We're committed to protecting your data with enterprise-grade security and complete transparency about how we collect, use, and safeguard your information.
Last Updated: January 15, 2025
Privacy at a Glance
Bank-Level Encryption
All data encrypted with AES-256 in transit and at rest
Never Used for Training
Your documents are never used to train AI models
GDPR & SOC 2 Compliant
Full compliance with global privacy regulations
1. Introduction
Welcome to Spredo AI ("Spredo," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered document analysis platform at spredo.ai and app.spredo.ai (collectively, the "Service").
We take your privacy seriously. This policy describes our practices regarding the collection and use of your personal information and data. By using Spredo, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide
Account Information: When you create an account, we collect your name, email address, password (encrypted), and optional profile information.
Payment Information: If you subscribe to a paid plan, we collect billing information including credit card details (processed securely through Stripe—we never store full card numbers).
Documents and Content: Files you upload (PDFs, DOCX, TXT, etc.), URLs you analyze, custom AI prompts you create, and the analysis results generated by our AI.
Communications: Messages you send us through support channels, feedback forms, or email correspondence.
Team Collaboration Data: Comments, tags, shared analyses, and team member interactions within the platform.
2.2 Information Collected Automatically
Usage Data: How you interact with our Service, including features used, documents analyzed, time spent, and navigation patterns.
Device Information: IP address, browser type and version, operating system, device identifiers, and screen resolution.
Cookies and Tracking: We use cookies, web beacons, and similar technologies to track activity and maintain sessions. See our Cookie Policy for details.
Performance Data: Error logs, crash reports, and performance metrics to improve service reliability.
2.3 Information from Third Parties
Authentication Providers: If you sign in with Google or other OAuth providers, we receive basic profile information (name, email, profile picture).
Payment Processors: Transaction confirmations and payment status from Stripe.
Analytics Services: Aggregated usage statistics from Google Analytics and similar tools (anonymized where possible).
3. How We Use Your Information
We use the information we collect for the following purposes:
Provide and Improve the Service: Process your documents with AI, generate analysis results, enable collaboration features, and continuously improve our algorithms and user experience.
Account Management: Create and maintain your account, authenticate your identity, process payments, and provide customer support.
Communications: Send you service updates, security alerts, billing notifications, and respond to your inquiries. We may also send promotional emails (you can opt out anytime).
Security and Fraud Prevention: Detect and prevent unauthorized access, abuse, fraud, and other illegal activities.
Analytics and Research: Understand how users interact with Spredo, identify trends, measure effectiveness of features, and conduct internal research (using aggregated, anonymized data).
Legal Compliance: Comply with applicable laws, regulations, legal processes, and enforceable governmental requests.
Important: AI Training Policy
Your documents are NEVER used to train AI models. We use third-party AI services (OpenAI, Anthropic, etc.) with strict data processing agreements that prohibit using your content for model training. Your data remains private and is only used to generate your specific analysis results.
4. Data Sharing and Disclosure
We do not sell your personal information. We may share your information only in the following circumstances:
With Your Consent: When you explicitly authorize us to share information (e.g., sharing an analysis with team members).
Service Providers: We work with trusted third-party vendors who help us operate Spredo:
• Cloud hosting providers (AWS, Google Cloud) for infrastructure
• AI service providers (OpenAI, Anthropic) for document analysis
• Payment processors (Stripe) for billing
• Email service providers (SendGrid) for transactional emails
• Analytics providers (Google Analytics) for usage insights
All service providers are bound by strict data processing agreements and can only use your data to provide services to us.
Business Transfers: If Spredo is involved in a merger, acquisition, or sale of assets, your information may be transferred. We'll notify you before your data is transferred and becomes subject to a different privacy policy.
Legal Requirements: We may disclose your information if required by law, court order, or governmental request, or if we believe disclosure is necessary to:
• Comply with legal obligations
• Protect our rights, property, or safety
• Prevent fraud or security threats
• Protect the rights and safety of our users
Aggregated Data: We may share anonymized, aggregated statistics about Spredo usage (e.g., "10,000 documents analyzed this month") that cannot identify individual users.
5. Data Security
We implement industry-leading security measures to protect your information:
Encryption
AES-256 encryption for data at rest, TLS 1.3 for data in transit
Access Controls
Role-based access, multi-factor authentication, and principle of least privilege
Infrastructure Security
SOC 2 Type II certified data centers, regular security audits, and penetration testing
Monitoring
24/7 security monitoring, intrusion detection, and automated threat response
While we implement robust security measures, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security but continuously work to protect your data using industry best practices.
6. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes outlined in this policy:
Account Data: Retained while your account is active and for 90 days after account deletion (to allow for account recovery).
Documents and Analysis: Retained while your account is active. Permanently deleted within 30 days of account deletion or upon your request.
Backup Data: Encrypted backups are retained for 90 days for disaster recovery, then permanently deleted.
Legal and Compliance Data: Some data may be retained longer if required by law or for legitimate business purposes (e.g., financial records for tax compliance).
You can request deletion of your data at any time by contacting us at privacy@spredo.ai or through your account settings.
7. Your Rights and Choices
You have the following rights regarding your personal information:
Access: Request a copy of the personal information we hold about you.
Correction: Update or correct inaccurate information through your account settings or by contacting us.
Deletion: Request deletion of your account and associated data (subject to legal retention requirements).
Data Portability: Export your data in a machine-readable format (CSV, JSON) through your account settings.
Opt-Out: Unsubscribe from marketing emails using the link in any promotional email or through account settings.
Restrict Processing: Request that we limit how we use your information in certain circumstances.
Object: Object to processing of your information for direct marketing or other purposes based on legitimate interests.
To exercise these rights, contact us at privacy@spredo.ai. We'll respond within 30 days. For EU residents, you also have the right to lodge a complaint with your local data protection authority.
8. International Data Transfers
Spredo is based in the United States. If you access our Service from outside the US, your information may be transferred to, stored, and processed in the US and other countries where our service providers operate. These countries may have different data protection laws than your country.
For EU users, we comply with GDPR requirements for international data transfers using Standard Contractual Clauses (SCCs) approved by the European Commission. We ensure that all international transfers are protected by appropriate safeguards.
9. Children's Privacy
Spredo is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@spredo.ai, and we will delete such information from our systems.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:
• Posting the updated policy on this page with a new "Last Updated" date
• Sending an email notification to your registered email address
• Displaying a prominent notice on our Service
Your continued use of Spredo after changes become effective constitutes acceptance of the updated policy. We encourage you to review this policy periodically.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: privacy@spredo.ai
Data Protection Officer: dpo@spredo.ai
Support: support@spredo.ai
Mailing Address: Spredo AI, Inc. 123 Innovation Drive San Francisco, CA 94105 United States
We take privacy seriously and will respond to all legitimate requests within 30 days.
Ready to analyze documents securely?
Your data is protected with enterprise-grade security. Start analyzing documents with confidence.