BaseLock
  • Pricing
  • How It Works
  • Documentation
    For Individuals For Businesses
  • Resources
    Blog Compare to Antivirus Password Check
  • About Us
  • Contact Us
  • Sign In
  • Get Started

Legal Documents

  • Privacy Policy
  • Terms of Service
  • SMS Terms

Privacy Policy

Effective Date: October 1, 2026. Last updated: October 8, 2026.

What changed on October 8, 2026: we added Google Drive, coming soon with Gmail, where we read file names and sharing settings only, never what is in your files; and we corrected what we read from a connected mailbox's settings: filters, forwarding and automatic replies, not delegates.

What changed on October 4, 2026: we now name the connectors that work today (Outlook.com, GitHub, Notion and Dropbox; Gmail and Zoom coming soon); say which data is erased at once when you delete your account and which waits 30 days; add Google Web Risk, RDAP, crt.sh and Slack to our providers; say that the Meta pixel reports paid sign-ups with their amount and currency; say that detection triage uses an Anthropic Claude model and receives command lines; list what Advisor can look up to answer you; add mailbox and service alerts and remote-access notices to the texts we send; and correct how long a message waiting for your CHECK reply is kept.

What changed on October 2, 2026: this policy now covers Security Advisor, our free text-message advisor, and the mailboxes you can connect to it. We added what Advisor collects, a section on Google and Microsoft data, the providers involved, a retention table, and what deleting your account erases. Advisor can also keep short notes from your own questions, described under Advisor notes below. We also corrected two earlier statements: Have I Been Pwned receives your phone number as well as your email address, and audit records are kept for up to seven years, not twelve months.

At BaseLock, we take your privacy seriously. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. BaseLock provides endpoint security and device management services for individuals and small businesses, and BaseLock's Security Advisor service ("Security Advisor" or "Advisor"), a text-message security advisor that answers security questions, checks content you forward, screens a mailbox you choose to connect, and alerts you to data breaches.

Information We Collect

We collect only what is needed to provide the service and bill for it. Specifically:

  • Account information: your name, email address, and mobile phone number, provided during registration.
  • Authentication data: one-time SMS verification codes and session tokens issued by Amazon Cognito.
  • Payment information: billing details are collected and stored by Stripe. BaseLock receives only a Stripe customer reference, the subscription plan, and the last four digits of the payment method for display.
  • Device telemetry: device identifiers, operating system and version, hostname, agent versions, and health indicators reported by the endpoint agents installed on your devices.
  • Threat detections: security events surfaced by the endpoint agent, including event type, severity, file path, file hash, process name, and timestamp. We do not receive file contents under normal operation.
  • Reported messages: both ways of reporting a suspicious message work the same way underneath. We store the message itself, exactly as you sent it, then extract technical indicators from it before deleting the stored copy. What we collect depends on how you report it. Text a message to our messaging number and we store the text of that message; the indicators we can pull from it are limited to registrable domains and file hashes, because a texted message carries no sender for us to extract anything from. Forward an email to the reporting address on your dashboard and we collect more: the message's full headers, the sender's complete email address, any attachments, and the authentication result (DKIM, SPF, and DMARC) for the sending domain, and here we can also extract a sender domain and a non-reversible hash of the sender address. A forwarded email will usually contain information about the person who sent it, who is not a BaseLock customer and has not agreed to this policy; we keep what they sent for the same period as the rest of the message, and it is removed on the same schedule, including as part of your account deletion. The stored message itself, however you sent it, is deleted within seven (7) days of when we receive it and is not shared with other customers. One narrow exception sends more: a link on a known link-shortening service is sent to VirusTotal as a full link so it can be checked, described under VirusTotal below. See Shared Threat Corpus below for what happens to the extracted indicators.
  • Advisor conversations: the messages you send Security Advisor and our replies. Before we store a conversation we replace anything that looks like a password, code or key, but this is not guaranteed to catch everything, so do not send them.
  • Advisor notes: short facts Advisor saves from your own questions to give you better advice, such as the devices you use or that you are travelling. Advisor tries to refuse links, codes, passwords, bank and account names, and anything that reads like an instruction, and nothing you forward to be checked becomes a note. Every note it saves is shown to you in a "Noted:" text, and you can delete it in Settings. Notes may mention people you tell us about, by relationship. You can see and delete them in Settings, and turn note-keeping off there; they cannot be deleted by text message.
  • Mailboxes you connect: the mailbox address, the permissions you granted, and an access token we keep encrypted. To look for phishing and other dangerous mail we read the content of new messages, including their headers, links and attachments, and the mailbox's forwarding rules, filters and automatic replies. What we keep from that is described under Google and Microsoft data below.
  • Content you forward: texts, emails and files you send us to check, as described under Reported messages above.
  • Data breaches: the names of published data breaches your email address or phone number appears in.
  • Product usage: sign-in timestamps, in-product actions, and notification preferences, used to operate the dashboard and improve the product.
  • Support communications: emails and forms you submit to BaseLock support.
  • Cookies and local storage: we store session tokens and a small number of preferences in your browser's local and session storage.
  • Support chat: if you open the support chat, Crisp sets a cookie so your conversation is still there when you come back. It is set only when you open the chat, never just because you visited a page, and it lasts 30 days. We delete support conversations 90 days after the last message in them.
  • Advertising measurement: our public marketing pages load the Meta (Facebook) pixel, which sets a cookie and reports page views, completed sign-ups and, when you sign up for a paid plan, the purchase with its amount and currency to Meta so we can measure which advertising works. It runs on the public site only, never inside your dashboard or on your devices, and it receives no device telemetry, threat detections, or support communications. You can turn it off at any time from the privacy panel on any public page, which also turns off error monitoring and session recording.

