PRIVACY POLICY
Privacy Policy
This policy covers Spock and spock.chat, operated by Seleya Labs Inc., a Delaware corporation. Mailing address: 1111B S Governors Ave STE 56751, Dover, DE 19904, USA. Our team works in South Africa. Seleya’s company website (seleya.ai) and the Seleya Autonomy Index (index.seleya.ai) have their own privacy notices.
Questions and requests: support@spock.chat, or our privacy contact, Louis-Neil Korsten, louis@spock.chat.
1. Who is responsible
Seleya is responsible (the “responsible party” or “controller”) for information it uses for its own purposes: running accounts, billing, security, support and spock.chat.
When an organisation uses Spock, it decides what content goes in and who sees it. For that content, the organisation is responsible and Seleya processes it on the organisation’s behalf, under our Data Processing Agreement. If you use an employer’s or another organisation’s workspace, their privacy notice also applies; contact them about their use, and we will help route your request.
TTL Technologies (Pty) Ltd, Seleya’s wholly owned South African subsidiary, sells and invoices Enterprise subscriptions. It is responsible for its own billing and business records. Team members engaged through TTL support Enterprise customers, with the same access rules and confidentiality duties as the rest of our team.
2. What we collect
| Information | Examples and sources |
|---|---|
| Account | Name, email, a hashed password, and sign-in identifiers if you use Apple, Google or Microsoft sign-in. We never receive your Apple, Google or Microsoft password. |
| Workspace | Memberships, roles, Space settings, sharing and connections. |
| Customer Content | Prompts, conversations, uploads, images, audio, connected files and records, generated documents and outputs, and their search indexes. |
| Memory | Notes Spock keeps from your work so it can continue and personalise it. |
| Hosted computers | Files, output and browser sessions created when Spock runs code or browses for you. |
| Usage and security | IP address, device and browser details, usage and billing measurements, diagnostic records and security logs. |
| Billing | Plan, invoices, billing contact and company details. Stripe handles card details; we never see full card numbers. |
| Messages and channels | Support and feedback emails, and messages on WhatsApp, Telegram or other channels you connect. |
| Notifications | Device tokens if you turn on push notifications. |
It comes from you, your workspace’s members, accounts you connect, documents and websites retrieved for your work, and our systems.
3. Why we use it
| Purpose | Basis |
|---|---|
| Providing your account and the Service, and taking payment | Performance of our contract with you |
| Running organisation accounts, support and business contacts | Our legitimate interest in serving our customers |
| Security, preventing abuse, keeping the Service reliable | Our legitimate interest in protecting people and systems; legal obligations where they apply |
| Accounting, tax and legal records | Legal obligation |
| Product news by email | Your consent, or an existing-customer relationship with an easy opt-out |
| Improving the Service | Our legitimate interest, using usage measurements and aggregated data. Never by training AI on Customer Content |
Under POPIA, the same purposes rest on section 11 (contract, legal obligation, legitimate interests, or consent where needed), and direct marketing follows section 69. You may withdraw consent, unsubscribe or object to legitimate-interest processing at any time.
4. AI, memory and agents
Spock sends the relevant parts of your request, such as the conversation, retrieved passages, files and tool results, to an AI model to produce an answer. It routes work between Seleya’s own models and third-party models, and uses separate providers for search, page reading and some file processing. The providers are listed in the DPA.
Neither Seleya nor its providers use your content to train AI models, unless your organisation asks us in writing to tune a model used only for it. Some providers keep requests for a short time for abuse monitoring, as stated in the DPA.
Spock keeps memory notes from your work so it can pick up where you left off. They are used only to serve you, never for advertising. Ask us to see, correct or delete them.
Hosted computers and their browser sessions can persist between tasks until deleted, and are deleted automatically after 30 days. Agents and automations can read and send information through accounts you connect while you are away, so set their scope with care. A public share link shows its content to anyone who has it.
Spock helps you work; it does not make decisions about people. If you use it for decisions that significantly affect someone, the safeguards and human review the law requires are your responsibility.
5. Who receives information
- Infrastructure: Hetzner (Germany), DigitalOcean (Frankfurt), Amazon Web Services (Frankfurt, and Cape Town for reading South African web pages), Cloudflare (Western Europe and its global network) and Google Cloud (Dallas, for Seleya’s own AI models).
- AI models: OpenAI, Google Gemini and Fireworks, all in the USA; Anthropic and xAI when selected.
