Privacy Policy
Last updated: March 24, 2026
1. Introduction
Welcome to Basecamp ("Company," "we," "us," or "our"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered automation and workforce management platform (the "Service").
By using Basecamp, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.
2. Information We Collect
2.1 Personal Information You Provide
We collect information you voluntarily provide when using our Service, including:
- Account Information: Name, email address, phone number, and password when you create an account
- Profile Information: Professional details, work history, certifications, skills, and resume data
- Employment Information: Job applications, offers, work schedules, time tracking data, and performance reviews
- Organization Information: Company name, address, business details, and team structure (for employers)
- Payment Information: Billing details processed securely through our payment processor, Stripe
- Communications: Messages, feedback, and support requests you send us
- Safety and Compliance Data: Safety form submissions, incident reports, hazard assessments, inspection records, OSHA logs, worker safety training records, certifications, and compliance documentation
- Workflow Recordings: Screen recordings, mouse/keyboard interaction patterns, and UI navigation data captured when recording workflows for automation
- Desktop Agent Data: Screenshots, screen content, application state data, and UI element information captured during automated task execution
2.2 Information Collected Automatically
When you access our Service, we automatically collect:
- Usage Data: Pages visited, features used, search queries, and interaction patterns
- Device Information: Browser type, operating system, device identifiers, and IP address
- Analytics Data: Performance metrics and error logs to improve our Service
- Screen Capture Data: Screenshots and screen content captured during automation sessions for AI processing and workflow execution
- Application Interaction Data: Information about which applications are accessed, UI elements interacted with, and actions performed during automated workflows
- Automation Telemetry: Performance data, success/failure rates, and execution logs from automated tasks
2.3 Information from Third Parties
We may receive information from:
- OAuth Providers: When you sign in with Google or LinkedIn, we receive your name, email, and profile information
- Integrated Services: When you connect cloud storage services (OneDrive, Google Drive), we index and process the contents of files in your connected folders to enable AI-powered search through the Knowledge Center. File contents are converted to vector embeddings and stored in our search infrastructure (Pinecone).
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our Service
- Deliver AI-powered knowledge search across your connected files, automation recommendations, and operational insights
- Execute automated workflows across your desktop applications via the Autopilot agent
- Index and search your organization's connected cloud storage files (OneDrive, Google Drive) to power the Knowledge Center
- Generate AI-powered safety compliance scores, gap analyses, and safety program recommendations
- Process and analyze safety form submissions, incident reports, and compliance documentation
- Provide insurance management tools, EMR calculations, and premium modeling
- Generate predictive safety analytics, incident pattern detection, and safety forecasts
- Build anonymized and aggregated proprietary industry datasets from operational and financial data across the platform (see Section 4D)
- Process payments through Stripe
- Send service notifications and updates
- Respond to your inquiries and provide customer support
- Ensure security and prevent fraud
- Comply with legal obligations
4. AI and Machine Learning
Important Notice: Basecamp utilizes artificial intelligence and machine learning technologies to power our platform features. By using our Service, you acknowledge and agree that:
- Third-Party AI Providers: We send your data — including screenshots, documents, workflow recordings, and business information — to third-party AI providers (Anthropic, Google) for processing. We do not control what these providers do with your data once it reaches their systems. Each provider's own terms of service and privacy policy govern their data handling. We select providers whose policies align with commercial data protection, but we cannot guarantee how they process, store, or use your data. You should review the privacy policies of Anthropic and Google to understand their practices. Separately, we use anonymized and aggregated operational data to build proprietary industry datasets and benchmarks (see Section 4D).
- AI-Generated Content: Some features, including desktop automation actions, workflow execution, knowledge center search results, compliance scoring, and document generation, are powered by AI. While we strive for accuracy, AI-generated content may not always be perfect.
- Data Processing: Your interactions with AI features (such as search queries and preferences) are processed to improve the relevance and quality of results.
We implement appropriate technical safeguards to protect personal information used in AI training, including anonymization and aggregation techniques.
4A. Safety and Compliance Data
Important Notice: When you use our safety compliance features, we collect and process additional categories of data:
- Safety Records: Safety form submissions, inspection reports, incident reports, near-miss reports, hazard assessments, job hazard analyses (JHAs), and toolbox talk records.
- Compliance Data: OSHA/OHS logs, compliance scores, safety program documentation, corrective and preventive action (CAPA) records, and regulatory compliance assessments.
- Worker Safety Records: Safety training completion records, certification status, and safety observation data.
- Industry Intelligence: We may use anonymized and aggregated safety patterns from your organization's data to build industry-level intelligence (e.g., "companies in this industry typically maintain these types of SOPs"). No company-identifiable information is shared. This aggregate data helps all users receive better safety recommendations.