How We Use Your Information

BaseLock uses your information to:

  • Provide and operate the service, including endpoint monitoring, threat detection, and incident response.
  • Authenticate you and protect your account through SMS one-time codes and session management.
  • Send transactional messages such as login codes, security alerts, billing receipts, and service updates.
  • Bill your subscription and process refunds.
  • Maintain audit logs of administrative actions for security and compliance.
  • Investigate and respond to suspected threats, abuse, or policy violations.
  • Answer the questions you send Security Advisor, check content you forward, screen a mailbox you connect for dangerous mail, and tell you when your information appears in a data breach.
  • Read a message you report to us so we can answer you about it, and extract technical indicators from it to protect every BaseLock customer; we never share the message content itself, including anything about who sent it, with other customers.
  • Improve product quality, reliability, and detection accuracy.
  • Measure which advertising brings people to the site, using the Meta pixel described above.

We do not sell your personal information. We do not use your data to train models that are shared with third parties outside the security workflows described below.

We do share limited browsing activity on our public marketing pages with Meta for advertising measurement, as described under Advertising measurement above. Under some state privacy laws this counts as "sharing" for cross-context behavioral advertising even though no money changes hands. You can opt out at any time using the privacy panel on any public page. This sharing never includes your device telemetry, threat detections, support communications, or SMS opt-in data.

Mobile Information and SMS Consent

Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. All of the categories above exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

We use your mobile number only to send the messages you consented to when you created your account: one-time passcodes to verify your number and sign you in, security alerts about your devices, which may include a single-use link to allow or block a program we flagged, account notifications such as when someone joins your team, alerts when our checks find something that needs your attention in a mailbox or other service you connected, notices when our staff will remotely access one of your devices and when that access ends, two-way conversations with Security Advisor, including the results of checks you ask for, and alerts when your email address or phone number appears in a data breach. Message frequency varies. Message and data rates may apply. Reply STOP to turn off texts, reply START or UNSTOP to turn them back on, reply HELP for help. You can also manage alerts from your BaseLock dashboard.

Data Access and Monitoring

We do not collect, access, or monitor personal content stored on your devices, including:

  • Files (documents, photos, videos)
  • Emails
  • Messages
  • Passwords
  • The pages you read or what you type into websites
  • Application data

The one exception is a mailbox you choose to connect: we read its mail and its settings to look for phishing and other dangerous mail, as described under Google and Microsoft data below. Nothing on your devices is read for this.

Our management tools (including device management and endpoint detection technologies) are configured to monitor only device health indicators, security compliance, and threat detections.

Web filtering is the one exception worth spelling out. To block dangerous sites, it checks the name of each site a filtered device looks up (for example, example.com), and we record the ones it blocks. It does not see the pages you read, what you type, or anything inside an encrypted connection.

