Privacy Policy

Effective January 1, 2026

Spendassay audits what companies spend on AI tools. That means we sit between a company's AI vendor bills and its engineering systems — so how we handle data is not a compliance footnote here, it's the product.

This policy explains what we collect, what we deliberately refuse to collect, who else touches it, and what you can make us do about it. If anything below is unclear, email privacy@spendassay.com and we'll answer in plain language.


1. Who we are

SpendAssay LLC, a Pennsylvania limited liability company, trading as Spendassay.

Privacy contact: privacy@spendassay.com Security contact: security@spendassay.com

This policy covers spendassay.com, the Spendassay web application, and Spendassay Meter.


2. The most important thing on this page: two different roles

Spendassay handles two categories of data under two different legal roles. Confusing them is the most common mistake people make when reviewing a product like ours, so we're stating it first.

We are a controller for account and business data

Data about you as our customer — your name, work email, company, billing details, how you use our website and app. We decide why and how this is processed. This policy governs it.

We are a processor for the data you connect

When you connect an AI vendor or an engineering system, we process data on your instructions and on your behalf. That data includes personal data about your employees — who holds which AI seat, when they last used it, activity metadata from your version control system.

For that data, you are the controller and we are the processor. We only process it to deliver the audit you asked for. We do not use it for our own purposes, we do not sell it, and we do not use it to train models. Our obligations are set by our Data Processing Agreement — available on request at security@spendassay.com — which takes precedence over this policy where the two differ.

If you are an employee of a Spendassay customer and you want to know what your employer has connected, ask your employer. They control that data; we can't disclose it to you without their instruction, and we'll tell you so if you ask.


3. What we never receive

These are architectural limits, not settings. There is no plan tier that turns them off and no support request that will unlock them.

  • Source code. We never ingest, store, or read the contents of your repositories.
  • Prompts and completions. We never receive the text you or your engineers send to or receive from an AI model. Spendassay Meter counts tokens and reads metadata tags; prompt and completion bodies are discarded and never written to storage.
  • Message content. We do not read the bodies of chat messages, issues, pull request discussions, or email.
  • Individual performance rankings. We do not produce them. Productivity figures render only for groups of eight people or more — a floor enforced below the interface, not a configurable default. This exists so our output survives works council consultation and GDPR proportionality review, and so no manager can use our product to rank a named individual.

If you need these limits evidenced for a security review, the control-by-control detail is on our security page and in the SOC 2 readiness report, available on request.


4. What we do collect

4.1 Account data — we are the controller

DataWhyLawful basis (GDPR)
Name, work emailCreate and secure your account; authenticate youPerformance of a contract
Company name, roleProvision your workspace; supportPerformance of a contract
Authentication identifiers (Google account ID, magic-link tokens)Sign you in without a passwordPerformance of a contract
Billing name, address, tax details, payment card tokenTake payment; meet tax and accounting obligationsPerformance of a contract; legal obligation
Support correspondenceAnswer your questionsLegitimate interests (running a support function)

We never receive or store your full payment card number. Card details go directly to Stripe; we hold a token and the last four digits.

4.2 Connected data — you are the controller, we are the processor

When you authorize a connection, we request read-only scopes and pull only what the audit needs:

  • Seat and licence records — who is assigned which AI tool seat, at what price, on which plan.
  • Usage metadata — counts, timestamps, and model identifiers. How many requests, when, against which model. Not what was in them.
  • Invoices and billing line items from your AI vendors.
  • Directory data — team and group membership, employment status, cost centre, from your identity provider.
  • Engineering activity metadata — commit counts, pull request counts and timings, review latency, incident and rework signals. Metadata only; never the diff, never the code, never the discussion text.

Connectors currently include GitHub, Anthropic, OpenAI, Cursor, ChatGPT Enterprise, Ramp, Okta, Google Workspace, and CSV import. Every connector has a CSV fallback if you would rather export a file than grant access.

You choose what to connect. Nothing is connected by default, and disconnecting a source stops the collection immediately.

4.3 Website and product analytics — we are the controller

DataWhyLawful basis
Pages viewed, referrer, approximate location from IP, device and browser typeUnderstand what's working on the site; fix errorsConsent where required; otherwise legitimate interests
In-product events (features used, errors hit)Improve the product; diagnose faultsLegitimate interests
Form submissions (demo requests, calculator results, contact)Respond to you; qualify sales enquiriesConsent; legitimate interests

We use PostHog for this. See §6 and §11.


5. What we do with it

  • Deliver the audit. Normalize your AI spend across vendors, identify recoverable spend, and produce your reports.
  • Run your account. Authenticate, provision, bill, support.
  • Keep the service secure. Detect abuse, investigate incidents, maintain the audit log.
  • Improve the product. Aggregate and de-identified usage patterns only.
  • Tell you things. Service notices always; marketing only where you've opted in or where we're permitted to email an existing business contact, and always with a working unsubscribe.

What we don't do

  • We do not sell personal data, and we do not share it for cross-context behavioural advertising. Under CCPA/CPRA definitions, we have not sold or shared personal data in the preceding twelve months.
  • We do not use your connected data to train machine learning models — not ours, not anyone's.
  • We do not use one customer's data to produce another customer's findings. Any benchmark we publish is aggregated across a population large enough that no customer is identifiable, and we will say so where we publish it.
  • We take no commission, margin, or referral fee on your AI spend. Our revenue does not change based on what your audit concludes.

6. Who else touches your data

We use a small number of subprocessors. Each is bound by a written agreement with confidentiality and security terms at least as protective as ours.