- Data Retention: Safety and compliance records are retained in accordance with applicable regulatory requirements, including OSHA record-keeping requirements (minimum 5 years for injury/illness records, 30 years for exposure records). You may request deletion of non-regulated safety data at any time.
- Regulatory Authorities: Safety data is NOT shared with regulatory authorities without your consent, except as required by law or valid legal process. You are solely responsible for any mandatory reporting to regulatory authorities.
4B. Insurance and Predictive Analytics Data
Important Notice: When you use our insurance management or predictive analytics features, we collect and process additional categories of data:
- Insurance Data: Insurance policy details, coverage information, claims history, Experience Modification Rate (EMR) history, and premium information. This data is used solely to provide insurance management features within your organization.
- Predictive Analytics Data: Incident patterns, safety forecasts, and trend analyses generated from your organization's safety records. These predictions are derived from your data and anonymized industry benchmarks.
- Data Access: Insurance and financial data is accessible only to users with appropriate administrative roles within your organization. We do not share your insurance data with insurance carriers, brokers, or third parties without your explicit consent.
- Data Retention: Insurance records are retained for the duration of your account plus any period required by applicable insurance regulations. Predictive analytics data is retained as long as the underlying safety records exist.
4C. Desktop Agent & Automation Data
Important Notice: When you use our desktop agent and automation features, we collect and process additional categories of data:
- Screen Capture Processing: Screenshots captured during automation are processed by AI to understand UI state and execute workflows. Screen content may include text, images, and data visible in applications at the time of capture.
- Full Device Access: The Autopilot desktop agent can access everything visible on your screen and everything accessible through your desktop applications — your files, email, financial software, project management tools, and any other application. The agent can see, click, and type anything you can. All data visible on your screen during an automation session may be captured and processed.
- Incidental Data Capture: During automation, the agent may incidentally capture sensitive information visible on screen (passwords, financial data, personal information of third parties). We process this data solely for automation purposes and do not intentionally extract or store incidentally captured sensitive data separately.
- Workflow Models: Recorded workflows are used to train automation models specific to your organization. Workflow data is not shared across organizations.
- Data Minimization: We capture only the screen data necessary to execute automations. Screenshots are processed in real-time and are not permanently stored unless required for workflow training.
- Third-Party Application Data: When the agent interacts with third-party applications, data from those applications may be processed. You are responsible for ensuring that sharing such data with our Service complies with the third-party application's terms and any applicable privacy laws.
- Cloud File Indexing: When you connect your organization's OneDrive, Google Drive, or other cloud storage to the Knowledge Center, we index the contents of your shared files into our vector database (Pinecone). This means the text content of your documents is processed, converted to vector embeddings, and stored in Pinecone to enable AI-powered semantic search. Authorized members of your organization can search across these indexed files.
- Automation Logs: We retain logs of automated actions (what was clicked, typed, navigated) for debugging, audit trails, and workflow improvement. These logs are retained for 90 days unless you request earlier deletion.
4D. Proprietary Datasets & How We Use Your Data
Important Notice: We want to be completely transparent about how your data is and is not used:
- What We Don't Do: We do NOT sell your data. We do NOT share your identifiable business data with competitors, other customers, or any third party. Your documents, workflows, financials, and business operations are yours. Note: we do send your data to third-party AI providers for processing (see Section 4 above) — what those providers do with it is governed by their own policies.
- What We Do: We use anonymized and aggregated data from across the platform to build proprietary industry datasets. These datasets include construction industry benchmarks for labor costs, safety incident rates, compliance patterns, insurance metrics, and operational efficiency. No individual company or person can be identified from these datasets.
- Why: These proprietary datasets power the features that make the platform valuable — accurate compliance scoring, meaningful industry comparisons, predictive safety analytics, and smart recommendations. The more organizations use the platform, the better these benchmarks become for everyone.
- Financial Data: We specifically collect and anonymize financial data including labor rates, project costs, insurance premiums, and EMR rates to build construction industry benchmarks. This data is aggregated at a level where no individual organization can be identified.
- Opt-Out: You may opt out of having your anonymized data included in proprietary datasets by contacting privacy@gobasecamp.ai. Note that opting out may reduce the accuracy of benchmarking features for your organization.
