Legal
Privacy Policy
Baseplate is a desktop application for building Roblox games with AI agents. This policy explains what personal data we process, why, and the rights you have. We designed Baseplate to be local-first, so for most of what the app does, we never receive your data at all.
1. Who we are (the data controller)
The controller of your personal data is:
- Name: Baseplate — an independent software developer
- Based in: Poland (European Union)
- Contact: contact@baseplatedev.com
We are based in the European Union, so we process personal data under the EU General Data Protection Regulation (GDPR / RODO).
2. The local-first principle
Baseplate's application server and Studio bridge run on your computer. The following are not uploaded to Baseplate's services:
- Your game source code, projects and workspaces.
- Your Roblox Open Cloud API key (stored locally on your device).
- Your full local chat transcripts, agent terminal history and Baseplate settings.
The app's local server binds only to 127.0.0.1 (your own machine) and validates the origin of every connection.
Your AI provider sees your prompts
Baseplate drives your own Claude Code, Codex, Gemini CLI, Grok or Cursor CLI account. When an agent runs, the prompts, code and context selected for that work are sent directly from your machine to your selected AI provider under your agreement with them. They do not pass through Baseplate's service. That provider's privacy policy governs its processing.
3. What we actually collect
We only process personal data in these limited situations:
a) When you buy a paid plan
Payments are handled by our payment provider (see below). We receive: your email address and which plan you bought, so we can issue and email your license key. We do not receive or store your card number or full payment details — the payment provider handles those.
b) When the app validates a paid license
The app sends your license key and a random per-installation identifier to our Cloudflare license service at activation and periodically while it runs. We use these to confirm the plan and enforce the stated device limit. The identifier is not derived from hardware serial numbers.
c) Optional anonymous product milestones
The app can send fixed product milestones such as first launch, workspace added, Studio connected, Verify scan completed, upgrade opened and license activated. The event deliberately excludes account and device identifiers, request IP from the analytics dataset, project names and paths, prompts, source code and file contents. This setting is visible in Baseplate Verify and can be disabled at any time.
d) When the app checks for updates
Direct-download builds ask GitHub whether a newer version exists. A Microsoft Store build uses the Store's update mechanism instead. The relevant provider receives the standard technical data of that request (such as your IP address and app version). This is necessary to deliver updates and security fixes.
e) When you enable team collaboration
This optional Studio-plan feature sends board cards, shared prompts and your display name through our Cloudflare team service so teammates can see them. Source files, Open Cloud keys, AI credentials and full agent transcripts are not included. A random team ID and 256-bit team key protect access; teammates must receive both from you.
f) When you visit this website
Our hosting provider processes standard server logs (IP address, browser type, pages requested) to serve the site and keep it secure. We also count a small fixed set of aggregate product-funnel events (for example landing view, live-demo start, download and checkout click) with coarse campaign labels. We do not attach an account, device or session identifier, store the request IP in the analytics dataset, collect free-form text, or use cookies/local storage for this measurement. Global Privacy Control and browser Do Not Track are respected. The site uses local system fonts and no advertising or cross-site tracking cookies. See our Cookie Policy.
g) When you contact us
If you contact support, we process the email address and content you send, to answer you.
4. Third parties we rely on (processors)
We use a small number of trusted providers to run the service. Each processes only what is needed:
| Provider | Purpose | Data |
|---|---|---|
| Our payment provider — Stripe | Process payments, tax & invoicing | Email, name, payment details, country |
| GitHub (Microsoft) | App downloads & auto-updates | IP, app version (request logs) |
| Microsoft Store (when used) | Windows app download, signing and updates | Microsoft account and device/request data under Microsoft's terms |
| Cloudflare | Website hosting, aggregate funnel counts, license validation and optional team sync | Request IP in transient infrastructure logs; fixed event names and coarse campaign labels; email, plan, license key and installation ID; opt-in board cards, prompts and display name |
| Resend | Delivering your license-key email | Email address, message content |
| Your selected AI provider | Runs the agents you invoke | Your prompts, code and context (direct from your machine) |
Some of these providers are located outside the European Economic Area (e.g. the United States). Where that is the case, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses or the EU–US Data Privacy Framework.
5. Legal basis for processing (GDPR Art. 6)
- Performance of a contract — issuing your license key and delivering the software you purchased.
- Legitimate interests — delivering security updates, preventing fraud/abuse, answering support requests, and improving the product using identifier-free aggregate funnel counts.
- Legal obligation — keeping tax and accounting records where required.
- Consent — any non-essential cookies or optional communications, which you can withdraw at any time.
6. How long we keep data
- Purchase & license records: for as long as your license is valid and afterwards as required by tax/accounting law (in Poland, generally 5 years).
- Support emails: up to 24 months after your last message.
- Server & update logs: a short period for security, then deleted or anonymised.
- Aggregate funnel events: retained only as long as useful for product decisions; they contain no account, device or session identifier.
7. Your rights
Under the GDPR you have the right to: access your data; correct it; erase it; restrict or object to processing; data portability; and withdraw consent at any time. To exercise any of these, email us at the address below.
You also have the right to lodge a complaint with your supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO), uodo.gov.pl.
8. Children
Baseplate is a developer tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.
9. Changes to this policy
We may update this policy as the product evolves. We will change the "last updated" date above and, for material changes, note it on the website.
10. Contact
Questions about privacy? Email contact@baseplatedev.com, or use our contact form.