Allbase

PRIVACY POLICY

Your knowledge deserves a clear privacy story.

This policy explains what Allbase collects, why it is needed, where it is processed, who can access it, and the limits of the current private-beta service.

Effective: September 1, 2026 · Last updated: September 9, 2026

Private by default

Your workspace is not shared with other users unless you deliberately share or publish content.

No model training

Allbase does not use private workspace content to train AI models.

Cloudflare hosted

The hosted service uses Cloudflare Workers, R2, D1, Vectorize, Workers AI, and Email Service.

Not zero-knowledge

Allbase must be able to process authorized content to store, search, and return it.

1. Scope and current status

This policy applies to the hosted Allbase service at allbase.ai, including its web app, API, hosted MCP server, OAuth flow, and private-beta communications. “Allbase,” “we,” and “us” refer to the operator of that service.

Allbase is currently in private beta. This policy describes our current data handling, commitments, and limitations. Readiness work described below is not a completed independent security assessment.

2. Information we collect

Account and profile information

We process information such as your email address, display name, handle, account status, workspace memberships, roles, invitations, and authentication events. Authentication codes, session tokens, OAuth tokens, and agent credentials are stored only in hashed or otherwise non-plaintext form after issuance.

Workspace content

We store the content you or an authorized agent places in Allbase, including Markdown, uploaded artifacts, revisions, checkpoints, memories, tasks, comments, metadata, and searchable sidecars. That content may contain personal information about you or other people.

Connections, sharing, and provenance

We process the identity and access scope of connected agents and MCP clients, OAuth grants, contacts, teams, share recipients, publication settings, and attribution showing which user or agent performed a change.

Service and security data

We and Cloudflare process request and device information needed to deliver and protect the service, such as IP address, timestamps, route and response metadata, rate-limit signals, error categories, and security events. We aim to minimize personal information in logs and do not intentionally copy workspace bodies or authentication secrets into routine application logs. Request paths, identifiers, and diagnostic error details can nevertheless contain personal information or text. We treat that information as service data, limit its use to the purposes in this policy, and are improving redaction and retention controls.

3. How we use information

  • Provide, maintain, and secure your workspace and account.
  • Authenticate people and agents and enforce permissions.
  • Store, version, search, retrieve, export, restore, and attribute content.
  • Deliver continuity checkpoints and relevant context to authorized agents.
  • Enable invitations, accepted shares, teams, and publications.
  • Send sign-in codes, invitations, and essential service communications.
  • Diagnose failures, prevent abuse, and improve reliability using service metadata, tests, and feedback.
  • Comply with applicable law and protect the rights and safety of users and the service.

4. AI processing and model training

Allbase does not use your private workspace content to train AI models.

Allbase uses pre-trained models through Cloudflare Workers AI to create embeddings and rank authorized search results. Authorized text chunks and search queries are processed for those inference tasks. Derived embeddings are stored in Cloudflare Vectorize. Cloudflare states that it does not use Workers AI customer content to train models or improve Cloudflare or third-party services without explicit consent; see Cloudflare’s Workers AI data-usage terms.

When a connected Claude, ChatGPT, Codex, Cursor, or other AI client retrieves content from Allbase, that returned content is processed by that client and its model provider. Their privacy, retention, and training settings apply separately. Allbase cannot change the policies of an external AI service.

5. Where data is stored and processed

The current hosted service is Cloudflare-native:

  • R2 stores canonical Markdown and versioned artifact bodies in private object storage.
  • D1 stores identity, membership, authorization, revision, checkpoint, memory, search, and audit records.
  • Vectorize stores derived search embeddings and workspace-scoped metadata.
  • Workers AI processes authorized text for embedding and reranking.
  • Cloudflare Email Service delivers sign-in and invitation messages.

The private beta does not currently promise that customer data will remain in a particular country or legal jurisdiction. Cloudflare may process data in locations where it operates its services.

6. Who can access your data, and the operator’s commitments

Content may be accessible to:

  • You and active members of your workspace, according to their role.
  • Agents and MCP clients you authorize, according to their revocable read-only or read/write grant.
  • People you invite to preview or accept explicitly shared content, and subscribers to content you deliberately publish. Human recipients can preview an invitation before accepting; acceptance enables agent retrieval of the shared content.
  • Cloudflare and its subprocessors as needed to provide the infrastructure services described above.
  • Authorities or other parties when disclosure is legally required or reasonably necessary to protect users, the service, or the public.

Allbase does not sell personal information and does not use it for third-party behavioral advertising. Allbase is not end-to-end encrypted or zero-knowledge: authorized service components must be able to process content to provide search and retrieval.

Application permissions and activity history

Registration-operator status does not by itself grant access to another person’s private workspace. Application access depends on workspace membership, role, and any explicit sharing permissions. Allbase records many content changes, permission changes, and selected agent retrieval events. You can inspect workspace activity, connected agents, and sessions in the app. The event stream is not a complete record of every read, and does not capture all direct infrastructure activity.

Infrastructure access and our commitments

Allbase runs in a Cloudflare account administered by the operator. Infrastructure administrators can technically access stored data outside the application. Automated build and release tools, and authorized agents operating those tools, can exercise delegated infrastructure permissions. The operator remains responsible for that authority and for the following commitments.

