Legal information
Privacy policy
Last updated: October 9, 2026
This policy explains which data SpectrAI processes, why, on what basis, with which providers and how to exercise your rights. SpectrAI is a project under development: this policy describes how the service actually works on the date shown.
Data controller
The data controller is the website’s publisher, described in the legal notice. Until a legal entity exists, this is the person behind the Spectr project, who can be reached at contact@spectr-ai.eu.
Data we process
- Account: first name, last name, email address, organization name and password, stored hashed by the authentication provider; if you enable it, the two-step verification factor.
- Use of the service: URL to test, DNS proof of control, guidance and API documents you provide, any test credentials, results, evidence and reports produced, and an audit log of sensitive actions.
- Contact form: name, email address, company (optional), profile and message.
- Technical data: IP address, browser, pages viewed and timestamps in the host’s logs; error reports; aggregated, cookieless audience and performance measurements.
- Emails: sending and delivery history of transactional emails (confirmation, invitation, report available).
Purposes and legal bases
- Creating and managing your account, running Assessments and delivering reports: performance of the contract (Article 6(1)(b) GDPR).
- Answering your contact requests: steps taken at your request before a contract (Article 6(1)(b)) or legitimate interest in answering the messages we receive (Article 6(1)(f)).
- Securing the service, preventing abuse, logging sensitive actions and fixing errors: legitimate interest (Article 6(1)(f)).
- Measuring audience and performance in aggregate, without cookies or individual tracking: legitimate interest (Article 6(1)(f)).
- Meeting legal obligations where they apply: legal obligation (Article 6(1)(c)).
Data from the applications you test
During an Assessment, the testing engine sends requests to the verified URL and analyses its responses with a third-party language model. The application’s responses, your guidance and, if you provide them, your test credentials are then processed in clear by this engine and by the model provider. Test credentials are stored encrypted and only decrypted for the Assessment that uses them; their deletion by the model provider cannot be guaranteed. Use dedicated test accounts, never real ones.
If the tested application holds personal data, you remain responsible for that processing and for the testing authorization; SpectrAI then acts on your behalf.
Recipients and processors
Your data is never sold or rented. It is available to the authorized people in your organization (and, for a client of a partner firm, to that firm), to the publisher for operations and support, and to the following providers:
- Vercel Inc. (United States): hosting of the website and the application; aggregated, cookieless audience and performance measurement (Vercel Analytics and Speed Insights).
- Supabase Inc. (United States): database, authentication and file storage.
- Sentry (Functional Software, Inc., United States): error monitoring. When an error occurs in the browser, a session recording (Session Replay) with text and fields masked may be attached to the error report in the application and sign-in screens; it is never enabled on the public pages of the site or on a page whose address carries a token (shared report, invitation, confirmation).
- Resend (United States): sending transactional emails and forwarding contact form messages.
- OpenAI (United States): language model used by the testing engine during Assessments; processing within the European Union is not guaranteed today.
- A dedicated server provider: Assessments run on a server administered by the publisher.
Several of these providers are based in the United States. Transfers rely on the safeguards each provider offers: certification under the EU–US Data Privacy Framework or the European Commission’s standard contractual clauses.
Retention
- Account and service data: as long as the account exists. You can delete your account from its settings; the data attached to it is then erased, subject to the providers’ technical backups.
- Contact messages: as long as needed to handle your request and the conversation that follows.
- Technical logs and error reports: according to the host’s and the error monitoring service’s own retention periods.
- Test credentials: encrypted, and limited to the Assessment that uses them.
Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to set instructions for your data after your death. To exercise them, write to contact@spectr-ai.eu; you will receive an answer within one month.
If you believe your rights are not respected, you can lodge a complaint with the CNIL, the French data protection authority (cnil.fr).
Cookies and local storage
SpectrAI sets no advertising cookie and no audience tracker. Only items strictly necessary for the service are used; they do not require consent, hence no banner:
locale: remembers the chosen language, for one year.sb-…-auth-token: keep you signed in; set by the authentication provider only when you sign in.current_organization_id: remembers the selected space once you are signed in, for one year.theme: browser local storage, remembers the light or dark theme.
Changes to this policy
This policy will change with the service. The date of the last update is shown at the top of the page.