Privacy Policy
Written to be read. If anything here is unclear, legal@basis.fin answers in plain language.
What we collect
Account details you provide (name, work email, company), financial data you connect (accounts, transactions, balances) strictly to provide the service, and product telemetry (feature usage, performance) to keep Basis fast and reliable.
What we never do
We never sell your data. We never share transaction data with advertisers. We never use your financial data to train models shared across customers. Your ledger is yours.
How data is protected
AES-256-GCM at rest with per-tenant keys, TLS 1.3 in transit, hardware-backed key custody with 90-day rotation, and access limited by least-privilege with hardware MFA. Full detail lives on our Security page.
Subprocessors
We use a short, published list of subprocessors (cloud infrastructure, partner banks, card issuing, connections). Each is bound by data-processing agreements at least as protective as this policy.
Your rights
Access, correction, export and deletion — for EU and California residents and everyone else alike. Write to privacy@basis.fin; we respond within 30 days, usually much faster.
Retention
Financial records are retained as required by law and your configuration. When you leave, we export everything and delete on your schedule, with written confirmation.
Cookies
A session cookie to keep you signed in and a first-party analytics cookie. No third-party ad trackers — check the network tab; we're proud of it.
Changes
We'll notify account owners by email 30 days before any material change. The changelog of this policy is public.