Introduction
Baseline (“we”, “us”, “our”) is a personal life intelligence app operated by TheMkHouse from India. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. By using Baseline on Android, iOS, or the web, you agree to this policy.
Who this app is for
Baseline is intended for adults (18+). It is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.
Information we collect
We collect only what is needed to provide pillar scores, trends, journal features, and AI-assisted insights.
- Account information: email address, display name, sign-in provider (e.g. Google), onboarding answers (age band, career context, personality snapshot), and subscription status
- Health & fitness (with your permission): steps, sleep, heart rate, HRV, active calories, exercise sessions, and related metrics via Apple Health (iOS) or Health Connect (Android)
- Location (with your permission): approximate location while you use the app to estimate mobility for your Social pillar — we do not track you continuously in the background
- Calendar (with your permission): event titles, times, and categories from Google Calendar to estimate social events and work–life balance
- Journal & voice: text you enter, voice recordings you submit for transcription, and AI-extracted topics, emotions, nutrition/work/career previews you confirm
- Financial (optional integrations): aggregated portfolio values and holdings categories (e.g. mutual funds, demat) — not full bank statements or transaction histories
- Connected services (optional): data you authorise from integrations such as Spotify, FatSecret, Todoist, or India open-banking/CAS providers when you connect them
- Device & app data: push notification tokens, app version, sync timestamps, and diagnostic logs needed to operate the service
What stays on your device
We minimise what leaves your phone. The following are processed or stored primarily on your device:
- Raw Health Connect / Apple Health reads until you choose to sync
- Google Search history classification: only topic-level aggregates are sent — not individual queries, URLs, or per-query timestamps
- OAuth authorisation happens in your system browser; tokens are stored encrypted on our servers only after you connect an integration
- Screen Time category totals on iOS (when enabled) are read on-device before sync
How we use your information
We use your data solely to operate and improve Baseline:
- Compute pillar scores, Life Score, trends, and weekly insights
- Power journal extraction, Baseline AI assistant replies, and integration sync
- Send optional push notifications (nudges, digests) you can disable in system settings
- Process subscription payments and show billing history
- Maintain security, prevent abuse, and fix errors
AI processing
Journal transcription may use OpenAI. Journal extraction, career/nutrition/work parsing, and Baseline AI chat use Anthropic Claude. These providers receive only the text or structured context needed for the feature — not a full dump of your device. Do not include passwords, OTPs, or sensitive identifiers in journal entries.
How we store and protect data
Data is transmitted over TLS (HTTPS). On our servers, sensitive fields — including OAuth tokens, financial amounts, journal transcripts, career descriptions, and selected integration metadata — are encrypted at rest using AES-GCM with per-user keys derived from our master encryption key. Pillar scores and normalised metrics used for benchmarking remain unencrypted so scoring can run efficiently.
- Hosted on Supabase (PostgreSQL) and TimescaleDB in secure cloud environments
- Access limited to authorised systems; no sale of personal data
- Decrypt access to sensitive fields is audit-logged on the server
Third-party services
When you connect an integration or sign in, data may be processed by:
- Google — Sign-In and Google Calendar API (subject to Google’s privacy policy)
- Supabase — authentication and database hosting
- Anthropic & OpenAI — AI features as described above
- Spotify, FatSecret, Todoist — only when you connect each service
- CAS Parser / Setu (India) — only when you connect financial integrations
- Razorpay — subscription payments (India)
- Apple / Google — app distribution, push delivery, and OS-level permissions
What we do not do
We do not sell your personal information, show third-party ads based on your life data, or share identifiable health or financial detail with advertisers.
- We do not store full search query histories from Google Takeout exports
- We do not read your calendar or health data without OS permission prompts
- Disconnecting an integration stops new data from that provider
Your choices and rights
You control your data through the app and applicable law (including India’s Digital Personal Data Protection Act, 2023 where it applies).
- Review and disconnect integrations in the Integrations screen
- Revoke Health Connect, location, calendar, or microphone permissions in Android Settings
- Sign out or delete your account — contact us to request erasure of server-side data
- Request access to or correction of your personal data by emailing us
- Opt out of marketing push notifications via device notification settings
Data retention
We retain account and synced data while your account is active and as needed to provide the service. When you request deletion, we delete or anonymise personal data within a reasonable period, except where law requires retention (e.g. payment records).
International transfers
Our service providers may process data in India and other countries. Where data is transferred outside India, we rely on contractual safeguards and provider security practices appropriate to the nature of the data.
Changes to this policy
We may update this policy as features, integrations, or regulations change. Material updates will be reflected in the app and on our website. Continued use after changes constitutes acceptance of the updated policy.
Contact us
For privacy questions, access requests, or account deletion, email support@baselineapp.in with the subject line “Privacy request”. We aim to respond within 30 days.
Legal entity: TheMkHouse · Brand: Baseline · Website: baselineapp.in