Privacy

Last updated 28 July 2026

This policy explains what we collect, why, and what you can do about it. It is written to be read, not to be survived.

What we collect

Your account. Your name and email address, through our authentication provider, so we know who you are when you sign in.

Your work. The threads, plans, tasks, campaigns, posts, documents and files you create in Selfbase, and the history of what the agent did on your instruction. This is the product: without it there is nothing to show you.

Your credentials. The model provider keys and connected-account tokens you give us, held as described below.

Operational data. Request logs, error reports and performance traces, so we can tell when something is broken. Credentials are stripped before anything is written to a log.

How your credentials are held

Model provider keys and connected-account tokens are encrypted before they are stored, using envelope encryption: a unique data key per secret, wrapped by a key held in AWS Key Management Service and bound to your workspace. A key is decrypted only at the moment a job needs it and is never written to a log or returned to a browser or app. You only ever see a masked version.

Where a provider allows it, we hold no long-lived token at all. Our GitHub integration stores only an installation identifier and mints a short-lived token, scoped to a single repository, each time it does work, then revokes it.

You can disconnect any account at any time. Disconnecting revokes the grant at the provider where their API allows it, and always removes our copy.

Model providers

Selfbase sends your prompts and the context needed to answer them to the model provider whose key you connected. Those providers process that content under their own terms and their own privacy policies. We do not train models on your content and we do not sell it.

Who processes your data

  • Amazon Web Services — hosting, storage and key management, in the United States.
  • Convex — the application database.
  • Clerk — authentication.
  • Sentry — error reporting, with credentials redacted before they are sent.
  • Apple — push notifications and, if you subscribe, payment.
  • The model providers and outside accounts you connect — only what a job you approved requires.

Your rights

You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Deleting your account removes your workspaces, your work and your stored credentials. Write to hello@selfbase.com and we will confirm when it is done. If you connected an account through a platform that offers its own deletion callback, see data deletion.

Retention

We keep your work for as long as your account exists. Operational logs are kept for a short period and then discarded. Deleted content is removed from our live systems promptly and ages out of backups on their own schedule.

Children

Selfbase is not intended for anyone under 16, and we do not knowingly collect their data.

Changes

If this policy changes in a way that matters, we will tell you before it takes effect rather than quietly editing this page.

Contact

Selfbase
hello@selfbase.com