Privacy Policy — Searchbase

Last updated: 2026-07-24


1. Data Controller

The Searchbase service (https://searchbase.org) is operated by:

[Searchbase — legal entity to be defined] Registered office: to be defined Privacy email: [email protected] General email: [email protected]

Data Protection Officer (DPO): not appointed — not mandatory under Art. 37 GDPR.


2. Data we collect

We collect only what we need to provide Searchbase.

2.1 Account data

  • Email
  • Password (stored only as a secure hash — we never see it in cleartext)
  • Google profile (if you sign in with Google): name, email, account identifier

2.2 Subscription and billing data

  • Your credit balance
  • Subscription details: subscription tier, billing periods, and a customer reference with our payment provider (Stripe)

Credit card data never transits our servers: it is collected directly by Stripe.

2.3 User-generated content

Stored in our EU-hosted database with per-user access isolation:

  • Chat conversations — titles, prompts, AI responses, tool results, timestamps
  • Scraping jobs — target URLs, extraction prompts, results, options
  • Long-term memory — free-text facts you author yourself (identity, projects, preferences)
  • Conversation summaries generated automatically to support long chats
  • Message feedback (thumbs up/down)
  • Workspaces and their members

2.4 Uploaded files

Audio and document uploads are stored in cloud object storage (Cloudflare R2) and served via short-lived signed links.

2.5 Data stored in your browser

  • Your cookie consent choice
  • Interface preferences and onboarding state
  • A local copy of your long-term memory entries

2.6 Server-side session cookies

  • Authentication cookies (httpOnly)
  • Analytics cookies — only if you accepted analytics consent

2.7 IP address and User-Agent

  • Collected by our CDN and security provider (Cloudflare) for DDoS / WAF protection
  • Collected in infrastructure request logs
  • Not sent to our error-tracking service
  • Anonymous visitors are not profiled by analytics

2.8 Connected mailboxes (Google / Microsoft)

If you connect your own mailbox so that Searchbase can send messages as you, we ask for send-only access and nothing else — gmail.send on Google, Mail.Send on Microsoft. Neither permission can read, list, or search a mailbox, and we do not request one that can.

From the provider we receive and store:

  • A refresh token, encrypted at rest (AES-128-CBC with HMAC authentication). It is decrypted in memory only, at the moment a message is sent.
  • The address of the connected mailbox, so the account page can show you which one is connected.
  • The permissions you actually granted, so that we can refuse to send — rather than fail halfway — if the send permission is missing.

We do not receive the contents of your mailbox. The message you approve is drafted in the chat, so it is retained as part of that chat session like any other content you write (§2.3) — the mailbox connection itself stores no message data, and the sent copy lives in your own Sent folder. Disconnecting the mailbox deletes the stored token immediately, and revoking access from your Google or Microsoft account settings has the same effect.

Limited Use. Searchbase's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use this data to develop, improve, or train generalised AI or ML models, we do not sell it, and we do not transfer it to others except as necessary to provide the sending feature you asked for, to comply with applicable law, or as part of a merger or acquisition. We do not allow humans to read this data unless we have your affirmative agreement for specific messages, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymised for internal operations.


3. Purposes and legal bases (Art. 6 GDPR)

PurposeData processedLegal basis
Account creation, service delivery, billingEmail, password (hash), subscription data, user contentArt. 6(1)(b) — performance of contract
Transactional email (verification, password reset)EmailArt. 6(1)(b) — performance of contract
AI processing of your prompts and filesPrompts, attachments, scraping resultsArt. 6(1)(b) — necessary to deliver the requested service
Long-term memory storageMemory entriesArt. 6(1)(a) — consent (you choose to enter the entries)
Product analyticsUsage eventsArt. 6(1)(a) — consent (cookie banner)
Security, anti-abuse, rate limitingIP, UA, user IDArt. 6(1)(f) — legitimate interest (protect the service)

4. Sub-processors and third parties

To operate Searchbase we rely on third-party providers, each acting as a sub-processor. We use them in the following categories:

CategoryPurposeData processedRegion
Cloud infrastructure & storageHosting, database, object storage, CDN, securityAccount data, all user content, uploaded files, IP/UA, request metadataEU + global
AI providersGenerate chat responses and summaries, transcribe audio, extract scraping resultsChat prompts, uploaded files, scraping descriptions and resultsUnited States / other non-EU
Search & data providersRun web, social and video searches requested by toolsSearch queries, handles, target URLsUnited States
PaymentsBilling and subscription managementBilling email, payment-method tokens, subscription metadataUnited States / Ireland
Transactional emailDeliver account emails (verification, password reset, notifications)Recipient emailUnited States
Analytics, error tracking & loggingProduct analytics (consent only), error monitoring, application logsUsage events, pseudonymous user ID, stack traces, structured logsEU / United States
AuthenticationSign-in with a third-party identity providerBasic profile + emailUnited States

A complete, up-to-date list of our sub-processors — with names, roles and links to their privacy policies — is available on request at [email protected]. For any transfer outside the EU we rely on the safeguards described in § 5.


5. International transfers (Art. 46 GDPR)

A significant portion of the sub-processors above are based in the United States or other non-EU countries. In particular, content you submit for AI processing (chat prompts, scraping descriptions, file content) is transmitted to AI providers in the United States (and, in fallback scenarios, to other non-EU providers listed above).

