//Privacy
What we collect,
and what we don’t.
This policy covers the Spectral website and the private admin area behind it. It says what we collect, why we collect it, who it reaches and what you can ask us to do about it. No dark patterns, no data broking.
Last updated 15 September 2026
Who we are
Spectral is the data controller for the personal data described in this policy. We operate www.spctrl.tech and the private admin area at os.spctrl.tech.
For anything in this policy — a question, a correction, a request to delete — write to hi@spctrl.tech. A person reads it.
What we collect
Three things, and only these three.
- What you send us
- If you use the contact form, we receive the name, email address, company and message you type into it. That is the whole form; there are no hidden fields.
- Your Google account, if you sign in
- The private admin area uses Sign in with Google. It receives your name, email address and Google profile picture. Nothing else. See “Signing in with Google” below.
- How the site is used
- Google Analytics records pages viewed, rough location by country or city, device and browser, and where you arrived from. It does not tell us who you are.
We do not buy personal data, we do not enrich it from third-party sources, and we do not run advertising or retargeting pixels on this site.
Signing in with Google
Spectral runs a private admin area — our own internal tooling, not a product anyone signs up for. It is reachable only by a fixed list of Spectral email addresses that we maintain by hand. Sign in with Google is how those people get in.
When you sign in with Google, Google sends us a signed token containing your basic profile: your name, your email address and your profile picture. We request no other scopes. We have no access to your Gmail, your Drive, your Calendar, your contacts or any other Google service, and we never ask for it.
We use that profile for one purpose: to confirm you are on the allowlist and to show who is signed in. If your address is not on the list, the session is ended immediately and nothing about your account is kept.
Sign-in and session records are held by Supabase Auth, our authentication provider, on our behalf. We do not sell data received from Google, transfer it to third parties for advertising, credit assessment or lending, or use it to train AI or machine-learning models, and we do not allow humans to read it except where you have asked us to, where it is needed for security or support, or where the law requires it.
You can revoke our access to your Google account at any time from your Google account permissions. To have the sign-in record itself deleted, email hi@spctrl.tech and we will remove it.
Why we use it, and on what basis
Under the GDPR we need a lawful basis for each use. Ours are these.
- To answer you — legitimate interests
- When you send an enquiry, we use your details to reply to it and to carry on that conversation. Replying to someone who asked us to is squarely what they expect.
- To run the admin area — legitimate interests
- Authenticating our own team into our own tooling, and keeping unauthorised people out of it, is a plain security interest.
- To understand the site — consent
- Analytics runs on your consent where that is required, and you can withdraw it through your browser or by blocking the analytics cookies.
- To meet our obligations — legal obligation
- Some records, particularly anything touching contracts, tax or accounting, we keep because the law says we must.
Where it goes
Some of these providers process data outside the UK and the EEA, mainly in the United States. Where that happens, the transfer is covered by the safeguards the GDPR requires — standard contractual clauses, the UK addendum, or an adequacy decision such as the EU–US Data Privacy Framework.
How long we keep it
- Enquiries: for as long as the conversation is live, and up to two years afterwards so we can pick a thread back up. Then deleted.
- Admin accounts and sessions: while the person is on the allowlist. Removed from the list, removed from the system.
- Analytics: on Google’s retention schedule, currently 14 months, then aggregated.
- Anything we are required to keep for tax, accounting or legal reasons: for the period the law sets, and no longer.
Your rights
If you are in the UK or the EEA you can ask us to do any of the following, and we will answer within one month.
- Tell you what we hold about you, and give you a copy.
- Correct it if it is wrong.
- Delete it, where we have no overriding reason to keep it.
- Restrict or object to how we use it, including anything we do on the basis of legitimate interests.
- Send it on to another provider in a portable format.
- Withdraw consent you have given, at any time, without affecting what we did before you withdrew it.
Email hi@spctrl.tech and say which one. We do not charge for it, and we will not make it difficult.
If you think we have got it wrong, you can complain to the data protection authority for your country. We would rather you came to us first.
Security
Everything is served over HTTPS. The admin area is behind Google sign-in and a hand-maintained allowlist, checked on every request, and it fails closed — an empty list admits nobody. Credentials for our providers are held as environment secrets, never in the codebase.
No system is perfect. If you find a security problem on anything of ours, email hi@spctrl.tech and we will take it seriously and act quickly.
Children
This site is for businesses and is not aimed at children. We do not knowingly collect data about anyone under 16. If we learn we have, we delete it.
Changes to this policy
When what we do changes, this page changes with it, and the date at the top moves. If a change materially affects how we handle data we already hold about you, we will tell the people affected directly.
Questions
Anything on this page that is unclear, or a request you want to make, goes to hi@spctrl.tech. A person reads it.