Privacy Policy
Effective January 1, 2026
Spendassay audits what companies spend on AI tools. That means we sit between a company's AI vendor bills and its engineering systems — so how we handle data is not a compliance footnote here, it's the product.
This policy explains what we collect, what we deliberately refuse to collect, who else touches it, and what you can make us do about it. If anything below is unclear, email privacy@spendassay.com and we'll answer in plain language.
1. Who we are
SpendAssay LLC, a Pennsylvania limited liability company, trading as Spendassay.
Privacy contact: privacy@spendassay.com Security contact: security@spendassay.com
This policy covers spendassay.com, the Spendassay web application, and Spendassay Meter.
2. The most important thing on this page: two different roles
Spendassay handles two categories of data under two different legal roles. Confusing them is the most common mistake people make when reviewing a product like ours, so we're stating it first.
We are a controller for account and business data
Data about you as our customer — your name, work email, company, billing details, how you use our website and app. We decide why and how this is processed. This policy governs it.
We are a processor for the data you connect
When you connect an AI vendor or an engineering system, we process data on your instructions and on your behalf. That data includes personal data about your employees — who holds which AI seat, when they last used it, activity metadata from your version control system.
For that data, you are the controller and we are the processor. We only process it to deliver the audit you asked for. We do not use it for our own purposes, we do not sell it, and we do not use it to train models. Our obligations are set by our Data Processing Agreement — available on request at security@spendassay.com — which takes precedence over this policy where the two differ.
If you are an employee of a Spendassay customer and you want to know what your employer has connected, ask your employer. They control that data; we can't disclose it to you without their instruction, and we'll tell you so if you ask.
3. What we never receive
These are architectural limits, not settings. There is no plan tier that turns them off and no support request that will unlock them.
- Source code. We never ingest, store, or read the contents of your repositories.
- Prompts and completions. We never receive the text you or your engineers send to or receive from an AI model. Spendassay Meter counts tokens and reads metadata tags; prompt and completion bodies are discarded and never written to storage.
- Message content. We do not read the bodies of chat messages, issues, pull request discussions, or email.
- Individual performance rankings. We do not produce them. Productivity figures render only for groups of eight people or more — a floor enforced below the interface, not a configurable default. This exists so our output survives works council consultation and GDPR proportionality review, and so no manager can use our product to rank a named individual.
If you need these limits evidenced for a security review, the control-by-control detail is on our security page and in the SOC 2 readiness report, available on request.
4. What we do collect
4.1 Account data — we are the controller
| Data | Why | Lawful basis (GDPR) |
|---|---|---|
| Name, work email | Create and secure your account; authenticate you | Performance of a contract |
| Company name, role | Provision your workspace; support | Performance of a contract |
| Authentication identifiers (Google account ID, magic-link tokens) | Sign you in without a password | Performance of a contract |
| Billing name, address, tax details, payment card token | Take payment; meet tax and accounting obligations | Performance of a contract; legal obligation |
| Support correspondence | Answer your questions | Legitimate interests (running a support function) |
We never receive or store your full payment card number. Card details go directly to Stripe; we hold a token and the last four digits.
4.2 Connected data — you are the controller, we are the processor
When you authorize a connection, we request read-only scopes and pull only what the audit needs:
- Seat and licence records — who is assigned which AI tool seat, at what price, on which plan.
- Usage metadata — counts, timestamps, and model identifiers. How many requests, when, against which model. Not what was in them.
- Invoices and billing line items from your AI vendors.
- Directory data — team and group membership, employment status, cost centre, from your identity provider.
- Engineering activity metadata — commit counts, pull request counts and timings, review latency, incident and rework signals. Metadata only; never the diff, never the code, never the discussion text.
Connectors currently include GitHub, Anthropic, OpenAI, Cursor, ChatGPT Enterprise, Ramp, Okta, Google Workspace, and CSV import. Every connector has a CSV fallback if you would rather export a file than grant access.
You choose what to connect. Nothing is connected by default, and disconnecting a source stops the collection immediately.
4.3 Website and product analytics — we are the controller
| Data | Why | Lawful basis |
|---|---|---|
| Pages viewed, referrer, approximate location from IP, device and browser type | Understand what's working on the site; fix errors | Consent where required; otherwise legitimate interests |
| In-product events (features used, errors hit) | Improve the product; diagnose faults | Legitimate interests |
| Form submissions (demo requests, calculator results, contact) | Respond to you; qualify sales enquiries | Consent; legitimate interests |
We use PostHog for this. See §6 and §11.
5. What we do with it
- Deliver the audit. Normalize your AI spend across vendors, identify recoverable spend, and produce your reports.
- Run your account. Authenticate, provision, bill, support.
- Keep the service secure. Detect abuse, investigate incidents, maintain the audit log.
- Improve the product. Aggregate and de-identified usage patterns only.
- Tell you things. Service notices always; marketing only where you've opted in or where we're permitted to email an existing business contact, and always with a working unsubscribe.
What we don't do
- We do not sell personal data, and we do not share it for cross-context behavioural advertising. Under CCPA/CPRA definitions, we have not sold or shared personal data in the preceding twelve months.
- We do not use your connected data to train machine learning models — not ours, not anyone's.
- We do not use one customer's data to produce another customer's findings. Any benchmark we publish is aggregated across a population large enough that no customer is identifiable, and we will say so where we publish it.
- We take no commission, margin, or referral fee on your AI spend. Our revenue does not change based on what your audit concludes.
