What this notice covers
This notice covers the public Sightspool website, the working-demo enquiry form, account creation, Builder Free and Team Trial workspaces, assisted-onboarding applications, sources you connect, AI assistants you connect Sightspool to, and people who take part in research run through Sightspool. It does not replace the written data-processing, security or confidentiality terms agreed for a managed implementation.
Information we collect
Information you give us
Your name, work email, company and the product question or message included in a demo request or assisted-onboarding application. Account creation records your email, authentication information and acceptance of the current Terms and Privacy Notice.
Information your workspace holds
A workspace may hold configuration, questions, assumptions, decisions, agent conversations, generated outputs and information read from sources that you deliberately connect. Source credentials are stored encrypted. Sightspool also records usage and provenance needed to enforce allowances, explain outputs, secure the service and diagnose failures.
Technical information collected automatically
Our hosting, database, authentication and security providers process ordinary technical request information, including IP address, browser or device information, timestamps and requested pages. If you sign in, authentication and session data is processed to keep the account secure.
Cookies and similar technologies
Sightspool uses a small number of cookies and equivalent browser storage. We do not use advertising cookies and we do not sell or share information for advertising.
- Authentication and session — set when you sign in, to keep you signed in and to protect the account. These are necessary for the product to work.
- Workspace preference — a cookie recording which workspace you last selected. It is only a pointer; access is re-checked against your membership on every request.
- Product analytics — set by our analytics provider, described in the next section. These can be declined using your browser or an opt-out signal without losing access to the product.
Product analytics
We use PostHog to understand how the Sightspool product and website are used, so we can find broken paths and decide what to build. PostHog processes this information on our behalf in the United States. Analytics requests are routed through our own domain, so your browser talks to Sightspool rather than directly to the analytics provider.
We record page views, ordinary product events such as signing up or connecting a source, and unhandled application errors. When you are signed in, we associate those events with your user account and include your email address on the analytics profile so we can support you and understand real usage rather than anonymous traffic.
Session replay is switched off. Sightspool does not record your screen, keystrokes or the contents of your workspace, and this is disabled in the product’s code rather than by a setting. That is deliberate: a signed-in workspace displays evidence read from sources you connected, and that information belongs to you and to the people it describes — not in an analytics tool. We also never place workspace content, source data, credentials, research responses or agent output into analytics events.
You can opt out by enabling “Do Not Track” or a global privacy control in your browser, by blocking analytics cookies, or by asking us to remove your analytics profile using the contact details below.
Connecting Sightspool to Claude and other AI assistants
You can connect Sightspool to an AI assistant or coding agent so it can read your register, findings and signals while you work. When you do, information you ask for is returned to that assistant and is then handled by its provider under their terms and your settings with them, not by this notice.
That connection is restricted to the workspace it was issued for. Sightspool does not request or store the assistant’s memory, your chat history, conversation transcripts or summaries, or files you have attached to a conversation. The connection cannot approve a decision, rule a verdict, launch research at your users, or change anything a person has not approved — it can only read, and record a draft for you to review. You can revoke the connection at any time from your workspace settings.
Research participants
Sightspool customers can run research — a short in-product question, survey or interview — with their own users. If you took part in one of these, this section is for you.
- We do not ask for your name, email address or an account. You are recorded against an opaque identifier that lets us avoid asking you the same question twice.
- We store your answer — your selection, your written response, and where a study uses voice, the recording and its transcript — so it can be analysed and quoted in the customer’s findings.
- Please do not include personal details about yourself or anyone else in a free-text or spoken answer. We do not need them.
- The customer running the study decides its purpose and is responsible for it. Sightspool processes the responses on their behalf. To access or delete your response, contact that organisation, or write to privacy@sightspool.com and we will pass the request on.
How we use it
- Respond to an enquiry and decide whether a working demo is relevant.
- Create and operate free and trial workspaces.
- Review assisted-onboarding eligibility and schedule approved help.
- Run approved AI functions against the context you provide.
- Deliver research a customer has approved, and analyse the responses.
- Enforce trial and usage allowances, secure and improve the service.
- Maintain business records and meet legal obligations.
We do not sell personal information, and we do not use your workspace content, connected source data or research responses to train our own models or anyone else’s.
Service providers we use
These providers process information on our behalf so we can run the service. They act on our instructions and do not acquire independent rights to customer content.
- Supabase — database, authentication and file storage.
- Vercel — application hosting and delivery.
- OpenAI — AI model inference for agent work, analysis and, where a study uses voice, speech-to-text.
- Mistral AI — text embeddings used for agent memory.
- Resend — transactional and notification email.
- PostHog — product analytics, as described above.
Information may also be disclosed when required by law or to protect the security and rights of Sightspool, its customers or others. If Sightspool is involved in a merger, acquisition or sale of assets, we will tell affected customers and this notice will continue to apply to the information transferred until replaced.
Sources you connect
When you connect a source — for example analytics, payments or a code repository — Sightspool reads from it using the credentials you provide, which are stored encrypted. We read what is needed to answer the questions your workspace is tracking; we do not write to a connected source except where you have explicitly asked for it, such as delivering a survey you approved.
Do not place sensitive information, regulated data or personal information that is not reasonably necessary into a free or trial workspace. You must have authority to connect a source and to provide the information it contains. A managed implementation may agree a different approved-data boundary in writing.
Retention
- Workspace content — kept while the workspace exists. Ending a Team Trial does not delete it; the workspace returns to Builder Free unless access is separately ended. Deleting a workspace removes its content, subject to routine backups which age out.
- Account records — kept while the account is open, and afterwards only as needed for security, dispute handling, business records or a legal requirement.
- Research responses — kept while the study and its findings are in use by the customer, and deleted with the workspace.
- Enquiries and applications — kept while relevant to the enquiry and for ordinary business records.
- Product analytics — retained by our analytics provider under their standard retention period, and removed sooner on request.
Where information is processed
Sightspool is operated from Australia. Service providers may process information in Australia, the United States, Japan and the European Union depending on the configured service; our analytics and model providers process information in the United States, and our email provider processes in Japan. We select providers and contractual arrangements appropriate to the information and the service.
Security
Access to workspace information is restricted to members of that workspace and enforced in the database itself, not only in the application. Source credentials are encrypted at rest, and access keys are stored as one-way hashes where we only ever need to verify them. No service can promise perfect security, but we will tell affected customers promptly if a breach affects their information.
Your choices
You may ask to access, correct, export or delete information associated with your account or submitted through the public website, and to opt out of product analytics. Use the contact details below and identify the account email so the request can be matched safely. We may need to retain limited records where law, fraud prevention, security or dispute handling requires it.
If you are in a jurisdiction with additional rights — including the European Economic Area or the United Kingdom — you may also object to or restrict certain processing and complain to your local data protection authority. In Australia you may complain to the Office of the Australian Information Commissioner. We would rather hear from you first.
Children
Sightspool is a product for people working on software, and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has provided information, contact us and we will delete it.
Changes and questions
This notice may change as the website and product mature. The effective date above will be updated when a material revision is published. Privacy questions, requests and complaints can be sent to privacy@sightspool.com or through the Sightspool contact page, and are handled by Cumulative Consulting Pty Ltd trading as Sightspool, Australia. To report a security vulnerability, write to security@sightspool.com.