← Back to home

Privacy policy

Last updated: August 24, 2026

The French version of this policy is the legally binding version. In case of discrepancy between the French version and this translation, the French version prevails.

1. Who we are

Basecamp Labs SAS (SIREN 101 988 111, registered office 18 rue du Bayle, 34000 Montpellier, France) publishes Vacarme and is the controller for the data processing described below, within the meaning of the General Data Protection Regulation (GDPR). For any question regarding your personal data: [email protected].

2. What Vacarme stores locally, on your machine

Vacarme is a desktop application. Most data related to your use of it stays local, on your computer, and is never transmitted to our servers:

  • Credentials for your third-party accounts (social networks, Gmail/Notion/Slack integrations): encrypted (AES-256) and stored only in the application's local database. The content of executed tasks, messages sent, pages visited, and your conversation history with the agent are likewise stored locally.
  • What this means in practice: we have no access to your third-party account credentials, nor to the detailed content the agent publishes or the messages it sends on your behalf. If you uninstall the application without deleting your account first, this local data remains on your machine, under your sole responsibility.

3. What we process on our servers

Our server infrastructure only stores what is necessary to manage your account, your subscription, and usage measurement:

  • Account: email, display name, password (managed by our authentication provider, Appwrite).
  • Subscription and billing: subscribed plan, subscription and customer identifiers with our payment provider (Stripe) — we never store your bank details, which are handled directly by Stripe.
  • Usage: volume of credits/tokens consumed per day and per feature, for billing purposes and to display your usage — without the detailed content of the underlying tasks.
  • Audience measurement for vacarme.ai: Google Analytics, only with your prior consent (cookie banner) — pages visited and conversion actions (download, sign-up, checkout started). Only applies to the website, never the desktop app, whose usage is only measured if you explicitly enable it in its privacy settings.

4. AI models

Calls to artificial intelligence models pass through our server-side gateway, which routes them to language model providers (via OpenRouter, which in turn routes to providers such as Anthropic, Google, or Perplexity depending on the task). Content sent to these models may include text you type, the content of web pages browsed by the agent, and, for certain tasks, screenshots of your browsing session. Our gateway does not retain this content after routing it — it only logs usage metadata (token counts, model used, cost, status).

These providers act as processors for the one-off handling of this data, under contracts that provide appropriate safeguards, including for transfers outside the European Union (European Commission standard contractual clauses or an equivalent mechanism, depending on the provider).

5. Data of the people you contact through Vacarme

When you configure the agent to engage with, comment to, or message third parties (outreach, social media engagement), the agent processes personal data of those people (name, public profile, message content) to carry out the task you defined. This processing takes place mainly locally, on your machine; the corresponding content may occasionally pass through our AI gateway under the conditions described in section 4, without being retained there.

For this type of processing, you act as the data controller within the meaning of the GDPR (see our Terms of service, section 7); Basecamp Labs acts as a technical processor. Given the volume and automated nature of these actions, individually informing each contacted person, as provided for in Article 14 of the GDPR, may represent a disproportionate effort within the meaning of Article 14(5)(b) of the GDPR; we nonetheless encourage you to remain transparent with your contacts and to respect their rights (in particular their right to object) as part of your own activity.

6. Legal bases for processing

  • Contract performance: managing your account and subscription, providing the Service.
  • Legitimate interest: Service security, fraud prevention, product improvement based on aggregated usage statistics.
  • Consent: optional sharing of anonymized learning data (see section 7), when you explicitly enable it.
  • Legal obligation: retention of certain accounting and billing data for the period required by law.

7. Sharing learning data (optional)

You may optionally enable, and revoke at any time, the sharing of anonymized data about how the agent performs (action type, platform, success or failure) to help us improve the automations offered to all users. This sharing is identified by a technical identifier specific to your installation, never linked to your identity, email, or task content. You can request deletion of this data at any time from the application's privacy settings.

8. Retention period

  • Account data: for the duration of your account, then deleted or anonymized when it is closed (see section 10).
  • Billing data: retained in accordance with legal accounting-retention obligations (up to 10 years in France), anonymized once the account is deleted.
  • Local data (credentials, task content): under your control, for as long as you keep the application installed.

9. Your rights

Under the GDPR, you have the right to access, rectify, erase, restrict, object to, and port the data we process about you, as well as the right to lodge a complaint with the French data protection authority (CNIL) or your local supervisory authority. To exercise these rights, contact [email protected].

10. Deleting your account

You can request full deletion of your account from your billing settings. This deletion, after email confirmation:

  • cancels your active subscription;
  • deletes your account and profile;
  • anonymizes (rather than deletes) your billing and usage history — amounts and dates are retained for accounting purposes, as required by law, but are no longer linked to your identity once the account is deleted;
  • does not delete data stored locally on your machine, which you control directly.

You can also write to us at [email protected] for any deletion request not covered by the self-service form. We respond to any erasure request within one month at most, in accordance with the GDPR.

11. Security

Credentials for your third-party accounts are encrypted locally (AES-256). Communications with our servers are encrypted (TLS). Access to our administration infrastructure is restricted and logged. No system being infallible, we encourage you to use strong, unique passwords for each service.

12. Changes to this policy

We may update this privacy policy to reflect changes to the Service or to applicable regulations. Any material change will be notified to you in the application or by email.

13. Contact

For any question regarding this policy or your personal data: [email protected]

This site uses Google Analytics to measure audience and understand how it's used. No measurement cookie is set without your consent. Learn more