Privacy Policy

How Busabase Cloud collects, uses, and protects your personal information, workspace records, and files.

Effective Date: August 12, 2026

Last Updated: August 12, 2026

This Privacy Policy describes how AI Organizer Company ("Busabase," "we," "us," or "our") collects, uses, and shares information about you when you use Busabase Cloud, including workspaces, bases and records, the review inbox, file storage, hosted APIs, and connected AI agents (collectively, the "Service"). By using the Service, you agree to the collection and use of information in accordance with this policy.

Key terms used in this policy:

  • User Account — your personal login identity (email + credentials). One person may belong to multiple Spaces using a single User Account.
  • Space — the workspace entity that acts as the billing and organizational unit. A Space holds bases, records, files, team members, and seats. Subscriptions are purchased at the Space level, not per individual User Account.
  • Change Request — a proposed change submitted by an agent, an integration, or a person. Depending on the permission level of the credential that submitted it, it is either applied immediately or held pending review until a human reviewer approves it.

1. Information We Collect

1.1 Information You Provide

  • Account Information: When you create an account, we collect your name, email address, and password (stored only as a salted hash). This constitutes your User Account.
  • Space Information: When you create or join a Space, we collect the Space name, owner details, member list, roles, and seat assignments.
  • Payment Information: When a Space owner buys a paid plan, payment details are collected and processed by our merchant of record, Creem (Armitage Labs OÜ). We never receive or store your full card number. We store only the subscription state, plan, seat count, order identifiers, and invoice metadata that Creem returns to us.
  • Profile Information: Any additional information you choose to provide, such as an avatar, display name, or workspace preferences.
  • Communications: When you contact support, request a demo, or submit a contact-sales or waitlist form, we collect the content of your message and the contact details you supply.

1.2 Workspace Content

  • Records and Bases: The structured data you and your agents create — tables, fields, records, views, and their field values.
  • Change Requests and Review History: Proposed changes, their diffs, review comments, approval and rejection decisions, and the identity and timestamp of the reviewer who made each decision. This review trail is core to the product and is retained for as long as the Space exists.
  • Files and Attachments: Files you upload, attach to records, or store in your Space's drive.
  • Metadata: File names, sizes, types, folder and node structures, view configurations, and access permissions.
  • Agent Interactions: Prompts, instructions, tool calls, generated content, and skill-related material processed on your behalf.

1.3 Information Collected Automatically

  • Usage Data: How you interact with the Service, including features used, records and files accessed, and review actions taken.
  • Device Information: Device type, operating system, browser type, and app version.
  • Log Data: Server logs including IP address, access times, API calls, webhook deliveries, and referring URLs.
  • Cookies and Similar Technologies: We use cookies and similar technologies for authentication, session management, language preference, and product analytics. See Section 11.

1.4 Information from Third Parties

  • OAuth Providers: If you sign in with Google or GitHub, we receive basic profile information (name, email address, avatar) from that provider.
  • Billing Provider: Creem sends us subscription, invoice, and payment-status events for your Space.
  • Self-Hosted Connections: If you connect a self-hosted or desktop Busabase instance to Busabase Cloud, we receive the connection metadata and the data your connection is configured to synchronize.

2. How We Use Your Information

We use the information we collect to:

  • Provide the Service: Store and serve your bases, records, files, and views; route change requests to the right reviewers; maintain the audit trail; and enforce your permission settings.
  • AI Processing: Route the requests, records, and files you submit to the AI model or agent runtime needed to provide review assistance, extraction, search, and automation features.
  • Billing: Determine the plan, seat count, and quotas that apply to a Space, and reconcile payments with our merchant of record.
  • Improve the Service: Analyze usage patterns, troubleshoot issues, and develop new features. We do not use your workspace content to train third-party foundation models for their general use.
  • Communicate with You: Send transactional email — review notifications, invitations, quota warnings, security alerts, and billing receipts — and, with your consent, product updates.
  • Ensure Security: Detect, prevent, and respond to fraud, abuse, unauthorized access, and security incidents.
  • Comply with Legal Obligations: Meet legal requirements, respond to lawful requests, and protect our rights.

3. How We Share Your Information

We do not sell your personal information or workspace content. We share information only in the circumstances below.

