Privacy Policy

Last updated: 31 July 2026

Spexd (“Spexd”, “we”, “us”) is a software-specification traceability tool that helps teams link requirements, acceptance criteria, design, and tasks. This Privacy Policy explains what information we collect when you use Spexd, how we use it, and the choices you have. By using Spexd you agree to the practices described here.

Information we collect

We collect the following categories of information:

  • Account and identity information. Authentication is handled by our identity provider, Clerk. When you sign up or sign in we receive your name, email address, and the organization(s) you belong to. Sign-in is by Google or GitHub single sign-on only — Spexd neither asks for nor stores a password.
  • Content you create. The specifications you author in Spexd — features, requirements, acceptance criteria, designs, tasks, and the links between them — along with any text or documents you add to them.
  • Usage and technical data. Basic information sent by your browser and generated as you use the service, such as pages viewed, actions taken, and diagnostic logs used to keep Spexd running reliably.

How we use your information

We use the information we collect to:

  • Provide, operate, and maintain the Spexd service.
  • Authenticate you and scope your access to your organization's data.
  • Respond to your requests and provide support.
  • Monitor, secure, debug, and improve the reliability and performance of the service.

We do not sell your personal information, and we do not use the content of your specifications for advertising.

Where your data is stored and who processes it

Spexd relies on a small number of trusted third-party providers to operate the service. Each processes data only to provide their part of the service:

  • Clerk — authentication and organization management.
  • Railway — application hosting and delivery, and the PostgreSQL database that holds the relational traceability graph (entity records and the links between them) and the document content attached to each specification.
  • Anthropic — the AI model provider for our in-app AI assistant (its Claude models). When you use the AI chat, your messages and the relevant specification content are sent to the model provider to generate a response, and for no other purpose. We configure that provider so that request and response contents are not retained and not used to train models. See Anthropic's privacy policy and its zero-retention documentation.

If your organization brings its own AI provider. An organization can be configured to use its own model provider and its own credentials for the AI assistant. Where that applies, the AI content described above is sent to that provider instead of the one named here, under your organization's own arrangement with them — their terms, their retention and training settings, and their billing — rather than ours. Your organization's administrator chooses that provider; if you are unsure whether it applies to you, ask them.

Your data is scoped to your organization: access is restricted so that members of one organization cannot read another organization's data.

AI features and automated processing

Spexd offers AI-assisted features that operate on your content:

  • AI chat assistant. Spexd includes an in-app AI assistant that can read your specifications and help you draft and refine them. When you send it a message, the assistant runs on our servers and sends your messages, along with the specification content relevant to your request, to an AI model provider (Anthropic's Claude models, or your organization's own provider if it has configured one — see above) to generate a response. Only the content needed to answer your request is sent, and it is processed only to return the assistant's reply. Where we provide the model, we configure it so that request contents are not retained and not used to train models; where your organization brings its own provider, those settings are governed by its arrangement with that provider. Actions that change your data (such as creating, editing, or publishing an entity) are only ever proposed by the assistant and require your explicit confirmation before they run.
  • MCP server. Spexd provides a Model Context Protocol (MCP) server that lets you connect external AI assistants and agent tools to your Spexd workspace. When you connect a client through the MCP server, it can read and act on the specification data your organization has granted it access to. Access is authenticated and scoped to your organization, but any assistant or tool you connect is operated by you or a third party and handles your data under its own terms, not this policy.

Data retention

We retain your account and content data for as long as your account or organization remains active, and as needed to provide the service. When data is deleted, it is removed from our active systems; residual copies may persist in backups for a limited period before being overwritten.

Security

We take reasonable technical and organizational measures to protect your information, including access controls that isolate each organization's data and encrypted connections in transit. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Your rights and choices

Depending on your location, you may have the right to access, correct, export, or delete the personal information we hold about you. You can update much of your account information directly within Spexd, and you can contact us to make any other request. We will respond in accordance with applicable law.

Children's privacy

Spexd is a tool for software teams and is not directed at children. We do not knowingly collect personal information from children.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Your continued use of Spexd after a change takes effect constitutes acceptance of the updated policy.

Contact us

If you have questions about this Privacy Policy or how we handle your information, contact us at admin@spexd.com.