Privacy Policy

Last updated: July 30, 2026

1. Introduction

Spun Life, LLC ("Spun," "we," "us," or "our") operates the Spun platform, including the website at spun.com and the web application at web.spun.com (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By accessing or using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, and authentication credentials (via Google Sign-In or email/password).
  • Organization Data: Business name, phone numbers, and WhatsApp integration details.
  • Payment Information: Billing details processed securely through Stripe. We do not store credit card numbers on our servers.
  • Contact Data: Contact information you upload or manage through the Service, including names, phone numbers, and any custom fields.
  • Message Content: WhatsApp messages sent and received through the Service, including text, media, and attachments.
  • Support Communications: Information you provide when contacting our support team.

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, timestamps, and interaction patterns.
  • Device Information: Browser type, operating system, device identifiers, and IP address.
  • Cookies & Local Storage: We use cookies and browser local storage to maintain sessions, remember preferences, and improve the user experience.
  • Error Reports: Automated error diagnostics to help us identify and fix issues (no personally identifiable content is included).
  • API Key Usage Data (including MCP): When your organization connects through an API key - including connecting an AI assistant via the Spun MCP server - we record for each use the key, the action, the IP address, and client software metadata, for security and audit purposes. IP addresses are treated as personal data.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service.
  • Process transactions and send related information (receipts, invoices).
  • Enable AI-powered features such as auto-replies, message composition, and transcription.
  • Send administrative messages, security alerts, and account notifications.
  • Respond to your comments, questions, and support requests.
  • Monitor and analyze usage trends to improve the Service.
  • Detect, prevent, and address technical issues, fraud, and abuse.
  • Comply with legal obligations.

4. AI Features & Data Processing

Our Service includes AI-powered features (auto-replies, message composition, transcription, and labeling). When you use these features:

  • Message content may be sent to third-party AI providers (such as OpenAI) for processing.
  • We do not use your message content to train AI models.
  • AI processing is performed on a per-request basis and content is not retained by AI providers beyond the processing window.
  • You can disable AI features at any time through your organization settings.
  • If a manager in your organization connects an external AI assistant (such as Claude or Cursor) through the Spun MCP server, that assistant accesses workspace data according to the API key scopes your organization grants. AI-initiated message sending is subject to human approval in the team inbox by default, and the organization can narrow access (channel allowlist, labels, groups) or switch this access off entirely at any time.

5. SMS Messaging

If your organization enables SMS coaching tips, the following applies:

  • SMS messages are sent via a third-party provider to US numbers only (TextGrid / 10DLC).
  • Recipients can reply STOP at any time to opt out of SMS messages.
  • Recipients can reply START to re-subscribe.
  • Phone numbers and opt-in/opt-out status are stored in our encrypted database.
  • Standard carrier messaging rates may apply to recipients.
  • SMS opt-in information (including mobile opt-in data) will not be sold, rented, loaned, or shared with third parties or affiliates for their marketing or promotional purposes.

6. Google User Data (Google API Services)

You can optionally connect your Google account to Spun. When you do, Spun accesses only the following Google user data:

  • Google Calendar (calendar.events): Spun creates and updates calendar events you explicitly request - Google Meet links for conversations, and reminders (alarms) you choose to sync to your calendar. Spun does not read or modify the rest of your calendar.
  • Google Drive (drive.file): Saving files you choose to save to your own Drive. This permission only grants access to files created or opened with Spun.
  • Email address (userinfo.email): Used solely to show you which Google account is connected in Settings.

How this data is used, stored, and shared:

  • Google user data is used solely to provide the features above, at your request. We do not use it for advertising, do not sell it, and do not transfer it to third parties - except as necessary to provide these features (the API calls to Google itself), as required by law, or as part of a merger/acquisition subject to this policy.
  • Google access tokens are stored encrypted on our servers. We do not store copies of your calendar events or Drive contents beyond the identifiers needed for syncing (for example, the calendar event ID of a reminder).
  • Retention and deletion: disconnecting your Google account in Settings deletes the stored tokens immediately. You can also revoke access at any time at myaccount.google.com/permissions. Deleting your Spun account (see our Account & Data Deletion page) deletes the connection data as well.
  • Google user data is not used to develop, train, or improve any artificial intelligence or machine learning models.

