Privacy Policy

Last updated: August 4, 2026

Spectr ("Spectr", "we", "us", or "our") is a product of Crowdlinker Inc., a company incorporated in Ontario, Canada. This Privacy Policy explains how we collect, use, store, and share information about you when you use Spectr's services, including our web application at app.spectr.pm and marketing website at spectr.pm (collectively, the "Service").

By using the Service, you agree to this Privacy Policy. If you do not agree, please discontinue use of the Service.

---

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Name and email address
  • Password (stored as a bcrypt hash - never in plain text)
  • Workspace name and optional profile details
  • Billing information (processed and stored by Polar.sh - we receive subscription status events, not raw payment card data)

1.2 Meeting Transcripts

Spectr's core function is processing meeting transcripts to extract actionable engineering work. We collect:

  • Uploaded transcripts: text, PDF, DOCX, or TXT files you upload directly
  • Imported transcripts and notes: meeting transcripts and notes you import from Fathom or Granola via their APIs when you connect those accounts

Transcripts are stored in encrypted AWS S3 buckets. You can delete any transcript at any time from within the app, which permanently removes it from our storage.

1.3 Integration OAuth Tokens

To connect third-party tools (Linear, Notion, GitHub, Google, JIRA, and Read.ai via OAuth; Shortcut, Fathom, Granola, and Harvest via API keys), we store the OAuth access and refresh tokens or API keys you provide on your behalf. These credentials are:

  • Encrypted at rest using AES-256 encryption before database storage
  • Never returned to the client in API responses - they are read server-side only, on a query-by-query basis
  • Revocable at any time from the Integrations settings page

1.4 AI-Generated Content

Specs, user stories, and AI memory files generated by the Service are stored in our database and S3. These are owned by you and can be deleted at any time.

1.5 Usage Data

We collect standard server logs (IP address, browser type, pages visited, timestamps) to operate and improve the Service. We may also collect anonymised product analytics (feature usage, error rates) using self-hosted tooling.

---

2. How We Use Your Information

  • Providing the Service: Processing transcripts, generating specs and stories, publishing to your project management tool
  • AI processing: Transcripts and project context are processed by Spectr's AI to generate structured output. See Section 4 for details
  • Account management: Authentication, subscription management, billing
  • Customer support: Responding to questions, diagnosing issues
  • Service improvement: Aggregated, anonymised usage analysis to improve features
  • Legal compliance: Responding to lawful requests from authorities where required
---

3. Data Storage and Security

  • All data is stored on AWS infrastructure in the us-east-2 region (Ohio, USA)
  • Data in transit is encrypted with TLS 1.2+
  • OAuth tokens are encrypted at rest with AES-256 before being written to the database
  • Meeting transcripts are stored in S3 with server-side encryption (SSE-S3)
  • Database backups are retained for 7 days
  • Access to production systems is restricted to authorised Crowdlinker engineering personnel
---

4. AI Processing

Spectr uses AI to process your meeting transcripts and generate specs and user stories. All AI processing runs within secure AWS infrastructure - your data is not exposed to third parties for AI processing and is not used to train any AI models.

What is processed by AI:

  • Meeting transcript text (up to 60,000 characters per processing job)
  • Your project description, preferences, and reference files (up to 20,000 characters)
  • Integration context (Notion pages, GitHub context, etc.) you have connected
  • AI memory files from previous sessions (contextual project knowledge you have built up)

What is NOT processed by AI:

  • Your password or authentication credentials
  • OAuth access tokens for third-party integrations
  • Payment information
---

5. Data Sharing and Third Parties

We do not sell your personal data. We share data only as necessary to operate the Service:

  • AWS: Infrastructure hosting (compute, database, storage, AI inference - all within AWS infrastructure)
  • Polar.sh: Subscription billing - they process your payment information under their own privacy policy
  • Fathom, Granola, and Read.ai (if connected): Meeting transcript and notes import only - we read your transcripts and notes via their APIs, scoped to your account
  • Third-party integrations you connect (Linear, Shortcut, Notion, GitHub, Google, Figma, Forecast): We read context from and/or write data to these services on your behalf, using the OAuth tokens or API keys you authorise
  • Atlassian / JIRA (if connected): We read and write issues and read your JIRA project's assignable-user list so we can publish and keep stories in sync on your behalf. Because JIRA user records include personal data (names, email addresses, and Atlassian account IDs), we store only the minimum needed to link and sync assignees, and - as Atlassian's developer policy requires - we report the inventory of Atlassian accounts whose data we hold back to Atlassian through their Personal Data Reporting API. When you disconnect JIRA from a project, we erase that stored Atlassian personal data
  • Harvest (if connected): Project budget and time data - we read your budget and spend figures via their API, scoped to your account
---

6. Cookies

CookiePurposeDurationType
pm_authenticatedClient-side indicator that a session exists, used to show "Go to App" on the marketing site7 daysFunctional
Auth tokens (localStorage)JWT access and refresh tokens for authenticated API requestsSession / 30 daysStrictly necessary

We do not use advertising cookies or sell cookie data to third parties.

---

7. Data Retention

  • Account data: Retained while your account is active. Deleted within 30 days of account deletion
  • Meeting transcripts: Retained until you delete them or close your account
  • AI memory files: Retained until you delete them or close your account
  • Generated specs and stories: Retained until you delete them or close your account
  • Server logs: Retained for up to 90 days
  • Billing records: Retained as required by applicable financial regulations (typically 7 years)
---

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate personal data
  • Deletion: Request deletion of your account and associated data
  • Portability: Request an export of your data in a machine-readable format
  • Objection: Object to certain processing activities
  • Withdrawal of consent: Where processing is based on consent, you may withdraw it at any time

To exercise any of these rights, email hello@crowdlinker.com. We will respond within 30 days.

---

9. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

---

10. International Transfers

Your data is processed and stored on servers in the United States (AWS us-east-2). If you are located in the European Economic Area, United Kingdom, or Canada, your data is transferred to the US in accordance with applicable data protection laws. We rely on standard contractual clauses or equivalent safeguards where required.

---

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top and notify you by email or in-app notification. Continued use of the Service after changes constitutes acceptance of the updated policy.

---

12. Contact Us

For privacy-related questions or requests:

Governing law: Ontario, Canada.