Legal
Privacy Policy
How Assistant for Basecamp handles your data.
Last updated: September 30, 2026
Summary
Assistant for Basecamp is a browser extension and web app that enhances Basecamp with features like tags, statuses, custom fields, Kanban boards, and automations. We take the minimum amount of data needed to run the product. We don't sell data. We don't share it with advertisers.
What we store
- Account metadata: Basecamp account ID, name, and your Basecamp user profile (email, name, avatar URL).
- Authentication tokens: OAuth access and refresh tokens from Basecamp, used to call Basecamp's API on your behalf. Encrypted at rest.
- API tokens (optional): If you create an API token on the dashboard so an AI agent or a script can act as you in one workspace, we store a salted hash of the token (never the token itself), its name, whether it may write or only read, the workspace it belongs to, when it was created, and roughly when it was last used. Requests made with a token are handled like your own requests from the extension: same records, same permissions, same logs. We send no analytics events for them. You can revoke a token on the dashboard at any time, and it stops working within a minute.
- Connected apps (optional): If you sign an AI client in to Assistant with OAuth instead of a token (the claude.ai or ChatGPT connectors, Claude Desktop, Claude Code, Codex, and similar), we store the app's registration (its name and callback address), the workspace you approved, whether it may write or only read, and the app's access and refresh tokens as hashes, with the approval details encrypted. Access tokens last fifteen minutes and are renewed by the app. Requests from a connected app are handled like requests made with a token: same records, same permissions, same logs, no analytics events. You can disconnect an app on the dashboard's MCP page at any time, and its access stops right away.
- Extension-added data: Tags, statuses, custom field definitions and their values, saved board views, per-column WIP limits, and automation rules you create inside Assistant, along with the Basecamp project and item identifiers they attach to.
- Voice note transcripts: When someone in your workspace clicks Transcribe on a Basecamp voice note, we store the resulting transcript text, its summary, and action items so the whole workspace can read it without transcribing again. Transcripts follow Basecamp's own project access: someone who can't open the project can't read its transcripts. The audio itself is fetched from Basecamp only for the seconds transcription takes and is never stored.
- Automation event records: Automations are driven by Basecamp webhooks and run on our servers. If an admin turns automations on for a project, Basecamp sends us an event whenever something in that project changes, and we keep the item's title and body text from that event so rules can match on them, plus a log of which rule ran and when. Projects without automations send us nothing.
- Billing data: Handled by Stripe. We store your Stripe customer ID and subscription status but never your card details.
- Technical logs: Request logs (IP, user agent, endpoint) kept for 30 days for security and debugging.
- Uninstall feedback (optional): If you fill out the survey shown when you uninstall the extension, we receive the reason you select, any comment you write, and an anonymous install ID (a random identifier not linked to your name or email). It's used only to improve onboarding.
- Contact messages: If you use our contact form, we receive your name, email, topic, and message so we can reply.
- Acquisition source: If you visited
getassistant.iobefore creating your account, we store which site or campaign first brought you here (source, medium, and landing page) with your account, and link this site's anonymous analytics ID to it. This tells us which channels bring real customers. Your account record stores only that first source and landing page, not your browsing history, though linking the analytics ID also connects your earlier visits to our marketing pages (never your Basecamp data) to your account inside our analytics tool. - Session recordings (marketing site only): On
getassistant.iowe record how visitors move through our pages (clicks, scrolling, and navigation) so we can see which parts are unclear. Anything you type is masked before it leaves your browser, so form contents are never captured. This does not run in the extension or inapp.getassistant.io, and it never touches your Basecamp projects.
What we do NOT store
- A copy of your Basecamp projects. When Assistant renders its features, the extension reads messages, to-dos, comments, and files live from the Basecamp API as the signed-in user, and we don't keep them. The two exceptions are the voice note transcripts and the automation event records described above, and each exists only for the projects where someone turned that feature on.
- Voice note audio. Transcription reads the audio in memory and discards it; the transcript, summary, and action items are what we keep.
- Your Basecamp password.
- Tracking pixels or advertising cookies.
How we use your data
- To authenticate you and keep your session active.
- To render Assistant features inside Basecamp by calling Basecamp's API with your OAuth token.
- To bill you via Stripe.
- To send transactional emails (password resets, billing receipts, seat invites).
- To investigate security incidents and debug errors.
- To understand which marketing channels lead to paying customers, by linking the first source that brought you to
getassistant.ioto your account (see "Acquisition source" above).
Who we share data with
Only these sub-processors, each for a specific purpose:
- Cloudflare: hosting, CDN, DDoS protection, and voice note transcription (Workers AI, running on Cloudflare's infrastructure; audio is processed transiently and not retained).
- Stripe: payment processing.
- Basecamp (37signals): to read/write data inside your Basecamp account via OAuth.
- PostHog: product analytics and marketing-site session replay (aggregate events, no PII sold or shared).
- Help Scout: the support widget on this site (live chat and email). If you send us a message through it, Help Scout receives what you write, your name and email, and technical details such as the page you were on and your browser, so we can reply.
We will never sell your data or share it with advertisers.
Your rights
- Access: Use our contact form to request a copy of your data.
- Delete: Disconnect your Basecamp account and we will purge your account data within 30 days. Automated deletion endpoint available on request.
- Revoke access: You can revoke our OAuth access from your Basecamp account settings at any time. We will no longer be able to call Basecamp on your behalf.
Data location
Data is stored on Cloudflare's global infrastructure (D1 database, KV store). Stripe data is stored by Stripe under their own policies, and support messages are stored by Help Scout under theirs.
Cookies
All cookies we set are first-party. No third-party cookies, no advertising cookies.
- Session cookie (
app.getassistant.io, HTTP-only): stores your session token so you stay signed in. - Login hint (
ga_logged_in,getassistant.io): a yes/no flag set after you sign in, containing no personal data, so this site can show "Dashboard" instead of "Sign in". - Analytics cookie (
ph_*,getassistant.io): a PostHog cookie holding a random visitor ID so repeat visits count as one visitor. - Attribution cookie (
afb_attr,getassistant.io, 90 days): remembers which site or campaign first brought you here (for example, Basecamp's integrations directory).
Visitors in Europe are asked before the analytics and attribution cookies are set, and declining keeps the site fully functional.
The support widget (Help Scout) sets no cookies. It keeps its own state, such as a message you started writing, in your browser's local storage.
Children's privacy
Assistant is not directed at children under 16. We do not knowingly collect data from children.
Changes to this policy
If we make material changes, we will email active admins and post a notice on this page. The "Last updated" date at the top will reflect the change.
Contact
Questions? Contact us.