Based Marketing

Privacy

What we collect, and who touches it

Last updated 19 September 2026

This is the current policy, and it describes Based as it is actually built today rather than a product we intend to build. Based is early and ships most weeks, so this page changes when the product does. If something here stops being true of the code, it gets corrected here and the date above moves.

How to reach us about your data

Based Marketing runs basedmkt.com. For anything to do with your information, including a copy of what we hold or a request to delete it, email hello@basedmkt.com. That is the address for privacy requests and a person reads it.

We have not set up a separate privacy desk, a data protection officer or a ticket queue, so there is no point pretending otherwise. One address, answered by us.

What we collect

All of it comes from one of three places: you typed it, you paid us, or we observed it on the website you gave us. There is no fourth source. We do not buy data about you and we do not enrich your account from anywhere.

  • Your account. Your email address, and either a password or your Google sign in. If you set a password, it goes from your browser to Supabase and is stored hashed. It never reaches a Based server and there is nowhere here that could show it to us. If you use Google instead, Google is where your email address and basic profile come from.
  • What you tell us about your business. In setup: your product name, a one line description, a category, who your customers are, optionally your company stage and product type, and your website address. In Brand Kit: tagline, industry, audience, the problem you solve, what you tried before, your best result, a testimonial if you paste one in, tone, what makes you different, and two brand colours.
  • Images you upload. A logo, a product screenshot, a product image.
  • What we observed on your website. The pages we read, what we found on them, the business facts we pulled out with the page and the sentence each one came from, the findings we raised, and the fixes we wrote for you.
  • Your billing record. Your Stripe customer and subscription identifiers, which plan, and its status. No card details, ever.
  • Your work in the product. Which listings and opportunities you are pursuing and what state each one is in, the assets we generated for you, and the notes you added.

Your website, and what we do with it

When you give us your website address, we read the public pages of that site. We find them from its sitemap and from its own links, we stay on the host you entered, and we read up to fifty pages in a run. Our crawler calls itself BasedMKT Analysis/1.0 in its requests, so you can find it in your own logs.

We keep observations rather than a copy of your site: page addresses and status codes, titles, headings, meta descriptions, the links and images on a page, its structured data, a word count, and roughly the first thousand characters of the readable text as an excerpt. We also read your robots.txt and your llms.txt, because what they say is part of what we report back to you.

Those observations, together with what you told us about your business, are sent to an AI model so it can pull out business facts, explain why a finding matters and draft copy. Groq is that model today and it is on the list below.

We only ever read what is already public on your site. We do not sign in to anything, we do not submit forms, and we change nothing.

One thing to know about uploaded images

Logos, screenshots and product images you upload are stored in a public storage bucket, which means each file has a web address that works without signing in. That is how the product puts your logo onto a generated asset. It also means anyone who has that address can open the file.

So: do not upload anything you would not be happy putting on your own website. If you already uploaded something you would rather was not there, email us and we will remove it.

Paying us

Checkout happens on Stripe. You are sent to a page Stripe hosts, you type your card there, and your card details go to Stripe and not to us. We never receive them, we have no field to put them in and no table to keep them in.

What comes back to us is the part we need to know whether you are a subscriber: the Stripe identifiers for you and your subscription, the plan, and the status. Changing your card, reading your invoices and cancelling all happen on Stripe's billing screen, which we open for you from Billing in your account settings.

Who else handles your data

This is the complete list of companies that touch your information as part of running Based, and what each one is for. It is a list we maintain by hand, and it is the first thing that changes when we add or drop a service.

Supabase
Accounts and sign in, the database every record on this page lives in, and file storage for images you upload. Supabase Auth also triggers your account email: the confirmation link, the sign in link and the password reset. Resend is what delivers it.
Resend
Email delivery for those account emails. Resend is set as the mail provider inside Supabase Auth rather than called from Based's own code, which does not make it any less real: your email address travels through Resend on its way to your inbox.
Vercel
Hosting. Every page and API request you make to basedmkt.com is served from Vercel.
Stripe
Payments and the subscription itself. You type your card on Stripe's own checkout page and it goes straight to Stripe. Based never sees a card number and has nowhere to store one.
Groq
The AI model. What we observed on your website, plus what you told us about your business, is sent to Groq so it can pull out the facts, write the reasoning on a finding and draft copy you asked for. Groq is the model we run today, and if we route those calls to an equivalent provider this list is the thing that changes first.
Google
Two separate things, both optional. Sign in with Google, if you choose that door instead of a password, in which case Google tells us your email address and your basic profile. And Google's image model, when the ad generator is configured to use it, which receives the image prompt built from your brand and nothing else.
Cloudflare
The other image model behind the ad generator, used when it is the one configured. Same input as above: the image prompt, not your account.
Serper
A search API we run ourselves, offline, to build the shared list of places a business can get listed. It is the same list for everybody and no customer data is sent to it.

Public links to a report

You can turn an analysis report into a public link and send it to somebody. That is the point of it: whoever opens the link reads the report without an account and without signing in to anything.

The link shows what the report says about the site that was analysed: the domain, the date we looked, how many findings there were, the verdict, the business facts we could confirm on that site with the page each came from, and the findings we selected, each with its evidence. It does not carry your email address, your account, your billing, or anything we learned anywhere other than on that site.

The link itself is a long random token, and we store only a hash of it. We genuinely cannot recover the link from our own database, so we cannot send it to you again and nor can anyone who steals a copy of the table.

You can revoke it. Revoking kills every live link for that report immediately and the address stops working for everybody, with no way to tell a revoked link from one that never existed. We keep the revoked record, including how many times the link was opened and when it was last opened, so there is a history of what you shared.

How long we keep it, and how to have it deleted

Your account and everything above stays while your account exists. We do not currently expire it on a schedule. One thing does get tidied automatically: when a new analysis of the same site finishes, the raw page records from your older runs of that site are pruned, while the findings and business facts from those runs are kept, because that is where the history you actually read lives.

There is no delete button in the product yet. To have your account and its data deleted, email hello@basedmkt.com from the address on the account and ask. Deleting the account removes what is attached to it: your profile, your brand kit, your analyses and their findings and facts, your report links, your listings work, and your billing record. It is a manual job on our side today, and we would rather say that than put a button on this page that does not exist.

Deleting your account does not remove your record from Stripe, which keeps payment records for its own accounting and legal reasons. Ask Stripe about those.

What we do not do

We do not run analytics, advertising pixels or session recording on this site. There are none in the code, which is why there is no cookie banner asking you to accept any.

The only cookies we set are the ones that keep you signed in. They come from Supabase's auth library and they are the reason a page knows who you are.

We do not sell your information, we do not rent it, and we do not share it with anyone outside the list above.

We are not claiming a certification here. We have not been audited against GDPR, CCPA or anything else, and we are not going to print a badge we did not earn. What we can do is tell you exactly what we hold, which is the point of this page, and delete it when you ask.

← Back to home