Skip to main content

Baseline

PMBOK 8

Legal

Privacy Policy

Last updated: August 25, 2026

This Privacy Policy explains what data Baseline collects, why, and how it's used. It applies to baseline.aboveone.net and the Baseline application. Baseline is a product operated by Praise Okonkwo, trading as Aboveone, who is the data controller for the purposes of UK GDPR and the EU GDPR. If any term here conflicts with our Terms of Service, the Terms govern the legal relationship and this Policy governs data handling.

1. Data We Collect

Account data: email, username, display name, bio, and your password (stored hashed by Supabase Auth; we never see it in plain text).

Project data: everything you create in the product: portfolios, programs, projects, work breakdown structures, tasks, notes, risks, stakeholders, issues, change requests, lessons learned, and reports.

Uploaded documents: files you upload to the knowledge base are stored, and their text is extracted and split into chunks with vector embeddings so you can search across them and so the AI assistant can reference them.

AI chat data: your chat sessions and messages with the AI assistant, and a log of AI feature usage (for reliability and cost monitoring, not advertising).

Payment data: handled by Stripe. We store your Stripe customer ID and subscription status, not your card details.

Optional AI provider key: if you add your own API key for a third-party AI provider in Settings, Baseline encrypts it at the application layer using AES-256-GCM before database storage. It is decrypted only on the server when routing your request to that provider.

Technical data: session cookies used to keep you signed in, and data processed by Cloudflare Turnstile to tell humans from bots on sign-up and login. Baseline does not use advertising or third-party analytics trackers.

2. How We Use Your Data

  • To provide, operate, and maintain the Service you signed up for.
  • To process your subscription payment and manage billing, via Stripe.
  • To send account-related email, such as password resets.
  • To protect the Service from bots, abuse, and unauthorized access.
  • To power AI features you actively use (search, chat, and report generation), as described below.
  • To maintain and improve the reliability of the Service.

Our legal basis for this processing is performance of our contract with you (providing the Service you subscribed to), and our legitimate interest in operating a secure, reliable product, where that interest doesn't override your rights.

3. AI Processing

When you upload a knowledge-base document, its extracted text is sent to Cloudflare Workers AI to create mathematical vector embeddings used for semantic search. Search queries are also sent to that service to create a query vector. The source files remain in private Supabase storage, and the embeddings and extracted chunks are stored in Baseline's database.

When you use AI chat or generate a report, the relevant text (your message, project data, and any document passages retrieved for the answer) is sent to the AI provider configured for your account: OpenAI, Anthropic, Google, OpenRouter, or Ollama. Each hosted provider processes that data under its own privacy terms. We don't use your data to train our own models.

Where you've entered your own provider API key, requests are made directly using that key and are also subject to that provider's terms and your agreement with them.

4. Who We Share Data With

We share data with the processors that make the Service work, and no one else:

  • Supabase: database, authentication, and file storage.
  • Stripe: payment processing and subscription management.
  • Resend: delivery of transactional email (e.g. password resets).
  • Cloudflare: bot protection on sign-up and login (Turnstile), and managed vector generation for knowledge-base search (Workers AI).
  • Vercel: application hosting.
  • Your selected AI provider: as described in the section above, only when you use an AI feature.

We don't sell your data, and we don't share it with anyone for advertising purposes. We may disclose data if required to by law, or to protect the rights, safety, or property of Baseline or others.

5. International Data Transfers

Our processors operate infrastructure in multiple countries, so your data may be processed outside the country you live in, including in the United States. Where that involves a transfer out of the UK or EU, we rely on the safeguards our processors themselves maintain (such as Standard Contractual Clauses) to protect your data.

6. Data Retention

We keep your data for as long as your account exists. If you cancel your subscription without deleting your data, it remains stored. Nothing is automatically deleted for non-payment. You control deletion directly from your profile:

  • Delete your data permanently removes your project data while keeping your account and login active.
  • Delete your account permanently removes your account and all associated data.

Both are irreversible once carried out. Some minimal records (such as billing history Stripe is required to retain, or logs kept briefly for security purposes) may persist after deletion where we're legally required to keep them.

7. Your Rights

If UK GDPR, EU GDPR, or a similar law applies to you, you have the right to access, correct, delete, or export your data, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. Most of these you can exercise directly in the product: editing your profile, or using "Delete my data" / "Delete account" on the profile page. For anything else, email baseline@aboveone.net. If you're not satisfied with our response, you have the right to complain to your local data protection authority (in the UK, the Information Commissioner's Office).

8. Cookies

We use cookies that are strictly necessary for the Service to function: keeping you signed in, and Cloudflare Turnstile's bot-verification cookie on sign-up and login. We don't use cookies for advertising or cross-site tracking.

9. Security

We use security measures including encrypted connections (TLS) and application-layer AES-256-GCM encryption for stored AI provider API keys. Encryption keys are held separately in the server environment. No system is ever completely secure, and we can't guarantee absolute security.

10. Children

Baseline isn't directed at anyone under 18, and we don't knowingly collect data from children.

11. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we'll notify active subscribers by email or in-app notice before they take effect.

12. Contact

Questions about this Policy or your data? Email baseline@aboveone.net.