Privacy Policy
Effective date: September 11, 2026
1. Information We Collect
We collect information you provide directly, including your name, email address, and payment information when you create an account. We also collect usage data such as task history, agent interactions, and platform analytics to improve the Service.
2. How We Use Your Information
We use your information to provide and improve the Service, process transactions, communicate with you about your account, and ensure platform safety. We do not sell your personal information to third parties.
3. AI Agent Data Processing
When you use Span, your task descriptions and relevant context are shared with AI agents to complete your work. Agents only receive the minimum context necessary for their assigned subtask. All agent interactions are logged and auditable through your dashboard.
4. Data Sharing
We share data with AI agent providers solely to execute your tasks. We may share anonymized, aggregated data for platform improvement. We will disclose information when required by law or to protect the safety of our users.
5. Data About People You Interact With
When the Span Brain is enabled, we record factual interaction-frequency data (counts and timestamps — never message content) about people you interact with through your connected accounts (email, calendar, messaging). This data is pseudonymized at ingest, retained for at most 90 days since last interaction, and excluded from training corpora, analytics warehouses, and audit logs. Any person can request access or deletion of records concerning them — we respond within 30 days (GDPR Article 12(3)), with an internal target of 14 days. See our public objection page (planned at https://usespan.ai/privacy/third-party-data, launching with the public objection release) and the full Legitimate Interest Assessment in our engineering documentation. Lawful basis: GDPR Article 6(1)(f) (legitimate interests), with the balancing test documented and reviewed annually.
6. Data Retention
We retain your account data for as long as your account is active. Task data is retained for 90 days after completion unless you request earlier deletion. Third-party interaction records (see Section 5) are hard-deleted 90 days after the last recorded interaction. You may export or delete your data at any time through your account settings.
7. Your Rights (GDPR, CCPA)
You have the right to access, correct, delete, and export your personal data. You may opt out of data processing for non-essential purposes. California residents have additional rights under the CCPA, including the right to know what data is collected and the right to non-discrimination. Non-users whose interaction data is recorded under Section 5 have the same rights of access and erasure. To exercise your rights, contact privacy@usespan.ai.
8. Security
We implement industry-standard security measures including encryption in transit and at rest, access controls, and regular security audits. Despite our efforts, no method of transmission over the Internet is completely secure.
10. Text Messaging (SMS)
If you connect a mobile number to Span, you opt in twice: once by entering the number in your account settings, and once by sending a confirmation text from that handset. Span sends messages only in reply to a conversation you started, or to tell you about work you asked Span to do. We never message a number that has not texted us first, and we send no marketing or promotional messages. Message frequency varies and depends on the tasks you ask Span to run. Message and data rates may apply. Reply STOP to any message to stop receiving them, or HELP for help. We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes. Transmitting a text message requires a licensed messaging carrier, which acts as our service provider under contract and may not use your number for its own purposes. Disconnecting the channel in your account settings deletes the number from our records.
11. Connected Services
You can connect Gmail, Google Calendar and GitHub to Span as sources for your own knowledge layer, the part of Span that learns your work. Every connection is optional, you choose each one yourself, and you see the exact permission before you grant it. The Gmail permission Span asks for covers your full mailbox. Span fetches only the sender, recipients, subject, labels, date and thread of each message, plus the short preview snippet Gmail attaches to it, and never fetches message bodies or attachments. From Google Calendar, Span reads events on your primary calendar and keeps the title, status, organizer, start time and duration, whether the event repeats, how many people were invited, and the email address of the first attendee listed. It does not keep event descriptions, locations or the full guest list. From GitHub, Span reads your activity feed across the repositories you can access: pushes and their commit messages, pull requests, reviews, issues and comments, stored as GitHub provides them. Span checks each connected source about every five minutes, records what it finds as events in your own knowledge store, and builds learnings and memories from those events. This data serves one purpose: an assistant that knows your work. It is never shared with other users, never used for advertising, and never used to develop, improve or train AI or machine learning models. Connecting Gmail or Google Calendar asks, in one Google screen, for permission to read and for permission to send email or change events. Google lets you untick any permission you do not want to grant, and a permission you decline simply leaves that feature off. Span never sends an email on your behalf without your approval of that specific message. Other changes, such as creating or updating a calendar event or saving a draft, are proposed to you first until you raise Span's autonomy level for that kind of work, after which Span may make them and tells you what it did. You can lower that level at any time. To stop a source, open Your brain, then Brain settings, then Manage connected sources, and choose Revoke access. Span stops collecting from that source at once, deletes the access token it held for it, and takes the learnings and memories built from it out of use. They stay stored until you delete them, so reconnecting the source later restores them. To delete them, write to privacy@usespan.ai naming the source and we will remove them within 30 days, or delete your account under Settings, then Privacy, which permanently removes every event, learning and memory built from your connected sources after a 30 day grace period. A control to delete one source's data yourself, without closing your account, is coming. You can also withdraw Span's access directly from your Google Account at https://myaccount.google.com/permissions or from your GitHub settings at https://github.com/settings/applications, after which Span can no longer read anything from that source.
12. Google User Data
Span's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. In plain words: Span uses Google user data only to provide and improve the knowledge layer features you connected the source for, all of which you can see in the app. We do not sell Google user data. We do not use it for advertising, and Span shows no ads. We do not use it to develop, improve or train AI or machine learning models. Nobody at Span reads your Google user data unless you ask us to, for example to resolve a support request, or unless we must for security reasons or to comply with the law. Google user data reaches other companies only in these cases: the providers that host Span's infrastructure and run the AI models behind your knowledge layer, who process it on Span's behalf under contract and may not use it for their own purposes; and where the law requires disclosure. Section 11 explains what Span reads from each Google product, how to revoke access, and how to have the data deleted.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 30 days before the changes take effect.
14. Contact
Questions about this Privacy Policy? Contact us at privacy@usespan.ai.