LEGAL · PRIVACY NOTICE

Privacy at SpecDeck.

How we collect, use, and protect data when you and your team use SpecDeck to write specifications and assign work to AI agents.

Effective August 9, 2026

01 · SCOPEWho this notice covers

This notice describes how Sensible AB ("SpecDeck", "we", "us") handles information when you use SpecDeck.

It applies to individual users (you), and to teams who use SpecDeck under a workspace owned by an organization. Where your workspace is owned by an organization, that organization is the controller of your workspace data and its own policies may apply on top of ours.

For the contractual side of using SpecDeck (accounts, billing, acceptable use, and so on), see the Terms of Service.

02 · COLLECTWhat we collect

We try to collect the minimum we need to run the product. The categories below describe what we collect, with the main examples in each.

Account
Account information you provide when you sign up, such as email, a hashed password, and an optional display name.
Invitations
If a SpecDeck user invites you by email before you have an account, we store that email address and who invited you. We use this solely to deliver the invitation and to connect it to your account if you sign up.
Workspace content
The workspaces you create, the specs and comments you write, and the outputs that flow through them. This is your data, and we hold it on your behalf.
Operational logs
Server‑side logs of the requests made to our servers, such as the path and response status, error traces, and aggregate latency. We use these to debug, secure, and improve the product. We never sell them.
Device
Technical information about your device, such as IP address, browser, operating system, and a session cookie. We use this for security and to keep you signed in.
Billing
Billing information needed to charge your account, such as plan, seat count, and a billing contact. Card and bank numbers are handled directly by our payment processor, Mollie; we never store them.
Support
Information from your interactions with our support team, such as the messages you send us and any context you choose to attach (screenshots, workspace IDs, logs).

What we don't collect

  • We do not buy data about you from data brokers.
  • We do not track you across other websites with third‑party advertising pixels.
  • We do not read or scan your source code repositories. AI coding agents run on your machines, not ours.

03 · USEHow we use what we collect

  • Run the product. Authenticate you, render your workspace, save your edits, route agent runs.
  • Keep it working. Monitor uptime, diagnose errors, and ship fixes.
  • Keep it safe. Detect abuse, brute‑force attempts, and policy violations.
  • Improve it. Aggregate, de‑identified usage signals help us decide what to build next.
  • Tell you things. Product updates, security advisories, and (if you opted in) the occasional newsletter.
  • Bill you. Calculate seats and process invoices.

We do not use your workspace content for behavioural advertising, and we do not sell personal information.

If you're in the EU or UK, the lawful bases we rely on are contract (running, supporting, and billing for the product), legitimate interests (security, debugging, abuse prevention, and product improvement), and consent (marketing emails, which you can withdraw at any time).

04 · AISpecs, prompts & AI

SpecDeck is built around AI agents, so this section gets its own heading.

  • Inference provider. When you use an AI feature, the spec and any attached context are sent to our inference provider, OpenRouter, which routes the request to the model you chose for the run (OpenAI, Anthropic, or Google). We pass your data through; we keep no copy of the prompt. We record only the token counts and cost of each request, to enforce usage budgets.
  • Search embeddings. On organization plans, published spec content is also embedded to power workspace search. This happens automatically rather than per run, through the same inference provider and the same model providers, configured the same way: no training, no prompt retention.
  • No training on your content. We do not train models on your workspace content, and we configure our inference provider to disable model training and prompt retention.
  • Where AI output lives. What an AI feature produces lands in your workspace as ordinary content — proposed spec changes, goals, comments — visible to people with access to it and deletable like anything else. Conversations with the in‑app assistant stay in your browser; we don't store them on our servers.

We don't make decisions about you using solely automated processing. AI agents propose work; a human on your team reviews, approves, and ships it.

