What Intspec holds, and for how long.
The privacy policy in full. Every line describes what the service does today, read from the code on 2026-09-14.
Who is responsible
Intspec is operated by Ing. arch. Marko Rimár, a sole proprietor established in Slovakia. For the purposes of the General Data Protection Regulation (GDPR) the operator is the data controller. Contact for anything on this page: hello@intspec.studio.
Intspec is offered to businesses and professionals. If you are using it in a business capacity, the data you put in about your suppliers and clients is yours; we process it on your instructions to provide the service.
What we hold
Your account
- Email address, display name, and a hashed password (never the password itself).
- Session records: when you sign in we store the IP address and browser identifier of the session alongside it. Sessions expire after 7 days of inactivity.
- Email verification and password-reset tokens, valid for one hour.
- Security counters that limit sign-in and password-reset attempts. They are keyed by a hashed email address or user id, and pruned after 48 hours. The sign-in library keeps a short-lived counter per IP address and path for the same purpose.
What you put in
- The supplier links you paste, with the page title, domain and product image address we read from them, and the name of any file you imported links from.
- Projects, spec pages, categories, fields, notes and the values in them, including edits you make.
- The values our extraction produced for each link (name, supplier, brand, code, type, dimensions, material, finish, price, image address) with a confidence for each.
- Share links you create, and the email addresses you type as recipients of a share. Those addresses belong to third parties: you are responsible for having a basis to share a project with them. A share link works for 90 days, then stops. Revoking a link, or its expiry, deletes the recipient list at once; the link itself is kept as a record of having been created. The link is stored hashed, so a copy of our database does not contain working links.
- PDF exports you generate, kept until you export the same page again or for 7 days.
What we do not keep
- Questions you ask the assistant and its answers are not stored. They are sent to the language model for the answer and dropped.
- Files you import are read in your browser. Only the links or the text extracted from them reach our servers; the file itself does not.
- Supplier pages we fetch are processed in memory (a digest of at most a few thousand characters) and are not stored after the extraction.
- No payment card details. Payments, when paid plans open, are handled by our payment provider.
Billing and usage
- Your plan and an append-only ledger of extraction allowance: grants, reservations, refunds.
- Usage records for each extraction: the supplier's domain, which processing tier ran, whether it succeeded, and the cost and token counts of the provider calls involved.
Errors and logs
Server errors are reported to Sentry (EU region) with the technical context needed to fix them. We do not switch on Sentry's personal-data defaults, and no error tracking runs in your browser. Our hosting provider keeps standard request logs for a short period.
The waitlist
If you leave an email address on the marketing site before early access opens, the site sends that address, the page it came from, the time, and the question you typed (if any) as one email to our support mailbox (hello@intspec.studio, at Proton), through Resend. That mailbox is the whole list — nothing is stored on the site or in the application. The purpose is one message when early access opens and at most one update a month before that, and an answer if you asked something — the legal basis is your consent, which you can withdraw at any time by writing to hello@intspec.studio. The list is deleted no later than six months after early access opens.
Why we process it, and on what basis
- To provide the service you signed up for (GDPR Article 6(1)(b)): your account, your projects, extraction, documents and shares.
- Our legitimate interest in running a secure, working service (Article 6(1)(f)): session and rate-limit records, error reports, usage records that tell us what an extraction costs and where it fails.
- Legal obligations (Article 6(1)(c)): invoicing and accounting records once paid plans open.
We do not use your data for advertising, profiling or automated decisions with legal effect.
Fetching supplier pages on your behalf
When you paste a link, Intspec fetches that one page, on your instruction, to read the product data. The supplier's site sees a request from our servers (or from our rendering provider, Zyte, for pages that need a browser), not from you. We fetch one page per link, never crawl a site, and keep the fetched page only in memory. Product images on your board and on share pages are shown straight from the supplier's servers, so the supplier sees the viewer's browser request for the image, as it would on the supplier's own site. PDF exports fetch images through our servers.
Who else processes your data
We use a small number of service providers, each bound by a data processing agreement. The current list, with what each one receives and where it runs, is at intspec.studio/subprocessors. Some of them (the language-model provider, the rendering provider, the code and backup host) run outside the European Economic Area; for those we rely on the transfer safeguards in their data processing terms, which are the European Commission's standard contractual clauses or, for US providers certified under it, the EU-US Data Privacy Framework. We do not sell data and we do not share it with anyone else, except when the law requires it.
Email we send
Three kinds only: an address verification when you sign up, a password reset when you ask for one, and the launch note (and an answer to your question) if you joined the waitlist — sent from noreply@intspec.studio through Resend (EU region). Replies reach hello@intspec.studio. Share links open in your own email client; we do not send mail to your recipients.
How long we keep it
- Your account and everything in it: for as long as the account exists.
- Waitlist addresses: kept in the support mailbox no later than six months after early access opens, or deleted as soon as you ask.
- Sessions: 7 days after their last use. Rate-limit counters: 48 hours. Background job records: 7 days.
- Projects, links, values and share records: until you delete them or the account. Share links stop working 90 days after they are created, and a revoked or expired link's recipient list is deleted within six hours. Finished PDF exports: 7 days. Per-page extraction telemetry (which fetch method ran, how long, whether it succeeded): 180 days. Inline image copies of a link you removed 30 days ago are deleted.
- Encrypted database backups: 14 days, then deleted. Data you delete may therefore survive in a backup for up to 14 days; backups are encrypted and used only to restore the service.
- Usage and cost records are kept for accounting after an account is deleted, with the link to the account removed.
Your rights
Under the GDPR you can access, correct, export, restrict, object to, and erase the personal data we hold about you, and complain to a supervisory authority. In the app:
- Export: Settings offers a JSON export of your profile, projects, library, shares (including recipient addresses), sessions and billing ledger.
- Delete: Settings deletes the account after you re-enter your password. This removes your projects, links, values, shares, recipient lists, exports, billing account and ledger immediately.
- Correct or change an email address, restrict or object: write to hello@intspec.studio from the address on the account; we answer within a month, as the GDPR requires, and usually much sooner.
The supervisory authority for the operator is the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov SR, dataprotection.gov.sk). You may also complain to the authority in your own country.
Changes to this policy
When the service changes in a way that changes this page, we update it and the date at the top, and tell signed-in users in the app if the change matters to them.