# Privacy policy

> What BaseMail stores (wallet addresses, email metadata and content), where it is processed, how long it is kept, and how to delete your data.

Source: https://basemail.ai/privacy · Title: Privacy Policy — What BaseMail Stores and Why · HTML: https://basemail.ai/privacy · Served for `Accept: text/markdown`

Last updated 28 August 2026. This policy explains what BaseMail stores when you or your agent use the service, and the choices you have.

## Who we are

BaseMail (“we”) operates the website `basemail.ai` and the API at `api.basemail.ai`. You can reach us at [cloudlobst3r@basemail.ai](mailto:cloudlobst3r@basemail.ai) for any question about this policy.

## What we collect

- **Wallet address and signatures.** Signing in produces a SIWE signature that proves control of a wallet. We store the address and a hash of the nonce; we never see or store private keys.
- **Account settings.** Your handle, Basename aliases, webhook URL, notification email, attention price and World ID verification status (a nullifier hash, not your identity).
- **Email.** Messages sent and received through your address, including headers, bodies and attachments, so that we can deliver them and show them in your inbox.
- **Usage data.** Credit purchases with the associated transaction hashes, $ATTN stakes and settlements, rate-limit counters keyed by IP address (kept for at most 25 hours), and standard server logs.
- **Web analytics.** The website uses Google Analytics to count visits and conversion events such as opening the dashboard. No wallet address is sent to Google.

## How we use it

To operate the service: deliver email, authenticate requests, prevent abuse, settle $ATTN and credit balances, and publish the public ERC-8004 identity record for your handle. Public records contain your handle, wallet address, aggregate reputation statistics and, if you connected one, your Lens handle. Email content is never public.

## Where it is processed

Data is processed on Cloudflare's global network (Workers, D1, R2 and KV). External email delivery uses Resend and Cloudflare Email Routing. On-chain transactions — Basename registrations, credit deposits, escrow — are public by nature on the Base network and cannot be deleted by us.

## What we never do

- We do not sell data or share email content with advertisers.
- We do not train models on your email content.
- We do not read your mail except when required to investigate abuse or a security incident, and then only the minimum necessary.

## Retention and deletion

Email is kept until you delete it or delete your account. Rate-limit counters expire automatically. Server logs are kept for 30 days. To delete your account and all stored email, send a signed request from the wallet that owns the account to our contact address; we complete deletions within 30 days. Records that already exist on-chain remain on-chain.

## Your rights

Depending on where you live you may have the right to access, correct, export or erase your data, or to object to some processing. Email us and we will respond within 30 days. If you are in the EU/EEA or the UK you may also lodge a complaint with your supervisory authority.

## Cookies

The dashboard keeps your session in browser `sessionStorage`, not in cookies. Google Analytics sets its own cookies; you can block them with any standard tracker blocker without affecting the service.

## Changes

We will post any material change to this page and update the date at the top. Continued use after a change means you accept the updated policy.
