Legal
Privacy Policy
Version of
This policy tells you which data Basement Gateway uses and why. NKODE AI makes and operates Basement Gateway.
1. Who is responsible
NKODE AI operates Basement Gateway: this site, the web app (app.basement.chat), the address for AI agents (mcp.basement.chat), the desktop app and the SDKs.
Each customer organization decides what it keeps in the Gateway and who has access. For that content, the organization is the data controller and NKODE AI is the processor.
For the account data and the usage data in this policy, NKODE AI is the controller.
For privacy questions, write to hello@nkodeai.com.
2. Data that we use
We use only the data that the service needs:
- Account: your name, your e-mail, your organizations and your role in each organization.
- Sign-in: a one-time code that we send to your e-mail. The code is valid for 15 minutes.
- Passkey: we keep only the public key. The private key and your biometric data stay on your device.
- Content: the documents, files, skills, folders and tasks that your organization keeps in Basement, with their versions.
- Connections: the address of each connected service and your credential (a token, an API key or an OAuth authorization). We keep the credential encrypted.
- SAP: the data of the system that you registered (identifier, server, address, instance, client and language) and your sealed credential.
- Agents and programs: the name, the access level and a hash of the key. We show the key one time and we do not keep it.
- Activity log: who called which tool, when, the result and the counts. The log does not copy the content.
- Desktop app: the name and the operating system of the computer, its public keys, the SAP systems that you confirmed and the connection status of each system.
- Technical data: the IP address, the date, the time and the browser data, in the logs of our providers.
This site does not use cookies for advertisements or for analytics. The web app keeps in your browser only the data for your session and your preferences.
3. Your SAP password and the data from your systems
Your computer seals the SAP user and password before it sends them. The Gateway keeps an encrypted block that it cannot open. Only the server of the SAP connector opens the block, at the logon to the system.
The SAP tools are read-only. No tool creates, changes or runs anything in the system.
The Gateway sends the data that an agent reads to that agent. The Gateway does not keep a copy of that data, with three exceptions:
- The format of SAP tables stays in a cache.
- The reference lists of a service (for example, statuses and request types) stay in a cache.
- A scheduled reply or change stays in the Gateway until the Gateway posts it or you cancel it.
4. Why we use the data
- To supply the service: to keep and send the content of the organization and to run the tools.
- To authenticate people, agents and programs, and to apply each access level.
- To keep the activity log. The organization uses the log for audits.
- To protect the service: rate limits, abuse prevention and incident investigation.
- To send service messages: the sign-in code, invitations and notices about a scheduled action.
- To give support when you ask for it.
We do not sell personal data. We do not use the content of your organization for advertisements or to train AI models.
5. AI agents and connected services
When you connect an AI agent (for example, Claude), the Gateway gives the agent the data that it asks for. The access level that you selected sets the limit.
After that, the provider of the agent uses the data. The terms and the privacy policy of that provider apply.
When you connect a service (for example, Jira, GLPI or MultiDados), the Gateway sends your requests to that service with your credential. The terms of that service apply to the data.
6. Providers
We use providers to operate the service. They use the data only for us:
- Convex: the database, the files and the functions of the service.
- Cloudflare: the web app and this site.
- Amazon Web Services: the server of the SAP connector and the installers.
- Resend: the e-mails of the service.
We also share data when the law or an order from an authority requires it. We do not share data with advertisers.
7. Location of the data
These providers use data outside Brazil. The United States is one of the locations.
8. Security
- All the communication with the service uses HTTPS.
- We keep the connection credentials encrypted. The Gateway cannot read the sealed SAP credential.
- The sign-in has no password: an e-mail code or a passkey.
- Each agent and each program has an access level. One organization cannot see the data of a different organization.
- The activity log shows the organization what each agent did.
No system is fully safe. If a security incident can cause you risk or damage, we tell the organization and the authority, as the law requires.
9. Storage time
- Account and content: while the organization uses the service.
- Sign-in code: 15 minutes. Session: a maximum of 30 days.
- Activity log: the calls stay in the log for approximately 90 days. Then they move to monthly files of the organization. Admins can download these files.
- Connection credentials: until you disconnect or remove the connection.
- Technical logs of the providers: the period of each provider.
When an organization stops the service or asks for deletion, we delete its data. We keep only the data that the law requires.
10. Your rights
The Brazilian data protection law (LGPD) gives you these rights:
- To get a confirmation that we use your data.
- To get access to your data.
- To correct your data.
- To make your data anonymous, to block it or to delete it.
- To move your data to a different provider.
- To know who we share your data with.
- To remove your consent.
Other data protection laws that apply to you can give you equivalent rights.
To use a right, write to hello@nkodeai.com. If the request is about the content of an organization, we send it to the admin of that organization. The admin decides about that content.
You can also complain to the Brazilian data protection authority (ANPD).
11. Professional use
Basement Gateway is a tool for work. It is for persons who are 18 years or older and who act for an organization. It is not for children or adolescents.
12. Changes to this policy
When this policy changes, we publish the new version on this page with its date. If the change is important, we send an e-mail to the admins of the organizations.
13. Contact
NKODE AI. E-mail: hello@nkodeai.com.
Questions about this text: hello@nkodeai.com