1. Who we are
Specc (“we”, “us”, “our”) operates the Specc platform at speccapp.com. We are the data controller for personal data processed through this service. If you have any questions about this policy, contact us at Conor@validar.co.uk.
2. Data we collect
- ·Account data: Your email address, collected when you sign up via email or Google OAuth.
- ·Repository context: File paths and source snippets scanned from a connected GitHub repo or files you upload, used only to produce an impact report.
- ·API change descriptions: The changelog text you paste so Specc can search for matching symbols and endpoints.
- ·Impact reports: Ranked findings Specc produces, stored so you can reopen them later.
- ·Billing data: Payment details are handled entirely by Stripe. We never store card numbers or bank details.
- ·Usage data: Basic usage counts (analyses per window) to enforce plan limits.
- ·Log data: Server logs including IP address and user agent for security and debugging. These are retained for up to 30 days.
3. Why we process your data
- ·Contract performance: To provide the Specc service you signed up for: scanning code, classifying API impact, and storing your reports.
- ·Legitimate interest: To maintain security, prevent abuse, and improve reliability.
- ·Legal obligation: To comply with applicable laws and respond to lawful requests.
4. Third-party processors
We share data with the following sub-processors only to the extent required to operate the service:
ProcessorPurposeLocation
SupabaseAuthentication & database hostingEU / US
StripePayment processingUS
AnthropicAI classification of matched codeUS
GitHubRepository access when you connect a repoUS
VercelApplication hosting & edge deliveryGlobal
5. Cookies
We use only strictly necessary cookies to keep you signed in. These are session cookies set by Supabase for authentication and cannot be disabled without breaking the service. We do not use advertising or tracking cookies. No cookie consent is required for strictly necessary cookies under the UK PECR and EU ePrivacy Directive.
6. Data retention
We retain your account data and analysis history for as long as your account is active. If you delete your account, all personal data including your email and generated reports is permanently deleted within 30 days. Stripe may retain billing records for up to 7 years for legal compliance.
7. Your rights
Under UK GDPR and EU GDPR you have the right to:
- ·Access the personal data we hold about you
- ·Correct inaccurate data
- ·Delete your account and all associated data
- ·Restrict or object to processing
- ·Data portability: receive your data in a machine-readable format
- ·Lodge a complaint with your supervisory authority (ICO in the UK, your national DPA in the EU)
To exercise any of these rights, contact us at Conor@validar.co.uk or use the “Delete account” option in your dashboard settings.
8. International transfers
Some of our sub-processors are based in the United States. Where personal data is transferred outside the UK or EEA, we rely on Standard Contractual Clauses (SCCs) or other appropriate safeguards as required by applicable data protection law.
9. Changes to this policy
We may update this policy from time to time. We will notify you of material changes by email or via a notice in the app. The “Last updated” date at the top of this page reflects the most recent revision.