Privacy policy

Last updated: July 2nd 2026

Exabase ("Exabase", "we", "us") operates exabase.io and provides infrastructure for AI agents through our APIs, SDK, and web workspace (together, the "Service"). The platform includes memory, versioned file storage, deep search, extraction, and autonomous workers.

This policy explains what personal information we collect, how we use it, and the choices you have. By using the Service you agree to the practices described here. Capitalised terms not defined here have the meaning given in our Terms of Service.

1. Two different roles

Exabase handles personal information in two distinct capacities, and the rules differ for each.

As a controller. For information about you as an account holder, such as your registration details, billing information, support correspondence, and how you use the Service, we decide why and how that information is processed. Sections 2 through 9 cover this.

As a processor. When you upload files, notes, bookmarks, conversations, or other content into a Base, or send content to our Extract, Memory, or Search endpoints, we process that content ("Customer Content") on your instructions and on your behalf. That content may include personal information about your own end users. You remain the controller of it; we act only as your processor. Section 10 covers this, and our Data Processing Addendum governs it contractually.

2. Information we collect

Account information. Name, email address, company or organisation name, password credentials, and any profile details you choose to add.

Billing information. Billing address, plan tier, and transaction history. Card details are collected and stored directly by our payment processor. We never receive or store full card numbers.

Log and usage data. When you call our API or visit the site, we automatically collect IP address, browser type and version, device and operating system, referring pages, pages viewed, time and date of access, time spent, API endpoints called, request volume, latency, error rates, and similar diagnostics.

Developer telemetry. API key identifiers (never the secret value in plaintext), Base identifiers, SDK version, and aggregate usage counts used for rate limiting, quota enforcement, billing, and abuse prevention.

Communications. Support tickets, emails, and feedback you send us.

Cookies and similar technologies. Small data files stored on your device that keep you logged in, remember preferences, and help us understand how the site is used. You can accept or refuse cookies through your browser, though refusing some may prevent parts of the Service from working. See our Cookie Policy for the specific cookies in use.

Identity resolution and advertising partners. When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email address. We, or service providers acting on our behalf, may then send communications and marketing to those email addresses.

You can opt out of receiving this advertising at app.retention.com/optout. You can opt out of the collection of your personal data under the GDPR at rb2b.com/rb2b-gdpr-opt-out. These opt-outs apply to marketing and website analytics only. They do not affect your account, your Bases, or any Customer Content.

3. How we use information

We use the information above to:

  • provide, operate, and maintain the Service;

  • authenticate you and secure your account;

  • meter usage, enforce plan limits, and process payments;

  • provide technical support and respond to your requests;

  • monitor performance, debug errors, and improve reliability;

  • detect, investigate, and prevent fraud, abuse, and security incidents;

  • send service notices, security alerts, and, where you have opted in or where permitted, product updates and marketing;

  • comply with legal obligations and enforce our terms.

4. Legal bases for processing

Where the GDPR or UK GDPR applies, we rely on:

  • Performance of a contract, for providing the Service, billing you, and responding to support requests.

  • Legitimate interests, for security, abuse prevention, service improvement, and analytics.

  • Consent, for marketing communications and non-essential cookies.

  • Legal obligation, for tax, accounting, and regulatory record-keeping.

Where we rely on legitimate interests, we have assessed that our interests do not override your rights. Where we rely on consent, you may withdraw it at any time.

5. AI and machine learning

We do not use Customer Content to train, fine-tune, or evaluate our own models, and we do not permit our vendors to do so. Memory extraction, embedding generation, transcription, OCR, and search indexing operate on your content solely to return results to you.

Model providers and processing vendors we use are contractually bound to zero-retention or no-training terms. Current vendors are listed on our subprocessor page.

We may use aggregated, de-identified operational metrics, such as request volumes, latency distributions, and error patterns, to improve the Service. These contain no Customer Content and cannot be linked back to you or your end users.

6. How we share information

We do not sell Customer Content, and we never share it for advertising purposes. We share other personal information only in these circumstances:

Service providers and subprocessors. Cloud hosting, storage, payment processing, transcription, model inference, email delivery, error monitoring, and customer support tools. Each is bound by contract to process data only on our instructions and to maintain appropriate security. A current list, with notice of changes, is maintained at exabase.io/subprocessors.

Advertising and identity resolution partners. Website visit data, cookie identifiers, and associated contact details may be shared with the partners described in Section 2 for marketing purposes. This category covers website visitors only. It never includes Customer Content, Base contents, memories, or anything you or your end users upload to the Service.

Affiliates. Exabase is part of the Fabric family of products. We may share information with affiliated entities for the purposes described in this policy, under equivalent protections.

Legal and safety. Where required by law, subpoena, or court order, or where necessary to protect our rights, users, or the public. Where legally permitted, we will notify you before disclosing Customer Content in response to a government request.

Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply to the transferred information.

7. International transfers

We operate globally, and your information may be processed in countries other than your own, including the United States. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses, the UK Addendum, or another approved transfer mechanism, together with supplementary technical measures including encryption in transit and at rest.

