Last updated · 2026-08-15
Privacy policy
We keep as little data as we can: enough to log you in, write your spec, take payment, stop people farming free specs, and email you. We don't run ad trackers or analytics cookies.
What we collect
GitHub login is the only auth method. When you sign in, we store your GitHub id, login, display name if available, primary email, avatar URL if available, and GitHub account creation date. We store your idea text, intake answers, generated brief, generation status, generated spec, public/private setting, and operational event history. We also store session records, payment attempt records, email delivery records, and server logs needed to operate and secure the service.
Free-claim fingerprint
When you claim a free Founding spec we store a one-way salted hash of your connection metadata (IP address, browser identifier) to prevent free-tier abuse. We cannot reverse it, we don't use it for tracking, and we delete it when the Founding 100 program data is archived.
The browser sends no fingerprint id. The server derives the hash from request metadata when evaluating or enforcing free eligibility.
Processors
We use GitHub for authentication, Stripe for payments, Resend for transactional email, and Anthropic through the CRHQ platform to process your idea text and intake answers into a spec. Stripe handles card data; we never see card numbers. CRHQ orchestrates the AI agent sessions that write the spec.
There are no advertising trackers and no analytics cookies. The only cookies are functional session and OAuth-state cookies.
Retention
| Account | When you delete your account, we archive it, revoke sessions, and scrub display PII such as email, name, login, and avatar. We retain the internal GitHub id and archived records needed for payment history, abuse prevention, free-claim limits, and public-license continuity. |
|---|---|
| Sessions | Rolling 30-day sessions; expired sessions are removed by maintenance. |
| Intake and brief data | Kept while your generation is active. Idle pre-payment work can be archived after 7 days and hard-deleted later if no payment exists. Specs and intake data tied to a deleted account are archived and hidden rather than erased from our records. |
| Payments | Payment audit records are retained because they support receipts, disputes, accounting, and manual refunds. Account deletion does not delete payment or Stripe webhook records. |
| Public specs | Public specs remain public under CC BY 4.0. Account deletion does not remove the public license. |
| Free-pool fingerprint | Kept for the life of the Founding-100 program and deleted when that program data is archived. |
Deletion rights and public specs
You can delete your account from the account page or contact support@generatespecs.com. Account deletion archives the account so it cannot be used again, revokes sessions, and obfuscates display PII on the archived row. We retain the internal GitHub id and historical spec, payment, webhook, email, fingerprint, and operational records needed for receipts, disputes, legal/accounting retention, abuse prevention, and the one-free-spec-per-GitHub-account rule. If you sign in again later with the same GitHub identity, you get a fresh account; the archived account remains closed.
Private specs attached to a deleted account are hidden from product access. Public specs are the carve-out: free specs and paid specs published for the discount stay public under their license. Deleting your account does not restore a used free slot.
License: CC BY 4.0. This spec is published under the Creative Commons Attribution 4.0 International license. Use it freely for anything — including commercial projects. Just credit GenerateSpecs.com with a link. Full license text: https://creativecommons.org/licenses/by/4.0/
We send transactional and lifecycle email only: welcome, generation started, generation complete, and payment receipt. We do not send marketing email unless you separately opt in later.