Privacy Policy
Last updated July 2026
Spicer OS stores things people usually consider private — journals, habits, finances, goals. This page explains exactly what is kept, who can reach it, and how to take it back or erase it. Plain language, no hedging.
What we store
Only what you put in, plus what's needed to run your account:
- Account — your email and authentication credentials.
- Your content — daily logs, journal entries, habits, goals, tasks, calendar entries, content pipeline items.
- Financial data you add — accounts, balances, transactions, and assets you enter or import.
- Alfred's memory — conversations with the assistant and the durable facts it saves about you.
- Security records — sign-in events, known devices, and an audit log, kept to protect your account.
- API keys you provide — encrypted at rest with AES-256-GCM.
We do not sell your data, we do not serve ads, and we do not use your content to train any AI model.
Who can see it
Every record is tied to your user ID and protected by database-level row security, so one account cannot read another's data — that boundary is enforced by the database itself, not just by application code.
Financial pages sit behind an additional vault requiring your PIN, two-factor code, and passkey. A stolen session alone cannot open them.
Staff access is limited to what is strictly necessary to operate the service or to respond to a support request you initiate.
AI processing
When you talk to Alfred, the relevant part of your data is sent to an AI provider (currently OpenAI) so it can answer. This is the core function of the product and cannot be switched off while using the assistant.
If you supply your own API key, those requests run on your provider account under your agreement with them — we never see the content of that exchange. If you use the included free trial messages, the requests run on our account instead.
Voice conversations stream audio to the provider in real time and are transcribed so they appear in your history.
Third parties who process data for us
- Supabase — database, authentication, file storage
- Vercel — application hosting
- OpenAI — AI features, unless you use your own key
- Stripe — payments. Card details go to Stripe directly; we never receive or store them.
- Resend — transactional email
- Notion — only if you choose to connect a workspace
Your data is yours
From Settings → Account you can, at any time and without asking us:
- Export everything as a JSON file.
- Delete your account. This permanently removes your content, cancels any active subscription, and cannot be undone.
Exports exclude credentials — API keys, passkeys, and two-factor secrets — because returning those would weaken your security rather than help you.
Retention
Your data is kept while your account exists. When you delete your account it is removed immediately; encrypted backups may retain copies briefly before rotating out. Security and audit records may be retained where required to investigate abuse.
Children
Spicer OS is not intended for anyone under 13, and we do not knowingly collect data from children.
Changes and contact
If this policy changes materially, we will notify account holders by email. Questions about your data — including access, correction, or deletion requests — can be sent through the support page.