Skip to the content
The operating system for desk work that lives in files
Try a sample
Trust

Your files are read. Not kept.

The short version: nothing you upload is stored. The documents we are bound by are below.

Data handling

Customer files are read in memory for the length of a session and discarded when it ends. No file is written to disk, kept in a database or used to train a model.

Every app opens on bundled sample data, so it can be evaluated without sharing anything.

What we do keep

Billing records, support conversations and a hashed log of legal acceptance. The Privacy Policy lists each item, its purpose and how long it is kept.

Outputs and AI

Outputs are drafts for review by a qualified person. Every finding shows its evidence so it can be checked. Where a language model assists, it is named on the sub-processor list and receives only what the task needs.

0
customer files kept after the session
Read in memory for the session, never written to disk, never used to train a model.
Hosting

Microsoft Azure, East US 2 (United States). Every sub-processor is named, with its purpose and location.

Payments

Dodo Payments is the Merchant of Record: checkout, invoices, sales tax and VAT. No card data reaches BaseLoom.

Contracts

A DPA with the EU Standard Contractual Clauses and the UK Addendum, and a HIPAA Business Associate Agreement for the health apps.

Security reports

Write to legal@baseloom.app. The security policy says how reports are handled.

Documents · effective 2026-09-23

Everything we publish.