Allbase

FREQUENTLY ASKED QUESTIONS

Straight answers about Allbase.

Allbase is a private-beta product, so these answers distinguish what is available today from what may come later. For the complete data handling terms, read the Privacy Policy.

Getting started and current features

How do I sign up?

Choose Sign up / Sign in and enter your email. Use the code we send you. There is no password or separate account creation step. Your first sign-in creates a workspace; connecting agents and collaborating with others require private-beta approval.

What does “Allbase a project” mean?

Give the work a home your authorized agents can return to: current decisions, useful sources, and a clear next step. Ask an agent to save that state, then have another retrieve it before continuing. Project members and their authorized agents can read the full checkpoint history, while each agent writes in its own lane.

For a teammate, create a project and invite them to join. Their project role controls checkpoint access. Share files and folders separately; unrelated personal notes stay private. Shared tasks are planned. See what teams can do today.

Where can I see project history and agent activity?

Projects lists project records and discovers workstreams saved by your agents. Open a project’s checkpoint timeline for objectives, decisions, next actions, and attribution. Agents shows observed activity, connection checks, and reported skill installations. The workspace brief collects tasks and questions waiting on you; it is not a background agent runner.

Can I reuse skills across my agents?

Knowledge → Library lets you import and review private skill drafts, keep revision history, publish fixed private releases, and download their exact files. “Use in a project” prepares an installation request for a supported local helper.

Managed installation currently supports eligible documentation-only skills in Claude Code repositories. Other harness installs, agent blueprints, and team skill distribution are not generally available. Connecting MCP does not install skills or run them. Read the supported workflow.

Who reviews registration requests?

Allbase’s platform operator can see signup and approval history and review pending requests in Admin → Registrations. This is separate from a workspace administrator’s permissions; it does not provide a screen for browsing someone else’s private notes.

Your data

Where does Allbase store my data?

The hosted service runs on Cloudflare. Canonical Markdown and versioned artifact bodies are stored in private Cloudflare R2 object storage. Identity, permissions, revision history, checkpoints, memories, search records, and audit metadata are stored in Cloudflare D1. Search embeddings are stored in Cloudflare Vectorize. Authorized text is processed by Workers AI to create embeddings and rank search results.

The private beta does not currently promise a specific country or data-residency jurisdiction.

Who can access my workspace?

You and active members of your workspace can access content according to their role. Each AI client you connect receives a separate, revocable read-only or read/write OAuth grant. Other users receive content only when you deliberately share or publish it. Eligible recipients can preview shared files before accepting access for their agents.

Allbase is not zero-knowledge. Cloudflare provides the infrastructure, and the operator can technically reach stored data outside the application. That access is bounded in writing: your written request, an incident affecting you, or a legal obligation, with recording and notice commitments. These are operating responsibilities, not a technical barrier. See “Can the person who runs Allbase read my notes?” below and section 6 of the privacy policy.

Does Allbase train AI models on my data?

No. Allbase does not use private workspace content to train AI models. It uses pre-trained models through Cloudflare Workers AI for embedding and search ranking. Cloudflare states that it does not use Workers AI customer content to train models or improve its own or third-party services without explicit consent.

When Allbase returns content to an external AI client, that provider’s privacy, retention, and training terms apply to the client session separately.

Is my data encrypted?

Core data in Cloudflare R2 and D1 is encrypted at rest using AES-256 with Cloudflare-managed keys. Allbase uses HTTPS/TLS in transit. This is managed platform encryption, not end-to-end encryption or customer-managed encryption. Allbase must decrypt authorized content to store, search, and return it.

Does Allbase sell my information or use advertising trackers?

No. Allbase does not sell personal information or use it for third-party behavioral advertising. The web app currently uses essential first-party session and security cookies, not third-party advertising cookies.

Mixed tools and platforms

What if my work is split across Google Drive, email, meetings, and different AI models?

Cross-agent continuity is the problem Allbase is built to solve. MCP-capable clients such as Claude, Claude Code, ChatGPT, Codex, and Cursor can use the same governed Allbase workspace even though their models and interfaces differ.

Today, Allbase does not continuously crawl or synchronize Google Drive, inboxes, meeting platforms, or complete AI-chat histories. You or an authorized agent must explicitly save, summarize, import, or upload the material you want in Allbase.

Does connecting an agent give Allbase my full chat history?

No. An MCP connection gives the client access to the Allbase tools and scope you approve. Allbase receives tool calls and content the client explicitly sends through those tools; it does not automatically receive every message in the chat.

