BastCare privacy
Named providers. Limited jobs.
Bast uses outside services only where they have a defined role in providing BastCare. This page names the current providers and the information involved.
Effective September 9, 2026Version 1.2
What this list means
A provider is not automatically given visit content.
Each provider receives only the information needed for its stated job. Ordinary open-source libraries that run inside the app or Bast services are not processors unless they send information to an outside company. Bast does not sell visit content or provide it for advertising.
BastCare chooses an AI model to suit the task. We evaluate quality, reliability, speed, and resource use, and may change the model or provider as those needs change. AI providers include Anthropic and OpenAI. A request uses the provider selected for that task; it does not automatically go to both.
Current providers
Who supports BastCare
The exact model version and individual software-library versions may change without changing these purposes or data boundaries.
Anthropic
Requested summary processing
Information: a temporary masked copy of transcript text and the resulting model response.
Purpose: create or regenerate the plain-language summary the user requested when an Anthropic model is selected. Bast does not save or log transcript text.
OpenAI
Requested summary processing
Information: a temporary masked copy of transcript text and the resulting model response.
Purpose: create or regenerate the plain-language summary the user requested when an OpenAI model is selected. Bast does not save or log transcript text.
Amazon Web Services
Bast infrastructure
Information: encrypted network traffic, account and operational metadata, and temporary request processing through Bast-hosted services.
Purpose: securely host and operate Bast authentication, summary, and CareTeam relay services.
MongoDB
Content-free evidence
Information: processing identifiers, timing, status, version, token-count, delivery, security, and deletion records.
Purpose: operational evidence, billing transparency, security, and deletion accountability. No audio, transcript, prompt, model-response, or summary words are intended for this ledger.
Apple
iPhone platform services
Information: information needed for device speech, Sign in with Apple, app distribution, and content-free notification delivery.
Purpose: provide core iPhone capabilities and account authentication.
Google
Optional account authentication
Information: the identity and sign-in information the user authorizes through Google.
Purpose: provide the optional Continue with Google account path. Google does not receive visit audio, transcript text, or summaries through this sign-in path.
DuploCloud
Deployment management
Information: infrastructure configuration, deployment status, and operational service information.
Purpose: manage Bast’s cloud deployment. Visit content is not intentionally placed in deployment logs or configuration.
The content boundary
Libraries and processors are different lists.
Open-source and commercial software libraries are tracked for security, licensing, and release management. They belong in Bast’s dependency inventory or acknowledgements. A library belongs on this processor page only when it sends information to an outside service.
Questions about this list can be sent to community@bast.ai. Material changes to providers, purposes, retention, or visit-data flows will update this disclosure and, where appropriate, the choice shown in BastCare.
Return to the BastCare Privacy Policy