Privacy Policy

Last updated: June 27, 2026

1. Introduction

SpecMake ("we", "us", "our") operates the specmake.com website and document translation service. This Privacy Policy explains how we collect, use, and protect your information when you use our service.

For GDPR purposes, SpecMake is the data controller responsible for your personal data. You can reach us at privacy@specmake.com.

2. What We Collect

We collect and store the following information:

  • Account information: Email address, password (hashed), your chosen role (e.g., engineering, quality/compliance), and optional company name.
  • Source documents: The original PDF, DOCX, or XLSX files you upload. Stored in private Supabase Storage, accessible only via authenticated short-lived signed URLs. Used to power click-to-verify source so you can check any extracted value against the original document.
  • Extracted content: The structured JSON output (fields, values, sections), the full extracted text layer, audit findings, compliance check results, and any images (diagrams, product photos, dimensional drawings) extracted from your documents. All stored in private storage with row-level security — accessible only to you and, if applicable, your team members.
  • Translations and glossaries: Any translated output you generate, along with correction metadata, and any terminology you save to your personal or team glossary.
  • Usage data: Pipeline processing metadata (document type, language pairs, audit coverage, processing duration, model used) for service operation, billing, and quality monitoring.
  • First-party analytics: Page views, the referring domain (not the full URL), UTM parameters, advertising click identifiers that arrive in your own URL (e.g., Google’s gclid/gbraid/wbraid), and anonymous session-level engagement data (e.g., time on results page). A per-session identifier is stored in sessionStorage only — it is deleted when you close the browser tab. We also store a first-party visitor identifier in your browser’s localStorage to understand how visitors find and navigate the site across visits; it is not a cookie, is never shared with third parties, and we load no advertising, cross-site tracking, retargeting, or fingerprinting scripts. For cookieless performance and usage analytics we additionally use Vercel Analytics and Speed Insights — see Section 9.
  • Payment information: Handled entirely by Stripe. We store only your Stripe customer ID — never your card details.
  • Marketing preferences: Whether you have opted in to receive marketing communications, and the date and time of your consent.

3. How We Use Your Data

  • Process and translate your uploaded documents.
  • Maintain your account, document history, and glossary.
  • Track usage against your plan limits.
  • Send transactional and service emails related to your account and the documents you process (e.g., password resets, billing confirmations, processing-complete notifications, and compliance-change alerts that tell you when a regulation we check against changes and affects your products). You can turn compliance-change alerts off in your notification settings.
  • Monitor aggregate service performance and cost.
  • Where you make a business enquiry or apply to a program, we may research your company from publicly available sources (e.g., your company website) to prepare for and respond to your enquiry. This is company-level research used internally to qualify and prioritize enquiries; it relies on our legitimate interest in responding to prospective customers.

4. Marketing Communications

We will only send you marketing emails (product updates, feature announcements, tips for technical documentation) where you have explicitly opted in — for example by subscribing to our updates through a form on our website (such as our newsletter, a launch waitlist, or DPP-readiness updates), by ticking the marketing checkbox during signup, or through your account settings. Requesting a one-off document or results summary by email is treated as a transactional request and does not, on its own, sign you up for marketing.

You can withdraw your consent and unsubscribe at any time by:

  • Clicking the "unsubscribe" link in any marketing email.
  • Updating your preferences in your account settings.
  • Contacting us at privacy@specmake.com.

Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal. Unsubscribing from marketing emails does not affect transactional emails necessary for service operation (e.g., password resets, billing notifications).

5. AI Processing

Your documents are processed using the Anthropic Claude API. Document content is sent to Anthropic's API for extraction, structuring, and translation. Anthropic's API does not use your data for model training. Refer to Anthropic's Privacy Policy for details on their data handling.

6. International Data Transfers

Your data is primarily stored in the EU. However, some of our service providers process data outside the EU/EEA:

  • Anthropic (Claude API): Document content is sent to Anthropic's servers in the United States for AI processing. This transfer is governed by Standard Contractual Clauses (SCCs) as per Anthropic's data processing terms.
  • Vercel: Our website is hosted on Vercel's global edge network, which may serve content from locations outside the EU/EEA. Vercel participates in the EU-U.S. Data Privacy Framework.
  • Stripe: Payment processing may involve data transfer to the United States. Stripe is certified under the EU-U.S. Data Privacy Framework.
  • Resend: Transactional and lifecycle email delivery may involve data transfer to the United States, governed by Standard Contractual Clauses (SCCs).

