Legal

Privacy Policy

Last updated: 25 September 2026 Effective: 25 September 2026 Company: Ask Spica LLC

1. The short version

Spica is software you install on your own Windows computer. It is not a website you log into and it is not a service that stores your business on our servers. There is no Spica server holding your customer list, your invoices, your messages or your notes, because there is no Spica server in the product at all.

That means the honest answer to "what does Spica the company collect about my business?" is: almost nothing. We do not have a copy of your data. We cannot look at it. If you asked us to produce everything we hold about your business, the answer today would be your billing details and whatever you have sent us directly, such as a support email.

Three things do leave your computer, and they are the parts worth reading carefully:

  1. When Spica thinks, your question and the relevant context are sent to your AI provider, under your own account with that provider. See section 4.
  2. When you connect a business tool such as Stripe or QuickBooks, information flows from that tool to your computer. See sections 5 and 5A.
  3. If you enter your email on our website, we keep it so we can contact you. See section 9.

Everything else stays on your machine.

2. Who this policy covers

This policy covers two different things, and it is worth keeping them apart:

Where a section applies to only one of them, it says so.

3. What stays on your computer

When you install Spica, the installer places a workspace folder in your Windows user profile named my-business. That folder holds Spica's operating instructions, playbooks, routines and the memory files she builds about your business as you work together. It is an ordinary folder. You can open it, read it, edit it, back it up, or delete it, the same as any other folder you own.

Other Spica files live in these places on your machine:

WhatWhere
Your workspace, memory, drafts and notesYour user profile, in a folder named my-business
App state such as routines and settingsThe Spica application folder on your machine
Meeting transcripts and recordings you import or recordThe application's local data folder
Files you attach to a conversationA local uploads folder
Conversation historyYour local configuration folder
Your AI key and your connection tokens, encrypted%LOCALAPPDATA%\Spica

None of these locations are on our infrastructure. We have no ability to read them, list them, or recover them. If your hard drive fails and you have no backup, we cannot restore your Spica data, because we never had it.

The Spica application listens only on 127.0.0.1, which is the address a computer uses to talk to itself. Other devices cannot reach it, including other devices on your own network, unless you deliberately turn on the optional phone feature described in section 7.

4. What is sent to your AI provider, and why this is the important section

Spica is powered by an AI model that does not run on your computer. When you ask Spica to do something, that request has to go somewhere to be answered. This is the single most important thing to understand about the product's privacy, so it is stated plainly:

When you give Spica a task, your prompt and the information she needs to complete it are transmitted over the internet to your AI provider. Today that provider is Anthropic, the maker of Claude.

What goes with the request can include:

This is not optional and it is not a setting. It is how the product works. Any AI assistant that gives useful answers about your business has to be given information about your business.

You bring your own key, and that changes the relationship. You create an account directly with Anthropic, you generate an API key in their console, and you paste it into Spica once. From that point:

Spica shows you the cost of each request, reported back by the provider, so you can see what you are spending as you go.

Web search and fetching pages

At every trust level, Spica can search the web and fetch a web page when a task calls for it. When that happens, the search terms or the page address travel to the AI provider's search infrastructure and, for a fetch, to the website being fetched. Those websites and search providers have their own privacy practices, which we do not control.

Additional AI providers, if you choose to add them

Spica includes an optional feature, sometimes called a council or a second opinion, that lets Spica ask an additional AI provider such as OpenAI, Google or xAI to look at a question independently and then tell you where the answers agree and disagree.

This feature is optional and off until you turn it on. It requires you to supply your own key for that provider. Nothing is sent to any additional provider unless you have supplied a key for it and asked for that feature. The provider bills you directly, and your data is handled under your agreement with that provider. A data-boundary setting lets you disable third-party AI models entirely, and for managed machines an administrator can lock that setting on. We will update this policy before adding any new provider, and we will name each provider here.

5. Business tools you choose to connect

Spica can connect to business systems you already use, so she can see what is going on without you opening five dashboards. Connecting anything is always your decision and always your action. Spica cannot connect an account by herself.

Available today:

Not yet available: Microsoft 365, Gmail, Outlook, Outlook Calendar and NetSuite appear in the product as tiles you can register interest in. They are not connectable yet.

