Legal

Privacy

What we store

Baaito stores the account identity you sign in with, the organisation you belong to, your role, and the documents, projects and sources your organisation creates in the workspace. Generated documents, their inputs, runs and versions stay inside the organisation that produced them.

Organisation isolation

Every workspace record carries an owning organisation. Access rules are enforced in the database, so a request signed with one organisation's session cannot read or write another organisation's documents, projects, prompts or integration settings.

Access and audit

Sign-in, invitation, role change, administration and integration configuration events are recorded in an audit trail visible to organisation administrators and auditors.

Model providers and keys

Provider credentials supplied by your organisation are stored server-side and are never returned to the browser. Documents are sent to the model provider your organisation's routing policy selects.

Deletion

An organisation owner can request deletion of organisation content. Removing a member immediately ends their access to organisation content.