SpectrAI Privacy Policy
Version: 1.0
Effective Date: 29.06.2026
Privacy Policy
This Privacy Policy ("Privacy Policy" or "Policy") explains how SpectrAI, an individual residing in the Republic of Bulgaria ("Provider", "SpectrAI", "we", "our", or "us"), collects, uses, stores, shares, protects, and otherwise processes personal data when you access or use the SpectrAI website, applications, APIs, and related services (collectively, the "Service").
Protecting your privacy is important to us. We are committed to processing personal data in a lawful, fair, transparent, and secure manner in accordance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and other applicable privacy legislation.
Please read this Privacy Policy carefully before using the Service.
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
The controller responsible for processing your personal data is:
SpectrAI
Republic of Bulgaria
Legal Contact
legal@spectrai.pro
Customer Support
support@spectrai.pro
Website
https://spectrai.pro
If you have any questions regarding this Privacy Policy or the processing of your personal data, you may contact us using the information above.
2. Scope of this Privacy Policy
This Privacy Policy applies to personal data collected through:
- the SpectrAI website;
- customer accounts;
- subscriptions;
- payment processing;
- AI features;
- APIs;
- customer support;
- communications with us;
- marketing communications where applicable;
- any other services operated by the Provider.
This Privacy Policy does not apply to third-party websites, applications, or services that are not controlled by the Provider, even if they are accessible through the Service.
3. Definitions
For the purposes of this Privacy Policy:
Account means a registered user profile used to access the Service.
Customer means any individual or organization using the Service.
Customer Content means prompts, text, files, images, documents, audio, or any other information submitted by a Customer.
Generated Content means outputs created by artificial intelligence in response to Customer requests.
Personal Data means any information relating to an identified or identifiable natural person.
Processing means any operation performed on Personal Data, including collection, recording, storage, organization, alteration, retrieval, use, disclosure, transfer, deletion, or destruction.
Service Providers means third parties engaged by the Provider to support operation of the Service.
Third-Party AI Provider means any independent provider of artificial intelligence technology used to deliver requested functionality.
4. Categories of Personal Data We Collect
Depending on how you use the Service, we may collect the following categories of Personal Data.
4.1 Account Information
When you create an account, we may collect:
- email address;
- username;
- encrypted password or password hash;
- account identifier;
- language preferences;
- profile settings;
- account creation date;
- account status.
4.2 Subscription Information
When you purchase a subscription or Credits, we may collect:
- subscription plan;
- subscription status;
- renewal dates;
- billing history;
- purchased Credits;
- subscription Credits;
- invoices;
- transaction references.
4.3 Payment Information
Payments are processed by independent payment providers such as Stripe.
The Provider does not collect or store complete payment card numbers, CVV codes, or payment authentication credentials.
We may receive limited payment-related information, including:
- payment confirmation;
- payment status;
- transaction identifier;
- billing country;
- currency;
- payment timestamp;
- partial payment method information supplied by the payment processor.
4.4 Customer Content
To provide AI functionality, we may process Customer Content submitted through the Service, including:
- prompts;
- uploaded documents;
- uploaded images;
- uploaded files;
- audio where supported;
- instructions provided to AI models;
- generated responses.
Customer Content is processed solely for the purpose of providing requested functionality and maintaining the operation and security of the Service.
4.5 Technical Information
When you access the Service, certain technical information may be collected automatically.
This may include:
- IP address;
- browser type and version;
- operating system;
- device type;
- language settings;
- referring website;
- pages visited;
- timestamps;
- session identifiers;
- diagnostic information;
- crash reports;
- API request metadata.
4.6 Usage Information
We may collect information regarding how the Service is used, including:
- features accessed;
- AI requests submitted;
- Credits consumed;
- subscription usage;
- login activity;
- account settings;
- support requests;
- interaction with Service functionality.
This information helps us improve reliability, security, and overall user experience.
