Privacy Policy
Effective August 8, 2026
We use the information we collect to:
We do not use your information to train AI models. We do not sell your information to third parties. We do not use your client profile information for any purpose other than delivering your pulls.
We retain your account and profile information for as long as your account is active. If you delete your account from the dashboard, your profile data is wiped immediately as part of the deletion (pulls, lenses, profile rows, Stripe customer record, and authentication user record are all removed in a single operation). In other termination scenarios (for example, if we close your account for non-payment or if your Stripe subscription lapses without you initiating a dashboard deletion), we delete your profile data within 30 days, except where we are required to retain it by law or to resolve a pending dispute.
Uploaded documents are never written to our database. They exist only in serverless function memory for the duration of one parse call (typically under thirty seconds) and are discarded the moment that call returns. Usage and log data is retained for as long as operationally needed for security, debugging, abuse prevention, and platform integrity; we do not retain log data indefinitely.
We keep a security log of sensitive actions for twelve months, and this outlives account deletion. The log records that an action happened, not what it concerned: an account identifier, the action (for example a data export, an account deletion, or a request for a record belonging to another account), the endpoint, and a timestamp. It never contains client names, document contents, or briefing text. We keep it because it is how we would establish what happened during a security incident, which is often discovered months after the fact, and deleting it on request would let an account erase its own trail. Twelve months after the entry is written it is deleted automatically.
Speider's hosting providers implement industry-standard security practices. Stored data is encrypted at rest by our database provider; data in transit is protected by TLS. Supabase, our database and authentication provider, maintains SOC 2 Type II compliance. These are baseline infrastructure practices common to modern hosted services, not unique features of Speider.
Within Speider, access to user data is restricted by per-account database-level isolation (row-level security). No user's data is accessible to any other user. For a full description of our security architecture, see our Security page.
If you believe your account has been compromised, contact us immediately at hello@speider.ai.
Speider acts as the data controller for personal information collected directly from you in connection with operating the Service (account registration, billing, support, security, platform usage). For information you upload about your clients (counterparty names, business descriptions, regulatory exposure, contractual obligations, and similar profile data), Speider acts as a data processor on your behalf. You, as the lawyer or organization using the Service, are the controller of that data and remain responsible for compliance with your own professional and legal obligations, including rules of professional conduct governing client confidentiality.
You have the following rights with respect to personal information we hold about you:
You can exercise your right of access and data portability yourself, right now, by downloading your data from your Account page. For any of the other rights, email hello@speider.ai. We will respond within 7 days, or such shorter period as required by applicable law. You may also lodge a complaint with the data protection supervisory authority in your jurisdiction.
If you are located in the European Economic Area or the United Kingdom, the legal basis for our processing of your personal information depends on the purpose:
Speider hosts its infrastructure in the United States. If you access the Service from the European Economic Area, the United Kingdom, or another jurisdiction with cross-border data transfer restrictions, your personal information will be transferred to and processed in the United States. Speider relies on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and other applicable transfer mechanisms with its subprocessors to provide appropriate safeguards for such transfers. A copy of the relevant clauses is available on request at hello@speider.ai.
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), we disclose the following categories of personal information we have collected in the preceding 12 months:
We do NOT collect: biometric information, audio or video recordings, education records, precise geolocation, or sensitive personal information as defined in Civil Code § 1798.140(ae) beyond what you choose to disclose. We do NOT sell personal information, and we do NOT share personal information for cross-context behavioral advertising as those terms are defined under California law.
California residents have the right to know, the right to delete, the right to correct, the right to portability, the right to limit use of sensitive personal information (not applicable to our processing), and the right to non-discrimination for exercising these rights. To submit a California privacy request, contact hello@speider.ai. You may also designate an authorized agent to submit a request on your behalf; we will require reasonable verification of the agent's authorization.
In the event of a personal data breach that creates a risk to your rights and freedoms, Speider will notify affected users without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Notification will include, to the extent known, the nature of the breach, the categories of data affected, the likely consequences, and the measures we have taken or propose to take.
Speider does not currently process personal data at a scale or in categories that require the designation of a dedicated Data Protection Officer or appointment of an EU representative under Article 27 of the GDPR. EU and UK data subjects may direct all privacy inquiries to hello@speider.ai. If our processing scale or categories change such that designation becomes required, we will update this Policy.
Speider is a professional research tool intended exclusively for use by adult legal professionals, paralegals, and authorized members of legal teams. The Service is not directed at, designed for, or available to minors. We do not knowingly collect personal information from anyone under 18 years of age. If you become aware that a minor has provided personal information to Speider, contact us at hello@speider.ai and we will delete the information promptly.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice in the platform before the changes take effect. The effective date at the top of this page reflects when the current version was last updated. Your continued use of Speider after the effective date of a revised policy constitutes your acceptance of the changes.
Questions about this Privacy Policy or how we handle your data:
Questions? Email hello@speider.ai or read our Security page.
Try it free