Back to home

Privacy Policy

Last updated 2026-08-04

This policy explains what DSpecs, operated by DSpecs, collects about you, why, and who else sees it. It describes the system as it actually works — not a generic template.

1. What we collect

Account data: your email address, your display name, which sign-in providers you have connected, and whether that provider told us your email is verified. There is no password, because DSpecs does not use passwords.

Content you create: your domain model, contexts, objects, usecases, constitution rules, update branches, code references, and documents you upload for AI import.

Activity data: a change log of edits (what changed, when, and by which user), when an API token was last used, and compile events used to count usage against your plan limits.

Technical data: your IP address when you request a sign-in link (used for rate limiting), and standard server logs.

2. Why we use it

To sign you in and keep your session secure. To store and show your content. To attribute changes so a team can see who edited what. To count usage against plan limits and to bill paid plans. To respond when you contact us.

We do not sell your data. We do not use your content to train AI models.

3. AI processing — read this one

If you use AI import, the content of the documents you provide is transmitted to Google's Gemini API for extraction. This is the only feature that sends your content to an AI provider, and it only happens when you start an import.

Google processes that content under its own terms. If your material must not leave your organisation, do not use AI import — every other part of DSpecs works without it.

4. Who else processes your data

Google — Gemini API for AI import, and Google Sign-In if you use it.

GitHub — GitHub Sign-In if you use it.

Resend — delivery of sign-in link emails.

Polar (Polar Software Inc.) and its payment processor — payments and subscription management. They receive your billing details directly; we receive only a customer identifier, plan, and status.

PostHog — product analytics, and only if you accept analytics cookies. Decline and nothing is sent.

Our hosting provider — servers and object storage where your content is stored.

5. Cookies

We use a session cookie to keep you signed in, a cookie to remember your language, a cookie to record your cookie choices, and a short-lived cookie during OAuth sign-in to prevent request forgery. These are necessary for the service to work.

Analytics are off until you accept them. The Cookie Policy lists every cookie and what it does, and you can change your choice at any time.

6. How long we keep it

Account and content data are kept while your account exists. Sign-in links expire after 15 minutes and can only be used once. Records of payments are kept as long as tax law requires.

There is currently no self-service account deletion. Write to [email protected] and we will delete your account and its content within 30 days, except where we are required to keep billing records.

7. Your rights

Depending on where you live — including anywhere in the EEA and the UK — you may have the right to access your data, correct it, delete it, get a copy in a portable format, object to certain processing, or withdraw consent you have given.

To exercise any of these, write to [email protected]. We will respond within 30 days. You also have the right to complain to your local data protection authority.

8. Legal bases (EEA/UK)

We process account and content data to perform our contract with you. We process usage and security data on the basis of our legitimate interest in running a reliable, non-abused service. We process analytics only with your consent. We keep billing records to comply with legal obligations.

9. International transfers

DSpecs is operated from Vietnam, and our sub-processors operate in several countries. Using the service means your data is transferred to and processed in those countries, which may have different data protection laws than yours.

10. Security

Sessions use HTTP-only cookies. API tokens are stored hashed and are scoped to a single project. Passwords do not exist, which removes an entire class of breach. Uploaded files are stored in access-controlled object storage.

No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant authority as the law requires.

11. Children

DSpecs is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, write to [email protected] and we will delete it.

12. Changes and contact

We may update this policy. The date at the top shows the current version; material changes will be announced before they take effect.

DSpecs · [to be completed] · [email protected]