What we collect
Specula collects account details, organization information, uploaded business files, import results, usage events needed to operate the app, support messages, and insight outputs generated from workspace data.
Privacy policy
This plain-language policy explains what Specula collects, why it is used, and how customer operating data is handled. It should be reviewed by counsel before broad commercial rollout. Effective date: June 12, 2026.
Specula collects account details, organization information, uploaded business files, import results, usage events needed to operate the app, support messages, and insight outputs generated from workspace data.
We use data to authenticate users, run imports, generate dashboards, create scan briefs, support customers, improve reliability, and maintain security. We do not sell customer operating data.
Customer data is scoped to organization workspaces. Specula uses secure authentication, environment-based secrets, HTTPS in production, and database access controls.
When AI insights are requested, relevant business metrics or summaries may be sent to an AI provider to produce recommendations. Specula is designed to use only the information needed for the requested analysis.
Specula limits internal access to customer data to support, troubleshooting, security, billing readiness, and product operation needs. We do not publish customer data or use it to expose another customer's business.
Customer rights
Customers should be able to ask what data is stored, request correction, request deletion where appropriate, and understand how their information is used.
Workspace owners can remove uploaded data and manage team access.
Support requests may require account ownership verification before details are shared.
Data deletion requests should be logged and handled within a reasonable timeframe.
Specula may retain limited records where needed for security, legal, billing, audit, backup, or dispute purposes.
Customers should avoid uploading payment card numbers, Social Security numbers, credentials, medical data, or files they are not allowed to share.
AI providers and infrastructure providers may process data only as needed to provide the service.
Privacy and security claims will stay clear and accurate as the service matures.