Legal Documents
Privacy Policy
Effective Date: October 1, 2026. Last updated: September 24, 2026.
What changed on September 24, 2026: we corrected the list of information we do not collect to describe how web filtering works, added Sentry session replay and Meta to our list of service providers, and corrected where to find the options to download or delete your data. These are corrections to earlier statements. How we handle your data did not change.
At BaseLock, we take your privacy seriously. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. BaseLock provides endpoint security and device management services for individuals and small businesses.
Information We Collect
We collect only what is needed to provide the service and bill for it. Specifically:
- Account information: your name, email address, and mobile phone number, provided during registration.
- Authentication data: one-time SMS verification codes and session tokens issued by Amazon Cognito.
- Payment information: billing details are collected and stored by Stripe. BaseLock receives only a Stripe customer reference, the subscription plan, and the last four digits of the payment method for display.
- Device telemetry: device identifiers, operating system and version, hostname, agent versions, and health indicators reported by the endpoint agents installed on your devices.
- Threat detections: security events surfaced by the endpoint agent, including event type, severity, file path, file hash, process name, and timestamp. We do not receive file contents under normal operation.
- Reported messages: both ways of reporting a suspicious message work the same way underneath. We store the message itself, exactly as you sent it, then extract technical indicators from it before deleting the stored copy. What we collect depends on how you report it. Text a message to our messaging number and we store the text of that message; the indicators we can pull from it are limited to registrable domains and file hashes, because a texted message carries no sender for us to extract anything from. Forward an email to the reporting address on your dashboard and we collect more: the message's full headers, the sender's complete email address, any attachments, and the authentication result (DKIM, SPF, and DMARC) for the sending domain, and here we can also extract a sender domain and a non-reversible hash of the sender address. A forwarded email will usually contain information about the person who sent it, who is not a BaseLock customer and has not agreed to this policy; we keep what they sent for the same period as the rest of the message, and it is removed on the same schedule, including as part of your account deletion. The stored message itself, however you sent it, is deleted within seven (7) days of when we receive it and is not shared with other customers. One narrow exception sends more: a link on a known link-shortening service is sent to VirusTotal as a full link so it can be checked, described under VirusTotal below. See Shared Threat Corpus below for what happens to the extracted indicators.
- Product usage: sign-in timestamps, in-product actions, and notification preferences, used to operate the dashboard and improve the product.
- Support communications: emails and forms you submit to BaseLock support.
- Cookies and local storage: we store session tokens and a small number of preferences in your browser's local and session storage.
- Support chat: if you open the support chat, Crisp sets a cookie so your conversation is still there when you come back. It is set only when you open the chat, never just because you visited a page, and it lasts 30 days. We delete support conversations 90 days after the last message in them.
- Advertising measurement: our public marketing pages load the Meta (Facebook) pixel, which sets a cookie and reports page views and completed sign-ups to Meta so we can measure which advertising works. It runs on the public site only, never inside your dashboard or on your devices, and it receives no device telemetry, threat detections, or support communications. You can turn it off at any time from the privacy panel on any public page, which also turns off error monitoring and session recording.
How We Use Your Information
BaseLock uses your information to:
- Provide and operate the service, including endpoint monitoring, threat detection, and incident response.
- Authenticate you and protect your account through SMS one-time codes and session management.
- Send transactional messages such as login codes, security alerts, billing receipts, and service updates.
- Bill your subscription and process refunds.
- Maintain audit logs of administrative actions for security and compliance.
- Investigate and respond to suspected threats, abuse, or policy violations.
- Read a message you report to us so we can answer you about it, and extract technical indicators from it to protect every BaseLock customer; we never share the message content itself, including anything about who sent it, with other customers.
- Improve product quality, reliability, and detection accuracy.
- Measure which advertising brings people to the site, using the Meta pixel described above.
We do not sell your personal information. We do not use your data to train models that are shared with third parties outside the security workflows described below.
We do share limited browsing activity on our public marketing pages with Meta for advertising measurement, as described under Advertising measurement above. Under some state privacy laws this counts as "sharing" for cross-context behavioral advertising even though no money changes hands. You can opt out at any time using the privacy panel on any public page. This sharing never includes your device telemetry, threat detections, support communications, or SMS opt-in data.
Mobile Information and SMS Consent
Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. All of the categories above exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
We use your mobile number only to send the messages you consented to when you created your account: one-time passcodes to verify your number and sign you in, security alerts about your devices, which may include a single-use link to allow or block a program we flagged, and account notifications such as when someone joins your team. Message frequency varies. Message and data rates may apply. Reply STOP to turn off texts, reply HELP for help. You can also manage alerts from your BaseLock dashboard.