Google and Microsoft Data

BaseLock's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Connectors work with Outlook.com, GitHub, Notion and Dropbox today; Gmail and Zoom are coming soon. When Gmail is available, we will ask Google only for the parts of your account you connect. For your mail, that is read-only access to your mail (gmail.readonly) and access to your mail settings (gmail.settings.basic), which we use only to read your filters, forwarding addresses and vacation responder. For your calendar, on every plan including free, it is read-only access to its events (calendar.events.readonly), so we can check invitations for disguised links. For Google Drive, it is read-only access to the names and sharing settings of your files (drive.metadata.readonly), so we can find files anyone with the link can open; we never read what is in them. For a Microsoft account we ask for the equivalent read-only permissions for the parts you connect: Mail.Read and MailboxSettings.Read for your mail, Calendars.Read for your calendar, and Files.Read for OneDrive. We use this access only to find phishing, dangerous mail, and settings an attacker has changed, and to tell you about them. We never send, move, change or delete your mail or your settings.

No person at BaseLock reads your mail, except with your consent, where it is necessary for security purposes such as investigating abuse, or where the law requires it. We never use data from your mailbox for advertising, we never sell it, and we never use it to train general AI models. The AI model that assesses a message is described under Automated Decision-Making below.

From the mail we read we keep only what we need: findings about dangerous messages or changed settings, which can include a message's sender and subject; fingerprints of the addresses you correspond with, made with a one-way salted hash so that no address can be read back from them; and records of which kinds of account notices (for example a bank's security alert) arrive, also hashed. Attachments are checked by their hash, and only an attachment that no reputation service recognises and whose file type is risky is held briefly for a malware scan, then deleted.

You can disconnect a mailbox at any time from Settings. Disconnecting a Google account revokes our access at Google. Microsoft provides no way for us to revoke access, so after disconnecting a Microsoft account, also remove BaseLock at account.live.com/consent/Manage. When you disconnect, we delete the access token and the findings from that mailbox and stop reading it; we keep the mailbox address and a record that it was connected, and the hashed records above expire on the schedule in the retention table. When an Individual subscription ends and the account moves to the free plan, we do the same for every connected mailbox except the oldest one, together with anything else connected through the same account as that mailbox. Deleting your account deletes all of it.

Metadata Collection by Third-Party Tools

Our authorized security tools may collect limited metadata such as:

  • Filenames and file hashes
  • Process names and command lines
  • Device identifiers
  • Software version information
  • Threat signatures

These metadata collections are standard for security purposes and are not used to access, view, or copy the contents of your files.

Security Incident Response

In the event of a confirmed security incident (such as a malware infection or targeted attack), BaseLock may collect and review limited forensic metadata necessary to investigate and respond to the threat. This may include:

  • Process activity
  • Application crash reports
  • Threat detection logs
  • File attributes (such as name, size, hash, or type)
  • Where strictly required for analysis, a copy of the malicious artifact that triggered the detection

All incident response activities are limited to the scope of the threat. We do not perform blanket scans of customer personal content.

Automated Decision-Making

We use automated systems, including an Anthropic Claude model through Amazon Bedrock, for two different purposes, and what is sent to the model differs between them. To triage a device detection and generate a plain-language summary of it, we send metadata about the detection: its severity, the file name, the attack tactics and techniques it matched, and, for up to five of the behaviours the endpoint agent recorded, the process name, its command line and its parent process. A command line is the instruction a program was started with, and it can include file and folder names or other text typed on the device. We do not send file contents, the detected file's own path, personal communications, or browsing data for this purpose, though a command line may itself contain file and folder paths. To judge a message you report to us, whether texted or forwarded by email, we send the model the message text itself, so it can decide whether the message is dangerous; see the Reported messages entry above and Shared Threat Corpus below for what we keep from a reported message and for how long. Neither use sends your message to VirusTotal: VirusTotal receives only the specific indicators described under VirusTotal below, plus a full link in the narrow case of a known link-shortening service. In both cases the model's output is advisory and does not by itself block legitimate activity on your device.

Security Advisor's answers, and our assessment of mail in a mailbox you connect, are also produced with Anthropic Claude models through Amazon Bedrock. To answer you, we send the model your message, your saved Advisor notes (unless you have turned note-keeping off), up to 8 earlier messages and replies from the last 7 days (your own questions and our replies, never anything you forwarded or pasted for checking), a summary of your account's security history from the last 90 days (the outcome of messages you asked us to check, the alerts we raised, how many sites were blocked, and the decisions about programs on your devices, never file names, site names, or the content of anything checked), and the results of our own checks; to assess mail, we send the text of the message being checked. Separately, when it needs them to answer you, Advisor can also look up your devices (their names, operating system and version, when each was last seen, and their update, disk encryption and firewall status), the file names of programs waiting for your allow or block decision, the sites you have blocked, the names of the data breaches your details appear in, your plan and subscription, the findings our checks still have open, and up to 20 of our own earlier replies to you. Bedrock may process these requests in AWS regions in the United States other than the primary region named under Service Providers below.