SubprocessorWhat it doesWhere
NeonManaged Postgres — the primary datastoreUnited States (Mid-Atlantic, Domain 2)
VercelApplication hosting and serverless computeUnited States
ResendTransactional email (sign-in links, alert digests)United States
PostHogWebsite and product analytics. In-product events, bucketed, plus approximate location derived from IP. Never finding contents or connected dataUnited States
StripeBilling and payment processingUnited States

We maintain the current list at this section and will give at least 30 days' notice before adding a subprocessor that processes customer data, so you can object. To receive those notices, email security@spendassay.com.

Website analytics

On our public marketing pages only — not in the application, and never against your connected data — we use Apollo.io to identify the company an anonymous visitor is browsing from. It does not identify individuals, and it does not process customer data, so it is not a subprocessor under this section and the 30-day notice above does not apply to it. We list it here anyway, because a visitor-identification tool that a reader discovers somewhere other than the privacy policy is a tool that looks concealed. Email security@spendassay.com to be excluded.

Note that Apollo.io does not honour Do Not Track. PostHog does.

We also disclose data where we're legally required to — a valid court order, subpoena, or regulatory demand. Where we're permitted to tell you, we will.

If Spendassay is acquired or merges, data may transfer as part of that transaction. You'll be notified, and the acquirer will be bound by this policy until it's superseded by one no less protective.


7. International transfers

We are based in the United States and our infrastructure is primarily US-hosted. If you are in the European Economic Area, the United Kingdom, or Switzerland, your data will be transferred to the United States.

For those transfers we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), together with supplementary technical measures — encryption in transit and at rest, and the architectural limits in §3 that mean the most sensitive categories of data never leave your systems in the first place.

A copy of the SCCs as we execute them is available on request.


8. How long we keep it

DataRetention
Account dataFor the life of your account, then 90 days after closure
Connected data (as processor)Per your instruction. Deleted within 30 days of disconnection or account closure unless you tell us otherwise
Invoices and billing records7 years, as tax and accounting law requires
Security audit log12 months. Append-only — entries can be added but never altered or deleted
Website analytics14 months
Support correspondence3 years from last contact

You can delete your workspace at any time from your account settings. That triggers deletion of connected data on the schedule above. Backups roll off within a further 35 days.


9. How we protect it

  • Read-only by architecture. For the audit (Snapshot and Observe) we request read-only scopes, and those plans have no write path back into your systems. Control is the one exception: it acts only on rules you configure, and it runs on your own provider keys.
  • Encryption. TLS 1.2+ in transit. AES-256-GCM at rest. Connector credentials encrypted with separately managed keys.
  • Tenant isolation enforced by the database, not by application logic — so a bug in the application layer cannot expose one customer's data to another.
  • Append-only audit log of access to customer data.
  • Least privilege. Staff access to production customer data is restricted, logged, and granted only where needed to support you.
  • SOC 2. We are pre-certification. As of the effective date of this policy, 20 of 34 controls are met and enforced in code. The full control-by-control readiness matrix, including the nine partial and five deferred controls, is available for a security review. We'd rather tell you exactly where we are than display a badge we haven't earned.

No system is perfectly secure. If we suffer a breach affecting your personal data, we will notify you and any applicable supervisory authority without undue delay and, where the law sets one, within the required deadline — 72 hours under GDPR.


10. Your rights

If GDPR or UK GDPR applies to you

You have the right to: access your data; correct it; erase it; restrict or object to its processing; portability (receive it in a machine-readable format); and to withdraw consent at any time where consent is the basis.

You also have the right to lodge a complaint with a supervisory authority — the ICO in the UK, or your national data protection authority in the EEA. We'd appreciate the chance to resolve it first.

We do not make decisions producing legal or similarly significant effects about individuals through solely automated means.

If California law applies to you

Under CCPA/CPRA you have the right to know what we collect and why, to delete it, to correct it, to opt out of sale or sharing (we do neither), to limit use of sensitive personal information (we don't collect any as defined by the statute), and to non-discrimination for exercising any of these.

Other US states

Residents of Colorado, Connecticut, Virginia, Utah, Texas and other states with comprehensive privacy laws have substantially similar rights. We apply the same process to all of them.

How to exercise any of this

Email privacy@spendassay.com. We'll verify your identity — usually by confirming control of the email on the account — and respond within 30 days, or tell you why we need longer. No charge, unless a request is manifestly unfounded or excessive.

You may use an authorized agent. We'll ask for proof of authorization.

If your employer is our customer, and your request concerns data they connected, we will forward your request to them and tell you we've done so. They control that data and we act on their instructions.


11. Cookies and tracking

We use:

  • Strictly necessary cookies — to keep you signed in and to protect against cross-site request forgery. These can't be turned off without breaking the service.
  • Analytics cookies — PostHog, to understand site and product usage.

We do not use advertising cookies and we do not permit third-party ad networks on our site.

Where consent is required — the EEA, the UK, and jurisdictions with equivalent rules — analytics cookies are set only after you consent, and you can change your mind from the cookie banner at any time. Elsewhere, you can opt out from the same control.

We honour Global Privacy Control signals as a valid opt-out of sale or sharing where the law recognises it.


12. Children

Spendassay is a business product. It is not directed to anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us personal data, email privacy@spendassay.com and we'll delete it.


13. Changes to this policy

If we make a material change we'll email account holders and post a notice on the site at least 14 days before it takes effect. The effective date at the top always reflects the current version. Prior versions are available on request.


14. Contact

Privacy: privacy@spendassay.com Security and DPA requests: security@spendassay.com General: hello@spendassay.com

Contact us about this policy at hello@spendassay.com. We answer privacy and data-subject requests by email; we do not publish a postal address. If a legal process requires one, ask at legal@spendassay.com and we will provide it directly.