5. Information We Do Not Intentionally Collect
The Service is not intended for children below the minimum legal age required under applicable law.
We do not knowingly collect Personal Data from children without appropriate authorization from a parent or legal guardian where such authorization is legally required.
If we become aware that Personal Data has been collected in violation of applicable child protection laws, we will take reasonable steps to delete such information without undue delay.
6. Information You Provide Voluntarily
You may voluntarily provide additional information when you:
- contact Customer Support;
- report bugs;
- submit feature requests;
- participate in surveys;
- communicate with us by email;
- respond to customer service inquiries.
You should avoid submitting confidential, sensitive, or regulated information unless it is necessary for the requested support or functionality.
7. Information Collected Automatically
For security, fraud prevention, diagnostics, and operational purposes, we automatically collect certain technical and operational information.
Such information may include:
- authentication logs;
- login attempts;
- failed login events;
- account security events;
- API usage logs;
- infrastructure diagnostics;
- error reports;
- system performance metrics.
These logs are used solely for maintaining the security, integrity, availability, and reliability of the Service.
8. Legal Bases for Processing
Where the GDPR or other applicable data protection laws apply, we process Personal Data only where we have a lawful basis to do so.
8.1 Performance of a Contract
We process Personal Data where necessary to:
- create and manage your Account;
- authenticate users;
- provide access to the Service;
- allocate Credits;
- process subscriptions;
- generate AI outputs;
- process payments;
- provide customer support;
- fulfill our contractual obligations.
8.2 Legitimate Interests
We may process Personal Data where necessary for our legitimate interests, provided such interests are not overridden by your rights and freedoms.
Legitimate interests include:
- maintaining platform security;
- detecting fraud;
- preventing abuse;
- monitoring system performance;
- improving Service reliability;
- troubleshooting technical issues;
- preventing unauthorized access;
- enforcing our Terms of Service;
- protecting intellectual property;
- maintaining business records.
8.3 Legal Obligations
We process Personal Data where necessary to comply with applicable legal obligations, including:
- accounting requirements;
- tax obligations;
- anti-fraud obligations;
- lawful requests from public authorities;
- court orders;
- legal claims;
- regulatory compliance.
8.4 Consent
Where required by applicable law, we rely on your consent for specific processing activities.
This may include:
- optional marketing communications;
- optional cookies;
- similar tracking technologies.
You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
9. How We Use Personal Data
We process Personal Data for the following purposes:
- providing access to the Service;
- authenticating users;
- maintaining Accounts;
- allocating Credits;
- processing subscriptions;
- generating AI responses;
- operating APIs;
- processing payments;
- preventing fraud;
- detecting abuse;
- improving Service performance;
- maintaining infrastructure;
- responding to customer inquiries;
- communicating important Service updates;
- complying with legal obligations.
We process only the amount of Personal Data reasonably necessary for each purpose.
10. Artificial Intelligence Processing
The primary purpose of processing Customer Content is to generate AI responses requested by Customers.
Customer Content may include:
- prompts;
- uploaded images;
- uploaded documents;
- uploaded files;
- conversations;
- instructions;
- generated outputs.
Processing occurs only to provide the requested functionality.
The Provider does not review Customer Content except where reasonably necessary for:
- technical support;
- abuse investigations;
- fraud prevention;
- security incidents;
- compliance with applicable law.
11. AI Model Training
The Provider does not use Customer Content to train its own proprietary artificial intelligence models.
However, in order to provide requested AI functionality, Customer Content may be transmitted to independent third-party artificial intelligence providers.
Those providers may process submitted content in accordance with their own terms, privacy policies, retention policies, and applicable laws.
The Provider encourages Customers not to submit confidential, classified, regulated, or highly sensitive information unless they fully understand the associated risks.
12. Third-Party Service Providers
To operate the Service efficiently, the Provider uses trusted third-party service providers.
These providers may assist with:
- payment processing;
- cloud infrastructure;
- hosting;
- AI inference;
- customer support;
- email delivery;
- analytics;
- security monitoring;
- logging;
- error reporting.
