Privacy policy
Last updated: 20 August 2026
Controller: Spairc AI Limited (CRO 822274), K27 Drinan Enterprise Centre, Feltrim Road, Swords, County Dublin, K67 WF58, Ireland. Privacy contact: sean@spairc.ai.
This policy covers the Spairc product (app.spairc.ai) and the spairc.ai website, including the waiting list.
1. What we process, and why
| Data | Examples | Purpose | Legal basis |
|---|---|---|---|
| Account data | Name, email, password hash, workspace membership, role | Operate your account | Contract |
| Customer content | Brand profiles, briefs, photos, logos, generated posts | Provide the service | Contract |
| Connection data | Social account identifiers and scheduling tokens | Publish approved posts | Contract |
| Billing data | Subscription status, trial dates, Stripe customer reference | Trials and billing | Contract |
| Usage data | Generation counts, quota usage | Fair use, billing | Contract / legitimate interest |
| Engagement data | Comments and messages received on your connected accounts | The inbox and reporting features | Contract |
| Technical | IP address, logs, error reports, rate-limit counters | Security, debugging | Legitimate interest |
| Alerts, invitations, verification, trial reminders | Operate the service | Contract | |
| Waiting list | Name, business, email (website form) | Contact you about launch | Consent |
We do not sell personal data or use it for advertising. Generated content is produced from the material you provide; our AI providers process it to generate your content and we use them under terms that do not permit training on your data. Payment card details are collected and stored by Stripe only; they never touch our servers.
2. Subprocessors
| Subprocessor | Role | Location |
|---|---|---|
| Vercel Inc. | Application hosting and file storage | US company, SCCs |
| Neon Inc. | Postgres database | Frankfurt, Germany |
| Anthropic | AI copy generation (Claude) | US, SCCs |
| AI image generation (Gemini) | US/EU, SCCs | |
| Pexels | Stock imagery search | US, SCCs |
| Kaleido AI GmbH (remove.bg) | Image background removal | Austria (EU) |
| Ayrshare Inc. | Social scheduling and publishing | US, SCCs |
| Stripe Payments Europe Ltd | Payments and subscriptions | Dublin, Ireland |
| Resend | Transactional email | US, SCCs |
| Inngest Inc. | Background job processing | US, SCCs |
| Functional Software Inc. (Sentry) | Error monitoring | EU region |
We will update this list and notify workspace owners before adding subprocessors that process customer content.
3. Retention
- Account data: while your account exists. You can delete your account from Settings; sole-owner workspaces are erased with it.
- Customer content: while the workspace exists; deleted 30 days after termination (export available first, from Settings or on request).
- Inbox items (comments and messages pulled from your connected accounts): 90 days.
- Logs, error reports and raw analytics payloads: 90 days. Resolved feedback reports: 180 days. Audit logs: 2 years.
- Database backups: a rolling point-in-time recovery window, after which deleted data ages out.
4. Your rights
You have GDPR rights of access, rectification, erasure, restriction, portability, and objection. You can export your data and delete your account directly from Settings, or contact sean@spairc.ai; we respond within one month. You may also complain to the Data Protection Commission (dataprotection.ie).
For personal data appearing inside customer content (for example, a customer comment or direct message shown in your inbox, or a testimonial naming a person), the customer workspace is the controller and we act as processor on its instructions. A data processing agreement covering these terms is available on request from sean@spairc.ai.
5. Security
Access to production systems is restricted and credentialed; passwords are hashed; scheduling tokens are stored encrypted; tenant data is isolated per workspace at the query layer; transport is TLS throughout. Media files are served from long, unguessable URLs. We will notify affected customers without undue delay of any personal data breach, as required by GDPR Articles 33 and 34.
6. Cookies
The app uses only strictly necessary cookies (session authentication, theme preference). The marketing website sets one optional analytics cookie (Google Analytics) only if you consent through the cookie notice; declining changes nothing about how the site works.