Legal
Privacy Policy
Effective 11 October 2026
Information we collect
Baton stores the account details you provide, such as your name, email address, and profile image; workspace and project content you create; and limited operational, security, and acquisition metadata needed to run and protect the service.
Google sign-in and account data
Google sign-in is optional. With your consent, Baton requests only openid, email and profile: your Google account identifier, email and its verification status, name and profile picture. We use this information to authenticate you, recognize your existing account, display your profile and apply your workspace permissions. Baton never receives your Google password and does not request Gmail, Google Drive, contacts or calendar access through sign-in.
Account identifiers and profile details are stored in our Convex backend. The authentication service also stores the session and OAuth token information needed to complete and maintain sign-in. Password credentials are hashed. Better Auth handles the new sign-in flow; existing Convex Auth records are retained during migration to preserve account access.
How we use information
We use information to provide project collaboration, authenticate users, enforce access controls, send transactional messages such as invitations and password reset codes, prevent abuse, diagnose failures, and improve reliability.
Sharing and service providers
Baton uses Cloudflare to serve the web application, Convex to store and process backend and authentication data, Google and GitHub for optional sign-in, and Resend for configured transactional email. These providers process the information necessary for their role, including request metadata used for delivery and security. Your profile and content may be visible to people who have access to the relevant workspace or shared content, according to its permissions. Optional provider or AI integrations process the content you choose to send through them under the access you grant; signing in with Google does not itself authorize those integrations.
We do not sell Google sign-in data or use it for advertising. We may disclose information when necessary to comply with law or protect users and the service. Our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Storage and retention
Account, Google profile and project data is retained while your account or workspace is active and as reasonably needed for security, recovery, dispute resolution or legal obligations. Authentication records expire according to their configured session and token lifetimes. Backups may retain earlier copies for recovery until their retention period ends. Session cookies support sign-in; theme and install preferences may be stored locally in your browser.
Security
We use access controls, encrypted transport, server-side secrets, and hashed credentials where applicable. No online service can guarantee absolute security; please use a unique password and protect access to your email and Google account.
Your choices and deletion
You can update profile and project information, sign out, disconnect optional integrations or use the account deletion controls in Baton. You can also request access, correction, export or deletion, including Google account data, at rahmanef63@gmail.com. Workspace ownership and shared content may require transfer or review before deletion; we will explain any information that must be retained for security or legal reasons.
You can revoke Baton's Google access in your Google Account connections. Revoking Google access stops future access through that grant; it does not by itself delete previously stored Baton account or project data. Contact us or use account deletion to request that removal.
Children
Baton is not directed to children under 13, and we do not knowingly collect their personal information.
Changes
We may update this policy as Baton changes. The effective date above will be revised when material changes are published.
Contact
Privacy questions and data requests can be sent to rahmanef63@gmail.com.