Privacy Policy

Last updated: May 10, 2026

PugBase is a product of One DD Digital Co., Ltd. This policy explains what we collect, how we use it, who we share it with, and the rights you have. By continuing to use the service, you accept this policy.

1. Information we collect

We only collect data needed to operate the service: • Account info: email, display name, profile photo, sign-in provider (Google/Microsoft/GitHub/Email) • Content you create: notes, workspaces, uploaded sources, AI-generated transcripts, chat history • Payment info: handled entirely by Stripe - we never see your card number • Usage info: tokens / bytes per billing cycle (for quota enforcement) • Technical logs: error logs and IP addresses for debugging and abuse prevention

2. How we use your data

We use your data to: • Operate PugBase (store + render notes, sync across devices) • Process AI requests you initiate (forward content to Gemini for transcription / Q&A) • Charge you for the plan (forward charge requests to Stripe) • Notify you of important events (invites, outages, billing) • Improve the product (aggregate, anonymized usage analysis)

3. Sharing with third parties

We use the following vendors and share only the data necessary for the service to work:

  • • An enterprise cloud provider - stores notes, authentication, and files
  • • Stripe - processes payments and manages subscriptions (card number, billing address)
  • • Google Gemini API - receives the files, YouTube links, note content, transcripts, and questions you submit for AI processing (transcription, summaries, Q&A, translation, diagrams). This is the default AI provider. Google does NOT use your data to train its models (per the Gemini API terms)
  • • Anthropic (Claude) - only when you explicitly choose one of their models for AI chat; the same note / file content is then sent to Anthropic instead of Google. They do not use your data to train their models under their API terms. We ask for your permission in the app before any content is first sent to a third-party AI service.
  • • Unsplash API - searches for cover photos (only the search query is sent, no personal data)
  • • PostHog (US servers) - product usage statistics: which pages are opened, and milestone events (sign-up, workspace created, plan created, agent connected) so we know what to improve. You are identified by user id only, never by email or name, and all on-screen text is masked, so your note content is never sent here.
  • • Apps you connect yourself - when you authorize an external app over MCP / OAuth (e.g. Claude), it can read and write the notes of the workspace you grant, on your behalf. The content it reads is sent to that app's provider (for Claude, Anthropic) and handled under their privacy policy. Revoke access anytime in Settings -> Developer.
  • We do not sell or trade your data to anyone for advertising purposes.

4. Where your data is stored

All data is stored on enterprise cloud infrastructure, primarily in the Southeast Asia (Singapore) region. Uploaded files are kept in encrypted object storage. Our provider delivers enterprise-grade protection (encryption at rest and in transit, ISO 27001 certified).

5. Cookies & local storage

We use browser local storage / cookies to: • Remember your login session • Save preferences (theme, locale, sidebar state) • Maintain a session id for real-time presence • Store a random PostHog id so we can tell repeat visits apart (product usage statistics) No tracking pixels. No advertising cookies. No cross-site tracking.

6. Data retention

• Notes / workspaces: kept as long as your account is open • Uploaded sources: also kept (the source file is deleted after transcription, but the transcript is retained) • Usage logs: 90 days • Payment records: retained for tax / accounting compliance (typically 7 years)

7. Your rights

You can: • Export all your data (notes + transcripts) as markdown • Edit or delete any note / source / workspace at any time • Delete your account from /account - all data is permanently removed within 30 days • Request the data we hold on you or ask any privacy question

8. Children's privacy

PugBase is not intended for children under 13. If we discover an account belongs to a minor without parental consent, we will remove all data immediately.

9. Changes to this policy

We may update this policy over time. If a change materially affects user rights, we'll notify you by email at least 30 days in advance. Continued use after the change takes effect constitutes acceptance.

10. Google Calendar integration & Google API Services

When you choose to connect Google Calendar (the Connect button in a schedule note), PugBase requests access through Google's consent screen with the calendar.events scope, to read and create events on your primary calendar: • Read your event list (title, time, details) to display alongside the app's own calendar • Write events you create in the app back to your Google Calendar The access token is held only in memory for the session (short-lived, around 1 hour; we do not store it on our servers). We do not sell it, use it for advertising, or use your calendar data to train AI. You can revoke access anytime at https://myaccount.google.com/permissions PugBase's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

11. Operator & Contact

PugBase is operated by: One DD Digital Co., Ltd. Bangkok, Thailand For privacy questions, data export / deletion requests, or to report an issue, contact support@pugbase.io

© 2026 One DD Digital Co., Ltd.