Legal
Privacy Policy
What personal data the platform collects, why, who it is shared with, where it is stored, and the rights available over it.
Version 1.1.0 · Effective
Draft — not yet reviewed by counsel
This text has not been reviewed by a qualified legal practitioner and is published for review rather than as an executed instrument. The review state is recorded in mybase/docs/legal/README.md.
Operator details outstanding
The operating entity name, registered address, governing-law jurisdiction and privacy contact have not been configured for this deployment. Each appears below as a marked placeholder rather than a guess.
1. Who controls your data
This platform is operated as white-label software: each community runs on infrastructure operated by us, on behalf of the organisation that runs that community.
- If you are a member of a community hosted here, the organisation running that community is the controller of your personal data. It decides what is collected and why. We act as its processor.
- If you are that organisation — our direct customer — [PENDING — operator to supply] is the controller of the account and billing data you give us directly.
- Where the organisation running your community publishes its own privacy policy, that policy governs your membership. This document is the default that applies where it has not.
Operator: [PENDING — operator to supply], [PENDING — operator to supply].
2. What is collected
- Account data — name, email address, password (stored only as a hash), and, where you sign in with Google or your employer’s single sign-on, the identifier and profile fields that provider returns.
- Profile and community content — anything you enter: profile fields, posts, comments, direct messages, group and channel membership, event registrations, project and course activity.
- Learning and gamification records — course progress, assessment attempts, certificates, points, streaks and achievements.
- Payment records — where you buy a subscription or an event ticket: billing contact details and transaction records. Card numbers are collected by Stripe and never reach the platform.
- Technical data — IP address, browser user agent, requested paths, timestamps and error diagnostics, generated automatically when you use the service.
- Assistant interactions — the prompts you send to the AI assistant and the responses returned.
3. Why it is used
- To operate the community you joined: authenticate you, show you content, deliver messages and notifications, and record your learning progress.
- To take payment where you purchase something.
- To keep the service secure and available: rate limiting, abuse prevention, error diagnosis, backups.
- To answer your questions through the AI assistant, where your community has enabled it.
Personal data is not sold, and it is not used to train third-party models on our instruction. Where an inference provider’s own terms govern training on submitted data, that provider’s terms apply — see the subprocessor list.
5. Where it is stored
Each community runs on its own dedicated Postgres database. Your data is not stored in a shared table alongside other organisations’ members, and one community’s database credentials do not reach another’s data.
Tenant databases are provisioned in AWS ap-southeast-2 (Sydney) by default; the region is set per tenant at provisioning time. Hosting, email, payment and AI subprocessors operate their own infrastructure and may process data elsewhere — see /legal/subprocessors §4.
6. How long it is kept
Community content is retained for as long as the community that holds it exists, or until it is deleted by you or by an administrator of that community. Account records are deleted on request; backups age out on their own schedule and a deleted record may persist in a backup for a limited period after deletion from the live database.
Configurable per-tenant retention policies are not yet available. When they are, this section will state the defaults.
7. Your rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal data, and to object to or restrict certain processing.
Because the organisation running your community is usually the controller, the fastest route is to raise a request with that organisation’s administrators; they can act on it directly in the product. Requests can also be sent to [PENDING — operator to supply], and we will pass them to the relevant controller and assist with fulfilment.
Account deletion is available from your account settings.
9. Contact
Privacy enquiries: [PENDING — operator to supply]. Postal: [PENDING — operator to supply], [PENDING — operator to supply].