Privacy Policy
1. The short version
Spica is software you install on your own Windows computer. It is not a website you log into and it is not a service that stores your business on our servers. There is no Spica server holding your customer list, your invoices, your messages or your notes, because there is no Spica server in the product at all.
That means the honest answer to "what does Spica the company collect about my business?" is: almost nothing. We do not have a copy of your data. We cannot look at it. If you asked us to produce everything we hold about your business, the answer today would be your billing details and whatever you have sent us directly, such as a support email.
Three things do leave your computer, and they are the parts worth reading carefully:
- When Spica thinks, your question and the relevant context are sent to your AI provider, under your own account with that provider. See section 4.
- When you connect a business tool such as Stripe or QuickBooks, information flows from that tool to your computer. See sections 5 and 5A.
- If you enter your email on our website, we keep it so we can contact you. See section 9.
Everything else stays on your machine.
2. Who this policy covers
This policy covers two different things, and it is worth keeping them apart:
- The Spica application, which you install and run on your own computer.
- Our website and waitlist, which we do operate, and which is a normal website.
Where a section applies to only one of them, it says so.
3. What stays on your computer
When you install Spica, the installer places a workspace folder in your Windows user profile named my-business. That folder holds Spica's operating instructions, playbooks, routines and the memory files she builds about your business as you work together. It is an ordinary folder. You can open it, read it, edit it, back it up, or delete it, the same as any other folder you own.
Other Spica files live in these places on your machine:
| What | Where |
|---|---|
| Your workspace, memory, drafts and notes | Your user profile, in a folder named my-business |
| App state such as routines and settings | The Spica application folder on your machine |
| Meeting transcripts and recordings you import or record | The application's local data folder |
| Files you attach to a conversation | A local uploads folder |
| Conversation history | Your local configuration folder |
| Your AI key and your connection tokens, encrypted | %LOCALAPPDATA%\Spica |
None of these locations are on our infrastructure. We have no ability to read them, list them, or recover them. If your hard drive fails and you have no backup, we cannot restore your Spica data, because we never had it.
The Spica application listens only on 127.0.0.1, which is the address a computer uses to talk to itself. Other devices cannot reach it, including other devices on your own network, unless you deliberately turn on the optional phone feature described in section 7.
4. What is sent to your AI provider, and why this is the important section
Spica is powered by an AI model that does not run on your computer. When you ask Spica to do something, that request has to go somewhere to be answered. This is the single most important thing to understand about the product's privacy, so it is stated plainly:
When you give Spica a task, your prompt and the information she needs to complete it are transmitted over the internet to your AI provider. Today that provider is Anthropic, the maker of Claude.
What goes with the request can include:
- The words you typed.
- Files from your workspace that Spica read in order to answer, including your memory files and anything you attached to the conversation.
- Spica's operating instructions, which ship as a file in your workspace.
- Results from any business tool you connected, if the task needed them.
- Results from a web search or a web page fetch, if the task needed those.
This is not optional and it is not a setting. It is how the product works. Any AI assistant that gives useful answers about your business has to be given information about your business.
You bring your own key, and that changes the relationship. You create an account directly with Anthropic, you generate an API key in their console, and you paste it into Spica once. From that point:
- The requests go from your computer to Anthropic under your account, not ours.
- Anthropic bills you directly for the usage, at their published prices. We do not add a markup, we do not meter your usage, and we do not resell AI access.
- Your prompts and your data are handled under your agreement with Anthropic, not under this policy. Their privacy policy and terms govern what happens to that data once it reaches them. You should read them; they are published on Anthropic's website at anthropic.com/legal.
- We never receive a copy. There is no relay, no proxy, and no Spica server in the path between your computer and Anthropic.
Spica shows you the cost of each request, reported back by the provider, so you can see what you are spending as you go.
Web search and fetching pages
At every trust level, Spica can search the web and fetch a web page when a task calls for it. When that happens, the search terms or the page address travel to the AI provider's search infrastructure and, for a fetch, to the website being fetched. Those websites and search providers have their own privacy practices, which we do not control.
Additional AI providers, if you choose to add them
Spica includes an optional feature, sometimes called a council or a second opinion, that lets Spica ask an additional AI provider such as OpenAI, Google or xAI to look at a question independently and then tell you where the answers agree and disagree.
This feature is optional and off until you turn it on. It requires you to supply your own key for that provider. Nothing is sent to any additional provider unless you have supplied a key for it and asked for that feature. The provider bills you directly, and your data is handled under your agreement with that provider. A data-boundary setting lets you disable third-party AI models entirely, and for managed machines an administrator can lock that setting on. We will update this policy before adding any new provider, and we will name each provider here.
