Privacy Policy

What we collect, how we use it, and what rights you have over it.

Effective August 8, 2026

1. What We Collect

Information you provide directly

  • Account registration information: email address and password when you create an account.
  • Profile information: the client profile details you enter to configure your monitoring pulls, including business descriptions, counterparty names, contract summaries, and regulatory exposure areas.
  • Payment information: billing details processed by our third-party payment processor. Speider does not store complete payment card numbers on its systems.
  • Communications: messages you send us directly at hello@speider.ai.

Information collected automatically

  • Usage data: pages visited, features used, session duration, and actions taken within the platform.
  • Device and connection information: browser type, operating system, IP address, and general location derived from IP.
  • Authentication data: login timestamps and session activity.

What we do not collect

  • We do not store the original text of any documents you upload. When you upload a document, we extract a narrow set of structured fields from it (such as industry, counterparty names, and agreement types). The file is never written to our database, never persisted to disk on our infrastructure, and is discarded the moment the extraction call returns (typically within thirty seconds). Names of individuals, regulatory agencies, dollar amounts, dates, and contract language are categorically excluded from extraction.
  • We do not collect or store confidential client documents, attorney-client privileged communications, or the contents of client matters beyond the profile information you choose to enter.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the Speider platform.
  • Generate your legal intelligence pulls based on your client profiles.
  • Process your subscription payments and manage your account.
  • Send you service-related communications including account confirmations, security alerts, and support responses.
  • Detect, investigate, and prevent security incidents, fraud, and abuse.
  • Comply with applicable legal obligations.

We do not use your information to train AI models. We do not sell your information to third parties. We do not use your client profile information for any purpose other than delivering your pulls.

3. How We Share Your Information

We share your information only in the following limited circumstances:

Service providers

We use a small number of third-party vendors to operate the platform. These vendors process your data only on our instructions and are contractually prohibited from using it for their own purposes:

  • Anthropic: AI model provider that processes your inputs to generate pull outputs, including running web searches on your behalf when needed. Anthropic does not train its models on your data under our agreement.
  • Voyage AI: Embedding provider used for semantic matching. Receives article text and search terms derived from your Client Lens, and returns only numerical vectors. Voyage AI does not train its models on your data and does not retain it after processing, under our account settings with them.
  • Supabase: Managed PostgreSQL database, authentication, and row-level security.
  • Vercel: Hosting and serverless function infrastructure. Processes HTTP requests on our behalf; no user data is stored on Vercel beyond the duration of a single request.
  • Stripe: Payment processing for subscription billing. Stripe stores cardholder data on its own infrastructure; Speider does not store complete payment card numbers on its systems.

Legal requirements

We may disclose your information if required to do so by law, court order, or valid legal process, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Speider, our users, or the public.

Business transfers

If Speider is acquired, merges with another company, or transfers its assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy.

We do not share your information with advertisers, data brokers, or any third party for marketing purposes.

4. Data Retention

We retain your account and profile information for as long as your account is active. If you delete your account from the dashboard, your profile data is wiped immediately as part of the deletion (pulls, lenses, profile rows, Stripe customer record, and authentication user record are all removed in a single operation). In other termination scenarios (for example, if we close your account for non-payment or if your Stripe subscription lapses without you initiating a dashboard deletion), we delete your profile data within 30 days, except where we are required to retain it by law or to resolve a pending dispute.

Uploaded documents are never written to our database. They exist only in serverless function memory for the duration of one parse call (typically under thirty seconds) and are discarded the moment that call returns. Usage and log data is retained for as long as operationally needed for security, debugging, abuse prevention, and platform integrity; we do not retain log data indefinitely.

We keep a security log of sensitive actions for twelve months, and this outlives account deletion. The log records that an action happened, not what it concerned: an account identifier, the action (for example a data export, an account deletion, or a request for a record belonging to another account), the endpoint, and a timestamp. It never contains client names, document contents, or briefing text. We keep it because it is how we would establish what happened during a security incident, which is often discovered months after the fact, and deleting it on request would let an account erase its own trail. Twelve months after the entry is written it is deleted automatically.

5. Security

Speider's hosting providers implement industry-standard security practices. Stored data is encrypted at rest by our database provider; data in transit is protected by TLS. Supabase, our database and authentication provider, maintains SOC 2 Type II compliance. These are baseline infrastructure practices common to modern hosted services, not unique features of Speider.

Within Speider, access to user data is restricted by per-account database-level isolation (row-level security). No user's data is accessible to any other user. For a full description of our security architecture, see our Security page.

If you believe your account has been compromised, contact us immediately at hello@speider.ai.

6. Your Rights and Our Compliance Commitments

Speider's role under privacy law

Speider acts as the data controller for personal information collected directly from you in connection with operating the Service (account registration, billing, support, security, platform usage). For information you upload about your clients (counterparty names, business descriptions, regulatory exposure, contractual obligations, and similar profile data), Speider acts as a data processor on your behalf. You, as the lawyer or organization using the Service, are the controller of that data and remain responsible for compliance with your own professional and legal obligations, including rules of professional conduct governing client confidentiality.

