Legal

Privacy Policy

Last updated 22 August 2026

Draft pending legal review

This document describes the product’s actual data handling accurately, but it has not yet been reviewed by a lawyer. Do not rely on it as a final legal instrument.

Who we are

Baseerah (“we”, “us”) provides software that screens startup investment opportunities against an investor’s own written thesis. This policy covers the Baseerah web application at baseerah.dev.

Questions about this policy or your data: privacy@baseerah.dev.

What we collect

Account information. Your email address, name, firm name and investor type, collected when you register and during onboarding. Authentication is handled by Supabase Auth; if you sign in with Google we receive your email address, name and profile picture from Google, and nothing else.

Deal data. Companies, founders, meeting notes, deck text, your written investment thesis, screening results, memos and chat threads — everything you create or upload in the product.

Mailbox data, only if you connect a mailbox. Described in detail below.

Billing information. Subscription status and plan, via Polar. We do not receive or store your card details.

Google user data

Connecting a Gmail account is entirely optional and the product is fully usable without it. If you do connect one, we request three scopes:

  • userinfo.email and userinfo.profile — to identify which mailbox is connected and display it back to you.
  • gmail.readonly — to read messages that carry a pitch deck attachment, and to download that attachment.

What we actually read. We do not read your mailbox generally. Every scan is filtered by a fixed search query that returns only messages which have an attachment, where that attachment is a PDF, PPTX, PPT or DOCX, excluding spam and trash, within a recent time window. For each matching message we read the subject, sender, timestamp, snippet, and the contents of the first supported attachment. You choose how many messages each scan may examine.

What we store. An encrypted Google refresh token, so scans can run without asking you to sign in again. It is encrypted with AES-256-GCM before it is written to our database. Message content is not stored unless you explicitly import a message as a deal, in which case the extracted deck text and the message’s subject, sender and identifier are saved to your account.

Write access. None. The scope we request is read-only. We cannot send, delete, label or modify anything in your mailbox.

Revoking access. Disconnect from Settings at any time. We revoke the token with Google and delete our stored copy. You can also revoke it directly at myaccount.google.com/permissions. Deals you already imported remain in your account until you delete them.

Limited Use

Baseerah’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, that means:

  • We do not use Google user data for advertising, and we never sell it.
  • We do not use Google user data to develop, improve or train generalised artificial intelligence models.
  • No human at Baseerah reads your Google user data, except with your explicit consent for a specific issue you have raised, where required by law, or for security purposes such as investigating abuse. Our AI subprocessor, Microsoft, may review flagged content under its own abuse-monitoring controls, as described below — that review is a security purpose and is the only circumstance in which a person outside Baseerah may see this content.
  • We transfer Google user data only as necessary to provide the feature you asked for, to comply with the law, or as part of a merger or acquisition with your consent.

Third parties who process your data

We do not sell data. These are the processors involved in delivering the product, and what each one sees:

  • Microsoft Azure AI Document Intelligence — receives deck attachments, including those downloaded from a connected mailbox, to convert them into text. This is necessary because a PDF or PowerPoint file cannot be screened without first being read.
  • Microsoft Azure OpenAI Service — receives the extracted deck text and the deal details in order to produce the screening analysis, memo or pass email you requested. Azure OpenAI does not use customer data submitted through the service to train or improve any Microsoft or third-party models.
    Microsoft operates automated abuse monitoring on this service: prompts and responses are retained by Microsoft for up to 30 days and may be reviewed by authorised Microsoft personnel where automated systems flag a potential policy violation. This is an abuse-prevention and security control operated by Microsoft, not by us — no Baseerah employee can access that content, and it is not used for advertising, profiling or model training.
  • Supabase — database, authentication and file storage.
  • Polar — subscription billing. Receives your email address; card details go to their payment processor, not to us.
  • Resend — delivers account emails such as confirmation and password reset.
  • Vercel — application hosting.

These transfers exist solely to provide features you have asked for. None of them use your data for their own purposes or for advertising.

Retention and deletion

Account and deal data is kept while your account is open. Delete an individual deal at any time from the pipeline and it is removed from the database. Disconnecting a mailbox immediately deletes the stored refresh token.

To delete your account entirely, email privacy@baseerah.dev. We remove your account data within 30 days, excluding records we are legally required to retain, such as billing records.

Security

All traffic is encrypted in transit with TLS. Google refresh tokens are encrypted at rest with AES-256-GCM using a key held only in server-side configuration and never sent to the browser. Tenant separation is enforced in the database itself through row-level security, so one account cannot read another’s rows even in the event of an application bug.

No system is perfectly secure. If you believe you have found a vulnerability, please write to security@baseerah.dev.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to certain processing. Contact privacy@baseerah.dev and we will respond within the period the applicable law requires.

Changes to this policy

If we change how we handle your data we will update this page and revise the date above. Material changes affecting Google user data will be notified to you in the product before they take effect.