Legal
Privacy Policy
What Spinal Cloud collects, why, how long we keep it, and what we can see.
Effective 26 July 2026
Who we are and how to reach us
[LEGAL ENTITY — TO BE COMPLETED ON INCORPORATION], a Delaware corporation with a registered address at [REGISTERED ADDRESS — TO BE COMPLETED ON INCORPORATION], is the controller of the personal data described in this policy.
For any privacy question, or to exercise the rights described below, write to privacy@spinal.cloud. For security reports, write to security@spinal.cloud.
What we collect and how long we keep it
This is the complete inventory. Retention windows marked with a duration are enforced by the Service automatically.
| Data | Where it comes from | Why we hold it | Retention |
|---|---|---|---|
| Email address | You, your identity provider, or an invitation | Signing you in, inviting you, transactional email | Life of the account |
| Display name | Your Google or GitHub profile | Showing who took an action in your organisation | Life of the account |
| Identity provider subject ID | Google or GitHub | Recognising you across sign-ins without relying on an email address that can change | Life of the account |
| Browser user agent | Your browser, at sign-in | Letting you recognise and revoke your own sessions | Until the session expires or is revoked |
| Organisation, space, key, and device names | You | Operating the Service | Life of the account |
| Audit records (who did what, and when) | Your actions in the Service | Security, and letting administrators see changes in their organisation | Life of the account |
| Project memory in transit (journal entries) | The machines you run | Delivering your memory to your other devices, including devices that were offline | 30 days |
| Compatibility queue entries | The machines you run | Delivering to older clients that cannot read the sealed format | 72 hours |
| Early-access request (email, and any note you write) | The form on our website | Replying to you about access | Until you ask us to remove it |
| Billing details | You, via Stripe | Taking payment once the beta ends | As required by tax and accounting law |
We do not store your IP address against your account. We do not collect location data, device identifiers for advertising, or behavioural profiles.
What we can see
This section is the one we would most want you to read.
Your project memory is held on the machines you run. To move it between your machines, it passes through our relay. While it is passing through, and for the retention window in the table above, it is stored in a form we are technically able to read.
We do not read it. Access is limited to a small number of staff, requires a reason, and is used only to operate the Service, to investigate a fault or a security incident, or where we are compelled by law. We do not use it to train models and we do not share it for advertising.
We are telling you this plainly because the alternative would be to imply a technical guarantee we cannot currently make. Group-keyed encryption that would put your content beyond our reach is planned but has not shipped. When it does, this section will change, and the change will be dated.
Content is encrypted in transit using TLS, and encrypted at rest by our infrastructure provider. Each organisation's data is isolated at the database level, and that isolation is tested from the attacker's side.
Our legal bases
Where the GDPR or a similar law applies, we rely on:
- performance of a contract — to give you the Service you asked for, including delivering your memory between your devices and taking payment;
- legitimate interests — to keep the Service secure, prevent abuse, maintain audit records, and reply to you about early access, balanced against your rights;
- consent — for anything we ask you to opt into; you can withdraw it at any time;
- legal obligation — where we must keep records or respond to a lawful request.
Who else processes your data
We use a small number of providers, each under a contract that limits them to processing data on our instructions.
| Provider | What it does | Where |
|---|---|---|
| Google Cloud | Hosting, the application database, and secret storage | Singapore |
| Resend | Sending sign-in links, invitations, and other transactional email | United States |
| Stripe | Payment processing, once the beta ends. Card details go to Stripe directly; we never see or store them | United States |
| Google and GitHub | Optional sign-in. They tell us your email, name, and a subject ID only when you choose to sign in with them | United States |
We will update this list before adding a provider that processes personal data. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
We may disclose data if required by valid legal process, or to protect the rights, safety, or property of our users or ourselves. Where we are lawfully permitted to tell you about such a request, we will.
International transfers
We are established in the United States and our infrastructure runs in Singapore. If you are in the European Economic Area, the United Kingdom, or another region with transfer restrictions, your personal data will be transferred outside it.
Where such a transfer needs a safeguard, we rely on the European Commission's Standard Contractual Clauses, or the UK Addendum, with each provider. You can ask us for details at privacy@spinal.cloud.
Your rights, and how to exercise them
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent. If you are in California, you additionally have the right not to be discriminated against for exercising these rights; we do not offer financial incentives for personal data.
There is currently no self-serve control for account deletion or data export in the dashboard. We are not going to describe a button that does not exist. Instead, write to privacy@spinal.cloud from the address on your account. We will acknowledge within 5 business days and complete the request within 30 days, and we will tell you if we need longer and why. We do not charge for this.
You can already delete some things yourself: spaces, keys, devices, and organisation members can be removed from the dashboard, and revoking a key or a device takes effect immediately.
Deleting your account removes your personal data and your organisation's content from our systems. Copies may remain in encrypted backups for a limited period until those backups age out on their normal cycle. Audit records may be retained where we are required to keep them, and are then limited to what that requirement covers.
If you are in the EEA or the UK and you think we have handled your data badly, you may complain to your local supervisory authority. We would rather you told us first at privacy@spinal.cloud so we can put it right.
Children
The Service is for adults working on software. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, write to privacy@spinal.cloud and we will delete it.
Changes to this policy
We will update this policy as the Service changes. When a change materially affects how we handle your personal data — including any change to what we are able to see — we will email the address on your account before it takes effect. The effective date at the top of this page always reflects the current version.