Your rights as a data subject

You have the following rights with respect to personal information we hold about you:

  • Right of access: Request a copy of the personal information we hold about you. You can also download it yourself at any time from your Account page.
  • Right to rectification: Correct inaccurate or incomplete information in your account.
  • Right to erasure: Request deletion of your account and associated personal data, subject to legal retention obligations.
  • Right to restriction of processing: Limit how we use your data in specific circumstances.
  • Right to data portability: Receive your data in a portable, machine-readable format. Your Account page exports it as a JSON file on demand.
  • Right to object: Object to processing based on our legitimate interests.
  • Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
  • Right to non-discrimination: Exercise these rights without facing discrimination or denial of service.

You can exercise your right of access and data portability yourself, right now, by downloading your data from your Account page. For any of the other rights, email hello@speider.ai. We will respond within 7 days, or such shorter period as required by applicable law. You may also lodge a complaint with the data protection supervisory authority in your jurisdiction.

Legal basis for processing (GDPR / UK GDPR)

If you are located in the European Economic Area or the United Kingdom, the legal basis for our processing of your personal information depends on the purpose:

  • Service delivery and account management: Performance of our contract with you (Article 6(1)(b)).
  • Subscription billing and payment processing: Performance of contract and compliance with legal obligations (Articles 6(1)(b) and 6(1)(c)).
  • Security, fraud prevention, abuse detection, and platform integrity: Our legitimate interests in protecting the Service and its users (Article 6(1)(f)).
  • Service-related communications and operational improvements: Performance of contract and legitimate interests (Articles 6(1)(b) and 6(1)(f)).
  • Legal compliance: Where required by applicable law, court order, or valid legal process (Article 6(1)(c)).

International data transfers

Speider hosts its infrastructure in the United States. If you access the Service from the European Economic Area, the United Kingdom, or another jurisdiction with cross-border data transfer restrictions, your personal information will be transferred to and processed in the United States. Speider relies on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and other applicable transfer mechanisms with its subprocessors to provide appropriate safeguards for such transfers. A copy of the relevant clauses is available on request at hello@speider.ai.

Categories of personal information (CCPA / CPRA)

Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), we disclose the following categories of personal information we have collected in the preceding 12 months:

  • Identifiers: Name (if provided), email address, account identifier, IP address.
  • Customer records: Billing and contact information.
  • Commercial information: Subscription status, billing history, transaction records.
  • Internet or other electronic network activity: Usage logs, session activity, pages and features accessed within the Service.
  • Geolocation data: Approximate location derived from IP address (city or region level only; we do not collect precise geolocation).
  • Professional or employment-related information: Lawyer role, practice area, and client type, as you have provided.

We do NOT collect: biometric information, audio or video recordings, education records, precise geolocation, or sensitive personal information as defined in Civil Code § 1798.140(ae) beyond what you choose to disclose. We do NOT sell personal information, and we do NOT share personal information for cross-context behavioral advertising as those terms are defined under California law.

California residents have the right to know, the right to delete, the right to correct, the right to portability, the right to limit use of sensitive personal information (not applicable to our processing), and the right to non-discrimination for exercising these rights. To submit a California privacy request, contact hello@speider.ai. You may also designate an authorized agent to submit a request on your behalf; we will require reasonable verification of the agent's authorization.

Breach notification

In the event of a personal data breach that creates a risk to your rights and freedoms, Speider will notify affected users without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Notification will include, to the extent known, the nature of the breach, the categories of data affected, the likely consequences, and the measures we have taken or propose to take.

EU representative and Data Protection Officer

Speider does not currently process personal data at a scale or in categories that require the designation of a dedicated Data Protection Officer or appointment of an EU representative under Article 27 of the GDPR. EU and UK data subjects may direct all privacy inquiries to hello@speider.ai. If our processing scale or categories change such that designation becomes required, we will update this Policy.

7. Cookies and Tracking

We use cookies and similar technologies for authentication, session management, and basic usage analytics. We do not use third-party advertising cookies or tracking pixels. You can control cookie settings through your browser, though disabling certain cookies may affect platform functionality.

8. Children

Speider is a professional research tool intended exclusively for use by adult legal professionals, paralegals, and authorized members of legal teams. The Service is not directed at, designed for, or available to minors. We do not knowingly collect personal information from anyone under 18 years of age. If you become aware that a minor has provided personal information to Speider, contact us at hello@speider.ai and we will delete the information promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice in the platform before the changes take effect. The effective date at the top of this page reflects when the current version was last updated. Your continued use of Speider after the effective date of a revised policy constitutes your acceptance of the changes.

10. Contact

Questions about this Privacy Policy or how we handle your data:

hello@speider.ai

Questions? Email hello@speider.ai or read our Security page.

Try it free