Legal
Privacy Policy
How Assistant for Basecamp handles your data.
Last updated: August 15, 2026
Summary
Assistant for Basecamp is a Chrome extension and web app that enhances Basecamp with features like tags, statuses, custom fields, Kanban boards, and automations. We take the minimum amount of data needed to run the product. We don't sell data. We don't share it with advertisers.
What we store
- Account metadata: Basecamp account ID, name, and your Basecamp user profile (email, name, avatar URL).
- Authentication tokens: OAuth access and refresh tokens from Basecamp, used to call Basecamp's API on your behalf. Encrypted at rest.
- Extension-added data: Tags, statuses, custom field definitions and their values, saved board views, per-column WIP limits, and automation rules you create inside Assistant, along with the Basecamp project and item identifiers they attach to.
- Voice note transcripts: When someone in your workspace clicks Transcribe on a Basecamp voice note, we store the resulting transcript text, its summary, and action items so the whole workspace can read it without transcribing again. Transcripts follow Basecamp's own project access: someone who can't open the project can't read its transcripts. The audio itself is fetched from Basecamp only for the seconds transcription takes and is never stored.
- Automation event records: Automations are driven by Basecamp webhooks and run on our servers. If an admin turns automations on for a project, Basecamp sends us an event whenever something in that project changes, and we keep the item's title and body text from that event so rules can match on them, plus a log of which rule ran and when. Projects without automations send us nothing.
- Billing data: Handled by Stripe. We store your Stripe customer ID and subscription status but never your card details.
- Technical logs: Request logs (IP, user agent, endpoint) kept for 30 days for security and debugging.
- Uninstall feedback (optional): If you fill out the survey shown when you uninstall the extension, we receive the reason you select, any comment you write, and an anonymous install ID (a random identifier not linked to your name or email). It's used only to improve onboarding.
- Contact messages: If you use our contact form, we receive your name, email, topic, and message so we can reply.
- Acquisition source: If you visited
getassistant.iobefore creating your account, we store which site or campaign first brought you here (source, medium, and landing page) with your account, and link this site's anonymous analytics ID to it. This tells us which channels bring real customers. Your account record stores only that first source and landing page, not your browsing history, though linking the analytics ID also connects your earlier visits to our marketing pages (never your Basecamp data) to your account inside our analytics tool. - Session recordings (marketing site only): On
getassistant.iowe record how visitors move through our pages (clicks, scrolling, and navigation) so we can see which parts are unclear. Anything you type is masked before it leaves your browser, so form contents are never captured. This does not run in the extension or inapp.getassistant.io, and it never touches your Basecamp projects.
What we do NOT store
- A copy of your Basecamp projects. When Assistant renders its features, the extension reads messages, to-dos, comments, and files live from the Basecamp API as the signed-in user, and we don't keep them. The two exceptions are the voice note transcripts and the automation event records described above, and each exists only for the projects where someone turned that feature on.
- Voice note audio. Transcription reads the audio in memory and discards it; the transcript, summary, and action items are what we keep.
- Your Basecamp password.
- Tracking pixels or advertising cookies.
How we use your data
- To authenticate you and keep your session active.
- To render Assistant features inside Basecamp by calling Basecamp's API with your OAuth token.
- To bill you via Stripe.
- To send transactional emails (password resets, billing receipts, seat invites).
- To investigate security incidents and debug errors.
- To understand which marketing channels lead to paying customers, by linking the first source that brought you to
getassistant.ioto your account (see "Acquisition source" above).
Who we share data with
Only these sub-processors, each for a specific purpose:
- Cloudflare: hosting, CDN, DDoS protection, and voice note transcription (Workers AI, running on Cloudflare's infrastructure; audio is processed transiently and not retained).
- Stripe: payment processing.
- Basecamp (37signals): to read/write data inside your Basecamp account via OAuth.
- PostHog: product analytics and marketing-site session replay (aggregate events, no PII sold or shared).
We will never sell your data or share it with advertisers.
Your rights
- Access: Use our contact form to request a copy of your data.
- Delete: Disconnect your Basecamp account and we will purge your account data within 30 days. Automated deletion endpoint available on request.
- Revoke access: You can revoke our OAuth access from your Basecamp account settings at any time. We will no longer be able to call Basecamp on your behalf.
Data location
Data is stored on Cloudflare's global infrastructure (D1 database, KV store). Stripe data is stored by Stripe under their own policies.
Cookies
All cookies we set are first-party. No third-party cookies, no advertising cookies.
- Session cookie (
app.getassistant.io, HTTP-only): stores your session token so you stay signed in. - Login hint (
ga_logged_in,getassistant.io): a yes/no flag set after you sign in, containing no personal data, so this site can show "Dashboard" instead of "Sign in". - Analytics cookie (
ph_*,getassistant.io): a PostHog cookie holding a random visitor ID so repeat visits count as one visitor. - Attribution cookie (
afb_attr,getassistant.io, 90 days): remembers which site or campaign first brought you here (for example, Basecamp's integrations directory).
Visitors in Europe are asked before the analytics and attribution cookies are set, and declining keeps the site fully functional.
Children's privacy
Assistant is not directed at children under 16. We do not knowingly collect data from children.
Changes to this policy
If we make material changes, we will email active admins and post a notice on this page. The "Last updated" date at the top will reflect the change.
Contact
Questions? Contact us.