Privacy Policy
Last updated: August 2026 · Draft for the early-access beta — not yet reviewed by a lawyer.
What we collect
Signing in with Google or GitHub gives us your name, email address, and profile photo — nothing else, and we never see a password. Signing in with ORCID gives us your ORCID iD and name; ORCID may not release an email, in which case your account simply has none. Guests are assigned an anonymous session identifier and provide no personal information.
How it's used
Your name (and ORCID iD, if you signed in with it or added it) is shown as the contributor on findings and spectra you choose to publish, and on your public profile. Your email is used for account identity only — no marketing — and is never displayed publicly or sold to third parties. Your follower/following relationships and your votes, shares, and comments on published records are public.
Where data lives
Account metadata lives in our PostgreSQL database; uploaded spectral files live in S3-compatible object storage (Cloudflare R2 in production). Error diagnostics may be processed by Sentry. When no built-in parser recognizes a file, its header is sent to our language model provider (OpenRouter) to extract metadata — the header text only, never the data body, and not tied to your identity.
By default those calls route through OpenRouter’s free-model router, which selects a different model for each request. We record which model answered and show it next to the result, so the provenance of machine-written metadata stays inspectable. The model providers’ own retention terms apply to whatever we send them; we do not control those.
You can take us out of that path entirely. Add your own provider API key under Settings and every model-backed feature — header parsing, structure detection, abstract summaries, filename suggestions and the lab consultant — calls your provider on your account instead of ours. Your key is encrypted at rest, is never returned by the API, and is deleted when you close your account. While your key is in use, the metadata templates derived from your files are also kept out of the shared format caches that other accounts read.
Your choices
Unpublished (draft) data is visible only to you. Your profile can be set to non-public during onboarding or later in settings. You can stop using the service at any time; contact us to request account deletion. Published data remains available under its license, as with any scientific repository.
Contact
Privacy questions and deletion requests: hello@spectra-in.site.
Questions? hello@spectra-in.site