5. Business tools you choose to connect
Spica can connect to business systems you already use, so she can see what is going on without you opening five dashboards. Connecting anything is always your decision and always your action. Spica cannot connect an account by herself.
Available today:
- Stripe. You create a restricted API key inside your own Stripe dashboard, set only the read permissions Spica needs, and paste it once.
- GoHighLevel. You create a Private Integration Token inside your own GoHighLevel sub-account, tick only the view permissions, and paste it along with your Location ID.
- Google Calendar and QuickBooks Online use a sign-in flow rather than a pasted key. You sign in on Google's or Intuit's own page, so your password never passes through Spica. QuickBooks is covered in detail in section 5A.
Not yet available: Microsoft 365, Gmail, Outlook, Outlook Calendar and NetSuite appear in the product as tiles you can register interest in. They are not connectable yet.
Three facts about every connection
- They are read-only. Every call Spica makes to a connected service is a read. There is no write path in the connector code. Spica cannot move money in Stripe, issue a refund, message a contact in GoHighLevel, move a deal, create or delete a calendar event, or create, edit or pay an invoice or bill in QuickBooks. The setup steps also walk you through granting only read permissions, so the credential itself has no ability to change anything.
- Data flows from the third party to your computer, and stops there. Spica reads your Stripe balance or your pipeline directly from that provider to your machine. It does not pass through us. We do not receive it, store it, or aggregate it.
- The credentials are encrypted on your machine and never leave it, except to go back to the service they belong to. See section 6.
Once information from a connected service is on your computer, Spica may include it in a request to your AI provider if a task requires it, exactly as described in section 4.
Each connected service has its own privacy policy and its own terms. Connecting them does not change your relationship with them, and we are not a party to it.
5A. QuickBooks Online (Intuit) data
If you connect QuickBooks Online, this section describes exactly what Spica accesses, why, where it goes, how it is stored, and how to disconnect. It reflects how the software actually behaves.
- What we access. Read-only access to your QuickBooks accounting data, such as account balances, invoices, bills, and transactions, needed to show you your own financial picture inside Spica.
- Why. Solely to present your own money view to you, the account owner, on your own machine. It is used for nothing else.
- Read-only, by construction. Spica cannot create, edit, pay, or delete invoices, bills, transactions, or any other records in QuickBooks. There is no write path in the connector.
- Where it goes. Your QuickBooks data flows directly from Intuit to your computer over the connection you authorized. It does not pass through Ask Spica's servers. We never receive it, store it, or aggregate it, and we never sell it. Once the data is on your machine, Spica may include relevant parts of it in a request to your own AI provider (Anthropic) if a task you asked for requires it, exactly as described in section 4.
- How the connection is stored. QuickBooks uses a sign-in (OAuth) flow, so your Intuit password never passes through Spica. The resulting refresh token is encrypted at rest on your machine using the Windows Data Protection API (DPAPI), scoped to your Windows user account. Short-lived access tokens are created in memory when needed and are never written to disk. The stored credential never leaves your machine except to talk to Intuit.
- Retention. The encrypted QuickBooks credential stays on your machine until you disconnect or delete it. We hold no copy, so there is nothing for us to retain or delete on our side.
- How to disconnect or revoke access. You can disconnect QuickBooks inside Spica at any time, which deletes the stored credential from your machine. You can also revoke Spica's access at any time from your Intuit account: sign in at accounts.intuit.com, open your account's connected apps / security settings, and remove Spica.
6. How keys and tokens are protected
Your AI key and every connector token are protected the same way:
- Checked before they are stored. Spica checks the format offline, then makes one real read-only call to the service to prove the credential works. A credential that fails is never written to disk.
- Encrypted at rest using Windows DPAPI, scoped to your Windows user account. In practice that means only that Windows user, on that machine, can decrypt them. Copying the file to another computer produces nothing usable.
- Never written in plain text. The stored file contains the encrypted form only.
- Never shown back to you or to the screen. After you paste a key, the product keeps only the last four characters so you can tell two accounts apart.
- Never logged. Error logs that could contain a key have the key pattern stripped out before anything is written.
- Never transmitted to us. A credential goes to exactly one place: the service it belongs to.
- Deletable by you at any time. Disconnecting deletes the stored credential from your machine.
For the sign-in style connections such as Google Calendar and QuickBooks, what gets stored is a refresh token, encrypted the same way. Short-lived access tokens are created in memory when needed and are never written to disk.
We want to be plain about the limit of this. DPAPI protects the credential against another user account or another machine. It does not protect against malicious software running as you, on your computer, with your privileges. That is true of every credential store on Windows, and it is why keeping your machine free of malware matters.
