Privacy Policy
Last updated: February 10, 2026
SpecSheet ("we," "us," or "our") operates the website specsheet.co (the "Service"). This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.
1. Information We Collect
a. Account Information
When you create an account, we collect your email address, full name, and a password (hashed, never stored in plain text). Authentication is handled by Supabase.
b. Usage Data
We track the number of spec sheets you generate each day to enforce tier limits. For anonymous users (no account), this count is stored locally in your browser and is not transmitted to our servers.
c. Payment Information
If you subscribe to a paid plan, payment is processed by Stripe. We do not store your credit card number. We store a Stripe customer ID and subscription ID in our database to manage your subscription status.
d. Specification Data
When you generate a spec sheet, the raw specification text you provide is sent to OpenAI's API (gpt-4o-mini) for processing. We do not permanently store your raw specification text or generated spec sheet data on our servers. Spec data is held temporarily in your browser session (sessionStorage) and is deleted when you close the tab.
e. Uploaded Files
Product images and documents (PDF, DOCX) you upload are processed in-memory on our servers and are not permanently stored. Images are resized and converted for inclusion in your spec sheet PDF.
2. How We Use Your Information
- To provide and maintain the Service
- To manage your account and subscription
- To enforce usage limits per your subscription tier
- To process your specifications using AI (OpenAI)
- To generate PDF spec sheets
- To communicate with you about your account or service changes
3. Third-Party Services
We share data with the following third-party services:
- OpenAI — Your raw specification text is sent to OpenAI's API for AI-powered structuring. OpenAI's use of this data is governed by their API data usage policy. Data sent via the API is not used to train OpenAI models.
- Stripe — Payment processing. Stripe receives your email address and payment details. See Stripe's privacy policy.
- Supabase — Authentication and database hosting. Your account information and usage data are stored in Supabase. See Supabase's privacy policy.
- Vercel — Application hosting. See Vercel's privacy policy.
4. Data Retention
Account information is retained for as long as your account is active. Usage logs are retained for operational purposes. Specification data and uploaded files are processed in-memory and not permanently stored on our servers.
5. Your Rights
a. Access and Portability
You may request a copy of the personal data we hold about you by contacting us at contact@specsheet.co.
b. Deletion
You may request deletion of your account and associated data by emailing contact@specsheet.co. We will process deletion requests within 30 days.
c. Correction
You may update your account information through the Service or by contacting us.
6. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know — You may request what personal information we collect, use, and disclose.
- Right to Delete — You may request deletion of your personal information.
- Right to Opt-Out of Sale — We do not sell your personal information to third parties. We share data with service providers (OpenAI, Stripe, Supabase) solely to operate the Service.
- Right to Non-Discrimination — We will not discriminate against you for exercising your privacy rights.
To exercise any of these rights, contact us at contact@specsheet.co.
7. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us so we can delete it.
8. Cookies and Local Storage
We use browser cookies for authentication session management (via Supabase). We use localStorage to track anonymous usage counts. We do not use third-party analytics, advertising cookies, or tracking pixels.
9. Security
We use industry-standard security measures to protect your data, including HTTPS encryption, hashed passwords, and secure API key management. However, no method of transmission over the Internet is 100% secure.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
11. Contact Us
If you have questions about this Privacy Policy, contact us at:
SpecSheet
Email: contact@specsheet.co