Spinda / Legal
Privacy Policy
Effective 2026-10-04
1. Who we are and what this covers
This Policy describes how Spinda (“we,” “us,” or “our”) handles personal information through the Spinda website, console, and decision-model API.
We manage account and operational information to run the Service. When an organization submits information about other people through the API, that organization is responsible for its own purposes, permissions, and notices. This Policy does not replace an agreement required for a particular regulated use or a separate data-processing agreement.
2. Information we collect
Account and organization information. We receive your name, email, identity-provider identifier, access-approval status, organization memberships, roles, and invitation details. If you choose Google or GitHub sign-in, the identity provider and WorkOS process the information needed to authenticate you. We do not request your Google or GitHub password.
API and playground content. We process the state, instructions, criteria, images, and other material you submit, together with the model’s results. Submit only information you are authorized to use.
Usage and security records. Records include model and organization identifiers, key identifiers, request times, token counts, costs, status, latency, and a keyed request fingerprint used to detect conflicting retries. The gateway’s usage ledger does not contain your state, questions, or raw images. API key secrets are shown once; the gateway stores a verification digest rather than the full secret.
Support information. If you contact us, we receive the information you provide in your message and attachments. Do not send API keys or other secrets in a support message.
Connection information. Infrastructure and identity providers may process IP addresses, browser and device information, timestamps, and security events while delivering the Service. Public HTTPS traffic is processed by the edge provider before reaching our server.
Cookies and browser storage. The console uses necessary sign-in and session cookies. The current gateway’s sign-in flow cookie lasts up to 10 minutes and its session cookie up to 12 hours. The browser remembers your selected organization in session storage. Playground drafts and displayed results are held in page memory while the page is open. WorkOS and your chosen sign-in provider may use their own authentication cookies. The public homepage does not set application cookies or load advertising trackers.
Payments. Payment collection is not currently enabled. The console tracks a service allowance and usage; it does not collect payment-card details. We will update this Policy before adding payment processing that changes these practices.
3. How information is used
We use information to approve and authenticate accounts, run organizations, answer API requests, meter usage, support retries, troubleshoot failures, communicate about access and service changes, respond to support requests, prevent abuse, protect the Service, and meet legal obligations.
We do not train or fine-tune models on your submitted content without your prior consent. We may use operational measurements and aggregated or de-identified information to evaluate capacity, understand errors, and improve the Service. We do not sell personal information or use it for cross-context behavioral advertising.
5. Retention and security
Request content. The customer gateway does not write raw states, questions, or images to its usage database. Content must still pass through network, application, and model memory to produce a result. If you include content in a support request, it can be retained with that correspondence.
Retry responses. Encrypted responses are available for idempotent replay for 24 hours after a request finishes. After that window, replay is refused and a background cleanup removes the stored response from active records. Cleanup may be delayed during an outage. Database storage and journals can retain encrypted remnants until they are reused; this is not a guarantee of physical erasure at exactly 24 hours.
Model caches. Customer requests use separate cache namespaces. Model caches can remain in memory until they are evicted or workers are stopped. Eviction depends on capacity and does not have a fixed wall-clock deadline. This is not a zero-retention service.
Accounts and metadata. Account, approval, organization, key, usage, and ledger records are retained to operate the Service, maintain account history, investigate abuse, resolve disputes, and comply with applicable law. We have not set a single automatic deletion deadline for all such records. Contact us to request deletion or account closure; we will explain any information that must be retained.
Backups. Console backups retain account and usage metadata and the secrets needed for restoration. The backup process removes replay response content, session records, and temporary sign-in records from completed snapshots. Backups are kept separately from active database files, but no fixed backup-expiry period is currently promised. Deletion from an active account does not imply immediate removal from every backup.
Safeguards. Measures include HTTPS for public connections, organization access checks, restricted storage permissions, API-key verification digests, and encrypted retry responses. These measures reduce risk but do not guarantee absolute security. No certification or end-to-end encryption claim is made by this Policy.
6. Your choices and requests
You can revoke API keys, sign out, and ask an organization owner to change your membership. To request access to, correction of, or deletion of your personal information, or to close an account, contact support@spinda.ai. Depending on the law that applies, you may have additional rights, including objection, restriction, portability, or a complaint to a privacy regulator.
We may need to verify your identity and authority before fulfilling a request. Some information may need to be retained for security, legal obligations, or another person’s rights. If your information was submitted by a customer organization, contact that organization first; we may refer the request to it and assist as appropriate.
Our account service is intended for adults, and we do not knowingly create accounts for children under 18. Contact us if you believe a child has provided account information. A customer’s submission of information about other people remains subject to its own legal responsibilities.
7. Contact and policy changes
Operator: Spinda.
Privacy and support contact: support@spinda.ai.
We will update this page when our practices change and identify the effective date. We will provide additional notice or obtain consent where applicable law requires it. A change to this Policy does not retroactively authorize model training that required your consent.