Privacy Policy
What we collect, how long we keep it, and what we do with it — including the parts most policies bury.
Last updated July 24, 2026
Scope
This policy covers Basecase, Inc. (“Basecase,” “we”) and the underwriting platform at basecase.xyz. It describes how we handle information belonging to our customers and information contained in the documents they upload.
What we collect
Account information. Name, email address, and company name, provided through our authentication provider when you sign up.
Documents you upload. Rent rolls, operating statements (T12s), and similar property financial documents, in the form you provide them.
Data derived from those documents. Structured extraction of what they contain — unit mixes, square footage, in-place and market rents, lease dates, income and expense line items.
Underwriting inputs and outputs. The assumptions you enter and the model results we compute from them.
Billing information. Handled by Stripe. We store a customer identifier and your plan status. We never receive or store your card number.
Resident information in rent rolls
Rent rolls frequently contain the names of residents — people who are not our customers and who have no relationship with us. We treat this as the most sensitive category of data in the system and hold it for the shortest period that still lets the product work.
Resident names are used only to display and verify the rent roll you uploaded. No calculation in our model uses a resident’s name. They are never included in the aggregated market data described below, and they are never shared with anyone.
We remove resident names from our structured data automatically within 90 days. They persist beyond that only inside the original document you uploaded, until that document is deleted.
Artificial intelligence and model training
We use Anthropic’s API to read and structure your documents. Those documents are transmitted to Anthropic for processing under its commercial terms.
Your data is not used to train AI models— not ours, not Anthropic’s, not anyone’s. Anthropic’s commercial API terms prohibit training on inputs submitted through it, and we do not train models of our own on customer content.
This is a separate question from the aggregated market data described below, which is a statistical dataset rather than model training. We state both so that neither is read as a substitute for the other.
Retention
Original documents you upload are retained until you delete the file, or for 12 months, whichever comes first. You can download your original documents at any time before then.
Resident names are removed from our structured data within 90 days, and from our systems entirely once the source document is deleted or reaches the end of its retention period.
Your deals, assumptions, and model outputs are retained for as long as your account is open, or until you delete them.
De-identified property and market data is retained indefinitely (see Aggregated market data, below).
Deleting your data
Deleting a file removes the original document from our storage immediately and strips resident names from the extracted data. The de-identified property data derived from it is retained.
Deleting a deal removes the underwriting, its assumptions, and its model output. The de-identified property data is retained.
Closing your account removes your uploaded documents, your model outputs, and the link between you and any data derived from your documents. The de-identified property data is retained.
If you need something removed that this does not cover, contact us and we will handle it individually.
Service providers
We share data with the following providers, each only to the extent needed to run the service. This list is complete as of the date above.
| Provider | Purpose | What it receives |
|---|---|---|
| Clerk | Authentication | Name, email |
| Supabase | Database and file storage | All customer data and uploaded documents |
| Anthropic | Document parsing | Contents of uploaded documents |
| Stripe | Payments | Name, email, payment details (card data never reaches us) |
| Google Maps Platform | Address autocomplete | Property addresses you type |
| Vercel | Frontend hosting | Request metadata |
| Railway | API hosting | Request data in transit |
| Sentry | Error monitoring | Error reports and stack traces (request bodies and document contents are excluded) |
| PostHog | Product analytics | Which features are used, by an anonymous account identifier |
We do not sell your data, and we do not share it with advertisers or data brokers.
Security
Data is encrypted in transit and at rest, and every record is scoped to its owner at the database level. Our security page describes our practices in detail.
Your rights
You can access, correct, export, or delete your data from within the app, or by contacting us. Depending on where you live, you may have additional statutory rights — including the right to know what we hold, to request deletion, and to object to certain processing. We honour these requests regardless of whether a specific law applies to you.
Because you control what you upload, you are responsible for having the right to provide us with the documents you submit, including any resident information they contain.
Aggregated market data
Basecase retains de-identified, property-level data derived from processed documents — unit mixes, rents, square footage, operating expense lines, and the underwriting assumptions applied to them — on an indefinite basis. This dataset is what allows us to provide rent and expense benchmarking against comparable properties in your submarket.
This data is not linked to the customer who uploaded it once your deal is deleted, and it never contains resident names. It describes buildings — not people, and not customers.
Your processed data contributes to this benchmarking dataset, and in return you gain access to comparables you could not otherwise assemble.
Changes to this policy
If we change how we handle data, we will update this page and the date at the top. For material changes affecting existing customers, we will give notice in the app or by email before the change takes effect.
Contact
Questions, requests, or concerns: privacy@basecase.xyz