Three facts about every connection

  1. They are read-only. Every call Spica makes to a connected service is a read. There is no write path in the connector code. Spica cannot move money in Stripe, issue a refund, message a contact in GoHighLevel, move a deal, create or delete a calendar event, or create, edit or pay an invoice or bill in QuickBooks. The setup steps also walk you through granting only read permissions, so the credential itself has no ability to change anything.
  2. Data flows from the third party to your computer, and stops there. Spica reads your Stripe balance or your pipeline directly from that provider to your machine. It does not pass through us. We do not receive it, store it, or aggregate it.
  3. The credentials are encrypted on your machine and never leave it, except to go back to the service they belong to. See section 6.

Once information from a connected service is on your computer, Spica may include it in a request to your AI provider if a task requires it, exactly as described in section 4.

Each connected service has its own privacy policy and its own terms. Connecting them does not change your relationship with them, and we are not a party to it.

5A. QuickBooks Online (Intuit) data

Intuit / QuickBooks disclosure

If you connect QuickBooks Online, this section describes exactly what Spica accesses, why, where it goes, how it is stored, and how to disconnect. It reflects how the software actually behaves.

6. How keys and tokens are protected

Your AI key and every connector token are protected the same way:

For the sign-in style connections such as Google Calendar and QuickBooks, what gets stored is a refresh token, encrypted the same way. Short-lived access tokens are created in memory when needed and are never written to disk.

We want to be plain about the limit of this. DPAPI protects the credential against another user account or another machine. It does not protect against malicious software running as you, on your computer, with your privileges. That is true of every credential store on Windows, and it is why keeping your machine free of malware matters.

7. The optional phone feature

Spica includes an optional feature that lets you read your daily brief on your phone over your local network. It is off unless you turn it on. With it off, nothing in the product listens to your network at all.

If you turn it on, here is exactly what happens:

One honest limitation, stated here rather than buried: pair only on a home or office network you control. The feature is off by default and turning it off leaves the desktop application exactly as private as it was.

8. Telemetry, analytics and crash reporting

There is none. This was checked against the source code rather than assumed, and it is worth saying clearly because it is unusual:

If we ever add any form of telemetry, we will say so here first, we will describe exactly what it sends, and it will be something you can turn off.

Support

If you contact us for help, whatever you choose to send us is what we see. We ask that support information contain diagnostics only: error messages, version numbers, and what you were doing. It should never contain your business data, message contents, memory files or credentials. If you send us something you did not mean to send, tell us and we will delete it. You can reach support at support@askspica.com.

9. Our website and waitlist

Our website is a normal website and this is the one place where we, the company, do collect something.

10. Billing

To subscribe to Spica you have to pay for it, which means a payment processor handles your card details. Payments are processed by Stripe. We never see or store your full card number; Stripe handles card data under its own terms and privacy policy.

11. How long data is kept, and how to delete it

On your computer. Spica's files stay on your machine until you delete them. There is no automatic expiry, because these are your working files and deleting an owner's business records without being asked would be wrong. To remove everything:

  1. Disconnect your AI key and any connected services from inside Spica. This deletes the stored credentials.
  2. Uninstall the application, which removes the shortcuts and the background start-up task.
  3. Delete the my-business workspace folder in your user profile, and the Spica folder in %LOCALAPPDATA%.

After that, nothing of Spica remains, and there is nothing for us to delete on our side, because we never held it.

On our side. What we hold is your billing record and your email address, plus any support correspondence you sent us. To have those deleted, contact us at the address in section 14. Billing records are kept for as long as tax and accounting law requires.

With your AI provider and your connected services. Data you sent to Anthropic, or that lives in Stripe, GoHighLevel, QuickBooks or another connected service, is governed by your agreement with each of them. Deleting Spica does not delete anything on their side. You would go to each of them directly.

12. Your rights

Depending on where you live, you may have rights to see what personal information a company holds about you, to correct it, to delete it, and to opt out of its sale.

We do not sell personal information.

The practical position is that we hold very little about you: your email address, your billing record, and any support correspondence. To exercise any right, contact us at the address in section 14 and we will respond within the timeframe required by the law that applies to you (generally 30 to 45 days).

13. Children

Spica is a business tool sold to business owners. It is not directed at children and is not intended for anyone under 18. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.

14. Contact us

Ask Spica LLC
Email: support@askspica.com

15. Changes to this policy

If we change how the product handles data, we will update this policy and change the "last updated" date at the top. For any change that meaningfully affects what leaves your computer, we will tell you before it takes effect rather than after. Adding an additional AI provider, as described in section 4, is exactly that kind of change and will be announced in advance.