01 · SCOPEWho this notice covers
This notice describes how Sensible AB ("SpecDeck", "we", "us") handles information when you use SpecDeck.
It applies to individual users (you), and to teams who use SpecDeck under a workspace owned by an organization. Where your workspace is owned by an organization, that organization is the controller of your workspace data and its own policies may apply on top of ours.
For the contractual side of using SpecDeck (accounts, billing, acceptable use, and so on), see the Terms of Service.
02 · COLLECTWhat we collect
We try to collect the minimum we need to run the product. The categories below describe what we collect, with the main examples in each.
What we don't collect
- We do not buy data about you from data brokers.
- We do not track you across other websites with third‑party advertising pixels.
- We do not read or scan your source code repositories. AI coding agents run on your machines, not ours.
03 · USEHow we use what we collect
- Run the product. Authenticate you, render your workspace, save your edits, route agent runs.
- Keep it working. Monitor uptime, diagnose errors, and ship fixes.
- Keep it safe. Detect abuse, brute‑force attempts, and policy violations.
- Improve it. Aggregate, de‑identified usage signals help us decide what to build next.
- Tell you things. Product updates, security advisories, and (if you opted in) the occasional newsletter.
- Bill you. Calculate seats and process invoices.
We do not use your workspace content for behavioural advertising, and we do not sell personal information.
If you're in the EU or UK, the lawful bases we rely on are contract (running, supporting, and billing for the product), legitimate interests (security, debugging, abuse prevention, and product improvement), and consent (marketing emails, which you can withdraw at any time).
04 · AISpecs, prompts & AI
SpecDeck is built around AI agents, so this section gets its own heading.
- Inference provider. When you use an AI feature, the spec and any attached context are sent to our inference provider, OpenRouter, which routes the request to the model you chose for the run (OpenAI, Anthropic, or Google). We pass your data through; we keep no copy of the prompt. We record only the token counts and cost of each request, to enforce usage budgets.
- Search embeddings. On organization plans, published spec content is also embedded to power workspace search. This happens automatically rather than per run, through the same inference provider and the same model providers, configured the same way: no training, no prompt retention.
- No training on your content. We do not train models on your workspace content, and we configure our inference provider to disable model training and prompt retention.
- Where AI output lives. What an AI feature produces lands in your workspace as ordinary content — proposed spec changes, goals, comments — visible to people with access to it and deletable like anything else. Conversations with the in‑app assistant stay in your browser; we don't store them on our servers.
We don't make decisions about you using solely automated processing. AI agents propose work; a human on your team reviews, approves, and ships it.
05 · SHARINGSharing & subprocessors
We share data only with the vendors we rely on to run the product. These are our subprocessors today:
We don't use third‑party analytics, advertising, or error‑tracking services.
We also disclose when we receive a valid legal request or need to protect someone from imminent harm. If SpecDeck is acquired or restructured, your data moves with the product under this same notice or one at least as protective.
06 · RETENTIONHow long we keep things
- Workspace content — for as long as your workspace is active. When you delete something, we remove it on request and during routine maintenance.
- Account — until you ask us to delete it. Accounts inactive for more than 24 months may be removed.
- Billing records — 7 years, as required by tax law.
- Operational logs — kept for up to 30 days, then deleted.
- Support tickets — 24 months from resolution.
Invitations expire after 7 days; we keep the invitation record afterwards, and you can ask us to remove it by emailing privacy@specdeck.ai.
You can ask us to delete your data at any time — see Your rights.
07 · SECURITYHow we protect it
- Data is encrypted in transit (TLS 1.2+) and at rest.
- Workspace data is logically isolated per customer.
- Access to production requires hardware‑backed multi‑factor authentication over a private network.
- We keep regular encrypted backups.
- We aim to disclose security incidents that affect your data within 72 hours of confirming impact.
No system is perfectly secure. If you discover a vulnerability, please report it to security@specdeck.ai.
08 · RIGHTSYour rights
Depending on where you live, you may have the right to:
- Access a copy of the personal information we hold about you.
- Correct information that is inaccurate.
- Delete your account and the personal information associated with it.
- Port your workspace content to a machine‑readable export.
- Object to processing, or restrict it, in certain circumstances.
- Withdraw consent for any processing that relies on consent.
You can update your display name yourself in Settings. To exercise any of the other rights, email us at privacy@specdeck.ai and we'll respond within 30 days. We won't charge you for a reasonable request, and we won't punish you for making one.
If your workspace is owned by an organization, some of these rights are fulfilled by that organization rather than by us, and we'll forward your request where required.
If you're in the EU or UK, you can also lodge a complaint with your local data protection authority — our lead authority is Sweden's Integritetsskyddsmyndigheten (IMY).
09 · TRANSFERSInternational transfers
Sensible AB operates from Sweden, inside the EU/EEA. Workspace content and other personal data are stored and processed in the EU by default.
Where a subprocessor — for example, our inference provider — is located outside the EU/EEA, we rely on appropriate safeguards for that transfer, such as the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant).
10 · COOKIESCookies & analytics
We use a single first‑party, strictly necessary cookie to keep you signed in. We don't use analytics, advertising, or any other tracking cookies.
UI preferences such as your theme are stored in your browser's local storage, not in a cookie. You can clear them from your browser.
11 · CHILDRENChildren
SpecDeck is built for professional software teams. It is not directed at anyone under 16 (or under the age of majority in your country, if that is higher), and we do not knowingly collect personal information from children. If you believe a child has signed up, contact us and we will delete the account.
12 · CHANGESChanges to this notice
We update this notice when the product changes, when the law changes, or when we adopt clearer language. For material changes we give at least 30 days' notice via email and in‑product before they take effect. Previous versions are kept on file and available on request.
13 · CONTACTTalk to a human
You can reach the privacy team directly. We read every message and respond within 5 business days for general questions, and within 30 days for formal rights requests.