Data Access and Monitoring
We do not collect, access, or monitor personal content stored on your devices, including:
- Files (documents, photos, videos)
- Emails
- Messages
- Passwords
- The pages you read or what you type into websites
- Application data
Our management tools (including device management and endpoint detection technologies) are configured to monitor only device health indicators, security compliance, and threat detections.
Web filtering is the one exception worth spelling out. To block dangerous sites, it checks the name of each site a filtered device looks up (for example, example.com), and we record the ones it blocks. It does not see the pages you read, what you type, or anything inside an encrypted connection.
Metadata Collection by Third-Party Tools
Our authorized security tools may collect limited metadata such as:
- Filenames and file hashes
- Process names and command lines
- Device identifiers
- Software version information
- Threat signatures
These metadata collections are standard for security purposes and are not used to access, view, or copy the contents of your files.
Security Incident Response
In the event of a confirmed security incident (such as a malware infection or targeted attack), BaseLock may collect and review limited forensic metadata necessary to investigate and respond to the threat. This may include:
- Process activity
- Application crash reports
- Threat detection logs
- File attributes (such as name, size, hash, or type)
- Where strictly required for analysis, a copy of the malicious artifact that triggered the detection
All incident response activities are limited to the scope of the threat. We do not perform blanket scans of customer personal content.
Automated Decision-Making
We use automated systems, including a security-focused machine learning model hosted on Amazon Bedrock, for two different purposes, and what is sent to the model differs between them. To triage a device detection and generate a plain-language summary of it, we send only metadata about the detection (event type, file name, process, severity); we do not send file contents, personal communications, or browsing data for this purpose. To judge a message you report to us, whether texted or forwarded by email, we send the model the message text itself, so it can decide whether the message is dangerous; see the Reported messages entry above and Shared Threat Corpus below for what we keep from a reported message and for how long. Neither use sends your message to VirusTotal: VirusTotal receives only the specific indicators described under VirusTotal below, plus a full link in the narrow case of a known link-shortening service. In both cases the model's output is advisory and does not by itself block legitimate activity on your device.
Shared Threat Corpus
When you report a suspicious message, whether by texting it or by forwarding it as an email, the indicators we extract from it (registrable domains and file hashes from either channel, plus sender domains and a non-reversible hash of the sender address from a forwarded email, all described under Reported Messages above) are added to a threat catalog shared across every BaseLock customer, not only the one who reported it.
There is no opt-out. The shared corpus is the product working as intended: letting one customer's reports be excluded would weaken what every other customer gets from that catalog, while the excluded customer kept receiving it.
Retention is set per indicator type, because one retention period would misdescribe most of them. File hashes are retained indefinitely, since a malicious file does not become safe with age. Registrable domains are retained for ninety (90) days, and sender domains and the non-reversible hash of the sender address are each retained for thirty (30) days, since a compromised mailbox is usually recovered by its owner within a month. Each of these periods restarts from the most recent time we observed that same indicator, not from the first, so a domain or address that keeps turning up in reports stays in the catalog for as long as it keeps turning up.
When you delete your account, we remove the link between your account and any indicator you contributed to the corpus. The indicator itself may remain in the catalog, in a form that identifies nobody.
Remote Access
A BaseLock analyst or engineer can remotely access a device you have enrolled, to investigate a security detection, to follow up on something you reported, or to carry out maintenance. This access uses CrowdStrike Real Time Response, the same tooling that protects the device.
We tell you every time. Before access begins we send a notice to the account's email address, and where you have a mobile number on file and have not opted out of our texts, to that number as well. The notice says which device, what the work is, and that it is time limited and logged. You can confirm the notice to let the work start sooner, and we tell you again when the session ends.
Whether we need your confirmation depends on why we are accessing the device. For routine maintenance, or when we are looking into something you reported, we do not proceed unless you confirm the notice, and if we do not hear from you we simply do not access the device. Where we have identified a security detection or are following one up, access is part of the service and does not wait on a reply, because an investigation that waits has already lost time it may not have. In that case the notice tells you what is happening and, where possible, lets you make it start sooner.
Each session is time limited. A session runs for four (4) hours and can be extended in further four (4) hour steps while the work continues. No single session may exceed twenty four (24) hours from the moment it starts. That ceiling is enforced automatically, so access that is not renewed is withdrawn without anyone having to remember to withdraw it.
Every session is recorded: who opened it, which device, the reason given, and when it ended.
A small number of administrative accounts, used to operate and repair the service itself, hold this access on a standing basis rather than session by session.
On a business account, the administrator receives the notice and can confirm it. The person who uses the device is told as well, every time, whether or not they administer the account.
Service Providers and Subprocessors
We share limited data with service providers that help us operate BaseLock. These providers are contractually bound to use your data only for the purposes we direct.