Shared Threat Corpus

When you report a suspicious message, whether by texting it or by forwarding it as an email, the indicators we extract from it (registrable domains and file hashes from either channel, plus sender domains and a non-reversible hash of the sender address from a forwarded email, all described under Reported Messages above) are added to a threat catalog shared across every BaseLock customer, not only the one who reported it.

There is no opt-out. The shared corpus is the product working as intended: letting one customer's reports be excluded would weaken what every other customer gets from that catalog, while the excluded customer kept receiving it.

Retention is set per indicator type, because one retention period would misdescribe most of them. File hashes are retained indefinitely, since a malicious file does not become safe with age. Registrable domains are retained for ninety (90) days, and sender domains and the non-reversible hash of the sender address are each retained for thirty (30) days, since a compromised mailbox is usually recovered by its owner within a month. Each of these periods restarts from the most recent time we observed that same indicator, not from the first, so a domain or address that keeps turning up in reports stays in the catalog for as long as it keeps turning up.

When you delete your account, we remove the link between your account and any indicator you contributed to the corpus. The indicator itself may remain in the catalog, in a form that identifies nobody.

Remote Access

A BaseLock analyst or engineer can remotely access a device you have enrolled, to investigate a security detection, to follow up on something you reported, or to carry out maintenance. This access uses CrowdStrike Real Time Response, the same tooling that protects the device.

We tell you every time. Before access begins we send a notice to the account's email address, and where you have a mobile number on file and have not opted out of our texts, to that number as well. The notice says which device, what the work is, and that it is time limited and logged. You can confirm the notice to let the work start sooner, and we tell you again when the session ends.

Whether we need your confirmation depends on why we are accessing the device. For routine maintenance, or when we are looking into something you reported, we do not proceed unless you confirm the notice, and if we do not hear from you we simply do not access the device. Where we have identified a security detection or are following one up, access is part of the service and does not wait on a reply, because an investigation that waits has already lost time it may not have. In that case the notice tells you what is happening and, where possible, lets you make it start sooner.

Each session is time limited. A session runs for four (4) hours and can be extended in further four (4) hour steps while the work continues. No single session may exceed twenty four (24) hours from the moment it starts. That ceiling is enforced automatically, so access that is not renewed is withdrawn without anyone having to remember to withdraw it.

Every session is recorded: who opened it, which device, the reason given, and when it ended.

A small number of administrative accounts, used to operate and repair the service itself, hold this access on a standing basis rather than session by session.

On a business account, the administrator receives the notice and can confirm it. The person who uses the device is told as well, every time, whether or not they administer the account.

Service Providers and Subprocessors

We share limited data with service providers that help us operate BaseLock. These providers are contractually bound to use your data only for the purposes we direct.