05 · SHARINGSharing & subprocessors

We share data only with the vendors we rely on to run the product. These are our subprocessors today:

Scaleway
Cloud hosting and transactional email. Hosts the service and the data you put in it, and sends account email (sign‑up, password reset, invitations). Based in France (EU).
OpenRouter
AI inference. When you use an AI feature, your prompt and the relevant spec content are routed to the model you chose (OpenAI, Anthropic, or Google); on organization plans, published spec content is also embedded for search through the same model providers. Configured to disable model training and prompt retention.
Mollie
Payment processing. Handles subscription charges and stores your payment mandate. Receives the payment details you enter at checkout and your billing contact details; we never see or store card or bank numbers. Based in the Netherlands (EU).
Bunny.net
DNS only. Resolves our domain names; it does not proxy your traffic, so no workspace content or personal data passes through it. Based in Slovenia (EU).

We don't use third‑party analytics, advertising, or error‑tracking services.

We also disclose when we receive a valid legal request or need to protect someone from imminent harm. If SpecDeck is acquired or restructured, your data moves with the product under this same notice or one at least as protective.

06 · RETENTIONHow long we keep things

  • Workspace content — for as long as your workspace is active. When you delete something, we remove it on request and during routine maintenance.
  • Account — until you ask us to delete it. Accounts inactive for more than 24 months may be removed.
  • Billing records — 7 years, as required by tax law.
  • Operational logs — kept for up to 30 days, then deleted.
  • Support tickets — 24 months from resolution.

Invitations expire after 7 days; we keep the invitation record afterwards, and you can ask us to remove it by emailing privacy@specdeck.ai.

You can ask us to delete your data at any time — see Your rights.

07 · SECURITYHow we protect it

  • Data is encrypted in transit (TLS 1.2+) and at rest.
  • Workspace data is logically isolated per customer.
  • Access to production requires hardware‑backed multi‑factor authentication over a private network.
  • We keep regular encrypted backups.
  • We aim to disclose security incidents that affect your data within 72 hours of confirming impact.

No system is perfectly secure. If you discover a vulnerability, please report it to security@specdeck.ai.

08 · RIGHTSYour rights

Depending on where you live, you may have the right to:

  • Access a copy of the personal information we hold about you.
  • Correct information that is inaccurate.
  • Delete your account and the personal information associated with it.
  • Port your workspace content to a machine‑readable export.
  • Object to processing, or restrict it, in certain circumstances.
  • Withdraw consent for any processing that relies on consent.

You can update your display name yourself in Settings. To exercise any of the other rights, email us at privacy@specdeck.ai and we'll respond within 30 days. We won't charge you for a reasonable request, and we won't punish you for making one.

If your workspace is owned by an organization, some of these rights are fulfilled by that organization rather than by us, and we'll forward your request where required.

If you're in the EU or UK, you can also lodge a complaint with your local data protection authority — our lead authority is Sweden's Integritetsskyddsmyndigheten (IMY).

09 · TRANSFERSInternational transfers

Sensible AB operates from Sweden, inside the EU/EEA. Workspace content and other personal data are stored and processed in the EU by default.

Where a subprocessor — for example, our inference provider — is located outside the EU/EEA, we rely on appropriate safeguards for that transfer, such as the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant).

10 · COOKIESCookies & analytics

We use a single first‑party, strictly necessary cookie to keep you signed in. We don't use analytics, advertising, or any other tracking cookies.

sw_session
Keeps you signed in. Strictly necessary. Expires in less than 24 hours.

UI preferences such as your theme are stored in your browser's local storage, not in a cookie. You can clear them from your browser.

11 · CHILDRENChildren

SpecDeck is built for professional software teams. It is not directed at anyone under 16 (or under the age of majority in your country, if that is higher), and we do not knowingly collect personal information from children. If you believe a child has signed up, contact us and we will delete the account.

12 · CHANGESChanges to this notice

We update this notice when the product changes, when the law changes, or when we adopt clearer language. For material changes we give at least 30 days' notice via email and in‑product before they take effect. Previous versions are kept on file and available on request.

13 · CONTACTTalk to a human

You can reach the privacy team directly. We read every message and respond within 5 business days for general questions, and within 30 days for formal rights requests.

Privacy team

Sensible AB · Prästkragevägen 27 · 746 37 Bålsta · Sweden

privacy@specdeck.ai