Privacy Policy — Searchbase
Last updated: 2026-07-24
1. Data Controller
The Searchbase service (https://searchbase.org) is operated by:
[Searchbase — legal entity to be defined] Registered office: to be defined Privacy email: [email protected] General email: [email protected]
Data Protection Officer (DPO): not appointed — not mandatory under Art. 37 GDPR.
2. Data we collect
We collect only what we need to provide Searchbase.
2.1 Account data
- Password (stored only as a secure hash — we never see it in cleartext)
- Google profile (if you sign in with Google): name, email, account identifier
2.2 Subscription and billing data
- Your credit balance
- Subscription details: subscription tier, billing periods, and a customer reference with our payment provider (Stripe)
Credit card data never transits our servers: it is collected directly by Stripe.
2.3 User-generated content
Stored in our EU-hosted database with per-user access isolation:
- Chat conversations — titles, prompts, AI responses, tool results, timestamps
- Scraping jobs — target URLs, extraction prompts, results, options
- Long-term memory — free-text facts you author yourself (identity, projects, preferences)
- Conversation summaries generated automatically to support long chats
- Message feedback (thumbs up/down)
- Workspaces and their members
2.4 Uploaded files
Audio and document uploads are stored in cloud object storage (Cloudflare R2) and served via short-lived signed links.
2.5 Data stored in your browser
- Your cookie consent choice
- Interface preferences and onboarding state
- A local copy of your long-term memory entries
2.6 Server-side session cookies
- Authentication cookies (httpOnly)
- Analytics cookies — only if you accepted analytics consent
2.7 IP address and User-Agent
- Collected by our CDN and security provider (Cloudflare) for DDoS / WAF protection
- Collected in infrastructure request logs
- Not sent to our error-tracking service
- Anonymous visitors are not profiled by analytics
2.8 Connected mailboxes (Google / Microsoft)
If you connect your own mailbox so that Searchbase can send messages as you, we ask for send-only access and nothing else — gmail.send on Google, Mail.Send on Microsoft. Neither permission can read, list, or search a mailbox, and we do not request one that can.
From the provider we receive and store:
- A refresh token, encrypted at rest (AES-128-CBC with HMAC authentication). It is decrypted in memory only, at the moment a message is sent.
- The address of the connected mailbox, so the account page can show you which one is connected.
- The permissions you actually granted, so that we can refuse to send — rather than fail halfway — if the send permission is missing.
We do not receive the contents of your mailbox. The message you approve is drafted in the chat, so it is retained as part of that chat session like any other content you write (§2.3) — the mailbox connection itself stores no message data, and the sent copy lives in your own Sent folder. Disconnecting the mailbox deletes the stored token immediately, and revoking access from your Google or Microsoft account settings has the same effect.
Limited Use. Searchbase's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use this data to develop, improve, or train generalised AI or ML models, we do not sell it, and we do not transfer it to others except as necessary to provide the sending feature you asked for, to comply with applicable law, or as part of a merger or acquisition. We do not allow humans to read this data unless we have your affirmative agreement for specific messages, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymised for internal operations.
3. Purposes and legal bases (Art. 6 GDPR)
| Purpose | Data processed | Legal basis |
|---|---|---|
| Account creation, service delivery, billing | Email, password (hash), subscription data, user content | Art. 6(1)(b) — performance of contract |
| Transactional email (verification, password reset) | Art. 6(1)(b) — performance of contract | |
| AI processing of your prompts and files | Prompts, attachments, scraping results | Art. 6(1)(b) — necessary to deliver the requested service |
| Long-term memory storage | Memory entries | Art. 6(1)(a) — consent (you choose to enter the entries) |
| Product analytics | Usage events | Art. 6(1)(a) — consent (cookie banner) |
| Security, anti-abuse, rate limiting | IP, UA, user ID | Art. 6(1)(f) — legitimate interest (protect the service) |
4. Sub-processors and third parties
To operate Searchbase we rely on third-party providers, each acting as a sub-processor. We use them in the following categories:
| Category | Purpose | Data processed | Region |
|---|---|---|---|
| Cloud infrastructure & storage | Hosting, database, object storage, CDN, security | Account data, all user content, uploaded files, IP/UA, request metadata | EU + global |
| AI providers | Generate chat responses and summaries, transcribe audio, extract scraping results | Chat prompts, uploaded files, scraping descriptions and results | United States / other non-EU |
| Search & data providers | Run web, social and video searches requested by tools | Search queries, handles, target URLs | United States |
| Payments | Billing and subscription management | Billing email, payment-method tokens, subscription metadata | United States / Ireland |
| Transactional email | Deliver account emails (verification, password reset, notifications) | Recipient email | United States |
| Analytics, error tracking & logging | Product analytics (consent only), error monitoring, application logs | Usage events, pseudonymous user ID, stack traces, structured logs | EU / United States |
| Authentication | Sign-in with a third-party identity provider | Basic profile + email | United States |
A complete, up-to-date list of our sub-processors — with names, roles and links to their privacy policies — is available on request at [email protected]. For any transfer outside the EU we rely on the safeguards described in § 5.
5. International transfers (Art. 46 GDPR)
A significant portion of the sub-processors above are based in the United States or other non-EU countries. In particular, content you submit for AI processing (chat prompts, scraping descriptions, file content) is transmitted to AI providers in the United States (and, in fallback scenarios, to other non-EU providers listed above).
