Scope and contact
This Privacy Policy describes how Specra collects, uses, stores, and discloses information when you use the Specra desktop application, website, dashboard, hosted projects, API-connected workflows, and hosted MCP services.
The Specra desktop application is local-first. Opening a local codebase does not, by itself, upload that codebase to Specra. This policy applies when information is provided to Specra, when a hosted feature is used, or when the desktop application sends information to a provider at your direction.
For privacy questions or requests, contact lance@linkage.dev.
Information we collect and its sources
We collect account and identity information, such as your email address, authentication identifiers, and profile information received from you or an authentication provider.
We collect hosted project content you choose to submit, which may include prompts, uploaded screenshots and reference images, generated artifacts, project metadata, design-system information, and related workspace content.
When you direct a desktop agent or hosted workflow to act on a project, the selected service or provider may receive the content needed for that run, such as scoped source code, prompts, Target UI details, screenshots, DOM and style context, design-system context, tool results, edits, and generated outputs.
We collect usage and device information from our hosted services, such as page and request activity, browser and device information, API activity, run status, diagnostics, security events, and operational telemetry. Desktop diagnostics generally remain local unless you choose to copy, export, or submit them.
The desktop application keeps a private, local, metadata-only audit journal for each exact project, Page, or component conversation. It may record timestamps, event order, opaque session and run identifiers, message roles and byte counts, attachment categories and counts, selected model or backend identifiers, run and recovery status, permission decisions, tool lifecycle status, storage failures, exports, and deletion tombstones. It does not store prompt or response text, source code, screenshots, DOM or selectors, file paths or URLs, hidden reasoning, secrets detected by its safeguards, or tool input and output. The journal is not uploaded merely because it exists; you may explicitly copy or export it for inspection or support.
We collect feedback and outcome information you choose to provide, such as ratings, review comments, accepted or rejected results, selected variants, approvals, and reports of problems. If an optional model-improvement program is enabled, the additional information described below may also be collected.
We collect subscription and transaction records. Payment card details are processed by our payment provider and are not stored directly by Specra.
These categories are collected from you, your device, the features and agents you direct, authentication and payment providers, and service providers that operate Specra on our behalf.
How we use information
We use information to authenticate accounts; provide local and hosted product features; process references and agent runs; store projects and artifacts; provide support; administer subscriptions; secure the service; prevent abuse; troubleshoot failures; and comply with legal obligations.
We may use operational telemetry, error information, and aggregated service metrics to evaluate reliability, safety, latency, and cost and to improve the service. We apply the additional conditions below before using Customer Content for generalized AI model training or fine-tuning.
AI inference and user-selected providers
Specra uses AI services to analyze references, assist with code and design work, and generate outputs. Content submitted to a hosted AI feature may be processed by Specra's AI providers. In the desktop application, you may also select a local or third-party agent; information sent to an independently selected provider is handled under your relationship, settings, and terms with that provider as well as any agreement that applies through Specra.
AI inference used to perform a requested task is separate from using content to train or fine-tune a generalized model. A provider is not authorized by Specra to use Customer Content for its own model training unless that use has been disclosed and is permitted by the applicable customer choice, provider terms, or agreement.
Optional model improvement and training
Specra may offer an optional model-improvement program or enter into written terms that permit us to use eligible Customer Content and interaction data to develop, train, fine-tune, distill, evaluate, and improve AI models and agent systems for design and software development. The account setting is off by default. If the setting is absent, stale, subject to renewed consent, or cannot be confirmed, no session is eligible under that setting. Participation is not required to use ordinary product features.
Turning on the account setting authorizes signed Specra desktop releases to automatically prepare and securely transfer eligible, sanitized sessions that begin afterward. You will not be prompted separately for every eligible transfer. By turning it on, you confirm that you have the rights and authority needed to share eligible content from the projects you use with Specra. Each transfer still requires a short-lived, single-episode authorization bound to the authenticated desktop installation and the exact sanitized episode. Separately negotiated written agreements may establish a different collection process for the content they expressly cover.
If an authorized collection flow is enabled, eligible training information may include prompts and instructions; scoped code and design-system context; screenshots, references, and Target UI context; allowlisted observable tool lifecycle metadata and sanitized tool summaries; user-visible intermediate and final outputs; code changes and diffs; verification and evaluation results; review comments; ratings; selected variants; approval, apply, rejection, retry, and undo signals; and technical metadata about model performance, latency, errors, and cost.
Authentication credentials and secrets detected by our safeguards, Specra system and developer prompts, provider-private hidden reasoning or chain-of-thought, and raw or hidden tool input and output are excluded from the optional program. These exclusions do not prevent us from keeping limited content-free operational and security metadata reasonably necessary to document consent, investigate abuse, or operate the service.
