1. Our approach
BaseHeart uses a strict privacy-by-default model. Technologies that are necessary for security, authentication, consent storage or a feature you explicitly request may operate without optional consent. Optional analytics, marketing and similar technologies remain disabled until you choose to allow the relevant category.
2. Current cookie and browser-storage inventory
This inventory reflects the current BaseHeart codebase. We do not list advertising or analytics technologies that are not actually configured.
| Name | Type | Purpose | Category | Typical duration |
|---|---|---|---|---|
baseheart_session_v2 | HTTP-only cookie | Keeps an authenticated BaseHeart account session active and binds requests to the signed-in account. | Necessary | Up to 30 days, or until logout/invalidated session. |
baseheart_wallet | HTTP-only cookie | Binds server-authoritative personal or workspace billing state to the correct BaseHeart wallet. It is cleared on logout and is not an advertising identifier. | Necessary | Up to 1 year, or until logout/replacement. |
baseheart_google_oauth, baseheart_auth0_oauth and connector state cookies | HTTP-only cookies | Short-lived OAuth state/PKCE and anti-forgery data used only while completing a sign-in or an explicitly requested connector authorization. | Necessary | Usually up to 10 minutes, then cleared or expired. |
baseheart_privacy_consent_v1 | Local browser storage | Stores your versioned privacy choices, consent receipt identifier, timestamps and Global Privacy Control state. It does not store advertising identifiers. | Necessary | Until policy version changes, browser storage is cleared, or you replace the choice. |
baseheart-new-language | Local browser storage | Remembers a language only after you explicitly choose it in the BaseHeart interface. Initial page setup does not create this preference. | Functional / user-requested preference | Until changed or browser storage is cleared. |
| BaseHeart interface preferences | Local browser storage | Remembers non-sensitive interface choices such as view, preview device and similar workspace preferences. Production account/project data remains server-authoritative. | Functional | Until changed or browser storage is cleared. |
_ga, _ga_<container-id> | First-party Google Analytics cookies | Distinguish users and retain session state for optional visit and product-usage measurement after Analytics consent. BaseHeart uses Google Analytics 4 measurement ID G-2970CSDCJ0 and does not load the Google tag before Analytics consent. | Analytics | Google's default is up to 2 years, subject to browser limits, earlier withdrawal, or browser clearing. |
G-2970CSDCJ0 for optional Analytics measurement. The Google tag is blocked until Analytics consent exists. Advertising storage, advertising user data and ad-personalization consent remain denied by the BaseHeart integration.3. Consent categories
| Category | What it covers | Default |
|---|---|---|
| Necessary | Security, authentication, anti-abuse controls, consent records and functions explicitly requested by you. | Always active where technically required. |
| Functional | Optional preference storage and convenience features that are not essential to the service. | Off until allowed, except a preference you directly ask BaseHeart to remember. |
| Analytics | Optional measurement of reliability, visits or product usage. | Off until allowed. |
| Marketing | Optional advertising, advertising measurement or targeted-marketing technology. | Off until allowed and overridden by applicable opt-out signals. |
4. Global Privacy Control
BaseHeart checks whether your browser exposes Global Privacy Control (GPC). When GPC is active, BaseHeart treats it as an opt-out of sale/sharing and targeted advertising and will not allow the marketing category to override that signal.
5. Change or withdraw your choices
You can change optional consent at any time. Withdrawing consent is as easy as giving it and does not affect processing that was lawful before withdrawal.
6. Changes to this Cookie Policy
When BaseHeart adds, removes or materially changes cookie or tracking technologies, we update this inventory and the effective date. A material change to optional consent purposes can cause the banner to appear again so a new choice can be made.
7. Contact
Questions about cookies or consent can be sent to kevin@baseheart.ai. For broader personal-data information, see the Privacy Policy.