Skip to main content
Skip to main content

Privacy Policy

Version 2026-07-08 · Last updated 8 July 2026

This document is provided for transparency and is not legal advice. Engage qualified counsel before relying on it for compliance decisions.

Who we are

Spine (Antler hackathon project) operates Spine. For privacy questions contact spine-ai.dev@proton.me.

We do not currently appoint a Data Protection Officer. We will publish one if required by law.

What we collect

Account data: email address and authentication credentials (hashed by our auth provider).

Product data: pipelines, documents you upload, inference runs, logs, billing metadata, and feedback you submit.

Early-access diagnostics: while the product is in early access we may log signed-in usage events to help us fix bugs — including buttons you click, text you type into form fields (up to 2,000 characters per field), tab navigation, pipeline step changes, log views, LLM call metadata, and error messages shown in the app. This is disclosed here and in our Terms; we use it only to operate and improve reliability, not for advertising.

Technical data: essential session cookies, IP address, and request logs needed to operate and secure the service.

Landing page demo (no account required): the full text of the automation task you submit, a short preview of the generated pipeline message, model and token-usage metadata, build identifiers, a one-way hash of your IP address for abuse prevention, and — after you accept the demo privacy banner — a session replay recording of the landing page (DOM mutations, clicks, and typed text via rrweb) so we can debug demo failures.

  • We do not require health, biometric, or children's data to use the core product or the public demo.
  • Do not enter personal, confidential, or special-category data (e.g. health, legal, or financial records) into the landing page demo — it is logged and sent to an LLM provider to generate a preview.
  • If you upload special-category data to a signed-in account (e.g. health or legal documents), you are responsible for having a lawful basis to do so.

Why we process data

We process personal data only for the purposes below.

  • Provide and secure the service (contract / legitimate interests).
  • Authenticate users and prevent abuse (legitimate interests).
  • Operate the public landing page demo, enforce rate limits, and maintain a separate demo budget (legitimate interests).
  • Process payments via Stripe (contract).
  • Send service emails such as confirmations and security notices (contract / legitimate interests).
  • Send marketing only if you opt in (consent — withdraw any time in Settings or by emailing us).
  • Improve reliability, understand common demo use cases, and debug issues using aggregated diagnostics (legitimate interests).
  • During early access, record per-user activity timelines and billing flow for operator debugging when you use a signed-in account (legitimate interests — see What we collect).
  • Record landing-page session replays after demo privacy consent to diagnose demo UX and pipeline-build failures (consent / legitimate interests).

Landing page demo

The marketing site at Spine lets visitors describe an automation task and receive a generated pipeline preview without creating an account.

When you use this demo we record your submitted task (up to 2,000 characters), the model response summary, pipeline name, build identifier, token counts, estimated cost, latency, and a salted hash of your IP address.

After you accept the demo privacy banner we also record a session replay of the landing page using rrweb (page structure, clicks, scrolls, and form input — passwords are masked). Replays are stored with your demo email and IP hash so we can reproduce bugs; they are not used for advertising.

Your prompt is transmitted to our LLM inference provider (OpenRouter and the underlying model provider) solely to produce the preview. We do not use landing demo prompts to train our own models.

Before you can click Generate, you must accept via the banner at the bottom of the page confirming you have read this Privacy Policy (version 2026-07-08) and agree that your task text will be logged and sent to an LLM, and that a session replay may be recorded, as described above.

Lawful basis: your consent when you click I accept, plus legitimate interests in preventing abuse and maintaining service reliability.

We do not sell landing demo data. We do not use it for advertising profiles.

  • Do not submit passwords, API keys, personal identifiers, or confidential business data.
  • You must be at least 16 years old (or the age of digital consent in your country, if higher) to use the demo.
  • To request deletion of a landing demo log entry or session replay, email us with the approximate time of your request and, if possible, the task text or email you submitted.

Sub-processors

We use vetted vendors that process data on our behalf under data-processing terms where required.

  • Supabase — authentication and database hosting (including landing demo call logs).
  • Stripe — payment processing (card data is handled by Stripe; we do not store full card numbers).
  • OpenRouter / model providers — LLM inference when you run pipelines or use the landing demo (prompts and outputs you send).
  • Upstash — rate-limit counters keyed by IP or session (when configured).
  • Vercel — application hosting and delivery.

International transfers

Some providers may process data in the United States or other countries outside your region.

Where required, we rely on appropriate safeguards such as Standard Contractual Clauses and vendor DPAs.

Retention

We keep account and project data while your account is active.

After account deletion we remove or anonymise personal data within 30 days, except where law requires longer retention (e.g. billing records).

Landing demo logs and landing-page session replays are kept for up to 12 months, then deleted or aggregated for statistics. You may request earlier deletion by email.

Early-access usage event logs are kept for up to 12 months, then deleted or aggregated. You may request deletion by emailing us from your account email.

Cached inference results may be deleted sooner via cache controls in the product.

Your rights

Depending on your location you may have rights to access, correct, delete, restrict, port, or object to processing.

California and other US state residents may have additional rights (e.g. to know, delete, and correct personal information, and to opt out of sale or sharing — we do not sell personal data).

Email spine-ai.dev@proton.me to exercise these rights. We respond within one month (or the shorter period required by applicable law).

You may lodge a complaint with your local supervisory authority.

Automated processing & AI

The product runs LLM-based pipeline steps you configure. Outputs are not professional advice.

The landing page demo uses the same class of automated LLM processing to generate a preview pipeline from your typed task.

We do not make solely automated decisions with legal or similarly significant effects about you.

Human reviewers should verify outputs before relying on them, especially for legal, medical, or financial use cases.

Back to sign in