8. Retention

We keep personal information only for as long as it is needed for the purpose it was collected for, or for as long as we are required to keep it by law. Different categories are kept for different periods:

  • Account profile, credentials, and settings. Kept for the duration of your account and deleted within 30 days of closure, because the purpose they were collected for ends when the account closes.

  • Invoices and transaction records. Kept for 10 years from the date of issue, to meet tax, accounting, and statutory record-keeping obligations.

  • Operational logs, such as API requests, latency, and errors. Kept for 90 days and then deleted or irreversibly aggregated, for service reliability, capacity planning, and debugging.

  • Security and audit logs, such as authentication events and administrative access. Kept for 12 months, to detect and investigate security incidents and abuse.

  • Support correspondence. Kept for 3 years from closure of the request, to handle follow-up questions and defend potential claims.

  • Marketing contact details and preferences. Kept until you unsubscribe, after which we retain only a suppression record so that we can honour your opt-out.

  • Backups. Held on a rolling 30 day cycle for disaster recovery.

Where a longer period is required to establish, exercise, or defend a legal claim, or to comply with a legal obligation or a lawful preservation request, we keep the relevant information for the duration of that requirement and no longer.

Once a retention period ends, we delete the information or irreversibly aggregate it so that it can no longer be linked to you or to any identifiable person. Aggregated data may be kept indefinitely.

Retention of Customer Content is described in Section 10.

9. Your rights

Depending on where you live, you may have the right to access your personal information, correct inaccuracies, request deletion, object to or restrict certain processing, receive a portable copy, and withdraw consent. California residents additionally have rights to know, delete, correct, and opt out of the sale or sharing of personal information.

We do not sell personal information for money. However, our use of the advertising and identity resolution partners described in Section 2 may constitute "sharing" for cross-context behavioural advertising, and in some readings a "sale", under the CCPA/CPRA. You can opt out using the links in Section 2 or by contacting us. We do not offer financial incentives in exchange for personal information, and we do not knowingly sell or share the personal information of anyone under 16.

To exercise any of these rights, contact support@exabase.io. We will respond within the period required by applicable law. We may need to verify your identity first. You will not be treated differently for exercising a right.

If your data is in a customer's Base and you are that customer's end user, see Section 11.

If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority.

10. Customer Content

What it includes. Files, documents, PDFs, images, audio, video, notes, bookmarks, folder structures, tags, conversations sent for memory extraction, extracted text and transcripts, embeddings and search indexes derived from your content, memories generated by our M-1 engine, and filesystem snapshots.

Isolation. Content is scoped to the Base it lives in. Isolation is enforced at the infrastructure level rather than by query filtering. Search returns results only from the requesting Base, memories are scoped per Base, and Workers can access only the Base they run in.

Processing. We process Customer Content only to deliver the features you invoke: indexing for search, extracting facts and relationships into memory, transcribing audio and video, running OCR on images, fetching and indexing URLs you bookmark, and executing scheduled Worker tasks you configure.

Your responsibility. You are responsible for having a lawful basis to upload content containing personal information, for providing any required notices to your end users, and for honouring their rights. Do not upload special-category data, health records, payment card data, or other regulated data unless your agreement with us expressly permits it.

Snapshots. If filesystem versioning is enabled, historical states are retained at hourly granularity for the last 24 hours and in six-hour windows for 1 to 7 days, with retention configurable on your plan. Deleted resources remain recoverable within the snapshot window by design.

Deletion. You can delete resources, memories, or entire Bases at any time through the API or workspace explorer. Deletion removes content from active systems immediately and from backups and snapshots within 30 days, subject to any configured snapshot retention. On account termination, we delete or return Customer Content within 30 days as set out in the DPA.

Access by our staff. Our personnel do not access Customer Content except where you request support that requires it, where necessary to investigate a security incident or suspected terms violation, or where legally compelled. Such access is logged and limited to authorised staff.

11. If you are an end user of an Exabase customer

If a company uses Exabase to power its product and your information ended up in that company's Base, that company, not Exabase, controls that data and decides what happens to it. Direct access, correction, and deletion requests to them. If you contact us, we will refer you to the relevant customer and assist them in responding.

12. Security

We protect information using measures including:

  • encryption in transit (TLS/SSL) and at rest (AES-256);

  • infrastructure-level tenant isolation between Bases;

  • scoped API keys, role-based access control, and least-privilege internal access;

  • logging and monitoring of administrative access;

  • CASA certification and periodic security assessment.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant authorities as required by law.

13. Children

The Service is a developer platform intended for business use and is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn we have done so, we will delete it. If you believe a child has provided us with personal information, contact us at support@exabase.io.

Customers deploying Exabase in educational or classroom settings are responsible for obtaining any consents required under COPPA, GDPR Article 8, or equivalent law.

14. Links to other sites

The Service may contain links to third-party sites, and our Extract and bookmark features may fetch content from URLs you provide. We do not control those sites and are not responsible for their content or privacy practices. Review their policies before providing them with information.

15. Changes to this policy

We may update this policy from time to time. The date at the top reflects the most recent revision. For material changes we will provide advance notice by email or in-product before the change takes effect. Continued use of the Service after that date constitutes acceptance.

16. Contact

Questions, requests, or complaints:

support@exabase.io


Exabase is part of the Fabric family. © 2026 Exabase. All rights reserved.