- We store your account details and what goes into pins. We never clone or scan your code.
- The GitHub app, if you install it, shares pull request and commit details so pins can follow the work.
- Pin text goes to OpenAI to make it searchable and to spot duplicates. None of it trains AI models.
- No ads, no tracking, and we'll delete your data whenever you ask.
Who we are
Laterbase is run by Joseph Smith, in the United States. For data protection law, we're the controller of your account information. For the content you and your agents put in a workspace, we act on behalf of the workspace's owner, and we can sign a data processing agreement if your organisation needs one. Questions go to privacy@laterbase.dev.
What we collect
Your account
- Your name, email address and profile photo, from GitHub, from the email you sign in with, or one you upload.
- Which workspaces you belong to and your role in each, and any logo an owner uploads for a workspace.
- For each signed-in session, the IP address and browser it came from, so you can be kept signed in and suspicious sign-ins can be spotted.
What goes in your pins
- Everything you or your agents write into a pin: titles, summaries, how it was found, gotchas, repository names, repo-relative file paths and line numbers, code snippets the agent chooses to include, links, and status changes and notes.
- Search embeddings: numeric representations of pin text, made so search can match on meaning.
From GitHub, if a workspace installs the GitHub app
- The names of the repositories the app is installed on, and for their pull requests, branches and commits: numbers, titles, descriptions, branch names, commit messages and SHAs, and whether each is open, merged or closed.
- The GitHub usernames and account ids of the people who opened, merged or pushed them, so a pin's history can say who did what. These people may not have a Laterbase account.
We never clone or scan your code. We see only what is put into a pin and, with the GitHub app, the details above.
Connections and usage
- API keys, stored only as a one-way hash plus a short visible prefix. We can't show a key again.
- Apps you connect through OAuth, such as Claude, and the access you granted them.
- How your agents use the Service. For each tool call: which tool, when, through which key or app, the name its client reports (for example "claude-code"), the workspace it acted in, whether it worked and how long it took. This lets you tell your connections apart and see what made each change to a pin, and shows us where the Service falls short. We never record what a call sent or got back.
- Technical logs from our hosting provider, such as IP addresses, request times and errors, kept for security and debugging.
How we use it
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Running the Service: signing you in, storing, searching and ranking pins | Performing our contract with you |
| Keeping it secure: rate limits, abuse prevention, debugging | Our legitimate interest in a safe, working service |
| Making it better: which tools agents reach for, from which clients, and where calls fail | Our legitimate interest in a service that keeps improving |
| Service emails: sign-in links, invitations, important changes | Performing our contract with you |
| Meeting legal obligations | Legal obligation |
We don't sell your data, we don't use it for advertising, and we don't use your content to train AI models.
Who we share it with
We use a small number of service providers to run Laterbase. Each only gets what it needs:
| Provider | What for | Data involved |
|---|---|---|
| Vercel | Hosting the website, dashboard and MCP server | All requests, and logs |
| Neon | Database | Everything we store |
| OpenAI | Making pins searchable, and checking new pins against similar ones for duplicates | Pin text (titles, summaries and similar fields), with no account details attached |
| GitHub | Sign-in, if you choose it, and the GitHub app, if a workspace installs it | Your GitHub profile name, email and avatar; the pull request and commit details listed above |
| Vercel Blob | Storing profile photos and workspace logos, at a public but unguessable link | The image |
| Resend | Sending sign-in links and invitations | Your email address |
Under OpenAI's API terms, data sent through its API isn't used to train its models by default and is kept only for a limited period for abuse monitoring. We may also disclose information if the law requires it, or as part of a sale or merger, in which case this policy continues to apply.
Where it's stored
We're based in the United States, and so is your data: the database is in Ohio and the app runs near Washington, D.C. The other providers above may process what they handle in other countries. If you use Laterbase from the UK or EEA, your data is transferred to the US, and our providers protect it with safeguards such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or the EU-US Data Privacy Framework.
How long we keep it
- Account information: while your account is open. Ask us at privacy@laterbase.dev to close it and we'll delete it within 30 days.
- Workspace content: for as long as the workspace exists. Pins are resolved or dismissed rather than deleted, so their history stays intact. A workspace owner can ask us to delete particular pins or the whole workspace, and we'll remove them from the live database within 30 days and from backups when those expire, within a further 30 days.
- Revoked API keys and disconnected apps: the hash, prefix and name are kept so a pin's history can still show what made each change, until the account they belong to is deleted.
- Tool call records: 12 months, after which they're deleted automatically.
- Sign-in sessions: until they expire or you sign out.
- Hosting logs: kept for the provider's standard retention period, typically a few days to weeks.
Security
Data is encrypted in transit and at rest by our providers, API keys are hashed, and access to production systems is restricted to the people who need it. No system is perfectly secure; if a breach affects your data, we'll tell you and the relevant regulator as the law requires.
Your rights
Depending on where you live, you can ask to access, correct, export or delete your personal data, and to object to or restrict how we use it. You can change your profile in the dashboard at any time; for a copy of your data, or to delete it, email privacy@laterbase.dev. We'll respond within a month.
If your data sits in someone else's workspace, we may pass your request to its owner, since they decide what's kept there. You can also complain to your data protection regulator; in the UK that's the ICO.
California residents: we don't sell or share personal information for cross-context behavioural advertising, and you have the right to know about, delete and correct the information we hold.
Children
Laterbase is a tool for software teams and isn't meant for anyone under 16. We don't knowingly collect their data.
Changes
If we change this policy in a way that matters, we'll tell you by email or in the dashboard before it takes effect. The date at the top shows when it last changed.
Contact
Anything about your privacy: privacy@laterbase.dev.