- Tools, when used: Serper (search), ZenRows (page reading) and Daytona (hosted computers).
- Operations: Stripe (payments), Cloudflare (email delivery), Slack (internal support alerts) and Google Firebase (push notifications).
- Our team in South Africa, including team members engaged through TTL.
- Apps you connect, under your own accounts and their terms.
- Services you sign in to with Spock: if you use your Spock account to sign in to another service and approve it, we tell that service your Spock account ID and nothing else.
- Advisers, auditors or authorities, when the law requires it or to protect legal rights. We check that any request from an authority is lawful and limited.
We do not sell personal information.
Google user data
When you connect a Google account, Spock accesses Google user data only to carry out a request you make in Spock:
- Gmail: your messages and attachments, to search, read and summarise them, to create drafts, and to send email you approve;
- Google Drive: your files, to search and read them, and to create files you approve;
- Google Docs, Sheets and Slides: to read them and to make edits you approve;
- Google Calendar: your events, calendar list and free/busy information, to answer questions and to make changes you approve.
Nothing is written, changed or sent in your Google account until you approve it in Spock. Google user data is sent to the AI model providers listed above only to produce the result you asked for.
Spock’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we transfer it only to provide or improve the features you use, for security, or to comply with law. We do not use data obtained through Google Workspace APIs to develop, improve or train generalized or non-personalized AI or ML models. No person at Seleya reads your Google user data unless you ask us to (for example, for support), it is needed for security or abuse investigation, or the law requires it.
Google user data stays in Spock only in the chats, files and memory where it was used; deleting them deletes it. OAuth tokens are encrypted at rest. Disconnecting Google in Integrations revokes Spock’s access at Google, and you can also remove it at myaccount.google.com/permissions.
6. International transfers
Seleya is a US company; our team works in South Africa; content is stored in Germany and processed by AI models in the United States. When information leaves South Africa, we transfer it only under binding agreements that give adequate protection, as section 72(1)(a) of POPIA requires, including for information about companies and other juristic persons. Where the GDPR applies, we use an approved transfer mechanism for the specific transfer, such as the EU Standard Contractual Clauses. Ask us for details of the safeguards that apply to you.
7. How long we keep information
| Information | How long |
|---|---|
| Account and Customer Content | While your account or your organisation’s agreement is active. Deleting your account removes your personal workspace at once; content you added to an organisation’s workspace stays with that organisation. Other deletion requests are completed within 30 days. |
| Deleted files | Removed from use at once; storage and search indexes cleared within minutes. |
| Diagnostic copies of AI requests | Up to 30 days, then reduced to records without content. |
| Hosted computers | Deleted after 30 days. |
| Backups | Expire within 30 days, and are never used to bring deleted data back. |
| Provider copies | As listed in the DPA, for example up to 30 days of abuse-monitoring logs at OpenAI. |
| Billing, tax and legal records | As long as the law requires, generally five to seven years. |
Deleting a file removes its stored copies and indexes. Conversations or memory notes that quoted it are separate: ask us and we will find and delete them too. For files synced from a connected source, delete them at the source as well, or a later sync can bring them back.
8. Security
Information is encrypted in transit, and our database, file storage and search index storage encrypt it at rest. Passwords are hashed, and only team members who need access to production systems have it. The DPA lists our security measures. If an incident affects your information, we will tell you without undue delay, and the organisation responsible where we act for one.
9. Your rights
Depending on where you live, you may ask to see, correct or delete your information, restrict or object to how we use it, or receive a copy to take elsewhere. Email support@spock.chat or louis@spock.chat. We may ask you to confirm your identity first. We answer within one month; if we need longer, we will tell you why. Requests are free.
If your information is in an organisation’s workspace, we may pass your request to that organisation and help it respond.
You can complain to the South African Information Regulator, to the data protection authority where you live or work in the EU or EEA, or to the UK’s ICO. You do not have to contact us first.
10. Cookies and analytics
Spock uses only the cookies and storage needed for sign-in, sessions and security. spock.chat is delivered through Cloudflare, which processes request and security information. We do not use advertising cookies. Websites you open in a hosted browser set their own cookies under their own terms.
11. Children and changes
Spock is for adults (18 and over). Do not add information about children unless you have a lawful basis and the required safeguards.
We will update this policy when our processing changes, and tell you by email or in the Service about material changes. Earlier versions are kept in the legal archive.