Spinal Cloudpowered by marrow
ProductAgentsHow it worksInstall MarrowSecurity
Sign in

Legal

Privacy Policy

What Spinal Cloud collects, why, how long we keep it, and what we can see.

Effective 26 July 2026

On this page

  1. Who we are and how to reach us
  2. What we collect and how long we keep it
  3. What we can see
  4. Our legal bases
  5. Cookies and tracking
  6. Who else processes your data
  7. International transfers
  8. Your rights, and how to exercise them
  9. Children
  10. Changes to this policy

1Who we are and how to reach us

[LEGAL ENTITY — TO BE COMPLETED ON INCORPORATION], a Delaware corporation with a registered address at [REGISTERED ADDRESS — TO BE COMPLETED ON INCORPORATION], is the controller of the personal data described in this policy.

For any privacy question, or to exercise the rights described below, write to privacy@spinal.cloud. For security reports, write to security@spinal.cloud.

2What we collect and how long we keep it

This is the complete inventory. Retention windows marked with a duration are enforced by the Service automatically.

DataWhere it comes fromWhy we hold itRetention
Email addressYou, your identity provider, or an invitationSigning you in, inviting you, transactional emailLife of the account
Display nameYour Google or GitHub profileShowing who took an action in your organisationLife of the account
Identity provider subject IDGoogle or GitHubRecognising you across sign-ins without relying on an email address that can changeLife of the account
Browser user agentYour browser, at sign-inLetting you recognise and revoke your own sessionsUntil the session expires or is revoked
Organisation, space, key, and device namesYouOperating the ServiceLife of the account
Audit records (who did what, and when)Your actions in the ServiceSecurity, and letting administrators see changes in their organisationLife of the account
Project memory in transit (journal entries)The machines you runDelivering your memory to your other devices, including devices that were offline30 days
Compatibility queue entriesThe machines you runDelivering to older clients that cannot read the sealed format72 hours
Early-access request (email, and any note you write)The form on our websiteReplying to you about accessUntil you ask us to remove it
Billing detailsYou, via StripeTaking payment once the beta endsAs required by tax and accounting law

We do not store your IP address against your account. We do not collect location data, device identifiers for advertising, or behavioural profiles.

3What we can see

This section is the one we would most want you to read.

Your project memory is held on the machines you run. To move it between your machines, it passes through our relay. While it is passing through, and for the retention window in the table above, it is stored in a form we are technically able to read.

We do not read it. Access is limited to a small number of staff, requires a reason, and is used only to operate the Service, to investigate a fault or a security incident, or where we are compelled by law. We do not use it to train models and we do not share it for advertising.

We are telling you this plainly because the alternative would be to imply a technical guarantee we cannot currently make. Group-keyed encryption that would put your content beyond our reach is planned but has not shipped. When it does, this section will change, and the change will be dated.

Content is encrypted in transit using TLS, and encrypted at rest by our infrastructure provider. Each organisation's data is isolated at the database level, and that isolation is tested from the attacker's side.

4Our legal bases

Where the GDPR or a similar law applies, we rely on:

  • performance of a contract — to give you the Service you asked for, including delivering your memory between your devices and taking payment;
  • legitimate interests — to keep the Service secure, prevent abuse, maintain audit records, and reply to you about early access, balanced against your rights;
  • consent — for anything we ask you to opt into; you can withdraw it at any time;
  • legal obligation — where we must keep records or respond to a lawful request.

5Cookies and tracking

We set one cookie, spinal_session, in the dashboard. It keeps you signed in. It is HttpOnly, so scripts cannot read it, restricted with SameSite, and marked Secure outside local development. It is strictly necessary, so we do not ask for consent to set it.

This marketing site sets no cookies. Your light or dark theme preference is stored in your browser's local storage and never leaves your device.

We run no analytics, no advertising, no session recording, and no third-party scripts of any kind. This is enforced structurally: the content security policy on both our sites permits connections and scripts only from our own origin, so a tracker could not load even if someone added one by mistake.

6Who else processes your data

We use a small number of providers, each under a contract that limits them to processing data on our instructions.

ProviderWhat it doesWhere
Google CloudHosting, the application database, and secret storageSingapore
ResendSending sign-in links, invitations, and other transactional emailUnited States
StripePayment processing, once the beta ends. Card details go to Stripe directly; we never see or store themUnited States
Google and GitHubOptional sign-in. They tell us your email, name, and a subject ID only when you choose to sign in with themUnited States

We will update this list before adding a provider that processes personal data. We do not sell personal data, and we do not share it for cross-context behavioural advertising.

We may disclose data if required by valid legal process, or to protect the rights, safety, or property of our users or ourselves. Where we are lawfully permitted to tell you about such a request, we will.

7International transfers

We are established in the United States and our infrastructure runs in Singapore. If you are in the European Economic Area, the United Kingdom, or another region with transfer restrictions, your personal data will be transferred outside it.

Where such a transfer needs a safeguard, we rely on the European Commission's Standard Contractual Clauses, or the UK Addendum, with each provider. You can ask us for details at privacy@spinal.cloud.

8Your rights, and how to exercise them

Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent. If you are in California, you additionally have the right not to be discriminated against for exercising these rights; we do not offer financial incentives for personal data.

There is currently no self-serve control for account deletion or data export in the dashboard. We are not going to describe a button that does not exist. Instead, write to privacy@spinal.cloud from the address on your account. We will acknowledge within 5 business days and complete the request within 30 days, and we will tell you if we need longer and why. We do not charge for this.

You can already delete some things yourself: spaces, keys, devices, and organisation members can be removed from the dashboard, and revoking a key or a device takes effect immediately.

Deleting your account removes your personal data and your organisation's content from our systems. Copies may remain in encrypted backups for a limited period until those backups age out on their normal cycle. Audit records may be retained where we are required to keep them, and are then limited to what that requirement covers.

If you are in the EEA or the UK and you think we have handled your data badly, you may complain to your local supervisory authority. We would rather you told us first at privacy@spinal.cloud so we can put it right.

9Children

The Service is for adults working on software. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, write to privacy@spinal.cloud and we will delete it.

10Changes to this policy

We will update this policy as the Service changes. When a change materially affects how we handle your personal data — including any change to what we are able to see — we will email the address on your account before it takes effect. The effective date at the top of this page always reflects the current version.

Spinal Cloud

One shared project memory for your team and coding agents.

Powered by marrow

ProductAgentsHow it worksSecurityTermsPrivacySign in

© 2026 Spinal Cloud

Your memory lives on your machines.