3.1 Service Providers

We share information with third-party vendors who perform services on our behalf:

  • Payments and Merchant of Record: Creem (Armitage Labs OÜ), Telliskivi tn 57b/1, Tallinn, Estonia — Creem is the seller of record for Busabase Cloud subscriptions and handles checkout, invoicing, tax, and refunds.
  • AI Model and Agent Infrastructure: providers and gateways used to serve the models available in Busabase, and sandboxed or tool-enabled agent runtimes.
  • Object Storage and File Delivery: S3-compatible storage and CDN providers used for uploads, attachments, downloads, and app bundles.
  • Email Delivery: transactional email providers such as Resend, Postmark, SendGrid, or AWS SES.
  • Hosting, Logging, and Operational Infrastructure: cloud, database, cache, search, monitoring, and security providers used to operate the Service.

All service providers are contractually obligated to protect your data and use it only for the purposes we specify.

3.2 Workspace Collaboration

When you invite members to a Space, share a link, or publish a view, we make the relevant records and files available to those users according to the permissions you set. Public share links are accessible to anyone who has the link (and the password, if you set one).

3.3 Outgoing Webhooks and Integrations

If you configure outgoing webhooks, MCP connections, API keys, or third-party integrations, we transmit the data you have configured those integrations to send. You control what is sent and where.

We may disclose information if required by law, subpoena, or other legal process, or if we believe disclosure is necessary to comply with applicable law, to protect the rights, property, or safety of Busabase, our users, or others, or to enforce our Terms of Service.

3.5 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.

We may share information with third parties when you give us explicit consent to do so.


4. Our Role: Controller and Processor

Busabase Cloud handles two different kinds of personal data, and our legal role differs for each. This distinction matters if you are subject to the GDPR, the UK GDPR, or similar laws.

  • Account and billing data — your name, email address, login credentials, Space membership, subscription and invoice records, and the server logs we generate. For this data we are the controller: we decide why and how it is processed.
  • Workspace content — the records, files, change requests, and review history inside your Space, including any personal data about third parties that you or your agents put there (for example, customer names in a CRM base). For this data you are the controller and we are your processor: we process it only on your documented instructions, which are the instructions you give through the Service and these policies.

As your processor we will: process workspace content only to provide the Service and as instructed by you; require confidentiality of personnel with access; apply the security measures in Section 5; engage sub-processors only under the conditions in Section 3.1; assist you with data subject requests and security notifications so far as reasonably practicable; and delete or return workspace content on termination as described in Section 4a.

If you need a signed Data Processing Agreement, including the current sub-processor list and Standard Contractual Clauses, write to support@busabase.com and we will provide one.

As the controller of the workspace content, you are responsible for having a lawful basis to put third-party personal data into your Space, and for telling those people how their data is used.


4a. Data Retention

We retain your personal information and workspace content for as long as your account and Space are active, or as needed to provide the Service.

The table below states the retention targets we operate to. They describe what we aim for in normal operation, not a guaranteed maximum: an incident, a legal hold, a provider's own backup cycle, or a law requiring longer retention can extend an individual period. If you need a binding commitment for a specific data category, ask us at support@busabase.com and we will confirm in writing what we can commit to.

DataRetention target after deletion or account closure
Records, files, and workspace contentRemoved from the active Service immediately; purged from primary storage typically within 30 days
Encrypted backups containing deleted contentTypically rotated out within 35 days
Account profile and credentialsDeleted or anonymized typically within 30 days of account closure
Security and access logsTarget 12 months
Billing, invoice, and tax recordsAt least 7 years, as required by tax law

Approval history and audit entries associated with a Space are retained for as long as that Space exists — they are what make the Space's records verifiable. Deleting the Space deletes them on the schedule above.

Where we are your processor, we delete or return workspace content on termination on the schedule above, unless you ask us in writing to do otherwise or the law requires us to keep it.


5. Data Security

We implement administrative, technical, and organizational safeguards designed to protect your information, including encrypted transport (TLS), hashed credentials, scoped API keys, role-based access controls, permission checks on every record and file request, and operational logging and monitoring.

However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

5.1 Breach Notification

If we become aware of a personal data breach affecting your information, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by the GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay, describing what happened, what data was involved, what we are doing about it, and what you can do.

Where we act as your processor (see Section 4), we will notify you without undue delay after becoming aware of a breach affecting your workspace content, so that you can meet your own notification deadlines.

5.2 Self-Hosted and Desktop

If you run the open-source desktop or self-hosted edition of Busabase, the data stored on that machine or server is under your control, and securing that environment is your responsibility.


6. Your Rights and Choices

Depending on your location, you may have the following rights:

6.1 Access and Portability

You can access your records and files through the Service, and export workspace data using the export and backup features and the hosted API.

