Baseline is built on a simple principle: your personal data belongs on your device, not ours.
All habit entries, mood scores, notes, streaks, and reflections you log in Baseline are saved only on your device. We have no servers or databases that store your personal tracking records.
Life Audit generates its month-by-month narrative from your on-device logs, mood scores, note count, habit names, and entry history — computed entirely on your device. Your written notes and reflections are processed locally and never leave your phone.
The Life Audit also offers an optional AI synthesis (the "arc") that you generate manually. Because it calls the Claude API, it is covered under "Optional AI Features" below — it sends anonymised monthly stats and habit names, never your written notes.
Trajectory projections and all Review-tab analytics are similarly computed on-device.
When you use Future Self, Extract Stack, Goal Stack, or the Life Audit AI synthesis, Baseline sends a payload to a Cloudflare Worker proxy operated by the developer. This proxy forwards the request to the Anthropic Claude API to generate a response. Using these features is always your choice — they are never triggered automatically.
The payload contains only:
The payload does not contain your name, email address, device identifier, written mood notes, written reflections, or any other directly identifying information.
The proxy logs anonymised request metadata — a random request ID, the feature name, the Claude model used, response status, response time, token count, and stop reason — for performance monitoring via Cloudflare's observability tools. No message content is logged.
Requests are processed in the United States. If you are located in the European Economic Area or UK, this constitutes an international transfer. Anthropic processes data under Standard Contractual Clauses; Cloudflare processes data under its Data Processing Addendum. The legal basis for this processing is your consent — processing only occurs when you actively invoke the feature.
If you explicitly publish a Habit Stack to share with others, only the template schema is stored — habit names, emojis, synergy relationship types, stack name, description, and the creator name you provide. No tracking history, mood data, or personal records are included. Published stacks are stored in Cloudflare KV with a 90-day automatic expiration. When a stack expires or you delete the link, all associated data — including the creator name you provided — is permanently removed. You can delete a published link at any time from within the app. The legal basis for this processing is your consent.
If you submit the in-app or website contact form, we collect your name, email address, and message. This information is transmitted via Resend (an email delivery service) to our support inbox. Your IP address is stored briefly (60 seconds) in Cloudflare KV solely to prevent spam. We use your contact details only to respond to your inquiry and do not add you to marketing lists. Contact form submissions are retained in our support inbox for up to 24 months, then deleted. The legal basis for this processing is our legitimate interest in providing customer support (GDPR Art. 6(1)(f)).
Baseline offers an optional auto-renewing subscription, Baseline Pro, which unlocks unlimited AI features. Payments are processed by Apple through the App Store; subscription status is managed via RevenueCat. Baseline never sees or stores your payment-card details, uses an anonymous RevenueCat identifier, and keeps no account.
Baseline contains no analytics frameworks, crash reporters, or advertising networks. We collect zero usage telemetry.
We implement appropriate technical security measures including HTTPS for all data in transit, access-controlled server-side infrastructure, and secret management via Cloudflare Worker secrets. Contact form data is encrypted in transit to Resend's servers. Because habit data is stored only on your device, it is protected by your device's own security (passcode, Face ID / Touch ID).
In the event of a personal data breach affecting data we hold (contact form submissions or published stack data), we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by applicable law (GDPR Art. 33). Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals without undue delay (GDPR Art. 34).
Baseline is not directed at children under 13 and does not knowingly collect data from them. If you believe a child has submitted a message via the contact form, email support@get-baseline.app and we will delete it promptly.
A Data Protection Officer (DPO) is not currently designated. Under GDPR Article 37, a DPO is required only where: (a) processing is carried out by a public authority; (b) core activities consist of large-scale systematic monitoring of individuals; or (c) core activities consist of large-scale processing of special category data. None of these conditions currently apply to Baseline. If the user base grows to a scale where condition (b) or (c) is triggered, or if features involving explicit medical data or systematic behavioural tracking are introduced, this policy will be updated and a DPO appointed accordingly.
If you are located in the European Economic Area, UK, or another jurisdiction with applicable privacy law, you have the right to:
Because your habit data is stored only on your device, you can delete it directly in the app via Settings → Danger Zone → Delete All Data. For data we hold (contact form submissions, published stacks), email support@get-baseline.app to exercise any of the above rights. We will respond within 30 days.
California residents (CCPA): Baseline does not sell or share your personal information as defined under the California Consumer Privacy Act. The rights listed above apply to California residents in addition to any rights conferred by state law.
If we make material changes to this policy, we will update the "Last updated" date above and, where appropriate, notify users via an in-app notice on the next app update.
Questions about this policy? Email support@get-baseline.app or use our contact form.