  • Amazon Web Services (AWS): hosting, storage, authentication (Cognito), email (SES), AI inference (Bedrock, which may process a request in another US region), and malware scanning (GuardDuty Malware Protection) of attachments held for scanning. Primary region: US East (N. Virginia).
  • Telnyx: delivery of your sign-in passcodes, security alerts and other text messages, your conversations with Security Advisor, and receipt of your replies and of texts and files you forward to us. Telnyx receives your mobile number and the content of those messages only.
  • Have I Been Pwned: receives your email address and your phone number, so we can tell you when either appears in a published data breach, and, on a business account, the business's domain. It receives nothing else: not your name, not your devices, not anything you have reported to us. We check only when a new breach is published rather than on a fixed schedule, so on most days nothing is sent at all, and we stop checking when you delete your account.
  • The password checker sends nothing to anyone, including us. If you use the password check on our site, the password is hashed in your own browser and only the first five characters of that hash are sent to Have I Been Pwned. Those five characters match hundreds of different passwords, so they identify nothing. The password itself never leaves your device and never reaches our servers.
  • VirusTotal: receives the registrable domains and file hashes extracted from a message you report, including the domain portion of the sender's address. In the narrow case where the message contains a link on a known link-shortening service, such as bit.ly or tinyurl.com, VirusTotal also receives that full link, because a shortened link cannot be evaluated without following where it leads. VirusTotal also receives the domains found in mail in a mailbox you connect, and the hashes of attachments in that mail. VirusTotal never receives a message body, a file or attachment, or a sender's full address.
  • Google Web Risk: receives the domain of a link we check, from a message you report or from mail in a mailbox you connect, sent as the bare address of that site (for example https://example.com/). It never receives the full link, its path or anything else from the message.
  • RDAP and crt.sh: public lookup services for domain registrations and for the logs of issued certificates. RDAP receives domains found in messages reported to us, so we can see how recently each was registered, and a domain you have proven you own, so we can check its registration lock and expiry. crt.sh receives a domain you have proven you own, and the first part of its name, so we can find certificates issued for it or for lookalikes of it. Neither receives anything else about you.
  • Slack: our internal workspace, where our staff request and track remote access to a device (see Remote Access above). It receives what a staff member enters to request access, which is the device's identifier or the account's email address, and the progress of that access. It never receives anything from your devices.
  • Amazon Textract: reads the text inside an image you send us, such as a screenshot attached to a reported email or sent to our messaging number, so we can examine what it says. Textract receives only the image.
  • Google and Microsoft: the sources of the mail, calendar and files you choose to connect, as described under Google and Microsoft data above. We send them only the requests needed to read what you granted, and, for Google, to revoke our access when you disconnect.
  • Other services you connect: connectors work with Outlook.com, GitHub, Notion and Dropbox today; Gmail and Zoom are coming soon. On every plan, including free, if you connect a service such as GitHub, Notion or Dropbox, we send it only the requests needed to read what you granted on its own consent screen.
  • On a paid plan only: if you ask us to watch a cryptocurrency wallet, its public address is sent to Etherscan. To look for accounts impersonating you, we search Bluesky and a fixed set of public Mastodon servers for your name.
  • CrowdStrike: endpoint detection and response agent installed on your devices.
  • JumpCloud: device management and remote command execution.
  • Stripe: payment processing.
  • Cloudflare: DNS, web application firewall, and content delivery. On an individual account, if you accept our offer to block a domain from a reported message, that domain is also written into a Cloudflare Zero Trust Gateway policy so it is refused across your devices. To check a domain found in a message you forward or in a mailbox you connect, we also search Cloudflare's URL Scanner for earlier scans of that domain.
  • Vercel: hosting of the BaseLock website and dashboard.
  • Sentry: application error monitoring and, if you allow it, masked session replays in which text, form inputs and images are hidden before they leave your browser.
  • Meta: advertising measurement on our public marketing pages only, as described under Advertising measurement above: page views, completed sign-ups, and paid sign-ups as purchases with their amount and currency. You can turn it off from the privacy panel.
  • Crisp: live support chat. Crisp receives the content of your support conversations, the page a conversation started from, and basic browser and device information. If you are signed in it also receives the email address on your account, so we can confirm we are talking to a real account holder. Crisp IM SAS is a French company and processes this data in the European Union.

Data Ownership

All customer data remains the sole property of the customer. BaseLock claims no ownership rights over customer files, communications, or any personal content.

Data Security

All data BaseLock holds about you and your devices is encrypted in transit (TLS 1.2 or higher) and at rest using AWS-managed encryption. Access to production data is restricted to authorized personnel following least-privilege principles, audited, and gated by multi-factor authentication. Public BaseLock domains sit behind Cloudflare's web application firewall and rate limiting.

Data Retention

We retain account and device records for as long as your account is active and for a limited period afterward for billing, audit, and abuse-prevention purposes. When you delete your account, we remove your personal data within thirty (30) days, except for a minimal tombstone record that allows us to honor your deletion request and meet legal obligations, and the records listed below as kept after deletion.

WhatHow long we keep it
Advisor conversations90 days from each message
Failed messagesUp to 4 days
A message waiting for your CHECK reply30 minutes, after which it can no longer be checked; it then expires and is deleted automatically, normally within a few days
A question waiting for you to choose which device you meant30 minutes, or until you answer it or text STOP; it then expires and is deleted automatically, normally within a few days
Advisor notesUntil you delete them, or 12 months after you last use Advisor; backups up to 35 days. Notes may mention people you tell us about, and are deleted the same way
Mailbox and other connectionsThe access token until you disconnect; the address and connection record until you delete your account
Findings (what our checks found)Up to 2 years
Hashed sender history from a connected mailboxUp to 400 days after we last see that sender
Hashed records of account notices in a connected mailboxUp to 2 years
Data breach resultsUntil you delete your account
Forwarded content, and attachments held for a malware scan7 days at most; a held attachment is deleted as soon as its scan result is read
Threat detection records, your allow or block decisions on them, and the security status of your devicesWhile your account is active; erased when you delete your account
Files you allowed or blocked on your devices (the file's hash and the name we saw), on an individual account or for your own device on a business accountWhile your account is active; erased when you delete your account
BackupsUp to 35 days

