Privacy Policy
Last updated: February 27, 2026
1. Information We Collect
We collect information you provide directly when using SpecBuilder.ai:
- Account information: name, email address, and profile picture from OAuth providers (GitHub, Google, GitLab)
- Project content: ideas, specifications, and documents you create or upload
- Usage data: pages visited, features used, and interaction patterns
- Payment information: processed securely through Stripe; we never store card details
2. How We Use Your Information
- To provide, maintain, and improve the Service
- To process your content through AI models for document generation
- To send transactional emails (account activity, quote notifications, share link alerts)
- To detect and prevent abuse or unauthorized access
- To analyze usage patterns and improve the user experience
3. AI Processing
Your project content is sent to third-party AI providers (Anthropic, Google) for document generation. This data is processed in real-time and is not stored by AI providers beyond the request lifecycle. We do not use your content to train, fine-tune, or improve any AI models. Your specifications remain yours.
4. Data Storage and Security
Your data is stored securely on Supabase (PostgreSQL) with row-level security enabled. All data is encrypted in transit (TLS/SSL) and at rest. OAuth tokens are stored with encryption. We follow industry-standard security practices and regularly review our security posture.
5. Data Sharing
We do not sell your personal information. We share data only with:
- AI providers (Anthropic, Google) — for document generation only
- Stripe — for payment processing
- Resend — for transactional email delivery
- Vercel — for application hosting and analytics
- Sentry — for error tracking (anonymized)
6. Shared Links
When you create a share link, the linked documents become accessible to anyone with the URL. Share links can be revoked at any time. Quote submissions through share links collect the submitter's name and email, which are visible to the project owner.
7. Cookies and Analytics
We use essential cookies for authentication and session management. We use Google Analytics to understand usage patterns. You can disable analytics tracking in your browser settings or by using an ad blocker.
8. Your Rights
You have the right to:
- Access and export your data at any time
- Correct inaccurate personal information
- Delete your account and all associated data
- Opt out of non-essential communications
- Request information about how your data is processed
9. Data Retention
We retain your data for as long as your account is active. If you delete your account, all personal data and project content will be permanently removed within 30 days. Anonymized usage analytics may be retained indefinitely.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on the Service.
11. Contact
For privacy-related questions, contact us at hello@specbuilder.ai.