Specra-owned and human-authored information may be collected under an active choice. Third-party provider-generated outputs are excluded unless the current notice and an authoritative rights policy permit the exact provider, model, output class, provider-terms version, and policy reference.
We may filter, label, annotate, redact, aggregate, or transform eligible information into training examples and evaluation datasets. Authorized personnel and service providers may review limited examples when reasonably necessary for quality, safety, annotation, or debugging, subject to confidentiality and access controls.
The account setting never enrolls a session that began before its recorded grant. We will provide a separate notice, choice, or agreement before expanding eligibility or using content under a materially different training program.
If participation is based on consent, you may withdraw it for future use as described in the applicable control or by contacting us. Withdrawal does not make prior processing unlawful. Because model development is iterative, deleting source information may not automatically remove every statistical influence from a model that completed training before the request. We will remove eligible source information from future training datasets and take any additional measures required by applicable law, subject to backup, security, fraud-prevention, and legal-retention requirements.
Legal bases for processing
Where applicable law requires a legal basis, we process information as necessary to perform our contract with you, comply with law, and pursue legitimate interests such as securing, operating, and improving Specra when those interests are not overridden by your rights.
Where we rely on consent for optional model training or another purpose, you may refuse or withdraw that consent without losing product features that do not require the processing. We may rely on a different basis when permitted by law and will describe it in the relevant notice.
Service providers and disclosures
We use providers for hosting, storage, databases, web analytics, authentication, payments, background jobs, customer support, AI inference, and, if enabled, model training, evaluation, annotation, and deployment. Current examples include Vercel, Google, Stripe, Inngest, OpenAI, and providers or agents selected by the user.
Providers acting for Specra are permitted to process information only for the contracted services and applicable instructions. We may also disclose information to comply with law, protect rights and safety, investigate abuse, complete a corporate transaction, or with your direction or consent.
Specra does not sell personal information or share it for cross-context behavioral advertising. If that practice changes, we will provide any notice and opt-out mechanism required by law before the change applies.
Retention and deletion
We retain account, billing, hosted project, uploaded-reference, artifact, security, and operational records for as long as reasonably necessary for the disclosed purposes, based on the life of the account or project, contractual requirements, security and fraud-prevention needs, backup cycles, dispute resolution, and legal obligations.
Training examples and evaluation records are retained according to the applicable model-improvement program, agreement, dataset lifecycle, and legal requirements. We seek to minimize identifiable content and keep it only while reasonably necessary for the stated development and evaluation purposes.
If you delete hosted content or request account deletion, we will use reasonable efforts to remove active data from our systems and direct applicable service providers to do the same, subject to lawful exceptions. Local desktop records remain under your control and can be removed through the available local controls or operating-system storage management.
Deleting a desktop conversation removes its saved messages and records a metadata-only deletion tombstone in the native audit journal. Resetting renderer workspace data does not erase that separate journal. The journal remains in Specra's private application data until removed through the operating system, subject to copies that may remain in device or filesystem backups.
Your choices and privacy rights
Depending on where you live, you may have rights to know or access the personal information we maintain; obtain a portable copy; correct inaccurate information; request deletion or restriction; object to certain processing; withdraw consent; and appeal a denied privacy request. You also have the right not to receive discriminatory treatment for exercising applicable privacy rights.
You may exercise these rights or ask about an applicable model-training choice by contacting lance@linkage.dev. We may need to verify your identity and authority before completing a request. Authorized agents may submit requests where permitted by law.
California residents may request the categories and specific pieces of personal information collected, the categories of sources and recipients, and our business purposes, and may request correction or deletion subject to exceptions. We do not currently sell personal information or share it for cross-context behavioral advertising.
Residents of the EEA, United Kingdom, or Switzerland may also contact their local data-protection authority. Where consent is the basis for optional training, it will be presented separately and may be withdrawn as described above.
International processing
Specra is operated from the United States. Information may be processed in the United States and other jurisdictions where Specra and its providers operate. Where required, we use approved contractual or other safeguards for international transfers.
Security
We use reasonable technical and organizational measures designed to protect information in transit and at rest, limit access, and reduce accidental or unauthorized use. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Do not submit secrets, credentials, regulated data, or sensitive personal information to a hosted or optional training feature unless the feature and your agreement expressly support that information.
Children
Specra is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Users who are not old enough to enter into a binding contract in their jurisdiction may use Specra only through an authorized organization or with any legally required permission.
Optional model-improvement programs are not intended to collect children's personal information. If you believe a child has submitted personal information, contact us so we can investigate and take appropriate action.
Changes to this policy
We may update this Privacy Policy as Specra evolves. We will post the updated version with a new effective date and provide additional notice or obtain consent when required for a material change. A policy update alone does not authorize retroactive use of previously collected content when applicable law requires a new notice or consent.