Baseraze
Pricing

Privacy Policy

Last updated 30 July 2026

This policy explains what personal data MeshAI Labs, Inc. (“MeshAI Labs”, “we”, “us”) collects when you use Baseraze, why we collect it, who else sees it, and what you can ask us to do with it. It covers baseraze.com, app.baseraze.com and our APIs.

It does not cover apps that other users build and publish on our hosting. Those are operated by the user who built them: see section 10.

Our Terms of Service govern the rest of the relationship.

1. What we collect

CategoryWhat it isWhere it comes from
Account dataYour email address, your name if you provide one, your sign-in identifiers, and the sign-up intent you select.You, through Clerk, our identity provider.
ContentYour project descriptions and prompts, the build plans, the generated source code, review reports and the build event log.You, and the Service acting on what you submit.
Billing dataYour Stripe customer and subscription identifiers, plan status, renewal date, credit balance and credit ledger entries.Stripe, and our own accounting of credits.
Product analyticsEvents recording what happened in the product, such as a build starting, completing, failing or being published, and the cost and duration of a run.The Service, as you use it.
Technical dataServer logs including IP address, request paths, timestamps, user agent and error traces.Automatically, when your browser or a client calls us.

We never receive your card number, expiry or security code. Card details are entered on Stripe’s hosted checkout and stay with Stripe.

We do not run advertising trackers, session recording, or third-party analytics scripts on our pages.

2. Why we use it

  • To run the Service: authenticate you, generate, verify, review and host your apps, and let you export your source.
  • To bill you: process purchases and subscriptions, meter credits, and keep records we are required to keep.
  • To keep the platform working and safe: debug failures, monitor capacity and cost, detect abuse, and enforce our terms.
  • To improve the product: understand where builds fail, what they cost, and which routing produces better results. This uses aggregated and de-identified operational data wherever it can.
  • To communicate with you about your account, your builds, incidents and changes to the Service.

We do not train our own models on your content, and we do not sell personal data or share it for cross-context behavioural advertising.

3. Legal bases

If you are in the EEA or the UK, we rely on: performance of a contract for running the Service and billing you; legitimate interests for platform security, abuse prevention, and product improvement, balanced against your rights; legal obligation for tax and accounting records; and consent where we ask for it, which you can withdraw at any time.

4. What leaves our systems during a build

This is the most important thing to understand about the Service. To build an app, we send your description and the code being written to large language model providers. In practice that means the prompt, the build plan, the files the agents produce and read, and the errors from verification runs are transmitted to and processed by the providers listed in section 5.

  • Provider calls are made through a gateway we operate, so provider API keys are never placed inside a build container.
  • Every build stage has a fallback provider. If the primary is down or fails, the same content goes to the fallback instead, which may be a different company than the one that normally handles that stage.
  • Providers process this content under their own API terms, which govern their retention and use of it. We select API tiers whose terms do not permit using customer API content to train their models, but their terms, not ours, control what they do.

Do not put credentials, secrets, personal data about other people, or confidential material belonging to someone else into a prompt or an uploaded file.

5. Who else processes your data

We share personal data with the service providers below, who process it on our behalf under contract. We do not sell it, and we do not disclose it to anyone else except where section 6 applies.

ProviderPurposeWhat they receive
ClerkAuthentication and account managementEmail address, name, sign-in and session data
StripePayments, subscriptions and billing portalEmail address, payment details you enter with them, transaction and subscription data
OpenAIModel provider for generation, review and repair stagesPrompts, plans, generated code and build errors
AnthropicModel provider for generation, review and repair stagesPrompts, plans, generated code and build errors
Moonshot AI (Kimi)Model provider used as a fallback and for some stagesPrompts, plans, generated code and build errors

The routing between model providers changes as we measure quality and cost, so any of the model providers listed may handle any generation stage. We will update this list before adding a new one.

6. Other disclosures

We may disclose data where we are legally required to, to respond to a valid legal request, to enforce our terms, to investigate abuse or fraud, or to protect the rights and safety of users and the public. If our business is transferred as part of a merger, acquisition or sale of assets, data may transfer with it, and we will tell you before it becomes subject to a different privacy policy.

7. Where data is stored

Account data, project data, build logs and generated artifacts are stored on infrastructure we operate ourselves, rather than on a public cloud. Our service providers listed in section 5 process data on their own infrastructure, which is located in the United States and, for some of them, in other countries.

Where personal data is transferred out of the EEA or the UK, that transfer relies on the European Commission’s Standard Contractual Clauses, the UK Addendum, or another lawful transfer mechanism offered by the provider.

8. How long we keep it

  • Account data, projects, prompts, builds and generated artifacts: for as long as your account is open, and then deleted or anonymised after it closes.
  • Backups: the platform database is backed up nightly and backups are kept for 14 days, so deleted data can persist in backups for up to that long before it ages out.
  • Billing and tax records: for as long as the law requires us to keep them, which is longer than the life of your account.
  • Server logs and analytics events: retained for a limited operational period, and kept in aggregated form afterwards.
  • Published apps and their hosting resources: removed when you unpublish them, when your entitlement ends, or when your account closes.

9. Security

We take measures appropriate to the risk, including: traffic to and from the Service is encrypted in transit; provider API keys are held by a gateway and never placed in a build container; generated code is built and run in sandboxed containers rather than on our own machines; published apps run in isolated namespaces under network policies that prevent them reaching our internal systems or each other; access to production systems is restricted to the people who need it; and backups are verified restorable.

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant regulator where the law requires it.

10. Apps built and published by users

If you publish an app, you are the controller of any personal data your app collects from its users, and we act as your processor for hosting it. You are responsible for telling your users what your app collects and for having a lawful basis to collect it.

If you are an end user of an app someone built on Baseraze, this policy does not describe what that app does with your data. Contact the operator of that app. You can contact us at devsupport@baseraze.com if you cannot reach them or believe an app is breaching our terms.

11. Cookies

We use cookies that are necessary to run the Service: session and authentication cookies set by Clerk to keep you signed in and to guard against cross-site request forgery, and cookies Stripe sets during checkout for fraud prevention. We do not use advertising or cross-site tracking cookies, so there is no tracking to opt out of. Blocking necessary cookies will stop you being able to sign in.

12. Your rights

Depending on where you live, you have some or all of the following rights over your personal data: access a copy of it; correct it; delete it; restrict or object to how we process it; receive it in a portable format; and withdraw consent you have given. If you are in California, you also have the right to know what we collect and disclose and the right not to be discriminated against for exercising your rights. We do not sell or share personal data as those terms are defined under California law.

To exercise any of these, email devsupport@baseraze.com from the address on your account. We will respond within the time the applicable law allows, normally within 30 days, and we may need to verify your identity first. There is currently no self-service deletion button: account and data deletion is handled by that email request.

You can export the full source of any build from the product at any time without asking us.

If you are in the EEA or the UK and you think we have handled your data wrongly, you can complain to your local supervisory authority. We would rather you told us first.

13. Children

The Service is not for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.

14. Changes to this policy

We will update this page when what we do changes, in particular when we add or remove a service provider. The date at the top shows when it was last changed, and we will give notice by email or in the product before a material change takes effect.

15. Contact

MeshAI Labs, Inc., Delaware, United States. For any privacy question or request, email devsupport@baseraze.com.