AI POLICY
AI Policy
This policy explains how Spock uses artificial intelligence: which models we run, what happens to your data, how autonomous features are controlled, and what we expect from you. It supplements the Terms of Service, Privacy Policy, and DPA.
1. The models we use
Spock routes your requests to the AI model you (or your workspace) select:
- The Spock model — our own model, self-hosted on Spock-managed EU infrastructure. Content processed with the Spock model never leaves the EU and never touches a third party.
- Third-party frontier models — from OpenAI, Anthropic, Google, and xAI, and hosted open-source models via Fireworks AI, all processed in the United States under Standard Contractual Clauses.
- Supporting models — Google’s models also power optional image generation and voice-note transcription; document OCR runs on self-hosted models on our own infrastructure.
The current model line-up is visible in the product. We may add, upgrade, or retire models; the provider list is maintained on the Trust Center and changes are announced per the DPA.
2. Your data is never training data
- Spock does not train, fine-tune, or otherwise develop AI models using your content. This is a non-derogable contractual commitment with a refund remedy (DPA §8).
- Every third-party AI provider we use is bound by API terms and data-processing agreements that prohibit training on your data.
- Third-party providers may retain request data transiently — up to 30 days — solely for abuse monitoring, after which it is deleted. The Spock model retains nothing beyond our standard application logs.
3. Choosing where your data goes
Model selection is data-flow selection:
| You select | Your prompt and context go to |
|---|---|
| Spock model | Spock EU infrastructure only |
| OpenAI / Anthropic / Google / xAI / open-source models | The respective US provider, for that request |
Workspace administrators can steer model availability for their teams. If data residency is critical for you, use the Spock model.
4. Autonomous features and human oversight
Spock includes agents that can act with a degree of autonomy: multi-step task execution, tool use (web search, file operations, code execution, connected apps), scheduled automations, and channel interactions (e.g. WhatsApp).
Our controls:
- You configure it, you can see it. Automations run only as configured by you or your workspace; runs and outputs are visible in the product.
- Approval gates. Sensitive tool actions can require explicit user approval before execution.
- Sandboxing. Code runs in isolated sandboxes with time and resource limits.
- Scoped access. Agents reach third-party systems only through the integrations you connect and can act only within the permissions you granted.
Your responsibilities (from the Terms): review agent output before relying on it; do not configure agents to take actions you would not be permitted to take yourself; do not use the Service for decisions with legal or similarly significant effects on people without meaningful human review, for medical diagnosis, or for unsupervised financial trading.
5. Accuracy and limitations
Large language models generate probabilistic output. They can be wrong, incomplete, outdated, or biased — sometimes convincingly so. Spock adds grounding (retrieval from your files, web search with citations) to reduce this, but no system eliminates it. Verify important outputs, especially anything used for professional, financial, medical, or legal purposes. AI output is not professional advice.
6. Provenance and disclosure
Content generated by Spock is AI-generated. Where you share or publish Spock outputs, you are responsible for any disclosure obligations that apply in your context (for example, not passing off AI output as human work where that would be deceptive, per the Terms’ acceptable-use rules).
7. Regulatory posture
- EU AI Act: Spock integrates general-purpose AI models from third-party providers and its own hosted model; we are not a provider of a high-risk AI system, and the Service’s terms prohibit uses that would fall into prohibited-practice categories. We monitor our obligations as a downstream provider/deployer and will update this policy as guidance evolves. Transparency information about the models we use is available on request for customers’ own AI-governance and AI-literacy obligations.
- GDPR/POPIA: AI processing of personal data follows the Privacy Policy and DPA, including the profiling disclosure for Spock’s memory feature and your right to object.
8. Questions
AI governance and model questions: support@spock.chat. Enterprise customers can request provider documentation packs (DPAs, no-training terms, TIAs) for vendor review.