Privacy Policy

Last updated: March 2026

What we collect

Account data: Email address, username, and a hashed (non-reversible) version of your password.

Device metadata: Device name, operating system type, registration date, last-seen timestamp, and WireGuard public key. Private keys are generated on your device and never transmitted to us.

Usage data: Connection events, session durations, and approximate bytes transferred per device, used for service operation and your account dashboard.

Server access logs: IP addresses, request paths, HTTP status codes, and timestamps of requests to our servers. Retained for 90 days, then deleted.

Payment data: Payment processing is handled entirely by Stripe. We do not receive, store, or have access to your full card number or payment credentials. We store only what Stripe provides: subscription status, plan type, and a Stripe customer ID.

What we do not collect

We do not access, inspect, store, or retain the content of data transmitted between your devices. Tunneled traffic passes through our infrastructure without logging or inspection. We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes.

How we use your data

To authenticate you, operate device connectivity, display your dashboard, process payments, send service-related notifications you have opted into, detect abuse, and maintain the security and reliability of the Service.

Third-party processors

  • Stripe (payments): stripe.com/privacy
  • Cloudflare (infrastructure and DDoS protection): cloudflare.com/privacypolicy
  • Twilio (optional SMS/WhatsApp notifications, if enabled): twilio.com/legal/privacy
  • Telegram (optional alerts, if enabled): telegram.org/privacy

Data retention

Account and device data is retained while your account is active and for 30 days following account deletion, after which it is purged. Access logs are retained for 90 days. Payment records are retained as required by applicable law.

Your rights

You may request access to, correction of, or deletion of your personal data at any time by contacting us. We will respond within 30 days.

Security

We implement reasonable technical and organizational measures to protect your data. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.

Children

The Service is not directed to individuals under the age of 18. We do not knowingly collect data from minors.

Changes

We may update this policy at any time. Continued use of the Service after changes constitutes acceptance.

Contact

[email protected]

basis.systems terms