Can I store PDFs, Office files, images, audio, or meeting recordings?

Allbase can store arbitrary non-Markdown file types as versioned artifacts, subject to current upload limits. The original file is preserved, but searchable knowledge requires a Markdown sidecar, summary, or transcript. Inline preview is currently limited to supported PDF, HTML, and image formats.

If I delete something in Google Drive or email, is it deleted from Allbase?

No. Saving or uploading external material creates a separate Allbase copy. Allbase does not currently maintain a live sync relationship with the source, so changes or deletions do not automatically propagate in either direction.

Control, sharing, and portability

How do agent permissions work?

Every connected client receives its own named OAuth grant for one workspace. You choose read-only or read/write access and can revoke the grant without changing other agents. Allbase rechecks the user, workspace membership, role, and scope when the client uses the service.

How does sharing work?

You can share a specific file or folder read-only or read/write with an accepted contact or team. The recipient reviews and accepts the share before it reaches their agents, and can disable it later. Shared results retain provenance, and shared writes retain user and agent attribution.

Projects organize people, roles, and linked shares; membership alone does not grant access to those files. Ownership transfers and organization member controls are available. Revocation blocks future access through a grant, but does not recall exported copies or content already returned to an external client.

Can I delete my account?

Yes. Settings → Account → Delete my account previews the scope and requires your sign-in email as confirmation. It removes your identity and access and starts removal of personal workspace data. Organization-owned work may need reassignment first; blocked transfers must be resolved before erasure can proceed.

Leaving a workspace does not delete other members’ work. Physical storage cleanup can require follow-up after an interruption; deletion is not a promise of immediate removal from every backup or external copy. Read the retention and deletion limits or contact us to confirm completion.

Can I export or import my data?

Yes, both, from Settings → Your data. Export downloads a ZIP of every current note as ordinary Markdown with paths, frontmatter, and wikilinks intact; it opens directly as an Obsidian vault and re-imports cleanly. Import accepts a ZIP of Markdown files (an Obsidian vault, a previous export, a folder of notes): you see a per-file preview first, choose whether existing notes are kept or replaced, and then apply. Every imported note gets normal revision history. Artifacts can be downloaded separately. The ZIP does not include historical revisions, audit records, checkpoints, or derived search indexes. Skill revisions have separate ZIP downloads. The local sync tool supports explicit pull and push, plus an optional watcher that uploads local edits. It does not automatically pull remote changes or propagate local deletions.

What happens when I delete a file or artifact?

Deletion is currently recoverable: the item becomes hidden from normal use, while revisions and history remain available for restore. This differs from account erasure, which is available in Settings with a scope preview and confirmation. See the retention and deletion details.

Security and product status

Can the person who runs Allbase read my notes?

The application has no operator role for browsing another person’s private notes. The infrastructure operator can technically access stored content, and authorized operational tools or agents can exercise delegated infrastructure authority. Allbase is not a zero-knowledge service.

Our policy limits direct content access to your written request, an incident affecting you, or a legal obligation, with recording and notice commitments. Revision history and selected activity events provide useful attribution, but do not record every read or all infrastructure access. See the access policy and its verification limits.

Is Allbase end-to-end encrypted or zero-knowledge?

No. Data is encrypted at rest and in transit, but Allbase must be able to process authorized content to index, search, and return it. Customer-managed keys and application-layer end-to-end encryption are not current beta features.

Where does Allbase stand on SOC 2?

We have begun readiness work toward a SOC 2 Type II examination. Allbase does not yet have an independent SOC 2 report. Existing application controls and release tests are a foundation; formal access reviews, recovery and incident exercises, vendor review, retention controls, and sustained operating evidence still need work.

We have not committed to an examination scope, observation period, or completion date. Cloudflare’s own report does not attest to Allbase’s application or operations. Read our readiness direction and current gaps.

Does Allbase meet regulated-industry requirements?

Allbase does not claim HIPAA compliance, ISO 27001 certification, or FedRAMP authorization. Native sign-in uses email codes; application-enforced MFA, workforce SSO, and SCIM are not current beta features. Review your requirements with us before relying on Allbase for regulated or contractually restricted information.

Can I choose a data-residency region?

Not in the current private beta. Allbase does not presently make a country-specific residency commitment. Region-restricted or dedicated deployments would require a separate product and contractual commitment.

Where can I read the full privacy terms or ask a question?

Read the Privacy Policy. During private beta, privacy questions can be sent to jason@allbase.ai.

TRY THE CORE WORKFLOW

Connect one agent with a revocable OAuth grant.

Open the setup guide