Skip to cookie policy
♥BaseHeart
LegalPrivacyCookiesTermsBack to BaseHeart

LEGAL · COOKIES

Cookie Policy

This page explains the cookies and browser storage BaseHeart actually uses, why they are used and how you can control optional technologies.

Effective: 6 September 2026Strict opt-in baselineEU + United States privacy controls
On this page 1. Our approach2. Current inventory3. Consent categories4. Global Privacy Control5. Change your choices6. Changes7. Contact

1. Our approach

BaseHeart uses a strict privacy-by-default model. Technologies that are necessary for security, authentication, consent storage or a feature you explicitly request may operate without optional consent. Optional analytics, marketing and similar technologies remain disabled until you choose to allow the relevant category.

No pre-ticked consent. Accept all, reject all and granular choices are available from the same first-layer banner. Rejecting optional technologies does not block access to core BaseHeart functionality.

2. Current cookie and browser-storage inventory

This inventory reflects the current BaseHeart codebase. We do not list advertising or analytics technologies that are not actually configured.

NameTypePurposeCategoryTypical duration
baseheart_session_v2HTTP-only cookieKeeps an authenticated BaseHeart account session active and binds requests to the signed-in account.NecessaryUp to 30 days, or until logout/invalidated session.
baseheart_walletHTTP-only cookieBinds server-authoritative personal or workspace billing state to the correct BaseHeart wallet. It is cleared on logout and is not an advertising identifier.NecessaryUp to 1 year, or until logout/replacement.
baseheart_google_oauth, baseheart_auth0_oauth and connector state cookiesHTTP-only cookiesShort-lived OAuth state/PKCE and anti-forgery data used only while completing a sign-in or an explicitly requested connector authorization.NecessaryUsually up to 10 minutes, then cleared or expired.
baseheart_privacy_consent_v1Local browser storageStores your versioned privacy choices, consent receipt identifier, timestamps and Global Privacy Control state. It does not store advertising identifiers.NecessaryUntil policy version changes, browser storage is cleared, or you replace the choice.
baseheart-new-languageLocal browser storageRemembers a language only after you explicitly choose it in the BaseHeart interface. Initial page setup does not create this preference.Functional / user-requested preferenceUntil changed or browser storage is cleared.
BaseHeart interface preferencesLocal browser storageRemembers non-sensitive interface choices such as view, preview device and similar workspace preferences. Production account/project data remains server-authoritative.FunctionalUntil changed or browser storage is cleared.
_ga, _ga_<container-id>First-party Google Analytics cookiesDistinguish users and retain session state for optional visit and product-usage measurement after Analytics consent. BaseHeart uses Google Analytics 4 measurement ID G-2970CSDCJ0 and does not load the Google tag before Analytics consent.AnalyticsGoogle's default is up to 2 years, subject to browser limits, earlier withdrawal, or browser clearing.
Current tracking status: Google Analytics 4 is configured with measurement ID G-2970CSDCJ0 for optional Analytics measurement. The Google tag is blocked until Analytics consent exists. Advertising storage, advertising user data and ad-personalization consent remain denied by the BaseHeart integration.

3. Consent categories

CategoryWhat it coversDefault
NecessarySecurity, authentication, anti-abuse controls, consent records and functions explicitly requested by you.Always active where technically required.
FunctionalOptional preference storage and convenience features that are not essential to the service.Off until allowed, except a preference you directly ask BaseHeart to remember.
AnalyticsOptional measurement of reliability, visits or product usage.Off until allowed.
MarketingOptional advertising, advertising measurement or targeted-marketing technology.Off until allowed and overridden by applicable opt-out signals.

4. Global Privacy Control

BaseHeart checks whether your browser exposes Global Privacy Control (GPC). When GPC is active, BaseHeart treats it as an opt-out of sale/sharing and targeted advertising and will not allow the marketing category to override that signal.

Checking Global Privacy Control…

5. Change or withdraw your choices

You can change optional consent at any time. Withdrawing consent is as easy as giving it and does not affect processing that was lawful before withdrawal.

Privacy Choices pageDo not sell or share
Consent status will appear here.

6. Changes to this Cookie Policy

When BaseHeart adds, removes or materially changes cookie or tracking technologies, we update this inventory and the effective date. A material change to optional consent purposes can cause the banner to appear again so a new choice can be made.

7. Contact

Questions about cookies or consent can be sent to kevin@baseheart.ai. For broader personal-data information, see the Privacy Policy.

Public BaseHeart cookie policy
LegalPrivacyPrivacy choicesTermsContact