Core and feature-dependent providers
This list is based on the providers currently integrated into BaseHeart's code and production architecture. A provider receives data only when the relevant BaseHeart function is used and only to the extent needed for that function.
VercelHosts the BaseHeart application. Customer-published project deployments use the project owner's separately connected Vercel account when that publishing feature is used.BaseHeart infrastructure and customer-connected hosting provider
ConvexProvides BaseHeart server-authoritative account/workspace storage where enabled. Production backends for customer-published projects use the project owner's separately connected Convex deployment.BaseHeart infrastructure and customer-connected backend provider
StripePayment processing for subscriptions, Hearts and eligible purchase flows. Payment-card data is handled by Stripe rather than stored directly by BaseHeart.Payment provider; may have independent legal obligations
OpenAIModel/API processing for BaseHeart Agent features when the OpenAI provider is selected. Relevant prompts, project context and requested task content may be processed.Model/API provider
Kimi / Moonshot providerAlternative model/API processing when that BaseHeart engine is configured and selected. Relevant task content may be processed for the requested Agent operation.Model/API provider when enabled
GoogleGoogle sign-in and optional Google Drive access after the user chooses to connect Google. Google API data is governed by the dedicated Google section of the Privacy Policy.Authentication and user-connected service
Google AnalyticsOptional website and product-usage measurement using Google Analytics 4 measurement ID G-2970CSDCJ0. The Google tag is not loaded until the user grants Analytics consent.Consent-based analytics provider
GitHubOptional repository connection, branch discovery and project push/sync actions initiated by the user.User-connected service
ResendEmail delivery for workspace invitations and other service messages when BaseHeart email delivery is configured and the relevant feature is used.Feature-dependent email delivery provider
Connected services are optional
Google, GitHub, Convex and similar connectors are not activated merely because you visit BaseHeart. They require an explicit connection flow and the permissions shown by the provider. You can disconnect supported connectors in BaseHeart and, where available, revoke them directly with the provider.
Model providers and project content
When you ask a BaseHeart Agent to build, analyze or modify a project, the minimum project context needed for the selected task can be sent to the selected model/API provider. BaseHeart's server-side cost, permission and project-access controls run before provider execution in production flows.
Do not put passwords, private API keys or unrelated sensitive personal information into prompts or project files unless the feature explicitly requires that information and you are authorized to use it.
Changes to providers
BaseHeart may add, replace or remove providers as the service changes. This page will be updated when a material provider change affects personal-data processing. Business customers that require contractual notice of subprocessor changes should use the contact below so the applicable DPA can define the notification process.