PRIVACY POLICY

Privacy Policy

This policy covers Spock and spock.chat, operated by Seleya Labs Inc., a Delaware corporation. Mailing address: 1111B S Governors Ave STE 56751, Dover, DE 19904, USA. Our team works in South Africa. Seleya’s company website (seleya.ai) and the Seleya Autonomy Index (index.seleya.ai) have their own privacy notices.

Questions and requests: support@spock.chat, or our privacy contact, Louis-Neil Korsten, louis@spock.chat.

1. Who is responsible

Seleya is responsible (the “responsible party” or “controller”) for information it uses for its own purposes: running accounts, billing, security, support and spock.chat.

When an organisation uses Spock, it decides what content goes in and who sees it. For that content, the organisation is responsible and Seleya processes it on the organisation’s behalf, under our Data Processing Agreement. If you use an employer’s or another organisation’s workspace, their privacy notice also applies; contact them about their use, and we will help route your request.

TTL Technologies (Pty) Ltd, Seleya’s wholly owned South African subsidiary, sells and invoices Enterprise subscriptions. It is responsible for its own billing and business records. Team members engaged through TTL support Enterprise customers, with the same access rules and confidentiality duties as the rest of our team.

2. What we collect

InformationExamples and sources
AccountName, email, a hashed password, and sign-in identifiers if you use Apple, Google or Microsoft sign-in. We never receive your Apple, Google or Microsoft password.
WorkspaceMemberships, roles, Space settings, sharing and connections.
Customer ContentPrompts, conversations, uploads, images, audio, connected files and records, generated documents and outputs, and their search indexes.
MemoryNotes Spock keeps from your work so it can continue and personalise it.
Hosted computersFiles, output and browser sessions created when Spock runs code or browses for you.
Usage and securityIP address, device and browser details, usage and billing measurements, diagnostic records and security logs.
BillingPlan, invoices, billing contact and company details. Stripe handles card details; we never see full card numbers.
Messages and channelsSupport and feedback emails, and messages on WhatsApp, Telegram or other channels you connect.
NotificationsDevice tokens if you turn on push notifications.

It comes from you, your workspace’s members, accounts you connect, documents and websites retrieved for your work, and our systems.

3. Why we use it

PurposeBasis
Providing your account and the Service, and taking paymentPerformance of our contract with you
Running organisation accounts, support and business contactsOur legitimate interest in serving our customers
Security, preventing abuse, keeping the Service reliableOur legitimate interest in protecting people and systems; legal obligations where they apply
Accounting, tax and legal recordsLegal obligation
Product news by emailYour consent, or an existing-customer relationship with an easy opt-out
Improving the ServiceOur legitimate interest, using usage measurements and aggregated data. Never by training AI on Customer Content

Under POPIA, the same purposes rest on section 11 (contract, legal obligation, legitimate interests, or consent where needed), and direct marketing follows section 69. You may withdraw consent, unsubscribe or object to legitimate-interest processing at any time.

4. AI, memory and agents

Spock sends the relevant parts of your request, such as the conversation, retrieved passages, files and tool results, to an AI model to produce an answer. It routes work between Seleya’s own models and third-party models, and uses separate providers for search, page reading and some file processing. The providers are listed in the DPA.

Neither Seleya nor its providers use your content to train AI models, unless your organisation asks us in writing to tune a model used only for it. Some providers keep requests for a short time for abuse monitoring, as stated in the DPA.

Spock keeps memory notes from your work so it can pick up where you left off. They are used only to serve you, never for advertising. Ask us to see, correct or delete them.

Hosted computers and their browser sessions can persist between tasks until deleted, and are deleted automatically after 30 days. Agents and automations can read and send information through accounts you connect while you are away, so set their scope with care. A public share link shows its content to anyone who has it.

Spock helps you work; it does not make decisions about people. If you use it for decisions that significantly affect someone, the safeguards and human review the law requires are your responsibility.

5. Who receives information

We do not sell personal information.

Google user data

When you connect a Google account, Spock accesses Google user data only to carry out a request you make in Spock:

Nothing is written, changed or sent in your Google account until you approve it in Spock. Google user data is sent to the AI model providers listed above only to produce the result you asked for.

Spock’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we transfer it only to provide or improve the features you use, for security, or to comply with law. We do not use data obtained through Google Workspace APIs to develop, improve or train generalized or non-personalized AI or ML models. No person at Seleya reads your Google user data unless you ask us to (for example, for support), it is needed for security or abuse investigation, or the law requires it.

Google user data stays in Spock only in the chats, files and memory where it was used; deleting them deletes it. OAuth tokens are encrypted at rest. Disconnecting Google in Integrations revokes Spock’s access at Google, and you can also remove it at myaccount.google.com/permissions.

6. International transfers

Seleya is a US company; our team works in South Africa; content is stored in Germany and processed by AI models in the United States. When information leaves South Africa, we transfer it only under binding agreements that give adequate protection, as section 72(1)(a) of POPIA requires, including for information about companies and other juristic persons. Where the GDPR applies, we use an approved transfer mechanism for the specific transfer, such as the EU Standard Contractual Clauses. Ask us for details of the safeguards that apply to you.

7. How long we keep information

InformationHow long
Account and Customer ContentWhile your account or your organisation’s agreement is active. Deleting your account removes your personal workspace at once; content you added to an organisation’s workspace stays with that organisation. Other deletion requests are completed within 30 days.
Deleted filesRemoved from use at once; storage and search indexes cleared within minutes.
Diagnostic copies of AI requestsUp to 30 days, then reduced to records without content.
Hosted computersDeleted after 30 days.
BackupsExpire within 30 days, and are never used to bring deleted data back.
Provider copiesAs listed in the DPA, for example up to 30 days of abuse-monitoring logs at OpenAI.
Billing, tax and legal recordsAs long as the law requires, generally five to seven years.

Deleting a file removes its stored copies and indexes. Conversations or memory notes that quoted it are separate: ask us and we will find and delete them too. For files synced from a connected source, delete them at the source as well, or a later sync can bring them back.

8. Security

Information is encrypted in transit, and our database, file storage and search index storage encrypt it at rest. Passwords are hashed, and only team members who need access to production systems have it. The DPA lists our security measures. If an incident affects your information, we will tell you without undue delay, and the organisation responsible where we act for one.

9. Your rights

Depending on where you live, you may ask to see, correct or delete your information, restrict or object to how we use it, or receive a copy to take elsewhere. Email support@spock.chat or louis@spock.chat. We may ask you to confirm your identity first. We answer within one month; if we need longer, we will tell you why. Requests are free.

If your information is in an organisation’s workspace, we may pass your request to that organisation and help it respond.

You can complain to the South African Information Regulator, to the data protection authority where you live or work in the EU or EEA, or to the UK’s ICO. You do not have to contact us first.

10. Cookies and analytics

Spock uses only the cookies and storage needed for sign-in, sessions and security. spock.chat is delivered through Cloudflare, which processes request and security information. We do not use advertising cookies. Websites you open in a hosted browser set their own cookies under their own terms.

11. Children and changes

Spock is for adults (18 and over). Do not add information about children unless you have a lawful basis and the required safeguards.

We will update this policy when our processing changes, and tell you by email or in the Service about material changes. Earlier versions are kept in the legal archive.