Spec AI Privacy Policy
Effective: September 18, 2026
Last updated: September 18, 2026
Document version: 2026-09-18-r03
This Privacy Policy explains how Spec AI, the California-based business operating spec-ai.co and app.spec-ai.co (Spec AI, we, us, or our), collects, uses, discloses, and retains personal information through those sites and related services (the Service).
1. Our roles
Spec AI acts in two different roles:
- Controller/business: We determine why and how we process website, account, security, billing, support, and business-contact information.
- Processor/service provider: A customer studio generally determines why project, client, collaborator, plan, specification, approval, and review data is processed. We process that Customer Personal Data on the studio's instructions under our Terms and Data Processing Addendum.
If your information was submitted by a studio, client, employer, designer, or other Spec AI customer, contact that organization first to exercise your rights. We will assist it as required by law and contract.
2. Information we collect
Information you provide
- Account and identity: Name, business email, profile image, company or studio, role, and Google account identifiers.
- Studio and project: Team members, client name, project name and address, deadlines, rooms, project brief, goals, constraints, and collaborators.
- Plans and documents: Optional PDFs, JPEGs, and PNGs; filenames and metadata; extracted text and page images; AI-proposed rooms, project type, addresses, drawing references, and other visible facts.
- Product and specification: Product URLs, selections, source documents, technical attributes, generated specifications and cut sheets, schedules, annotations, and approval decisions.
- Feedback and support: Product ratings, comments, concerns, support messages, optional support-ticket screenshots, and feature suggestions.
- Shared-review information: Reviewer name, email, comments, corrections, approvals, and timestamps when a person uses a review or approval link.
- Billing: If paid billing is enabled, billing contact, subscription, invoice, tax, transaction, and limited payment metadata. The disclosed payment processor receives full payment-card details; Spec AI is not intended to receive or store them.
Information collected automatically
- IP address, browser and device type, operating system, referring page, timestamps, request logs, authentication and session events, feature usage, error and security logs, and approximate location derived from IP.
- Strictly necessary cookies or similar storage used for authentication, security, preferences, and session continuity.
Information from other sources
- Google provides name, email, profile image, and authentication identifiers according to the permissions shown during sign-in.
- Customer administrators and collaborators may provide your business contact information to invite you.
- Manufacturers, distributors, marketplaces, and public websites provide product names, identifiers, attributes, availability evidence, technical data, images or links, and provenance information.
3. How we use information
We use personal information to:
- create and administer accounts, studios, permissions, and authentication;
- provide project workflows, search, recommendations, plan analysis, specifications, cut sheets, reviews, approvals, schedules, and exports;
- send transactional invitations, security messages, service notices, and billing communications;
- process subscriptions, prevent fraud, collect amounts due, and maintain tax and accounting records;
- operate, troubleshoot, secure, monitor, and improve the Service;
- respond to support, privacy, copyright, and legal requests;
- enforce contracts, prevent abuse, and comply with law; and
- create deidentified and aggregated metrics that do not reasonably identify a person, studio, client, or project.
Where applicable law requires a legal basis, we rely on performance of a contract, our legitimate interests in operating and securing a B2B service, compliance with legal obligations, and consent where required. A customer studio determines the legal basis for Customer Personal Data it submits.
4. Address lookup and artificial intelligence
Optional address suggestions
If you activate Google Maps address suggestions, Spec AI sends the address text you enter, an optional country filter and a short-lived session token to Google Places API (New). Selecting a suggestion sends its place identifier to Google to resolve the address. Google processes these requests under the Google Privacy Policy; use of the feature is subject to the Google Maps End User Additional Terms of Service.
Spec AI does not send plans, client names, your account identity or the separate unit/suite field with these requests. Manual entry does not use Google address lookup. We keep no raw suggestion history or provider-response cache. A selected address that you recognize as the project's address and its place identifier are retained with that project; the address may appear in its specifications, schedules and exports. Short-lived sessions and usage counters support security and shared request limits. Suggestions are not contributed to the shared product catalog.
AI features
The Service uses AI to extract structured product information, analyze optional plans, propose project facts, rank products, generate or validate specification content, and answer user-submitted support questions.
Depending on the feature, we may send product-page text, source documents, extracted plan text, plan page images, or questions and conversation text entered into the AI help feature to OpenAI or another disclosed AI subprocessor. Support-ticket screenshots are available to authorized support personnel but are not automatically sent to the AI help feature. AI output may be stored with project, catalog, or support records and may be reviewed and corrected by Authorized Users. Designer-entered information controls over conflicting AI suggestions.
When Google Document AI OCR is enabled for a studio, starting plan analysis sends the uploaded PDF or image file to the configured US-region Google Document AI processor, with instructions to process the selected pages. The original uploaded file, not a separately redacted document, is transmitted. Selected page images and extracted text are then sent to OpenAI for interpretation. Uploading a plan for storage alone does not start these analysis requests; plans and analysis remain optional, and manual project entry is available.
Plan recognition results, source locations, warnings and bounded analysis diagnostics are retained privately with the project. Detailed diagnostics are retained for up to the ten latest completed attempts per document; older attempt identities and outcome summaries may remain. Deleting the plan removes its active analysis records, subject to the recovery-copy and legal-retention provisions below. An unresolved reading is not verified geometry, and designer review is required before applying suggestions or using measurements for estimates.
Spec AI does not use Customer Content to train general-purpose AI models unless the customer separately opts in. Our API providers process content under applicable business or API terms. Providers may retain limited content for abuse monitoring or legal compliance according to their then-current policies. We do not claim Zero Data Retention unless it is enabled for the relevant account, model, and endpoint.
5. Product intelligence and shared signals
Product information may be obtained from public or licensed sources and normalized into a shared catalog. A source URL, observation date, and confidence or verification status may be stored to support provenance and freshness.
