SpeSense

Privacy Policy

Last updated: July 6, 2026

This Privacy Policy describes how SpeSense ("SpeSense", "we", "us") collects, uses, and protects information when you use our spec-quality analysis platform (the "Service").

1. Information we collect

Account information. When you sign up, we collect your name, email address, and organization name. If you sign in with Google or an SSO/SAML provider, we receive the profile information your identity provider shares with us (typically name and email).

Workspace content. Specifications, findings, comments, and related content that you or your team upload or create while using the Service.

Billing information. If you subscribe to a paid plan, our payment processor (Stripe) collects your payment details directly. We never see or store your full card number.

Usage data. Basic technical logs (timestamps, actions taken, error reports) used to operate and secure the Service.

2. How we use your information

  • To provide and operate the Service, including spec quality analysis.
  • To analyze the specifications you submit using a third-party AI provider (Anthropic) — see "Third parties" below.
  • To process payments and manage subscriptions.
  • To communicate with you about your account or the Service.
  • To maintain security, prevent abuse, and comply with legal obligations.

3. Third parties we work with

We rely on the following processors to operate SpeSense:

  • Google Firebase — authentication (email/password, Google sign-in, SSO).
  • Supabase — hosts our primary database, in the EU region.
  • Stripe — payment processing for paid subscriptions.
  • Anthropic — processes the text of specifications you submit for analysis to generate quality scores and findings.

Each of these providers processes data only as necessary to perform their function for us.

4. Data location and retention

Workspace content (specifications, findings, audit logs) is stored in our primary database, hosted in the EU. Retention periods for specs and audit logs are configurable per organization in Settings, with sensible defaults if left unchanged.

5. Multi-tenant data isolation

Each organization's data is isolated at the database level using row-level security — one organization can never query or see another organization's data, regardless of application-level bugs.

6. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these rights, contact us at the address below.

7. Changes to this policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date above when we do.

8. Contact

Questions about this policy or your data can be sent to c.mouzeler@cmtech.cloud.