Service providers process Personal Data only to the extent necessary to perform services on behalf of the Provider.
Where required by law, appropriate contractual safeguards are implemented.
13. Payment Processing
Payments are processed by independent payment providers, including Stripe.
The Provider receives only information necessary to:
- verify successful payment;
- activate subscriptions;
- allocate Credits;
- issue invoices;
- detect payment fraud;
- maintain accounting records.
The Provider does not receive or store:
- complete payment card numbers;
- CVV codes;
- payment authentication credentials.
Payment information is processed directly by the payment provider in accordance with its own legal terms and privacy practices.
14. Cookies and Similar Technologies
The Service uses cookies and similar technologies to ensure proper operation and improve user experience.
Cookies may be categorized as:
Strictly Necessary Cookies
These cookies are essential for:
- authentication;
- account security;
- fraud prevention;
- session management;
- website functionality.
These cookies cannot generally be disabled because they are necessary for operation of the Service.
Functional Cookies
Functional cookies remember user preferences, including:
- language settings;
- interface preferences;
- account settings.
Analytics Cookies
Subject to applicable law and your preferences where required, analytics cookies may be used to understand:
- website traffic;
- feature usage;
- performance metrics;
- error rates;
- user experience.
Marketing Cookies
Where applicable and with your consent where required by law, marketing technologies may be used to:
- measure advertising effectiveness;
- prevent advertising fraud;
- improve marketing campaigns.
The Provider does not sell Personal Data for advertising purposes.
15. Data Sharing
The Provider does not sell Personal Data.
We disclose Personal Data only where necessary for legitimate business purposes or where required by law.
Recipients may include:
- payment processors;
- cloud infrastructure providers;
- AI service providers;
- hosting providers;
- analytics providers;
- customer support providers;
- legal advisers;
- accountants;
- governmental authorities where legally required.
Each recipient receives only the information reasonably necessary for the applicable purpose.
16. International Data Transfers
The Service operates internationally.
As a result, Personal Data may be transferred to and processed in countries outside the European Economic Area or the United Kingdom.
Where required by applicable law, the Provider implements appropriate safeguards, which may include:
- Standard Contractual Clauses approved by the European Commission;
- adequacy decisions;
- contractual safeguards;
- additional technical and organizational security measures.
International transfers are performed only where legally permitted.
17. Data Minimization
The Provider follows the principle of data minimization.
We collect only Personal Data that is reasonably necessary to:
- provide the Service;
- comply with legal obligations;
- maintain security;
- prevent fraud;
- improve reliability.
We do not intentionally collect unnecessary Personal Data.
18. Accuracy of Information
Customers are responsible for ensuring that information provided to the Provider is accurate and up to date.
Customers may update certain Personal Data through their Account settings.
Where inaccurate information is identified, reasonable efforts will be made to correct or update such information.
19. Data Retention
We retain Personal Data only for as long as necessary to fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, enforce agreements, and protect the security and integrity of the Service.
Retention periods vary depending on the category of data and applicable legal requirements.
Examples include:
- Account Information — While the Account remains active and for a reasonable period after closure where necessary for legal or security purposes;
- Subscription and Billing Records — As required by applicable accounting and tax laws;
- Customer Support Communications — For as long as reasonably necessary to resolve requests and improve support quality;
- Security Logs — For fraud prevention, security investigations, and dispute resolution;
- AI Processing Logs — For operational, diagnostic, abuse prevention, and security purposes, subject to applicable law.
Where Personal Data is no longer required, it will be deleted, anonymized, or securely destroyed unless continued retention is legally required.
20. Security Measures
The Provider implements commercially reasonable technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
Security measures may include:
- encrypted HTTPS/TLS communications;
- secure cloud infrastructure;
- restricted administrative access;
- password hashing using industry-standard algorithms;
- authentication controls;
- firewall protection;
- activity logging;
- intrusion monitoring;
- software updates and security patches;
- regular security reviews.
