Tentmate

Privacy

Four different things happen here — you can visit this site, you can leave an address on the waitlist, you can connect Tentmate to a Basecamp account, and you can install our browser extension. They involve different data and different responsibilities, so they are described separately.

Who is responsible

Tentmate , established in Spain, reachable at [email protected]. You can contact us about anything on this page, and you do not have to give a reason.

Visiting this site

We count page views so we know whether anyone is reading. It is deliberately minimal: no cookies are set and nothing is stored on your device, so there is no banner to dismiss. We record the page, where you arrived from, and a coarse idea of your browser. We ask our analytics provider not to keep your IP address.

The provider is PostHog, in the United States. The lawful basis is our legitimate interest in knowing whether the site works — not consent, because we are not storing anything on your machine to ask consent for.

You can object, and it takes effect immediately. Turn on “Do Not Track” or Global Privacy Control in your browser and nothing at all is recorded. You can also write to us.

The waitlist

When you use the form on the front page, we store:

  • Your email address, to send you an invite to the beta.
  • Whatever you type into "what type of business do you run on Basecamp?", which is optional, to decide who we invite next. Please leave other people's names out of it.
  • The wording you agreed to and when, so it is possible to check later what was actually consented to.
  • Your IP address, for that same purpose and no other.

The basis is your consent, given by ticking the box. Withdrawing it and asking to be erased are the same thing. We keep the list until Tentmate opens, plus twelve months, and then delete addresses that have not become accounts. You will hear from us about beta access and nothing else. Not a newsletter.

Using Tentmate with Basecamp

This is the part worth reading closely. When you connect an account, Tentmate creates a Basecamp person of its own and works as that person. It can read what that person can read — every project it has been added to, including comments, to-dos, cards, documents and chat.

In our own database we keep:

  • The names of people in your account, and whether Basecamp classes them as staff, clients or outside collaborators, so the bot knows who is allowed to set it working.
  • The title and link of each thread it was asked to work in, so its history is readable.
  • What each run cost, and any commands it ran.

The agent runs in a sandbox on our own runtime, hosted on Cloudflare. The content — the thread it was asked about and anything it read while working, such as a connected code repository — goes to the model provider your team selects for each agent: Anthropic, in the United States, for Claude models, or OpenRouter, a gateway that carries the request to the model's vendor, such as DeepSeek.

Tentmate also keeps memory in that same runtime so it does not start from nothing each time. There are three kinds: one about your company, one for each project, and one for each person it works with, which can include how that person prefers to be worked with. Any of them can be deleted on request.

How long: a working session is reused for up to 28 days and then started fresh. Sessions, their transcripts and the memories live in the runtime we host, and we delete them on request.

For this data you are the controller and we are the processor. It is your team's information; we handle it on your instructions and for no purpose of our own. We do not use it to train models, and Anthropic's commercial terms bar it too when a Claude model is selected. Other vendors handle content under their own terms — which vendor sees it is your team's model choice. A data processing agreement is available — write to us and we will send it.

The browser extension

Tentmate: AI agent for Basecamp, our Chrome extension, shows a session's status and transcript on the Basecamp page where it was started, shows what one of your bots can reach on its own profile card, and offers a one-click @-mention of the bot when you write a comment. It is optional, and Tentmate works the same without it.

On a Basecamp page it reads the session ids on Tentmate's own boosts and the card ids on a project board. It sends those ids to tentmate.ai, signed in as you, and shows you the answer. Once per session it also asks tentmate.ai which Basecamp people are your bots. In a comment box it reads the names of the people on that project from Basecamp's own @-picker, in the page, to decide which mention buttons to show; that list is not sent anywhere. When you open one of your bots' profile cards it sends that card's Basecamp person id to tentmate.ai and shows you how that bot is set up. Each of those requests also carries the extension's version number, which we note against your account so we know which versions are still in use. No message text and no thread content leave the page, and nothing is sent anywhere but tentmate.ai.

It stores nothing on your computer, sets no cookie of its own and carries no analytics. What it can show you is exactly what your Tentmate account is already allowed to see — signed out, it shows nothing.

Who else sees any of it

Here is everyone, and what each sees:

  • Cloudflare hosts the runtime and the sandbox the agents work in, including their sessions and memory, and keeps the encrypted nightly backups of our database.
  • The model vendor behind the model your team selects for each agent sees the content the agent works with — Anthropic, in the United States, for Claude models; DeepSeek for DeepSeek models.
  • OpenRouter, the gateway that carries the request when the selected model is served through it — DeepSeek's, for example.
  • PostHog, in the United States, which counts page views.
  • DigitalOcean hosts the server this site runs on, and with it the database of accounts, teams and agent runs.
  • Stripe takes payments and keeps your billing details. Card numbers go to Stripe directly and never reach us.
  • Resend, in the United States, delivers the emails we send you — account notices such as running out of credits, and the waitlist invite.

And Basecamp itself: the agent reads and writes your account through Basecamp's own API, as the guest person you invited.

Nobody else. There is no marketing email, no advertising, no data broker, and no error-tracking service. If that list ever changes, this page changes first.

Your rights

You can ask for a copy of what we hold, ask us to correct it, ask us to delete it, object to how we use it, or ask for it in a portable form. Write to [email protected] and we will answer within a month.

If the request concerns something in your company's Basecamp, we may need to pass it to whoever administers that account, because it is their data and we hold it for them.

You can also complain to a data protection authority in the country you live or work in.

Changes

When this page changes materially we will say so here and, if you are on the waitlist or hold an account, tell you before it takes effect.

Last updated 2026-08-11. Terms · Back

Get help

Tell us what is going on.

Name
Email
Message