7. The optional phone feature
Spica includes an optional feature that lets you read your daily brief on your phone over your local network. It is off unless you turn it on. With it off, nothing in the product listens to your network at all.
If you turn it on, here is exactly what happens:
- A second, separate, limited server starts. The main Spica application never changes its address and stays reachable only from your own computer. Conversations, terminals, file reads and key management are not served to your phone at all.
- Your phone must pair first, using a short code shown on your computer, which is exchanged once for a device token. Device tokens are encrypted on your computer, and only a hash of the token is stored, so even a defeated encryption yields hashes rather than working credentials.
- Tapping something on your phone records an intent. It does not execute anything. You apply it from your computer.
- A device not seen for 30 days stops being trusted. Every paired device is visible and revocable from your computer.
One honest limitation, stated here rather than buried: pair only on a home or office network you control. The feature is off by default and turning it off leaves the desktop application exactly as private as it was.
8. Telemetry, analytics and crash reporting
There is none. This was checked against the source code rather than assumed, and it is worth saying clearly because it is unusual:
- The application has no analytics library, no crash reporting service and no product telemetry SDK.
- The application does not phone home. It does not check in with us on launch, it does not report usage, and it does not send us error reports.
- Whether your subscription tier is active is decided by reading a local file on your machine. On a paid subscription, Spica periodically confirms the subscription is still active by sending only your signed licence token to our licensing endpoint, and nothing else: no files, no prompts, no usage counts, no business data.
- There is one local diagnostic file the application appends to for troubleshooting. It stays on your computer and is never transmitted.
If we ever add any form of telemetry, we will say so here first, we will describe exactly what it sends, and it will be something you can turn off.
Support
If you contact us for help, whatever you choose to send us is what we see. We ask that support information contain diagnostics only: error messages, version numbers, and what you were doing. It should never contain your business data, message contents, memory files or credentials. If you send us something you did not mean to send, tell us and we will delete it. You can reach support at support@askspica.com.
9. Our website and waitlist
Our website is a normal website and this is the one place where we, the company, do collect something.
- The waitlist form collects your email address. That is the only field a real person fills in. The form contains one hidden field that only automated bots fill in, which we use to discard spam.
- Your email is stored in our customer relationship system, GoHighLevel, tagged as a Spica waitlist signup, so we can contact you when a seat opens.
- We use your email to contact you about Spica. We do not sell it.
- You can ask us to remove you at any time using the contact details in section 14.
- The site loads fonts from Google Fonts, which means your browser makes a request to Google and Google receives your IP address as part of that. We mention it because it is technically a third party receiving something.
- The site is hosted on Vercel, our hosting provider, which keeps standard server logs.
- We have not installed any web analytics on the site, and we do not set advertising or analytics cookies.
10. Billing
To subscribe to Spica you have to pay for it, which means a payment processor handles your card details. Payments are processed by Stripe. We never see or store your full card number; Stripe handles card data under its own terms and privacy policy.
11. How long data is kept, and how to delete it
On your computer. Spica's files stay on your machine until you delete them. There is no automatic expiry, because these are your working files and deleting an owner's business records without being asked would be wrong. To remove everything:
- Disconnect your AI key and any connected services from inside Spica. This deletes the stored credentials.
- Uninstall the application, which removes the shortcuts and the background start-up task.
- Delete the
my-businessworkspace folder in your user profile, and theSpicafolder in%LOCALAPPDATA%.
After that, nothing of Spica remains, and there is nothing for us to delete on our side, because we never held it.
On our side. What we hold is your billing record and your email address, plus any support correspondence you sent us. To have those deleted, contact us at the address in section 14. Billing records are kept for as long as tax and accounting law requires.
With your AI provider and your connected services. Data you sent to Anthropic, or that lives in Stripe, GoHighLevel, QuickBooks or another connected service, is governed by your agreement with each of them. Deleting Spica does not delete anything on their side. You would go to each of them directly.
12. Your rights
Depending on where you live, you may have rights to see what personal information a company holds about you, to correct it, to delete it, and to opt out of its sale.
We do not sell personal information.
The practical position is that we hold very little about you: your email address, your billing record, and any support correspondence. To exercise any right, contact us at the address in section 14 and we will respond within the timeframe required by the law that applies to you (generally 30 to 45 days).
13. Children
Spica is a business tool sold to business owners. It is not directed at children and is not intended for anyone under 18. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.
14. Contact us
Ask Spica LLC
Email: support@askspica.com
15. Changes to this policy
If we change how the product handles data, we will update this policy and change the "last updated" date at the top. For any change that meaningfully affects what leaves your computer, we will tell you before it takes effect rather than after. Adding an additional AI provider, as described in section 4, is exactly that kind of change and will be announced in advance.