Automated catalog operations may also store content hashes, bounded structured evidence, remote asset links, extraction and taxonomy versions, crawl status, retries, incidents, validation results, publication history, and administrator audit records. Administrator names or business emails may appear in restricted operational records and transactional crawler notifications. Public-source catalog and operational records generally persist independently of a particular studio account; studio offboarding removes the studio's Customer Personal Data and associations but does not require deletion of independent shared product facts or security and audit records, subject to applicable law.
Raw product feedback, comments, concerns, and author identity submitted inside a studio remain visible only to that studio unless the studio expressly opts in to network-level contribution. If it opts in, we use only deidentified, thresholded aggregates for cross-studio ranking and trends. We do not disclose another studio's raw comments, project context, author, client, or identity.
6. How we disclose information
We may disclose information to:
- Customer organizations: Studio administrators and Authorized Users according to roles and project access.
- People you invite: Review and approval recipients receive the project and product information selected for the shared link.
- Subprocessors: Hosting, database, restricted recovery-copy storage, AI, authentication, email, web-retrieval, payment, security, and support providers listed on our Subprocessor page. They process information under contractual restrictions.
- Professional advisers: Lawyers, auditors, insurers, and consultants subject to confidentiality duties.
- Authorities and protection: When reasonably necessary to comply with law, respond to valid process, protect rights and safety, investigate abuse, or secure the Service.
- Corporate transactions: A buyer, investor, lender, or adviser in a financing, merger, acquisition, reorganization, or sale, subject to appropriate confidentiality and notice where required.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising and do not use Customer Content for advertising. If that practice changes, we will update this Policy and provide legally required choices before the change.
7. Cookies and analytics
The app uses cookies and similar technologies necessary to authenticate users, protect sessions, remember settings, and operate requested features. No consent banner is needed for strictly necessary technologies in many jurisdictions. If we add non-essential analytics or advertising technologies, we will update this notice and provide consent or opt-out controls where required.
We currently do not respond to browser Do Not Track signals because no common standard requires a particular response. We will honor legally required opt-out preference signals, including Global Privacy Control, if we engage in a processing activity to which the signal applies.
8. Retention
We retain information only as long as reasonably necessary for the purposes described, including to provide and secure the Service, maintain source provenance and catalog quality, follow lawful customer instructions, resolve disputes, enforce agreements, and meet legal, tax, accounting, fraud-prevention, and recordkeeping obligations. Retention depends on the type of information, the status of the account, project, source, or crawl, operational need, legal requirements, and whether a dispute, investigation, rights claim, or preservation duty applies.
Customers should retain source files and exports needed for their own records. The Service is not an archival or backup service, and we do not promise that deleted or lost information can be restored. In addition to provider-managed recovery or security copies, Spec AI may hold encrypted, access-restricted recovery snapshots of application data and private files with Google Cloud. A snapshot can contain information later deleted from active systems. Recovery copies are not used for ordinary product purposes and remain subject to configured retention, lifecycle, and provider soft-delete controls, applicable legal holds, and legal requirements. Before restored information enters ordinary service, applicable deletion and access-revocation requests made after the recovery point must be reconciled. We do not promise a fixed recovery-copy deletion or restoration period unless law or a signed agreement requires one. Deidentified information may be retained while it remains deidentified.
9. Security
We use administrative, technical, and organizational safeguards designed for the nature of the information, including access controls, private object storage, encryption in transit, provider security controls, logging, and role-based permissions. No method of storage or transmission is completely secure. Customers should use appropriate access roles, protect Google accounts with multifactor authentication, and avoid uploading prohibited sensitive information.
10. International transfers
Spec AI and its providers are based in the United States and may process information in other countries. Where applicable law requires a transfer mechanism, the parties may use an available lawful mechanism, such as an adequacy decision, the European Commission's Standard Contractual Clauses, or the UK Addendum. Customers that require a DPA or transfer mechanism should complete it before submitting covered personal data.
The standard Service is currently offered from the United States. A customer that requires EEA, UK, or Swiss restricted-transfer terms must arrange an applicable written transfer addendum before submitting covered personal data.
11. Your choices and rights
Depending on your location, you may have rights to know or access personal information, correct it, delete it, obtain a portable copy, restrict or object to processing, withdraw consent, or appeal a decision. You may also have the right to complain to a data-protection authority.
Account holders may update certain information in the Service. To submit a request, email privacy@spec-ai.co. We may verify identity and authority before acting. If a studio controls the information, we will direct the request to the studio or assist it. Authorized agents must provide proof of authority. We will not discriminate for exercising privacy rights.
California residents may request the categories and specific pieces of personal information collected, sources, purposes, categories of recipients, correction, and deletion, subject to exceptions. Spec AI does not sell or share personal information as those terms are used for cross-context behavioral advertising. These disclosures do not concede that Spec AI currently meets the statutory thresholds for application of the CCPA.
12. Children
The Service is for business and professional users at least 18 years old. It is not directed to children, and we do not knowingly collect personal information from children. Do not upload information about minors unless it is necessary for a legitimate professional project, the customer has legal authority, and Spec AI has expressly permitted that category of data.
13. Third-party sites
The Service links to manufacturers, marketplaces, and other websites we do not control. Their terms and privacy notices govern their services. A link or product listing does not mean Spec AI endorses their practices.
14. Changes to this Policy
We may update this Policy to reflect product, legal, or operational changes. We will post the updated version and change the date above. We will provide notice or obtain consent when required by applicable law.
15. Contact
Privacy requests: privacy@spec-ai.co
Security reports: security@spec-ai.co
Spec AI does not currently designate an EEA/UK representative or data-protection officer. Contact privacy@spec-ai.co before submitting personal data that requires such arrangements.