6.2 Correction

You can update or correct your information through your account settings, or by contacting us.

6.3 Deletion

You can delete individual records, files, and Spaces, or your entire account. We will delete your data unless we are required to retain it by law.

6.4 Opt-Out

  • Marketing Emails: Unsubscribe using the link in any marketing email. Transactional email required to operate your account cannot be disabled while the account is active.
  • AI Processing: You can choose not to connect agents to a Space, and you can revoke API keys and integrations at any time.
  • Cookies: Manage cookie preferences through your browser settings.

6.5 Objection and Restriction

You may object to, or ask us to restrict, certain processing of your personal information where we rely on legitimate interests as the legal basis.

To exercise these rights, contact us at support@busabase.com.


7. AI and Machine Learning

7.1 How We Use AI

Busabase uses AI so that agents can propose changes to your data. Depending on the feature and your Space configuration, your requests may be processed within Busabase-managed agent runtimes, or by third-party model providers and compatible gateways, using workspace context such as prompts, records, files, and prior review decisions.

7.2 AI Training

We do not use your records, files, or review history to train third-party foundation models for their general use. We may use aggregated or de-identified operational data to improve Busabase itself.

7.3 Review Before Trust

Busabase is designed so that AI output arrives as a Change Request that records what changed, who proposed it, and when. Whether that change is applied immediately or held for review depends on the permission level of the credential that submitted it, and you control that setting. AI output may still be incomplete, incorrect, outdated, or biased. You remain responsible for configuring review where you want it, for reviewing proposed changes before approving them, and for validating anything you rely on for legal, financial, employment, security, compliance, or other high-impact decisions.

7.4 Model Availability

The specific model, provider, or processing path used for a request may vary over time based on the model you choose, your plan, feature requirements, availability, safety controls, or infrastructure configuration.


8. International Data Transfers

Busabase Cloud is operated from the United States, and our service providers operate in multiple countries. Your information may be transferred to and processed in countries other than your own. Where required, we rely on appropriate safeguards, such as Standard Contractual Clauses approved by the relevant authorities.


9. Children's Privacy

The Service is not intended for children under 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected such information, we will delete it promptly.


The Service may link to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies.


11. Cookies and Tracking Technologies

11.1 Types of Cookies We Use

TypePurpose
EssentialRequired for the Service to function (authentication, session management, CSRF protection, security)
PreferencesRemember your language, theme, and workspace settings
AnalyticsHelp us understand how the Service is used, in aggregate

11.2 Managing Cookies

You can control cookies through your browser settings. Disabling essential cookies will prevent you from signing in.

For the full list of individual cookies, their retention periods, our analytics providers, and how to opt out, see our Cookie Policy.


12. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

  • Right to know what personal information we collect, use, and disclose
  • Right to request deletion of your personal information
  • Right to opt out of the sale of personal information (we do not sell personal information)
  • Right to non-discrimination for exercising your privacy rights

13. European Privacy Rights (GDPR)

If you are in the European Economic Area or the United Kingdom, you have rights under the GDPR and UK GDPR:

  • Legal Basis: We process your data on the basis of contract performance (providing the Service), consent (marketing), legal obligations (tax and accounting), and legitimate interests (security, abuse prevention, product improvement).
  • Controller and Processor: AI Organizer Company is the controller for account, billing, and log data, and acts as your processor for the content inside your Space. See Section 4 for what that means in practice, and write to support@busabase.com for a signed Data Processing Agreement.
  • International Transfers: We rely on Standard Contractual Clauses for transfers out of the EEA and UK. The current sub-processor list is available on request.
  • Supervisory Authority: You have the right to lodge a complaint with your local data protection authority.
  • EU/UK Representative: We have not yet appointed an Article 27 representative in the EU or UK. Until we do, send GDPR requests directly to support@busabase.com and we will handle them within the statutory deadlines.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last Updated" date. For significant changes, we may also send you an email notification.


15. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

Customer Support: support@busabase.com

Data Protection and GDPR/CCPA Requests: support@busabase.com

Security Issues: support@busabase.com

Company: AI Organizer Company

Registered Address: 8 The Green, STE R, Dover, DE 19901, USA

Billing and Refunds: handled by our merchant of record, Creem (Armitage Labs OÜ), Telliskivi tn 57b/1, Tallinn, Estonia. Write to support@busabase.com first and we will help.


By using Busabase Cloud, you acknowledge that you have read and understood this Privacy Policy.