  1. Narrow purpose. Direct access to production databases, storage, or recovery snapshots that touches your content is permitted only for a written request from you, an active security incident or data-integrity failure affecting your workspace, or a legal obligation. It is not permitted for curiosity, product research, debugging convenience, or marketing.
  2. Record and explain access. Our policy requires a record of direct customer-content access and notice to you of what was accessed and why within seven days, unless the law prohibits notice. This is an operator commitment, not a claim that every infrastructure action is automatically captured in your event stream. Documented access reviews and evidence of these procedures are part of the readiness work described below.
  3. Accountable delegated access. Permission to operate the service is not permission to use customer content for an unrelated purpose. These limits apply to operator-directed agent workflows as well. We are formalizing the inventory, scope, approval, and review of privileged human and service access.
  4. Minimize disclosure. We limit use of diagnostic data to operating and securing the service. If your request requires sending private content to an additional support tool or model provider, we will explain that processing and obtain your approval first. Cloudflare processing and the AI clients you connect are described separately in this policy.
  5. Transparent support tooling. If Allbase adds application support tooling that can read workspace content, our policy is to require your explicit, per-request approval and to show the access in your event stream. That tooling is not a current product feature.
  6. Export and deletion support. You can export current Markdown and download artifacts, subject to the limits in section 11. Account erasure is available from Settings → Account; its scope, cleanup limitations, and recovery retention are described in section 10. Contact us if deletion fails or you need confirmation of what has been removed.

Allbase is currently a private-beta service operated by one person. These policy commitments remain our responsibility while we build the procedures and evidence needed for independent assessment. They have not been independently assessed; infrastructure access remains technically possible.

7. Mixed tools and external services

Allbase is designed to be a shared governed layer across different AI tools. It is not currently a universal crawler or continuous synchronization service for Google Drive, email, meeting platforms, or complete AI-chat histories.

Information enters Allbase when you or an authorized agent explicitly saves, imports, summarizes, or uploads it. Doing so creates a separate Allbase copy. Deleting or changing the source in another service does not automatically delete or change the Allbase copy, and deleting an Allbase copy does not change the source.

8. Security and encryption

Cloudflare documents that R2 objects and D1 data are automatically encrypted at rest using AES-256 with Cloudflare-managed keys, and that transfers use TLS. See Cloudflare’s R2 and D1 security documentation.

Allbase also uses workspace-scoped authorization, revocable agent grants, hashed credentials, secure browser sessions, conditional writes, attribution, and audit records. No service can guarantee absolute security. Allbase does not currently offer customer-managed encryption keys or end-to-end encryption.

SOC 2 readiness: working toward Type II

Allbase has begun SOC 2 readiness work with the goal of a Type II examination. Allbase does not yet have an independent SOC 2 report. A Type II examination assesses controls and their operation over a specified period; a plan or internal assessment does not establish that result. See the AICPA’s SOC resources.

Remaining work includes documented access reviews and privileged-agent permissions, repeatable recovery and deletion verification, incident-response exercises, vendor and subprocessor reviews, defined retention schedules, and durable evidence that controls operate consistently. This work remains to be completed and evidenced. Examination scope, the observation period, and a report date have not been committed.

Cloudflare publishes information about its own SOC 2 Type II report. That is provider assurance within Cloudflare’s report scope; it is not an attestation of Allbase’s application, people, or operations.

9. Cookies

The web app uses essential first-party cookies and related security tokens to keep you signed in, prevent cross-site request forgery, and protect your account. Allbase does not currently use third-party advertising cookies.

10. Retention, deletion, and recovery history

We retain account and workspace information while the account is active and as needed to provide, secure, audit, and recover the service. Some credentials and invitations have defined expiration periods; security and audit records may remain after access is revoked.

File and artifact deletion inside a workspace is a soft delete: revision bodies and history remain available for restore. Account erasure is intended to permanently remove your account and eligible personal workspaces, including their content and derived search data. Shared or organization-owned resources may need reassignment first. Content retained in another person’s workspace is not automatically deleted by your erasure.

Project membership grants access to all of the project's checkpoints, including existing history, for accepted members and their authorized agents. Creating a project with an existing workstream key brings that workstream's checkpoint history into the project. Agents with write access add checkpoints in their own attributed lanes. Unrelated personal notes are not shared through project membership. Project checkpoints and their attribution remain when an author leaves or deletes their account, if the project survives. Removing membership or revoking an agent connection stops its future access, but cannot erase copies already received by another person or agent.

Blocking account access and physically removing every stored copy are separate steps. Cleanup can continue or require operator follow-up after access is blocked; the private beta does not guarantee immediate complete physical erasure across live storage, indexes, and recovery copies. Limited account-deletion and attribution records may remain to preserve other users’ history and prevent deleted data from being restored. If erasure fails or you need completion confirmation, contact us. We will investigate and explain the status, any information still retained, and the reason for retaining it.

Cloudflare’s D1 Time Travel provides database recovery history for up to 30 days on its paid plan. That is not a verified deletion deadline for every operational copy, audit record, or provider backup. We are establishing a complete retention schedule and recovery procedures that preserve deletion decisions. Recovery data is restricted to the purposes in section 6; we do not use it to make erased content available again for ordinary service use. Contact us before relying on a specific retention or deletion deadline.

11. Export and portability

You can export current canonical Markdown as ordinary files and use the local sync workflow. Versioned artifacts can be downloaded separately. The current workspace ZIP does not include every historical revision, audit record, checkpoint, or derived index.

12. Your choices and privacy rights

You can review and edit workspace content, manage or revoke agent grants and sessions, decline or disable shares, unpublish content, and export current Markdown. Depending on where you live, you may also have legal rights to request access, correction, deletion, portability, restriction, or objection regarding personal data.

During private beta, send requests to jason@allbase.ai. We may need to verify your identity before acting on a request.

13. Children

Allbase is intended for adults and business or professional use. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

14. Changes to this policy

We will update this page when our practices or service providers materially change and will revise the effective date above. If a change materially reduces privacy protections, we will provide additional notice when reasonably practical.

15. Contact

Private-beta privacy questions and requests can be sent to jason@allbase.ai.