Spun's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. Data Sharing & Disclosure

We do not sell your personal information. We may share information with:

  • Service Providers: Third-party vendors that assist in operating the Service, such as messaging providers, cloud hosting providers, payment processors, authentication providers, AI providers, and email delivery providers.
  • Messaging Providers: Message data may be transmitted through third-party messaging providers that enable messaging functionality with WhatsApp and/or SMS.
  • Legal Requirements: When required by law, court order, or governmental regulation.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets.
  • With Your Consent: When you explicitly authorize sharing.

8. Data Storage & Security

  • Application servers and the primary PostgreSQL database are hosted on Hetzner Cloud in Nuremberg, Germany (EU).
  • Spun runs a regional cell architecture. Each organisation is assigned to a region, and its operational data (messages, contacts, conversations) is stored in that region's database. The EU region is hosted on Hetzner in Nuremberg, Germany; the US region is hosted on netcup in Manassas, Virginia, USA. For organisations assigned to the US region, that data is stored in the United States.
  • Voice and video calls are routed to the nearest media node. We operate self-hosted nodes on netcup in Nuremberg (EU) and Manassas (USA), so real-time media for participants in the Americas may transit infrastructure in the United States. Media is relayed in real time and is not stored on these nodes.
  • If you enable the optional Self Proxy feature, your WhatsApp connection is routed through relay servers operated by Spun. We operate relays on Hetzner in Nuremberg, Germany (EU) and on netcup in Manassas, Virginia, USA, and the connection uses the relay closest to the computer running your Self Proxy. Relay traffic is TLS-encrypted and forwarded in real time only - it is not stored on the relay servers.
  • Media files (images, video, audio, documents) are stored using Cloudflare R2 object storage with server-side AES-256 encryption.
  • The marketing site and static assets are served from Cloudflare Pages' global edge network.
  • We implement industry-standard security measures including encryption in transit (TLS 1.2+), database-level row isolation, and secure authentication.
  • Payment data is handled by Stripe, a PCI-DSS Level 1 compliant processor.
  • Despite our efforts, no method of electronic storage is 100% secure. We cannot guarantee absolute security.

9. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Retention periods for message data depend on your subscription plan:

  • Free Trial: 30 days
  • Pro: 90 days
  • Pro Plan: 1 year
  • Max 40x: Unlimited

API key and MCP usage and audit records - including IP addresses, client software metadata, approval decisions, and the reason text the AI supplied for an action - are retained for 180 days.

Upon account deletion, we will delete or anonymize your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, financial records).

For more information and to submit a deletion request, see our Account & Data Deletion page.

10. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate personal data.
  • Deletion: Request deletion of your personal data.
  • Portability: Download a machine-readable export of your data directly from your organization settings, or request one by email.
  • Objection: Object to certain processing of your personal data.
  • Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, please contact us at [email protected].

11. Monitoring & Error Tracking

We use the following services to maintain reliability, detect errors, and monitor system health. These services receive technical operational data. Our operational logs include contact phone numbers, because our support and engineering teams need them to trace a specific conversation when something goes wrong. Credentials and email addresses are automatically redacted before logs leave our servers, and WhatsApp message content is not routinely logged.

  • Sentry (Functional Software, Inc.) - captures application error reports including stack traces, browser metadata, and minimal user context (email, org ID) to help us identify and fix bugs quickly. No message content is sent to Sentry.
  • Better Stack (Better Uptime, s.r.o.) - monitors the availability of our public API endpoints. It receives only probe results (endpoint URL, HTTP status, response time); no customer data is sent to it.
  • Axiom (Axiom, Inc.) - aggregates server and container logs from across our infrastructure: timestamps, host and service names, request paths, error messages and stack traces, and contact phone numbers where they appear in an operational event. Credentials and email addresses are redacted before logs leave our servers, and message content is not routinely logged. Logs are stored in the EU (Frankfurt) and retained for 30 days.

You can view our real-time service status at spun.betteruptime.com.

12. Cookies

We use essential cookies and local storage to maintain your login session and preferences. We do not use third-party advertising or tracking cookies. You may configure your browser to refuse cookies, but some features of the Service may not function properly.

13. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 18, we will take steps to delete it promptly.

14. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws. By using the Service, you consent to the transfer of your information to these countries.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

16. Contact Us

If you have questions about this Privacy Policy, please contact us at:

Spun Life, LLC
Email: [email protected]
Website: https://spun.com
Additional privacy information, including encryption practices, sub-processors, compliance posture, and WhatsApp messaging policies, is available at: https://spun.com/privacy