For these transfers we rely on:
- Standard Contractual Clauses (SCCs) issued by the European Commission (Decision 2021/914)
- The provider's adherence to the EU–US Data Privacy Framework, where applicable (e.g. Stripe, Google, Microsoft, Cloudflare)
- Supplementary technical measures: encryption in transit, authenticated access, data minimization
6. Data retention
We keep data only as long as necessary for the purposes for which it was collected. Summary table:
| Data category | Retention period |
|---|---|
| Account data | Until you request deletion (today via email request, self-service on the roadmap) |
| Chat sessions and messages | Until you delete them, or until account deletion |
| Scraping jobs | Until you delete them, or until account deletion |
| Long-term memory | Until you delete the entries |
| Uploaded files | Deleted when the parent session is deleted, or on account erasure |
| Connected mailbox tokens | Until you disconnect the mailbox, revoke access at the provider, or delete the account |
| Application logs | ~30 days (provider default) |
| Error-tracking events | 90 days |
| Analytics events | 90 days |
| Billing data (Stripe) | Per Stripe's policy, typically 7 years (tax / accounting obligations) |
| Administrative audit records | Retained for compliance and security; on account erasure, user identifiers may be removed from the records, but the action records are preserved |
7. Cookies and similar technologies
| Category | Purpose | Type | Consent |
|---|---|---|---|
| Strictly necessary | Authentication (session cookies, httpOnly) | HTTP cookie | Not required |
| Functional | Your cookie choice, interface preferences, onboarding state, local copy of your memory entries | localStorage | Not required |
| Analytics | Product analytics (PostHog, ph_*) | Cookie + localStorage | Required (opt-in) |
The cookie banner is binary (accept all / reject all). Rejection fully disables analytics.
Full details — including individual cookie names, durations and the third parties that set them — are in the Cookie Policy.
8. Security
We implement concrete technical and organizational measures:
- In transit: TLS 1.2+ end-to-end encryption
- At rest: encryption managed by our cloud providers; application secrets held in a dedicated secret store
- Per-user isolation: access controls enforced at the database level
- Anti-abuse: WAF, DDoS protection and per-user rate limiting
- Admin access control: role-based access with audit logging of every privileged action
- Error minimization: error tracking configured to exclude personal data
No system is 100% secure. In the event of a personal data breach we will notify the competent supervisory authority within 72 hours under Art. 33 GDPR and, if high-risk, also data subjects under Art. 34.
9. Your rights (Art. 15–22 GDPR)
You have the following rights, exercisable free of charge:
- Access (Art. 15) — obtain a copy of your data. How: email
[email protected]. We export your data as JSON (currently capped at 10,000 rows per table for operational reasons). - Rectification (Art. 16) — you can edit account, memory and workspaces directly in the app. For other corrections, email
[email protected]. - Erasure (Art. 17) — email
[email protected]. Erasure removes your files, analytics profile and database records. - Restriction (Art. 18) — email request.
- Portability (Art. 20) — same mechanism as access (JSON export).
- Objection (Art. 21) — email request.
- Withdrawal of consent — analytics consent can be withdrawn from the cookie banner (reject all). Long-term memory consent is withdrawn by deleting the entries from the app.
Account erasure and data requests are currently handled by our team upon your email request; self-service tools are on the roadmap.
10. Automated decision-making and profiling (Art. 22)
We do not make solely-automated decisions producing legal effects or similarly significant effects on you.
Searchbase's AI models generate content (extractions, summaries, chat responses) but they are assistive tools: we do not automatically score your reliability, do not compute risk scores, do not deny access to services based on AI output.
We do not profile users for marketing purposes.
11. AI and user content
This section requires explicit honesty.
When you enter a prompt in chat, describe a scraping job, upload a file or audio, that content is sent to third-party AI providers in the United States (or other non-EU countries) for processing. Specifically:
- Chat prompts and AI responses are processed by our primary AI provider, based in the United States.
- If a fallback is active, prompts may be processed by an alternative AI provider (in the United States or another non-EU country).
- Audio files uploaded for transcription are processed by a specialist transcription provider in the United States.
- Scraping prompts and target URLs may be processed by third-party scraping providers in the United States.
- Text search queries are processed by third-party search providers (web, social and video).
What this means in practice:
- The data you enter in chats is seen by the AI sub-processor for the time needed to generate the response.
- By contract / configuration, we do not use your data to train AI models, and our main AI sub-processors commit not to train their models on API data.
- Do not enter in chats personal data of others without a legal basis, secrets, passwords, health data or other special categories under Art. 9 GDPR. Searchbase is not currently designed to process special categories of data.
12. Minors
Searchbase is not directed at minors under 16. We do not knowingly collect personal data from minors under 16. If you become aware that a minor has provided us personal data without parental consent, contact [email protected] and we will delete it.
13. Changes to this policy
This notice may be updated. The current version is always available at https://searchbase.org/privacy. For material changes we will notify you by email at the address linked to your account, with at least 15 days' notice.
The version and last-updated date are shown at the top of this document.
14. Contact and complaints
Privacy email: [email protected]
General email: [email protected]
If you believe the processing of your personal data violates the GDPR or Italian law, you have the right to lodge a complaint with a supervisory authority:
-
For users resident in Italy: Garante per la Protezione dei Dati Personali Piazza Venezia 11, 00187 Roma Website: https://www.garanteprivacy.it
-
For users resident in other EU Member States: the supervisory authority of your country of residence, place of work, or place of the alleged infringement (Art. 77 GDPR).