions: hello@getbasin.co