For these transfers we rely on:

  • Standard Contractual Clauses (SCCs) issued by the European Commission (Decision 2021/914)
  • The provider's adherence to the EU–US Data Privacy Framework, where applicable (e.g. Stripe, Google, Microsoft, Cloudflare)
  • Supplementary technical measures: encryption in transit, authenticated access, data minimization

6. Data retention

We keep data only as long as necessary for the purposes for which it was collected. Summary table:

Data categoryRetention period
Account dataUntil you request deletion (today via email request, self-service on the roadmap)
Chat sessions and messagesUntil you delete them, or until account deletion
Scraping jobsUntil you delete them, or until account deletion
Long-term memoryUntil you delete the entries
Uploaded filesDeleted when the parent session is deleted, or on account erasure
Connected mailbox tokensUntil you disconnect the mailbox, revoke access at the provider, or delete the account
Application logs~30 days (provider default)
Error-tracking events90 days
Analytics events90 days
Billing data (Stripe)Per Stripe's policy, typically 7 years (tax / accounting obligations)
Administrative audit recordsRetained for compliance and security; on account erasure, user identifiers may be removed from the records, but the action records are preserved

7. Cookies and similar technologies

CategoryPurposeTypeConsent
Strictly necessaryAuthentication (session cookies, httpOnly)HTTP cookieNot required
FunctionalYour cookie choice, interface preferences, onboarding state, local copy of your memory entrieslocalStorageNot required
AnalyticsProduct analytics (PostHog, ph_*)Cookie + localStorageRequired (opt-in)

The cookie banner is binary (accept all / reject all). Rejection fully disables analytics.

Full details — including individual cookie names, durations and the third parties that set them — are in the Cookie Policy.


8. Security

We implement concrete technical and organizational measures:

  • In transit: TLS 1.2+ end-to-end encryption
  • At rest: encryption managed by our cloud providers; application secrets held in a dedicated secret store
  • Per-user isolation: access controls enforced at the database level
  • Anti-abuse: WAF, DDoS protection and per-user rate limiting
  • Admin access control: role-based access with audit logging of every privileged action
  • Error minimization: error tracking configured to exclude personal data

No system is 100% secure. In the event of a personal data breach we will notify the competent supervisory authority within 72 hours under Art. 33 GDPR and, if high-risk, also data subjects under Art. 34.


9. Your rights (Art. 15–22 GDPR)

You have the following rights, exercisable free of charge:

  • Access (Art. 15) — obtain a copy of your data. How: email [email protected]. We export your data as JSON (currently capped at 10,000 rows per table for operational reasons).
  • Rectification (Art. 16) — you can edit account, memory and workspaces directly in the app. For other corrections, email [email protected].
  • Erasure (Art. 17) — email [email protected]. Erasure removes your files, analytics profile and database records.
  • Restriction (Art. 18) — email request.
  • Portability (Art. 20) — same mechanism as access (JSON export).
  • Objection (Art. 21) — email request.
  • Withdrawal of consent — analytics consent can be withdrawn from the cookie banner (reject all). Long-term memory consent is withdrawn by deleting the entries from the app.

Account erasure and data requests are currently handled by our team upon your email request; self-service tools are on the roadmap.


10. Automated decision-making and profiling (Art. 22)

We do not make solely-automated decisions producing legal effects or similarly significant effects on you.

Searchbase's AI models generate content (extractions, summaries, chat responses) but they are assistive tools: we do not automatically score your reliability, do not compute risk scores, do not deny access to services based on AI output.

We do not profile users for marketing purposes.


11. AI and user content

This section requires explicit honesty.

When you enter a prompt in chat, describe a scraping job, upload a file or audio, that content is sent to third-party AI providers in the United States (or other non-EU countries) for processing. Specifically:

  • Chat prompts and AI responses are processed by our primary AI provider, based in the United States.
  • If a fallback is active, prompts may be processed by an alternative AI provider (in the United States or another non-EU country).
  • Audio files uploaded for transcription are processed by a specialist transcription provider in the United States.
  • Scraping prompts and target URLs may be processed by third-party scraping providers in the United States.
  • Text search queries are processed by third-party search providers (web, social and video).

What this means in practice:

  • The data you enter in chats is seen by the AI sub-processor for the time needed to generate the response.
  • By contract / configuration, we do not use your data to train AI models, and our main AI sub-processors commit not to train their models on API data.
  • Do not enter in chats personal data of others without a legal basis, secrets, passwords, health data or other special categories under Art. 9 GDPR. Searchbase is not currently designed to process special categories of data.

12. Minors

Searchbase is not directed at minors under 16. We do not knowingly collect personal data from minors under 16. If you become aware that a minor has provided us personal data without parental consent, contact [email protected] and we will delete it.


13. Changes to this policy

This notice may be updated. The current version is always available at https://searchbase.org/privacy. For material changes we will notify you by email at the address linked to your account, with at least 15 days' notice.

The version and last-updated date are shown at the top of this document.


14. Contact and complaints

Privacy email: [email protected] General email: [email protected]

If you believe the processing of your personal data violates the GDPR or Italian law, you have the right to lodge a complaint with a supervisory authority:

  • For users resident in Italy: Garante per la Protezione dei Dati Personali Piazza Venezia 11, 00187 Roma Website: https://www.garanteprivacy.it

  • For users resident in other EU Member States: the supervisory authority of your country of residence, place of work, or place of the alleged infringement (Art. 77 GDPR).