Who we are
Basalt (“Basalt”, “we”, “us”, “our”) is an AI-assisted architecture-diagramming service available at basaltarch.io and basaltarch.in. Basalt is currently operated by Satvik Mishra and is offered on a limited pilot basis. This Privacy Policy explains what information we collect when you use Basalt, how we use it, who we share it with, and the choices you have.
If you have questions about this policy or your data, contact us at satvikmishra04@gmail.com.
Scope
This policy applies to the Basalt web application, its backend API, and related services (together, the “Service”). It does not apply to third-party services we rely on, which are governed by their own privacy policies (see Section 8).
Information we collect
Information you provide or generate
- Account information. When you sign in with Google, we receive your name, email address, and profile image from Google. We use your email as your account identifier.
- Access codes. If you join through a pilot or access-code program, we record that a code was redeemed against your email, and the time of redemption.
- Content you create. The diagrams, diagram source (DSL), titles, and the text prompts and edit instructions you enter to generate or refine diagrams.
- Connected-repository content. If you connect GitHub, we read repository metadata (such as repository names) to list your repositories, and the contents of the specific .basalt files you choose to open in Basalt. We do not clone or copy your repositories. See Section 6.
- Sharing data. If you share a diagram, we store that the diagram is shared and the settings you chose for it, so that people you make it available to can open it. See Section 7.
- Communications. Any information you send us directly (e.g. by email or support requests).
Information collected automatically
- Usage data. Records of your activity on the Service — for example the number of diagrams and generations you create, token counts, and the associated cost, used for budgeting and pilot analytics.
- Technical and security data. Basic technical information such as IP address and request metadata. We log the IP address of access-code redemption attempts to detect and prevent abuse, and we keep operational logs for security and reliability.
We do not intentionally collect special-category or sensitive personal data, and we ask that you do not enter it into diagrams or prompts.
How we use your information
We use the information above to:
- provide, operate, and secure the Service;
- authenticate you and manage your account and access;
- generate and refine diagrams in response to your prompts;
- read the repositories you connect, so you can open (and, as that capability ships, save) diagrams stored in your own GitHub repositories;
- enable sharing when you choose to share a diagram;
- meter usage and enforce pilot budgets and rate limits;
- detect, prevent, and investigate abuse, fraud, and security incidents;
- communicate with you about the Service; and
- improve and develop the Service.
AI processing of your prompts and diagrams
Please read
Do not enter confidential, regulated, personal, or security-sensitive information (for example, live production system details, credentials, or non-public infrastructure information) into prompts or diagrams unless you are authorized to share that information with third-party processors and are comfortable doing so.
This applies equally to the contents of any .basalt file you open from a connected repository: when you use AI features to generate or refine a diagram, that diagram’s content is processed as described below, whether you typed it or opened it from GitHub.
To generate and refine diagrams, the prompts you enter and the diagram content you work on are sent to our third-party AI provider, OpenAI, for processing. This is essential to how the Service works.
According to OpenAI’s stated API data-usage policies, content submitted through its API is not used to train its models by default; however, you should review OpenAI’s current policies directly, and we may update this statement as those policies change.
GitHub connector and connected repositories
The GitHub connector lets you link a GitHub account so you can work with .basalt diagram files that live in your own repositories. It is optional — the Service works without it — and you can disconnect it at any time.
- Authorization. Connecting happens through GitHub’s own OAuth authorization screen. You approve the scope of access on GitHub, and Basalt never receives your GitHub password.
- Access token. The access token GitHub issues is passed to Basalt’s backend and held in an access-controlled store that only our server can reach. It is never returned to your browser.
- What we read. We read repository metadata to list the repositories you can work with, and we read the contents of the specific .basalt files you choose to open. We do not clone or copy your repositories, and we do not read files you do not open.
- Current scope. Today the connector is read-only: you can connect your account and list and open repositories. The ability to save changes back to GitHub as commits and pull requests, and to run automated compliance checks on pull requests, is being rolled out; when it is available to you, the diagram content you commit will be written to your repository under your own account, and we will update this policy to reflect any change in how data is handled.
- Tied to your account, and revocable. The connection belongs to your Basalt account and is removed if you delete your account. You can revoke Basalt’s access at any time from your GitHub account settings, which stops the connection immediately.
Because connected-repository content you open and process is handled as described in Section 5, please only connect and open repositories you are authorized to process using our sub-processors.
Third-party services (sub-processors)
We rely on the following providers to run the Service. Each processes some of your data on our behalf and under its own privacy terms:
We do not sell your personal information, and we do not share it with third parties for their own advertising.
International data transfers
Some of the providers above process and store data on servers located outside your country, including in the United States. By using the Service you understand that your information may be transferred to and processed in these locations, which may have different data-protection laws than your own.
Data retention
We keep your information for as long as your account is active or as needed to provide the Service, and thereafter as required to comply with legal obligations, resolve disputes, and enforce our agreements. Operational and security logs are kept for a limited period appropriate to their purpose.
Your GitHub access token is retained only while the connection is active; it is deleted when you disconnect GitHub or delete your account. Sharing links and sharing state are retained until you stop sharing the diagram or delete it. When you delete your account (see Section 11), we delete or de-identify your personal data except where we are required to retain it.
Your rights and choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these rights, email satvikmishra04@gmail.com and we will respond as required by applicable law.
You can also, at any time: disconnect the GitHub connector (revoke it from your GitHub account settings, which also stops it on our side); stop sharing any diagram you have shared; and request deletion of your account and associated diagrams, sharing records, and usage records by contacting us.
Security
We take reasonable technical and organizational measures to protect your information, including access controls on our database, authenticated API access, and rate limiting. Access tokens issued by connected services such as GitHub are held in an access-controlled store reachable only by our backend and are never exposed to your browser. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal data, we will act in accordance with applicable law.
Eligibility
Basalt is intended for users aged 13 and over. The Service is not directed to, and we do not knowingly collect personal data from, children under 13. If you are a parent or guardian and believe a child under 13 has provided us personal data, contact us at satvikmishra04@gmail.com and we will delete it.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, notify you. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
Contact
Questions or requests about this policy or your data: satvikmishra04@gmail.com.
Governing law: India · Operated by Satvik Mishra
