Privacy Policy
Effective April 18, 2026
SpaceSpider ("we", "us") builds a desktop app and companion website for developers. This policy explains what we collect, why, and what rights you have. We've written it in plain language so you can actually read it.
What we collect
Account data
When you sign in with Google, we receive your email address, name, and profile image. We store your email as your account identifier. We never see your Google password.
Payment data
Payments are handled by Stripe. We receive a Stripe customer ID, the plan you purchased, and subscription status. We do not store credit card numbers or CVV codes. Stripe's privacy policy governs how they handle payment details.
License + device data
When you activate the desktop app on a machine, we receive a device fingerprint (hash of hostname, platform, architecture), hostname, platform, and architecture. This is used to enforce seat limits and let you manage active devices from your dashboard. We do not collect file contents, project paths, terminal output, or AI prompts/responses.
Website analytics
We may log aggregate, anonymized request metadata (page, referrer, timestamp) for operational purposes. We do not use third-party advertising trackers or sell data.
What the desktop app does NOT send us
- Your code, files, or directory contents
- Terminal input or output
- AI prompts or AI responses (those go directly from the CLI to the AI provider)
- Keystrokes, screenshots, or screen recordings
SpaceSpider runs AI CLIs (like Claude Code, Codex, Qwen Code) inside local pseudo-terminals. Those tools talk to their respective providers directly. Your traffic to Anthropic, OpenAI, or any other AI provider does not pass through us.
How we use your data
- Authenticate your sign-in
- Issue and verify license keys
- Process subscription billing
- Send critical service emails (receipts, license issuance, subscription changes)
- Diagnose and fix bugs you report
We do not sell your data. We do not share your data with advertisers. We do not use your data to train AI models.
Third parties we rely on
- Google — OAuth sign-in
- Stripe — payment processing
- Neon — Postgres database hosting
- Vercel — website + API hosting
Each provider has its own privacy policy. We share only the minimum data required for them to do their job.
Data retention
We keep account data while your account is active. If you delete your account, we remove your user record and associated licenses within 30 days, except where we must retain records for tax or legal compliance (typically 7 years for payment records, per local law).
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your data. Email privacy@spacespider.app and we will respond within 30 days.
Security
We use TLS for all network traffic, encrypted storage for credentials, and limit employee access to production data. No system is perfect — report suspected vulnerabilities to security@spacespider.app.
Children
SpaceSpider is not directed at children under 16. We do not knowingly collect data from them.
Changes to this policy
We'll update the date above when we change this policy. Material changes will be announced via the website or email.
Contact
Questions? Email privacy@spacespider.app.