We ensure that all international transfers of personal data are protected by appropriate safeguards as required by GDPR, including Standard Contractual Clauses, adequacy decisions, or certification under the EU-U.S. Data Privacy Framework.

7. Data Storage & Security

Your data is stored in Supabase (PostgreSQL + Object Storage) hosted in the EU. All data is encrypted in transit (TLS) and at rest.

Database: row-level security policies restrict access so each user can read and write only their own rows. Team members can access shared documents only through their team membership.

File storage (source documents and extracted images): stored in private Supabase Storage. Files are never publicly accessible and are served only via authenticated short-lived signed URLs scoped to a single file.

8. Payments

All payment processing is handled by Stripe. We never receive or store your credit card number, expiration date, or CVC. We only store your Stripe customer ID to manage subscriptions and billing.

9. Cookies, Analytics & Tracking

We use only essential cookies required for authentication (session tokens managed by Supabase Auth). We do not use any advertising, cross-site tracking, or retargeting scripts, advertising cookies, pixels, or fingerprinting.

First-party analytics: we collect a small amount of anonymous usage data to improve the product — page views, the referring domain (not full URL), UTM parameters, advertising click identifiers passed in your own URL (such as Google’s gclid/gbraid/wbraid, used to measure which campaigns lead to enquiries), and session-level engagement (e.g., time spent on the results page). A per-session identifier is generated and stored in browsersessionStorageonly, which is deleted when you close the tab. We additionally store a first-party visitor identifier (a random value) in your browser’slocalStorageso we can understand how visitors find and move through the site across visits, and connect that to an enquiry if you later contact us or sign up. It is not a cookie and is never shared with third parties. You can clear it any time by clearing your browser storage. The data is stored in our own database and is never shared with third parties.

We also use Vercel Analytics and Vercel Speed Insights to measure website usage and performance. These are first-party-style analytics provided by our hosting partner Vercel: they are cookieless, do not use persistent identifiers, do not track you across other websites, and are designed to be GDPR-compliant. They are listed as a sub-processor in Section 12.

10. Data Retention

Your documents, source files, extracted images, translations, and glossary entries are retained for as long as your account is active. You can delete individual documents at any time from your dashboard — deletion removes the database row, the stored source file, and all associated images immediately, within a single server operation.

If you delete your account, all associated data — documents, translations, glossary entries, templates, source files, extracted images, audit data, and usage logs — is permanently deleted, including the underlying stored files in our object storage. We retain only: (a) a minimal, anonymized record that an account was deleted (no email or content), kept as a security and audit record; and (b) aggregated, non-identifying metrics (e.g., total document counts per month) for billing and legal purposes. If you previously asked us not to email you, we keep the minimum needed to honor that request (an unsubscribe suppression entry).

If you contacted us, subscribed, or used a tool without creating an account (for example, requesting your DPP readiness results by email or submitting the contact form), we retain the email address and the related enquiry record for as long as needed to respond and to maintain our marketing-suppression and anti-abuse records, and we delete it on request. You can ask us to delete this data at any time via privacy@specmake.com.

Documents submitted to the anonymous EU DPP readiness check tool at /dpp-check are never saved to our database or file storage — only the immediate processing response is returned, after which no record of the document remains.

11. Your Rights (GDPR)

If you are in the EU/EEA, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate data.
  • Request deletion of your data.
  • Export your data in a portable format.
  • Object to or restrict processing of your data.
  • Withdraw consent at any time (including marketing consent).
  • Lodge a complaint with your local data protection authority.

To exercise any of these rights, contact us at the address below.

12. Third-Party Services (Sub-Processors)

The following service providers act as sub-processors for specific parts of our infrastructure. Each is bound by a Data Processing Agreement (DPA) that meets GDPR requirements.

  • Supabase: Database, authentication, and private file storage (EU).
  • Anthropic (Claude API): AI-powered document processing (US, SCCs). Content is not used for model training.
  • Vercel: Website and serverless function hosting (global edge, EU-U.S. DPF participant). Includes Vercel Analytics & Speed Insights — cookieless usage and performance monitoring with no persistent identifiers.
  • Stripe: Payment processing (US, EU-U.S. DPF certified).
  • Resend: Transactional and lifecycle email delivery (US, SCCs).
  • Cloudflare Turnstile: Optional CAPTCHA on contact forms (global, privacy-first alternative to reCAPTCHA).

A current, detailed list of sub-processors including their contact details and the specific data they process is available on request — emailprivacy@specmake.com.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. Continued use of the service after changes constitutes acceptance.

14. Contact

For privacy-related questions or to exercise your rights, contact us at: privacy@specmake.com