Advance Basis Privacy Policy
Effective July 14, 2026
This Privacy Policy explains how Greater Expanse LLC ("we," "us," and "our") collects, uses, discloses, retains, and deletes personal information when you use the Advance Basis website, autonomous research service, reports, exports, sharing features, and related services. Greater Expanse LLC is a California limited liability company and operates Advance Basis. Advance Basis is the product name of the service, not a separate legal entity.
1. Information We Collect
Account and identity information
When you sign in with Google or GitHub, we receive the provider identity, verified email when available, display name, and related authentication claims. We store account profile information, linked identity records, invitation and access-request records, sessions, agreement acceptance, and account status.
Research Content and Reports
We collect prompts, questions, intake answers, research plans, uploaded files, notes, source suggestions, and other material you submit. To perform the work, we create and retain research queries, source URLs and payloads, evidence passages, compressed source notes, claims, verification results, workflow events, Reports, and exports.
Billing and transaction information
Stripe collects payment-card information. We receive and store transaction identifiers, amount, currency, status, refund and dispute events, and an append-only Credit ledger. We do not receive or store the complete card number.
Technical, security, and usage information
We collect session identifiers, IP addresses, user agents, request and correlation identifiers, timestamps, authentication events, provider-call usage, run duration and status, error records, and other logs needed for security, fraud prevention, billing, debugging, and reliability.
2. How We Use Information
We use personal information to:
- authenticate accounts and control access;
- prepare research plans, acquire and analyze sources, verify claims, generate Reports, and create exports;
- preserve report provenance and make private or customer-directed public sharing work;
- operate Credits, purchases, reserves, refunds, and disputes;
- send transactional invitations, account notices, and report notices;
- secure, maintain, troubleshoot, and improve the reliability of the Service;
- prevent abuse and enforce the Terms of Service; and
- comply with law and establish, exercise, or defend legal claims.
We do not sell personal information, use Research Content for targeted advertising, or build advertising profiles. We do not train our own models on customer Research Content or opt Research Content into optional provider model-training programs.
3. Cookies and Browser Storage
The Service uses a secure, HTTP-only session cookie for authentication. Temporary cookies preserve state during Google and GitHub sign-in. Theme choice is stored in browser local storage or a first-party cookie. Request-forgery tokens are derived from the authenticated session rather than stored in a separate tracking cookie.
There are no advertising cookies, cross-site analytics cookies, tracking pixels, or browser-fingerprinting scripts. Google Fonts is currently loaded from Google, so the browser sends a network request and connecting IP address to Google when loading those typefaces.
4. Research Processing
We send the portions of Research Content and workflow context reasonably needed for a task to providers that perform search, retrieval, content extraction, AI inference, and independent claim verification. Public source websites receive network requests from the Service's infrastructure when the Service retrieves them.
Provider processing is governed by the applicable business or API terms. A provider may retain limited query, usage, safety, or technical data for service operation, abuse prevention, security, or service improvement. Do not place unnecessary personal or highly sensitive information in research queries or uploads.
We do not publicly disclose the internal provider and model assignment matrix. A current subprocessor list can be supplied when required by law or a written agreement.
5. How We Disclose Information
We disclose information only as described below:
- Service providers. Fly.io, Neon, Cloudflare, Amazon Web Services, Stripe, Google, GitHub, and contracted research-processing providers process the information needed to provide their services.
- Authorized support and operations. Limited personnel or contractors may access information when reasonably necessary for customer support, billing, security, reliability, legal compliance, or debugging. They do not approve, review, or unblock customer research as a product step.
- At your direction. A fixed Report version becomes available to anyone with its bearer link when you choose public sharing. Reports are private by default.
- Legal and safety purposes. We may disclose information to comply with law or valid legal process, protect rights and safety, investigate fraud or security incidents, enforce our Terms, or establish or defend legal claims.
- Business transfers. Information may be transferred in connection with a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and notice where required.
We do not sell personal information or share it for cross-context behavioral advertising.
6. Public Share Links
A public Report link is a bearer link. Anyone who receives it can view the fixed Report version until you revoke or rotate the link. Do not share a Report that contains confidential, personal, or restricted information you are not authorized to disclose.
Revocation prevents future access through the prior link. It cannot delete copies another person already downloaded, copied, quoted, indexed, or redistributed.
7. Retention and Deletion
We retain information only for as long as reasonably necessary to provide the Service, maintain security and reliability, resolve disputes, enforce agreements, and satisfy legal, tax, accounting, and audit obligations.
Delete Report
The authenticated Delete Report control permanently removes the Report and its owned research record, including associated request material, retained source payloads, evidence, compressed notes, claims, verification results, workflow events, exports, and public links. A source record is retained if another research run still references it. Financial ledger entries are retained, but their direct run reference is removed.
Account closure
You can close an eligible account from Account settings. Closure is blocked while research is active, a Credit reserve is held, a payment balance is negative, or unused Purchased Credits remain. Those items must be resolved first. Billing support refunds remaining unused Purchased Credits before closure, including after the ordinary refund-request window.
Closure deletes user-owned Research Content, Reports, ordinary profile data, linked sign-in identities, sessions, invitations, access requests, and public access grants. Transactional email content is deleted or redacted. Remaining Promotional Credits are forfeited. The live account record is disabled and its email, display name, and sign-in subject are replaced with nonidentifying values.
We retain payment-provider identifiers and related payment, Credit-ledger, refund, dispute, agreement, security, fraud-prevention, and legal records only as reasonably necessary for those purposes. These retained records remain associated with the disabled internal account identifier and may contain information required to process or document a transaction, dispute, security event, or legal obligation. Backup copies can persist for a limited period until ordinary rotation, but are not restored to the live Service except for disaster recovery.
For deletion help or a request that cannot be completed in the product, contact privacy@advancebasis.com from the email associated with the account. We may verify identity before acting. Some information may be retained where an exception or legal obligation applies.
8. Security
We use administrative, technical, and organizational safeguards appropriate to the nature of the Service, including authenticated access, private object storage, encrypted network transport, provider access controls, and restricted operational access. No system or transmission method is completely secure.
Report security concerns to security@advancebasis.com.
9. Data Location
The Service primarily operates from infrastructure configured in the United States. Infrastructure, identity, payment, research, email, and public-source providers may process information in other locations under their applicable terms. We do not currently promise a particular data-residency region.
10. Your Choices and Rights
You can review and update profile information, download Reports and report packages, revoke public links, delete Reports, and close an eligible account through the Service. You may also ask to access, correct, or delete personal information by contacting privacy@advancebasis.com.
Depending on where you live, law may provide additional rights, including the right to know, correct, delete, or receive a portable copy of personal information, and to appeal a denied request. We do not discriminate against a person for exercising a privacy right. We may need to verify identity and may decline or limit a request where law permits.
Because we do not sell personal information or share it for cross-context behavioral advertising, there is no sale or targeted-advertising opt-out to apply.
11. Children
The Service is intended for adults and is not directed to children under 18. We do not knowingly collect personal information from a child through an Advance Basis account. Contact us if you believe a child has provided information.
12. Changes and Contact
We may update this Policy prospectively as the Service or legal requirements change. We will post the current version and effective date and provide reasonable notice of material changes.
For privacy and deletion requests, contact privacy@advancebasis.com. For account or service support, contact support@advancebasis.com. For security concerns, contact security@advancebasis.com. Formal legal notices may be sent to legal@advancebasis.com or to Greater Expanse LLC, 2108 N ST STE N, Sacramento, CA 95816, USA.