Legal

Privacy Policy

Effective April 18, 2026

SpaceSpider ("we", "us") builds a desktop app and companion website for developers. This policy explains what we collect, why, and what rights you have. We've written it in plain language so you can actually read it.

What we collect

Account data

When you sign in with Google, we receive your email address, name, and profile image. We store your email as your account identifier. We never see your Google password.

Payment data

Payments are handled by Stripe. We receive a Stripe customer ID, the plan you purchased, and subscription status. We do not store credit card numbers or CVV codes. Stripe's privacy policy governs how they handle payment details.

License + device data

When you activate the desktop app on a machine, we receive a device fingerprint (hash of hostname, platform, architecture), hostname, platform, and architecture. This is used to enforce seat limits and let you manage active devices from your dashboard. We do not collect file contents, project paths, terminal output, or AI prompts/responses.

Website analytics

We may log aggregate, anonymized request metadata (page, referrer, timestamp) for operational purposes. We do not use third-party advertising trackers or sell data.

What the desktop app does NOT send us

  • Your code, files, or directory contents
  • Terminal input or output
  • AI prompts or AI responses (those go directly from the CLI to the AI provider)
  • Keystrokes, screenshots, or screen recordings

SpaceSpider runs AI CLIs (like Claude Code, Codex, Qwen Code) inside local pseudo-terminals. Those tools talk to their respective providers directly. Your traffic to Anthropic, OpenAI, or any other AI provider does not pass through us.

How we use your data

  • Authenticate your sign-in
  • Issue and verify license keys
  • Process subscription billing
  • Send critical service emails (receipts, license issuance, subscription changes)
  • Diagnose and fix bugs you report

We do not sell your data. We do not share your data with advertisers. We do not use your data to train AI models.

Third parties we rely on

  • Google — OAuth sign-in
  • Stripe — payment processing
  • Neon — Postgres database hosting
  • Vercel — website + API hosting

Each provider has its own privacy policy. We share only the minimum data required for them to do their job.

Data retention

We keep account data while your account is active. If you delete your account, we remove your user record and associated licenses within 30 days, except where we must retain records for tax or legal compliance (typically 7 years for payment records, per local law).

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your data. Email privacy@spacespider.app and we will respond within 30 days.

Security

We use TLS for all network traffic, encrypted storage for credentials, and limit employee access to production data. No system is perfect — report suspected vulnerabilities to security@spacespider.app.

Children

SpaceSpider is not directed at children under 16. We do not knowingly collect data from them.

Changes to this policy

We'll update the date above when we change this policy. Material changes will be announced via the website or email.

Contact

Questions? Email privacy@spacespider.app.