Privacy Policy

Last updated: July 17, 2026

The short version

EscapeBase44 migrates your Base44 app onto infrastructure you own. The whole point of the product is that your app, code, data and users end up in your hands — not ours. We collect the minimum needed to run the migration, and your app's runtime data never flows through us afterwards.

What we collect

  • Your Base44 account basics — email, name, and the app you pick — when you log in with Base44 to start a migration.
  • Your app's export — we read your app through Base44's API to analyze it and to migrate it. It lands on infrastructure you own; we keep the analysis (feature counts, sizes) to price and run the migration. You can revoke our access at any time.
  • Provider credentials you paste — stored encrypted (Supabase Vault), used only to set up your accounts, reusable by you on your next migration.
  • Usage and advertising measurement through PostHog, Google Ads, and Meta, plus payment records through PayPal — we never see card numbers. Meta receives browser activity and hashed contact details for conversion matching; it does not receive your app's code or data.

Google user data

Migrated apps can use Google sign-in and Google integrations (Sheets, Calendar, and similar) through EscapeBase44's Google application. Here is exactly what that means:

  • When someone connects a Google account, Google sends the authorization response through auth.eb44.app, which immediately relays it to the app's own server. EscapeBase44 does not receive, store, or use Google access tokens or any Google user data. Tokens are issued to, stored on, and used by the migrated app's own infrastructure — which belongs to the app's owner, not to us.
  • Google user data accessed by a migrated app (spreadsheets, calendar events, email sending) is processed entirely on that app's own servers, for that app's own features. We have no access to it.
  • EscapeBase44's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We never sell Google user data, never use it for advertising, and never let humans read it.
  • App owners can switch to their own Google client at any time from the post-migration page, removing EscapeBase44's application from the loop entirely. Users can revoke access at myaccount.google.com/permissions.

Sharing of Google user data

We do not share, transfer, or disclose Google user data to anyone. Not to third parties, not to service providers, not to advertisers — no one. The authorization response that passes through auth.eb44.app is relayed only to the one destination the user just authorized: the migrated app's own server, owned by the app's owner. That relay is the entire data flow. The only exception would be a valid legal requirement (a court order), which has never happened.

How Google user data is protected

  • All data in transit — including every OAuth authorization response relayed through auth.eb44.app — is encrypted with TLS (HTTPS), end to end.
  • The relay is stateless: authorization responses are forwarded in-memory and are never written to disk, logged, or stored. Google access and refresh tokens exist only on the migrated app's own infrastructure, never on ours.
  • The relay forwards only to destinations we can verify belong to a migrated app (its assigned eb44.app subdomain or its registered custom domain) — it cannot be used to send an authorization response anywhere else.
  • The few credentials we do store for the migration itself (your provider tokens — never Google user data) are encrypted at rest in a dedicated secrets vault with strict access controls.

Retention and deletion of Google user data

  • EscapeBase44 retains no Google user data. Retention period: zero. The relay holds an authorization response for the milliseconds it takes to forward it, then it's gone. There is nothing for us to delete because nothing is kept.
  • Google user data a migrated app accesses (spreadsheets, calendar events, sent email) lives on that app's own infrastructure, under its owner's control and its own privacy policy. To have it deleted, contact the app's owner — they own the servers.
  • Anyone can cut off access instantly by revoking the eb44.app application at myaccount.google.com/permissions. Revocation invalidates the tokens the app holds; no residual data remains with us afterwards because none was ever with us.
  • We do not use Google user data — or any data obtained through Google Workspace APIs — to develop, improve, or train generalized artificial intelligence or machine-learning models.

What we never do

We don't sell data. We don't give advertisers your app's code or data. We don't read your app's database or your users' content — after migration it lives on your infrastructure, behind your credentials.

Deletion & questions

Want your account data, stored credentials, or analysis deleted — or have any question about this policy? Email daniel.frishtik@gmail.com and it's handled.