- Amazon Web Services (AWS): hosting, storage, authentication (Cognito), email (SES), and AI inference (Bedrock). Primary region: US East (N. Virginia).
- Telnyx: delivery of your sign-in passcodes and security alert text messages, and receipt of your replies to them. Telnyx receives your mobile number and the content of those messages only.
- VirusTotal: receives the registrable domains and file hashes extracted from a message you report, including the domain portion of the sender's address. In the narrow case where the message contains a link on a known link-shortening service, such as bit.ly or tinyurl.com, VirusTotal also receives that full link, because a shortened link cannot be evaluated without following where it leads. VirusTotal never receives the message body, any attachment, or the sender's full address.
- Amazon Textract: reads the text inside an image you send us, such as a screenshot attached to a reported email or sent to our messaging number, so we can examine what it says. Textract receives only the image.
- CrowdStrike: endpoint detection and response agent installed on your devices.
- JumpCloud: device management and remote command execution.
- Stripe: payment processing.
- Cloudflare: DNS, web application firewall, and content delivery. On an individual account, if you accept our offer to block a domain from a reported message, that domain is also written into a Cloudflare Zero Trust Gateway policy so it is refused across your devices.
- Vercel: hosting of the BaseLock website and dashboard.
- Sentry: application error monitoring and, if you allow it, masked session replays in which text, form inputs and images are hidden before they leave your browser.
- Meta: advertising measurement on our public marketing pages only, as described under Advertising measurement above. You can turn it off from the privacy panel.
- Crisp: live support chat. Crisp receives the content of your support conversations, the page a conversation started from, and basic browser and device information. If you are signed in it also receives the email address on your account, so we can confirm we are talking to a real account holder. Crisp IM SAS is a French company and processes this data in the European Union.
Data Ownership
All customer data remains the sole property of the customer. BaseLock claims no ownership rights over customer files, communications, or any personal content.
Data Security
All data BaseLock holds about you and your devices is encrypted in transit (TLS 1.2 or higher) and at rest using AWS-managed encryption. Access to production data is restricted to authorized personnel following least-privilege principles, audited, and gated by multi-factor authentication. Public BaseLock domains sit behind Cloudflare's web application firewall and rate limiting.
Data Retention
We retain account and device records for as long as your account is active and for a limited period afterward for billing, audit, and abuse-prevention purposes. Threat detection records and audit logs are retained for up to twelve (12) months. When you delete your account, we remove your personal data within thirty (30) days, except for a minimal tombstone record that allows us to honor your deletion request and meet legal obligations.
A message you report to us, whether by text message or by forwarding an email, including its headers, any attachments, and any information it contains about the person who sent it, is deleted within seven (7) days of when we receive it, with no exception for the stored message itself. That does not apply to the indicators we extract from it before deletion, such as a sender domain or the non-reversible hash of a sender address: those are retained separately and for longer, as described under Shared Threat Corpus above.
Your Rights
You have the following rights regarding your data, exercisable directly from the dashboard or by emailing privacy@getbaselock.com:
- Access: request a copy of the personal data we hold about you using "Request a copy of my data" under Settings, Account, or "Download my data" in the privacy panel.
- Deletion: request deletion of your account and associated personal data using "Delete account" under Settings, Account, or "Delete my data" in the privacy panel. Your data is erased after a 30-day grace period, during which you can ask us to undo it. If you have reported a message that has not yet reached its seven-day retention limit, this also removes it; the process that performs this removes the stored message without ever reading it.
- Correction: update inaccurate account information from your account settings.
- Objection / restriction: ask us to limit how we use your data for specified purposes.
Depending on your location, you may have additional rights under laws such as the California Consumer Privacy Act (CCPA), the EU General Data Protection Regulation (GDPR), or the UK Data Protection Act. We honor verified requests under those laws.
Children's Privacy
BaseLock is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have collected information from a child without verifiable parental consent, we will delete it promptly.
International Data Transfers
BaseLock is operated from the United States. If you access BaseLock from outside the United States, your information may be transferred to, stored, and processed in the United States. Where required by law, we use appropriate safeguards (such as Standard Contractual Clauses) for these transfers.
SMS Communications
By providing your phone number, you consent to receive SMS messages from BaseLock for authentication, security alerts, and service updates. Standard message and data rates from your carrier may apply. See Section 15 of our Terms of Service for full details on SMS, including frequency, opt-out, and phone number changes.
Changes to This Policy
We will update this Privacy Policy when our practices change. Material changes will be communicated through the dashboard or by email at least thirty (30) days in advance, except where a shorter notice period is required by law or to address a security issue.
Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Email: privacy@getbaselock.com