Skip to content
Unbase44

Legal

Privacy policy

Last updated

Moving an app means handling other people’s data, so this policy tries to be specific: what we read, why, where it goes, and how quickly it is gone. Questions go to hello@unbase44.com.

1. Who is responsible

Codama Advanced Engineering, Inc. (“Codama”, “we”), 8 The Green, Ste A, Dover, DE 19901, USA, is responsible for the personal data described here as it relates to your use of Unbase44: the website, the Unbase44 app and the migration service.

The data inside your Base44 app, including information about your app’s own users, belongs to you. When we process it during a migration, we act on your behalf as your processor (in US terms, your service provider), and you remain responsible for it. We will sign a data processing agreement on request.

2. What we collect, and why

Your Base44 sign-in

You sign in through Base44’s own device sign-in: you approve a code on Base44, where it appears as a sign-in for Base44’s command-line tool. Base44 then gives us an access token, a refresh token, and your account’s email address and name. We never see your Base44 password. We keep the tokens encrypted until you revoke access, and use them to list your apps, read the app you choose, add and remove the secrets helper described in the terms, and copy new data from Base44 when you ask.

The app you choose to analyse and migrate

To analyse, price and migrate an app, we read it through Base44’s interfaces: its source code, table definitions, records (or, if the app has no live data yet, its test data), user records (such as email addresses, names and roles, but never passwords), backend functions, automations and workflows, agent settings and agent conversations with the files attached to them, connector types (not their tokens), SEO, domain and redirect settings, whether payments are set up, uploaded files including private ones, and the names of its secrets. We read secret values only in the way the terms describe: through a temporary helper function that is removed straight after, or by you entering them.

The analysis summary

We keep a summary of each analysis, such as counts of pages, tables, records and functions, file sizes and the features the app uses, so we can show your quote, continue where you left off, provide support and improve our pricing.

Provider credentials

The keys and tokens you enter for services like GitHub, your hosting provider or your database provider are encrypted before they are stored, are never shown back to you or anyone else, and are used only to set up your migration and carry out follow-up actions you ask for. “Revoke access” on your app’s live page deletes all of them; before your app is live, or to close your account, write to us and we will delete them.

Keys we keep for your live app

So the actions on your app’s live page work (updating its server, copying new data, connecting a domain or an email sender), we keep, encrypted: an admin key to your moved app, which lets us read and import its data through its admin interface; the secret your app signs its users’ sign-ins with; and, when it runs on Railway, a deploy token we create in your Railway project. When an action needs your app’s own keys for Stripe, PayPal, Twilio or Telegram, we read them from your host for that request only and don’t store them. “Revoke access” deletes all of these.

Payments

Migrations are free during the beta. Once paid migrations begin, payments will be processed by our payment processor; we receive a confirmation and limited details, never your full card number.

Your account

Besides your name and email address, we keep your answer to the optional “How did you hear about us?” question, and for each sign-in session the browser’s user agent. A session lasts 30 days unless you sign out.

Messages and technical data

If you email us, we keep the conversation to help you. Our own servers don’t log IP addresses; our hosting providers record technical information, such as IP addresses and timestamps, to keep their networks secure.

3. Your app’s data during a migration

Your app’s code, records, users and files travel from Base44 to the accounts you chose, through our migration workers. The working copy is deleted as soon as your app is live, or about three days after the last activity on a migration that stops. We do not keep your records afterwards. What remains with us is the analysis summary, a record of the migration’s steps (counts, statuses and messages, not your records), the list of links to the files we copied, and the keys described in section 2 until you revoke access. The values of your app’s secrets are deleted when the app is live, or when you revoke access.

Your users’ passwords never reach us. So users can keep their passwords, the migrated app checks each user’s first sign-in against Base44 once. That check runs from your own server, not ours.

After the migration your app runs in your accounts, and none of its traffic passes through Unbase44.

4. How we use information

  • to provide the Service: sign-in, analysis, quotes, migrations and support;
  • to keep the Service secure and prevent misuse;
  • to improve the Service, using aggregated information that doesn’t identify you or your app’s users;
  • to meet legal obligations.

We don’t sell personal data, we don’t use it for advertising, and we don’t use your app’s data to train AI models.

Where the GDPR applies, our legal bases are the performance of our contract with you, our legitimate interest in running a secure and reliable service, compliance with legal obligations, and your consent where we ask for it.

5. Who else is involved

Services you choose. A migration sends your app’s data to the providers you pick, such as GitHub, Railway or your own server. They receive it because you instruct us to deploy there, and their use of it is governed by your agreements with them. Base44 is likewise your provider, not ours; we access it on your instruction.

Our subprocessors. We use a small number of companies to run Unbase44 itself:

CompanyPurposeLocation
Cloudflare, Inc.Hosting and delivery of this website and the Unbase44 app, visit counts (Web Analytics), and forwarding mail sent to our addressGlobal network
Railway CorporationHosting of the Unbase44 API, migration workers and database (accounts, migration status, encrypted keys)United States
Google LLC (Google Workspace)Our mailbox, for the emails you send usUnited States

We will update this list before adding a subprocessor that handles your app’s data, and before we take payments.

We may also disclose information if the law requires it, or to protect the rights and safety of our users or others.

6. International transfers

We are a US company and our systems run primarily in the United States. Where personal data from the European Economic Area, the UK or Switzerland is transferred, we rely on Standard Contractual Clauses or another recognised mechanism.

7. How long we keep things

  • Your app’s code, records, users and files: deleted when your app is live, or about three days after the last activity on a migration that stops.
  • Your app’s secret values: until the app is live, or until you revoke access.
  • Provider credentials, Base44 tokens and the keys for your live app: until you revoke access or ask us to delete them.
  • Account details, analysis summaries and migration records: while your account is open; we delete them within 30 days of your request to close it.
  • Logs at our hosting providers: up to 30 days, unless needed to investigate a security issue.
  • Payment records, once paid migrations begin: as long as tax and accounting law requires.

8. Security

Data is encrypted in transit. Provider credentials, Base44 tokens and the keys we keep for your live app are encrypted at rest. Our team can see account emails and each migration’s status, steps and summaries, and can run a migration again or copy its data again to fix a problem. Access to our systems is limited to the people at Codama who run the Service. No system is perfectly secure; if a breach affects your data, we will tell you without undue delay and as the law requires.

9. Your rights

Depending on where you live, you can ask to access, correct, delete or export your personal data, and object to or restrict how we use it. California residents can ask what we collect and why, and ask us to delete or correct it; we don’t sell or share personal data for cross-context advertising. Email hello@unbase44.com and we will respond within 30 days. You can also complain to your local data protection authority.

If you are a user of an app that was migrated with Unbase44, the app’s owner controls your data; please contact them first.

10. Cookies and analytics

This website and the Unbase44 app set no cookies and use no advertising trackers. We count visits with Cloudflare Web Analytics, which uses no cookies and doesn’t follow you across sites. Fonts are served from our own domains, so browsing doesn’t send your details to font providers.

The Unbase44 app stores a sign-in session in your browser so you stay signed in; this is strictly necessary and is removed when you sign out. If we add any other analytics, we will list it here first and ask for consent where the law requires it.

11. Children

Unbase44 is not intended for children, and we don’t knowingly collect data from anyone under 16.

12. Changes to this policy

If we change this policy we will update the date at the top, and for significant changes we will tell you by email or in the app first.

13. Contact

Codama Advanced Engineering, Inc., 8 The Green, Ste A, Dover, DE 19901, USA. Email: hello@unbase44.com.