Kept after you delete your account:

WhatWhy, and for how long
Audit recordsSecurity and compliance; up to 7 years
Decisions and lists on a business accountThey belong to the business and stay with it when one member deletes their account
The record that your number opted out of text messagesSo we never text a number that sent STOP; until it texts START or UNSTOP
The Stripe customer record of a past paid subscriptionTax and refund records
Indicators you contributed to the shared threat catalogUnlinked from your account; see Shared Threat Corpus above

A message you report to us, whether by text message or by forwarding an email, including its headers, any attachments, and any information it contains about the person who sent it, is deleted within seven (7) days of when we receive it, with no exception for the stored message itself. That does not apply to the indicators we extract from it before deletion, such as a sender domain or the non-reversible hash of a sender address: those are retained separately and for longer, as described under Shared Threat Corpus above.

Your Rights

You have the following rights regarding your data, exercisable directly from the dashboard or by emailing privacy@getbaselock.com:

  • Access: request a copy of the personal data we hold about you using "Request a copy of my data" under Settings, Privacy, or "Download my data" in the privacy panel. The copy includes your Advisor conversations, your Advisor notes, findings, data breach results, connections (never the access tokens), a message you sent that is waiting for your CHECK reply, a question waiting for you to choose a device, your reporting address, notifications and subscription. We email you a link to it; if your account has no email address, the link is shown to you instead and expires after one hour.
  • Deletion: request deletion of your account and associated personal data using "Delete account" under Settings, Account, or "Delete my data" in the privacy panel. Most of your data is erased immediately. Your account record, with your device list, notifications and subscription records, is kept for 30 days and then removed; until then you can ask us to restore your account, but data that has already been erased cannot be restored. If you have reported a message that has not yet reached its seven-day retention limit, deletion removes it immediately; the process that performs this removes the stored message without ever reading it. Deletion also immediately erases your Advisor conversations, your Advisor notes, a message waiting for your CHECK reply, a question waiting for you to choose a device, your findings and data breach results, your connections (revoking our access at Google; for Microsoft, also remove BaseLock at account.live.com/consent/Manage), your hashed sender history, your reporting address, any attachments held for scanning, the threat detection records for your devices, your decisions on them, the files you allowed or blocked, and the security status of your devices. Data in our backups expires within 35 days. Deletion does not remove the record that your number opted out of text messages, and our messaging provider keeps blocking texts to a number that sent STOP until it texts START or UNSTOP. We keep the Stripe customer record of any past paid subscription for tax and refund records. You must cancel an active paid subscription before you can delete your account.
  • Correction: update inaccurate account information from your account settings.
  • Objection / restriction: ask us to limit how we use your data for specified purposes.

Depending on your location, you may have additional rights under laws such as the California Consumer Privacy Act (CCPA), the EU General Data Protection Regulation (GDPR), or the UK Data Protection Act. We honor verified requests under those laws.

Children's Privacy

BaseLock is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have collected information from a child without verifiable parental consent, we will delete it promptly.

International Data Transfers

BaseLock is operated from the United States. If you access BaseLock from outside the United States, your information may be transferred to, stored, and processed in the United States. Where required by law, we use appropriate safeguards (such as Standard Contractual Clauses) for these transfers.

SMS Communications

By providing your phone number, you consent to receive SMS messages from BaseLock for authentication, security alerts, service updates, conversations with Security Advisor, and data breach alerts. Standard message and data rates from your carrier may apply. See Section 15 of our Terms of Service for full details on SMS, including frequency, opt-out, and phone number changes.

Changes to This Policy

We will update this Privacy Policy when our practices change. Material changes will be communicated through the dashboard or by email at least thirty (30) days in advance, except where a shorter notice period is required by law or to address a security issue.

Contact Us

If you have any questions about this Privacy Policy, please contact us at:

Email: privacy@getbaselock.com

Pricing

  • View Plans
  • Compare to Antivirus

Documentation

  • For Individuals
  • For Businesses

Company

  • About Us
  • Changelog

Legal

  • Privacy
  • Terms
  • SMS Terms
  • Status

BaseLock

BaseLock is a product of AB Foundry LLC

Follow BaseLock on X, Instagram and Facebook. Founded by Asante Babers.