Legal
Privacy Policy
Draft — last updated 15 August 2026. This is an early-access product; this policy will be reviewed as features ship.
Who we are
SpectoSite is operated by Ged Hogan. If you have questions about this policy or your data, contact the SpectoSite owner through the account associated with your workspace once sign-in is available.
What we collect
Once account creation is enabled, SpectoSite will collect:
- Account information: email address, authentication factors (password hash or passkey, and MFA enrolment status — never the underlying TOTP seed in plaintext).
- Workspace and project data: specifications, plans, build events, deployment records, and evidence you create while using the product.
- Provider credentials you choose to add (builder/reviewer API keys), stored only in encrypted form — see Security.
- Operational logs needed to run the service securely (audit events, rate-limiting signals).
What we do not do
- We do not sell your data.
- We do not use your provider credentials to fund or run another customer’s work.
- We do not store your provider API keys in plaintext, and we never return them to any client after initial submission.
- We do not make your projects, specifications, or evidence public — only entries you or the SpectoSite owner explicitly publish to the portfolio are visible to anonymous visitors.
Data isolation
Every tenant-owned record is protected by database-level Row-Level Security, tested against cross-tenant access. See Security for what has been verified and what is still in progress.
Your rights
Once accounts are live, you will be able to export or delete your workspace data through your account settings. Until then, no personal account data is collected by this site beyond standard, anonymised web server logs.
Changes
As SpectoSite moves from early access toward general availability, this policy will be updated to reflect the features actually shipped, and the “last updated” date above will change accordingly.