5. Information Sharing and Disclosure
5.1 We Do NOT Sell Your Personal Information
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
5.2 Service Providers
We share information with trusted third-party service providers who assist us in operating our Service:
- Stripe: Payment processing (subject to Stripe's Privacy Policy)
- Clerk: Authentication and identity services
- Google (Gemini AI): AI processing of documents, field notes, photos, and vision-based screen analysis for content analysis and generation
- Anthropic (Claude AI): AI processing for desktop automation, workflow understanding, and vision-based screen analysis
- Pinecone: Vector database for semantic search and document similarity
- Vercel: Application hosting and web analytics
- PostHog: Product analytics and user behavior analysis
- Meta (Facebook): Advertising pixel for conversion tracking on our marketing pages
- Inngest: Background job processing for automated workflows
- Cloud Infrastructure (AWS): Data hosting, storage, and computing
These providers are contractually bound to protect your information and may only use it to provide services to us.
5.3 Business-to-Business Data Sharing
We do not share employer company information with third parties for purposes outside of providing the Service. Employer data (company details, job listings, team information) remains confidential and is not disclosed to competitors or external parties.
5.4 Within the Platform
Certain information is shared within the platform to enable core functionality:
- Team members within an organization can view relevant organizational data
- Knowledge Center search results are accessible to authorized members of your organization
- Automation workflows and templates may be shared among team members within your organization
5.5 Legal Requirements
We may disclose your information if required by law, legal process, or government request, or to protect the rights, property, or safety of Basecamp, our users, or others.
6. Data Retention
We retain your information for as long as necessary to:
- Provide our Service and maintain your account
- Comply with legal and regulatory requirements
- Resolve disputes and enforce our agreements
Upon account deletion, we will delete or anonymize your personal information within 30 days, except where retention is required by law or for legitimate business purposes (such as maintaining transaction records for tax compliance).
Automation Data Retention: Screen captures are processed in real-time and are not permanently stored. Automation logs (action records, execution data) are retained for 90 days. Workflow models trained from your recordings are retained for the duration of your account and deleted upon account termination.
7. Data Security
We implement industry-standard security measures to protect your information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication and access controls
- Regular security assessments and monitoring
- Employee access restrictions and training
- Encryption of screen capture data in transit to AI processing services
- Automated purging of temporary screen capture data after processing
- Access controls on automation logs and workflow data, restricted to authorized organization members
While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
8. Your Rights and Choices
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal information
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your personal information
- Portability: Request a portable copy of your data
- Opt-Out: Opt out of certain data processing activities
- Withdraw Consent: Withdraw consent where processing is based on consent
To exercise these rights, please contact us at privacy@gobasecamp.ai.
8.1 California Residents (CCPA/CPRA)
California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information we collect and how it's used, and the right to opt out of the sale or sharing of personal information (though we do not sell your data).
8.2 European Users (GDPR)
Users in the European Economic Area have rights under the General Data Protection Regulation (GDPR). Our legal basis for processing includes contract performance, legitimate interests, and consent where applicable.
8.3 Canadian Users (PIPEDA and BC PIPA)
Basecamp is headquartered in British Columbia, Canada. Canadian users have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (PIPA), including:
- The right to access your personal information held by us
- The right to request correction of inaccurate personal information
- The right to withdraw consent for the collection, use, or disclosure of your personal information (subject to legal or contractual restrictions)
- The right to file a complaint with the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia
We collect, use, and disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances. We obtain meaningful consent for the collection, use, and disclosure of personal information, except where permitted by law.
9. Cookies and Tracking Technologies
We use cookies and similar tracking technologies for the following purposes:
9.1 Essential Cookies
- Authentication (Clerk): Session cookies to keep you signed in and maintain your account security
- Preferences: Cookies to remember your settings and display preferences
9.2 Analytics and Performance
- Vercel Web Analytics: Collects anonymous page view and performance data to help us improve our Service. No personally identifiable information is collected.
- PostHog: Product analytics that tracks feature usage, user flows, and interaction patterns to help us improve the user experience. PostHog data is processed through our own domain (first-party) to ensure reliable delivery. You may opt out of PostHog tracking by contacting us at privacy@gobasecamp.ai.
9.3 Advertising and Conversion Tracking
- Meta (Facebook) Pixel: Used on our marketing pages to measure the effectiveness of our advertising campaigns and track conversions (such as sign-ups). The Meta Pixel may collect browsing data and use it for targeted advertising on Meta platforms. You can opt out of Meta tracking through your Facebook Ad Preferences or by using browser-based ad blockers.
9.4 Your Choices
You can control cookies through your browser settings. Most browsers allow you to block or delete cookies. However, disabling essential cookies may prevent you from using certain features of our Service. You may also use browser extensions or privacy tools to block specific tracking technologies.
10. Children's Privacy
Our Service is not directed to individuals under 16 years of age. We do not knowingly collect personal information from children. If we learn we have collected such information, we will promptly delete it.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international data transfers in compliance with applicable laws.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
- Email: privacy@gobasecamp.ai
- Website: https://app.gobasecamp.ai
© 2026 Basecamp. All rights reserved.