How SpecSprout handles your data
This page describes the behavior of the current SpecSprout account, cloud, AI, security and billing build. Live operator/provider details are loaded from the server so legal identity is never guessed in source code.
Loading live privacy configuration…
Account information
SpecSprout stores the name and email address associated with your account, email-verification state, linked sign-in providers and security metadata needed to operate account sessions. Passwords are never stored in plain text; password credentials are stored as salted password hashes. Active browser sessions use random server-side session records and an HttpOnly browser cookie with a finite lifetime, SameSite protection and Secure on HTTPS.
Private cloud workspace and local cache
Each verified account is associated with a private cloud workspace. Project names, descriptions, requirement models, decisions and history are synchronized to server-side Netlify Blobs storage. A local browser copy is also kept so temporary connection problems do not immediately interrupt work.
Evidence files
Evidence selected for analysis is stored locally in the browser and can also be uploaded to the account's private cloud evidence store so the same evidence can be recovered on another device. Evidence is separated by account workspace and project. Server-side format/signature checks reject unsupported executable or active-content formats before cloud storage or AI processing.
AI processing
When you run product analysis or request decision help, the information needed for that request is sent to SpecSprout's server-side function and then to the configured OpenAI API. Uploaded files and founder text are treated as untrusted product evidence, not as instructions that may override the application's system rules. OpenAI states that API/business inputs and outputs are not used to train models by default unless the API organization explicitly opts in. Because provider-account settings and retention modes live outside this codebase, the Trust Center separately shows the provider policy, the deployment-specific review state, and whether Zero Data Retention is actually claimed.
Security and abuse prevention
SpecSprout records security activity, rate-limit information and account-level AI usage needed to protect accounts, prevent abuse and control service cost. The application security audit stores a one-way salted hash rather than intentionally persisting raw network addresses. Security events may include browser/device user-agent information and action metadata.
Email verification and account recovery
Password accounts use expiring single-use tokens for email verification, email-address changes and password resets. If transactional email is enabled, those links are delivered through the configured email provider. Google OAuth and Cloudflare Turnstile appear in the live provider list only when those integrations are enabled.
Payments and subscriptions
SpecSprout uses Stripe-hosted payment surfaces for subscription checkout and billing management when billing is configured. Payment-card and bank-payment credentials are entered into Stripe/Link and are not stored in the SpecSprout application. SpecSprout stores the billing identifiers, subscription state, invoice references, refund/dispute state and billing history needed to operate the account.
Backups, retention and deletion
The Cloud & backups screen lets the user choose 7, 30 or 90 days for recently deleted product data and old automatic backup retention. Those settings govern SpecSprout-managed deleted data/backups; they do not rewrite an external processor's own legally/contractually controlled retention. Users can use the Delete cloud data control to remove cloud product data while keeping the login account, or permanently delete the whole SpecSprout account. Account deletion attempts to stop any active chargeable subscription first, then removes SpecSprout account/workspace data and active sessions. External providers may retain records they are legally required to keep.
Access, portability and rectification
The Privacy Center's Download all my data export combines account/session/security/billing/AI-usage metadata with the current project records and current evidence files. Name changes and verified email changes are available in Account & security. These controls are intended to make access, portability, rectification and erasure practical without requiring a support ticket for routine cases.
Cookies and tracking
SpecSprout uses an essential account session cookie plus local browser storage and IndexedDB needed for the application/offline evidence workflow. Optional first-party product analytics can be enabled by the operator only with the reviewed privacy flag and are recorded only after the user explicitly allows them. Marketing/advertising tracking is not enabled by the current build. Direct referral/partner links can temporarily use first-party browser storage to carry an attribution code into account creation; no third-party advertising tracker is introduced. If you separately opt into an optional launch/beta waitlist, the email address and information you submit are used for those consented communications and can be unsubscribed independently of your account.
Sensitive information
Only upload product information and files that you are authorized to process. Avoid including unrelated personal data, credentials, passwords, special-category personal data or other secrets in product evidence unless there is a clear lawful and necessary reason to process it.
Privacy requests and complaints
Routine access, correction, retention and deletion controls are available inside the app. The live operator section above shows the privacy contact only when the operator has configured it. Rights, complaint routes and regulatory notices that depend on the operator's jurisdiction must be finalized in legal review before serious public commercial launch.