Privacy Policy

Effective: September 1, 2026

This Privacy Policy explains how Samebase handles personal information when you use samebase.com, the Samebase web app, the Samebase remote MCP server, or a published Samebase agent plugin.

Who operates Samebase

The Samebase team operates Samebase. It is responsible for the processing described in this Policy and is the controller where that term applies.

For privacy questions, requests, or complaints, email contact@samebase.com.

Information Samebase handles

Samebase handles these categories of personal information:

  • Account and organization information, such as your name, email address, profile image, sign-in and session information, memberships, roles, invitations, and records of agreements and privacy choices.
  • Connected-service information, such as account identifiers, permissions, credentials, and repository or infrastructure information from services that you connect.
  • Repository and workspace content and related metadata.
  • MCP requests, inputs, results, authorization records, and security events.
  • Communications and feedback that you choose to send to Samebase.
  • Billing contact, plan, subscription, and transaction information.
  • Use and device information, such as IP address, browser and device information, page and request information, errors, security logs, analytics, and service-use information.
  • Session replay information, such as visible pages and clicks, only when you consent.

Samebase gets this information from you, your browser or device, members of your organization, services that you connect, providers that help operate Samebase, and public sources such as GitHub.

How Samebase uses information

Samebase uses account, organization, connected-service, repository, workspace, MCP, and billing information to provide the service and perform the actions that you request. Where applicable, the legal basis is the contract to provide Samebase. When contract is not the applicable basis, Samebase relies on its legitimate interest and the interests of your organization in operating the requested service.

Samebase uses account, connection, use, device, log, communication, and feedback information to review access, secure the service, prevent abuse, find errors, provide support, measure use, and improve reliability. The legal basis is Samebase's legitimate interest in operating a safe and reliable service.

Samebase uses account information to send account, security, billing, and service communications. Samebase sends optional product updates and announcements by email only when you consent. You can withdraw this consent at any time in Account settings.

Samebase uses session replay only with your consent. Samebase can also handle information when needed to meet a legal obligation or to establish, exercise, or defend legal claims.

Account and sign-in information is required to use a Samebase account. Connected-service and billing information is required only when you connect a service or use a paid plan. Feedback and session replay are optional. Product-update emails are optional.

This Policy is a notice. Samebase does not treat your acceptance of this Policy as consent when the law requires a separate choice.

Who receives information

Samebase uses providers for hosting, database services, authentication, network delivery, email, billing, analytics, diagnostics, content delivery, and embedded video. Current providers include Convex, Cloudflare, Google, GitHub, Polar, PostHog, jsDelivr, and YouTube. The information that each provider receives depends on its role and the services that you choose to use.

Samebase also shares information:

  • With connected services, MCP clients, and agent providers when you request or authorize an action. They can keep copies under their own terms.
  • With members of your organization when collaboration requires it.
  • With authorized Samebase staff when needed to operate, secure, and support the service.
  • When required by law or needed to protect people or the service.

Invitation links disclose public GitHub profile information to people who open them.

Samebase does not sell personal information or share it for cross-context behavioral advertising.

Browser storage and analytics

Samebase and its sign-in or embedded-content providers use browser storage to keep you signed in, protect the service, remember choices, cache workspace information, and provide content.

Samebase uses PostHog for browser analytics. PostHog can receive your IP address and Samebase user ID. Session replay starts only after you consent. You can withdraw that consent in Account settings. Withdrawal stops new session replay.

Retention and deletion

Samebase keeps account information until you delete your account. It keeps organization, workspace, and connection information while the related organization, workspace, or connection remains active. It keeps billing information while the related organization or subscription exists and afterward as needed for disputes or legal obligations. It keeps communications, feedback, logs, security records, records of communication choices, and limited deletion records while needed for the service, security, support, dispute resolution, or legal obligations.

You can delete your account from Settings after you complete any required organization cleanup. Samebase disables the account immediately. Before you confirm, Samebase tells you when permanent deletion will start.

Permanent deletion removes information tied only to your account. Limited records, backups, organization information and subscriptions, external resources, and copies held by other members or third parties can remain. Deletion can remove Samebase's saved credential without revoking authorization at the connected service.

International processing and security

Samebase and its providers can process information outside your country. Processing locations and transfer protections depend on the provider, connected service, and resource location. Email contact@samebase.com for information about a specific transfer.

Samebase uses safeguards that include encrypted network connections, access controls, scoped authorization, credential protection, and security monitoring. No security method removes all risk.

Your rights and choices

Depending on the law where you live, you can request access, correction, deletion, restriction, or a portable copy of your personal information. You can object to processing based on legitimate interests. You can withdraw consent at any time. Withdrawal does not affect processing that was lawful before the withdrawal.

You can change your product-update email and session replay choices in Account settings.

Email contact@samebase.com to make a request or complaint, including a deletion request when account closure is not available in Settings. Samebase can ask for information needed to verify your identity. You can also complain to the data protection authority that applies to you.

Children

Samebase is not intended for children under 13 and does not knowingly collect their personal information. Where local law requires parental permission at a higher age, you must have it. Email contact@samebase.com if you believe that a child provided personal information without the required permission.

Changes to this Policy

Samebase can update this Policy when its processing changes. Samebase will publish the new date and give additional notice or request consent when required by law.

checking login