While we strive to protect Personal Data, no method of transmission over the Internet or electronic storage is completely secure. Accordingly, we cannot guarantee absolute security.
21. Your Privacy Rights
Depending on your country of residence and applicable law, you may have the right to:
- request access to your Personal Data;
- request correction of inaccurate Personal Data;
- request deletion of Personal Data;
- request restriction of processing;
- object to certain processing activities;
- withdraw consent where processing is based on consent;
- request portability of Personal Data;
- lodge a complaint with a competent supervisory authority.
We may request reasonable information to verify your identity before responding to your request.
We will respond within the time period required by applicable law.
Requests may be submitted to:
legal@spectrai.pro
22. Right to Delete Your Account
Customers may request deletion of their Account at any time.
Deletion of an Account generally results in removal of access to the Service.
Certain information may continue to be retained where necessary:
- to comply with legal obligations;
- for accounting and taxation;
- to prevent fraud;
- to investigate abuse;
- to resolve disputes;
- to enforce contractual rights;
- to protect the security of the Service.
Backup copies may continue to exist for a limited period before automatic deletion in accordance with disaster recovery procedures.
23. Marketing Communications
We may send communications necessary for the operation of the Service, including:
- security notifications;
- billing notices;
- subscription updates;
- changes to legal documents;
- maintenance announcements.
Where permitted by applicable law or with your consent where required, we may also send promotional communications.
You may unsubscribe from marketing communications at any time by following the instructions contained in the communication or by contacting us.
Service-related communications that are necessary for operation of the Service may continue to be sent even if you opt out of marketing communications.
24. Automated Decision-Making
Artificial intelligence is used to generate content requested by Customers.
The Provider does not use automated decision-making that produces legal effects concerning Customers or similarly significant effects without appropriate human involvement, except where permitted by applicable law.
Customers remain responsible for reviewing and evaluating AI-generated outputs before relying on them.
25. Confidential Information
Although the Provider takes reasonable measures to protect Customer Content, Customers should avoid submitting information that is:
- classified;
- subject to legal privilege;
- protected by professional secrecy;
- highly confidential;
- regulated by industry-specific confidentiality requirements,
unless they have determined that submission is appropriate for their intended use.
Customers remain responsible for deciding what information they choose to submit to the Service.
26. Changes to this Privacy Policy
The Provider may update this Privacy Policy from time to time to reflect:
- legal developments;
- regulatory changes;
- improvements to the Service;
- new technologies;
- security requirements;
- operational changes.
The updated version will be published on the Service together with its effective date.
Material changes may be communicated through the Service or by email where appropriate.
Continued use of the Service after the effective date constitutes acceptance of the revised Privacy Policy.
27. Contact Information
For questions regarding this Privacy Policy or our privacy practices, please contact:
Legal
legal@spectrai.pro
Customer Support
support@spectrai.pro
Website
https://spectrai.pro
28. Supervisory Authorities
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction providing similar rights, you may have the right to lodge a complaint with your local data protection supervisory authority.
We encourage you to contact us first so that we may attempt to resolve your concerns promptly and amicably.
29. Severability
If any provision of this Privacy Policy is found to be invalid or unenforceable under applicable law, the remaining provisions shall remain in full force and effect.
Any invalid provision shall be interpreted, modified, or replaced to the minimum extent necessary to make it enforceable while preserving its original intent.
30. Governing Language
This Privacy Policy is published in the English language.
Translations may be provided for convenience only.
In the event of any conflict or inconsistency between a translated version and the English version, the English version shall prevail to the fullest extent permitted by applicable law.
Contact Summary
Provider
SpectrAI
Republic of Bulgaria
Legal
legal@spectrai.pro
Support
support@spectrai.pro
Website
https://spectrai.pro
Version: 1.0
Effective Date: June 25, 2026
Last Updated: June 25, 2026
