Safety

What Spica will and won't do

Everyone asks what an AI can do. The question that decides whether you can actually use one is what it is allowed to do without asking you first. Ask Spica™ has a fixed answer, and this page is all of it, plus exactly where your data goes.

The floor that does not move

Spica cannot email your customers, move money, or delete anything. Not even with your permission. Those tools are not wired into her.

The hard floor, not on the dial at any level: moving money, deleting data, signing anything, HR decisions. Those are always, permanently, your click. The floor does not change at any plan or any setting.
What she does

Reads, drafts, lines things up

  • Reads the tools you connect.
  • Drafts replies, quotes and follow-ups in your voice.
  • Lines up what is due, in order.
  • Tells you what is waiting for you.
What stays your click

Anything that leaves or costs

  • The send.
  • The payment.
  • Deleting anything.
  • Signing anything, and HR decisions.

What a refusal looks like

Tell her to auto-pay invoices as they arrive and she will say no. Then she offers you the version that works: every Friday, one list of what is due, in order, so paying takes you five minutes. You still do the paying.

That refusal is not a missing feature. It is the reason the rest of it is safe to switch on. An operator you have to watch is not saving you anything, and an operator that can move money on its own is not an operator. It is a liability.

Above the floor, you set the rope

Spica ships careful and earns trust level by level. Autonomy is granted by you, never assumed, and you can widen it as you learn to trust her.

Level 0: Watch & tell

She observes, summarizes, flags. Where everything starts.

Level 1: Draft & hold

She prepares the work. Nothing leaves without your tap.

Level 2: Act & report

Routine internal work, done and shown in your brief.

Level 3: Autonomous, within limits

Not built yet, and we will say so until it is. The design is opt-in per task, with caps you set, offered only after she has earned it.

Where your data lives

Spica runs on your own computer. Your business data lives there, not on our servers. We cannot see it, and none of it is sent to us.

  • Conversations, notes, files and contacts are written to your own disk.
  • Spica edits your real files in place. There is no upload step and no second copy held anywhere.
  • The access tokens for accounts you connect are stored on your disk, encrypted, and tied to your user account on that computer.
  • She never sees your passwords. Logins happen in each service's own secure window.

What leaves your machine, all of it

If a tool has AI in it, something leaves your machine, because the thinking has to happen somewhere. The useful thing is a company that tells you exactly where. This is the complete list.

  1. The AI provider, on your own account

    When Spica thinks, the relevant part of your work goes to Anthropic, using your own key, under your own account and your own agreement with them. Same as if you had typed it into their app yourself. We are not in the middle of that and we never see it.
  2. Extra AI models, only if you turn on Council

    Council asks several AI models the same question. It is off until you add your own keys. When it is on, your question also goes to Google, OpenAI and xAI, under your own accounts with them. One setting switches all third-party models off.
  3. The services you connect

    Anything you connect, like Stripe, is read from that service directly, from your machine, using the access you granted. Nothing is proxied through us.
  4. Web pages and web searches

    Spica can read a web page and run a web search while answering you, at every trust level, without stopping to ask. These are not limited to an approved list of sites today. If you need a fixed list of permitted domains, tell us before you buy.
  5. A subscription check

    On a subscription, Spica periodically checks with us that it is still active. That sends your licence and nothing else: no files, no prompts, no usage counts, no business data. If the check fails, nothing changes and nothing is deleted.
The optional phone app. A phone away from home cannot reach your computer without something in the middle, so phone traffic passes through a small relay we operate. Your phone and your computer agree an encryption key the relay never sees. We route that traffic and cannot read it. If that is more than your setup allows, leave the phone app off and the desktop app stays exactly as private as described above.

What does not happen

  • No telemetry. No usage reporting, no analytics and no crash reporting to us from the app.
  • No training on your data by us. We do not receive your data, so we could not train on it. What the AI providers do is governed by your agreement with them.
  • No shared database. There is no multi-customer store. Your install is yours alone.

What we do not claim

  • No SOC 2. We are an early-stage company and will not claim a certification we do not hold.
  • HIPAA needs a conversation. The agreements that matter are between you and Anthropic, because that is who processes the text. We can tell you exactly what is sent. We cannot sign for Anthropic.
  • ITAR, CUI and similar regimes are not supported yet. If that is you, talk to us before buying rather than after.
  • It does not run offline. The AI models are cloud services.

Something not answered here? Email support@askspica.com. A wrong answer is worse than no answer, so we will check and answer precisely.

Try her on your own work

The quickest way to see where the floor sits is to run Spica on your own business and watch what she asks before she acts.

See plans and start your free trial

14-day free trial on every plan. No charge until it ends, cancel anytime.