Privacy Policy

Last updated: February 10, 2026

SpecSheet ("we," "us," or "our") operates the website specsheet.co (the "Service"). This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.

1. Information We Collect

a. Account Information

When you create an account, we collect your email address, full name, and a password (hashed, never stored in plain text). Authentication is handled by Supabase.

b. Usage Data

We track the number of spec sheets you generate each day to enforce tier limits. For anonymous users (no account), this count is stored locally in your browser and is not transmitted to our servers.

c. Payment Information

If you subscribe to a paid plan, payment is processed by Stripe. We do not store your credit card number. We store a Stripe customer ID and subscription ID in our database to manage your subscription status.

d. Specification Data

When you generate a spec sheet, the raw specification text you provide is sent to OpenAI's API (gpt-4o-mini) for processing. We do not permanently store your raw specification text or generated spec sheet data on our servers. Spec data is held temporarily in your browser session (sessionStorage) and is deleted when you close the tab.

e. Uploaded Files

Product images and documents (PDF, DOCX) you upload are processed in-memory on our servers and are not permanently stored. Images are resized and converted for inclusion in your spec sheet PDF.

2. How We Use Your Information

3. Third-Party Services

We share data with the following third-party services:

4. Data Retention

Account information is retained for as long as your account is active. Usage logs are retained for operational purposes. Specification data and uploaded files are processed in-memory and not permanently stored on our servers.

5. Your Rights

a. Access and Portability

You may request a copy of the personal data we hold about you by contacting us at contact@specsheet.co.

b. Deletion

You may request deletion of your account and associated data by emailing contact@specsheet.co. We will process deletion requests within 30 days.

c. Correction

You may update your account information through the Service or by contacting us.

6. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

To exercise any of these rights, contact us at contact@specsheet.co.

7. Children's Privacy

The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us so we can delete it.

8. Cookies and Local Storage

We use browser cookies for authentication session management (via Supabase). We use localStorage to track anonymous usage counts. We do not use third-party analytics, advertising cookies, or tracking pixels.

9. Security

We use industry-standard security measures to protect your data, including HTTPS encryption, hashed passwords, and secure API key management. However, no method of transmission over the Internet is 100% secure.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

11. Contact Us

If you have questions about this Privacy Policy, contact us at:

SpecSheet
Email: contact@specsheet.co