6. Who else touches your data
We use a small number of subprocessors. Each is bound by a written agreement with confidentiality and security terms at least as protective as ours.
| Subprocessor | What it does | Where |
|---|---|---|
| Neon | Managed Postgres — the primary datastore | United States (Mid-Atlantic, Domain 2) |
| Vercel | Application hosting and serverless compute | United States |
| Resend | Transactional email (sign-in links, alert digests) | United States |
| PostHog | Website and product analytics. In-product events, bucketed, plus approximate location derived from IP. Never finding contents or connected data | United States |
| Stripe | Billing and payment processing | United States |
We maintain the current list at this section and will give at least 30 days' notice before adding a subprocessor that processes customer data, so you can object. To receive those notices, email security@spendassay.com.
Website analytics
On our public marketing pages only — not in the application, and never against your connected data — we use Apollo.io to identify the company an anonymous visitor is browsing from. It does not identify individuals, and it does not process customer data, so it is not a subprocessor under this section and the 30-day notice above does not apply to it. We list it here anyway, because a visitor-identification tool that a reader discovers somewhere other than the privacy policy is a tool that looks concealed. Email security@spendassay.com to be excluded.
Note that Apollo.io does not honour Do Not Track. PostHog does.
We also disclose data where we're legally required to — a valid court order, subpoena, or regulatory demand. Where we're permitted to tell you, we will.
If Spendassay is acquired or merges, data may transfer as part of that transaction. You'll be notified, and the acquirer will be bound by this policy until it's superseded by one no less protective.
7. International transfers
We are based in the United States and our infrastructure is primarily US-hosted. If you are in the European Economic Area, the United Kingdom, or Switzerland, your data will be transferred to the United States.
For those transfers we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), together with supplementary technical measures — encryption in transit and at rest, and the architectural limits in §3 that mean the most sensitive categories of data never leave your systems in the first place.
A copy of the SCCs as we execute them is available on request.
8. How long we keep it
| Data | Retention |
|---|---|
| Account data | For the life of your account, then 90 days after closure |
| Connected data (as processor) | Per your instruction. Deleted within 30 days of disconnection or account closure unless you tell us otherwise |
| Invoices and billing records | 7 years, as tax and accounting law requires |
| Security audit log | 12 months. Append-only — entries can be added but never altered or deleted |
| Website analytics | 14 months |
| Support correspondence | 3 years from last contact |
You can delete your workspace at any time from your account settings. That triggers deletion of connected data on the schedule above. Backups roll off within a further 35 days.
9. How we protect it
- Read-only by architecture. For the audit (Snapshot and Observe) we request read-only scopes, and those plans have no write path back into your systems. Control is the one exception: it acts only on rules you configure, and it runs on your own provider keys.
- Encryption. TLS 1.2+ in transit. AES-256-GCM at rest. Connector credentials encrypted with separately managed keys.
- Tenant isolation enforced by the database, not by application logic — so a bug in the application layer cannot expose one customer's data to another.
- Append-only audit log of access to customer data.
- Least privilege. Staff access to production customer data is restricted, logged, and granted only where needed to support you.
- SOC 2. We are pre-certification. As of the effective date of this policy, 20 of 34 controls are met and enforced in code. The full control-by-control readiness matrix, including the nine partial and five deferred controls, is available for a security review. We'd rather tell you exactly where we are than display a badge we haven't earned.
No system is perfectly secure. If we suffer a breach affecting your personal data, we will notify you and any applicable supervisory authority without undue delay and, where the law sets one, within the required deadline — 72 hours under GDPR.
10. Your rights
If GDPR or UK GDPR applies to you
You have the right to: access your data; correct it; erase it; restrict or object to its processing; portability (receive it in a machine-readable format); and to withdraw consent at any time where consent is the basis.
You also have the right to lodge a complaint with a supervisory authority — the ICO in the UK, or your national data protection authority in the EEA. We'd appreciate the chance to resolve it first.
We do not make decisions producing legal or similarly significant effects about individuals through solely automated means.
If California law applies to you
Under CCPA/CPRA you have the right to know what we collect and why, to delete it, to correct it, to opt out of sale or sharing (we do neither), to limit use of sensitive personal information (we don't collect any as defined by the statute), and to non-discrimination for exercising any of these.
Other US states
Residents of Colorado, Connecticut, Virginia, Utah, Texas and other states with comprehensive privacy laws have substantially similar rights. We apply the same process to all of them.
How to exercise any of this
Email privacy@spendassay.com. We'll verify your identity — usually by confirming control of the email on the account — and respond within 30 days, or tell you why we need longer. No charge, unless a request is manifestly unfounded or excessive.
You may use an authorized agent. We'll ask for proof of authorization.
If your employer is our customer, and your request concerns data they connected, we will forward your request to them and tell you we've done so. They control that data and we act on their instructions.
11. Cookies and tracking
We use:
- Strictly necessary cookies — to keep you signed in and to protect against cross-site request forgery. These can't be turned off without breaking the service.
- Analytics cookies — PostHog, to understand site and product usage.
We do not use advertising cookies and we do not permit third-party ad networks on our site.
Where consent is required — the EEA, the UK, and jurisdictions with equivalent rules — analytics cookies are set only after you consent, and you can change your mind from the cookie banner at any time. Elsewhere, you can opt out from the same control.
We honour Global Privacy Control signals as a valid opt-out of sale or sharing where the law recognises it.
12. Children
Spendassay is a business product. It is not directed to anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us personal data, email privacy@spendassay.com and we'll delete it.
13. Changes to this policy
If we make a material change we'll email account holders and post a notice on the site at least 14 days before it takes effect. The effective date at the top always reflects the current version. Prior versions are available on request.
14. Contact
Privacy: privacy@spendassay.com Security and DPA requests: security@spendassay.com General: hello@spendassay.com
Contact us about this policy at hello@spendassay.com. We answer privacy and data-subject requests by email; we do not publish a postal address. If a legal process requires one, ask at legal@spendassay.com and we will provide it directly.