Privacy Policy

1. Who we are and scope

Spek is operated by RELOAD TECHNOLOGIES - FZCO, Dubai, United Arab Emirates ("Reload," "Spek," "we," or "us"). This Privacy Policy explains how we handle personal data when you visit spek.app, create or use a Spek account or workspace, connect an App Store Connect account, use AI-assisted features, contact us, or otherwise interact with the Service.

"Personal data" means information relating to an identified or identifiable natural person. This Policy applies only to Spek's handling of personal data. Apple, Google, the App Store, websites, and other third parties process data under their own policies.

2. Our data protection roles

Reload is the controller of personal data used to run our Website and business, administer accounts, secure the Service, communicate with you, and manage our legal obligations.

For Customer Content that a business customer submits, connects, or instructs us to process through a workspace, that customer generally determines the purpose and means of processing. In that context, the customer is the controller and Reload acts as its processor or service provider, as those terms are defined by applicable law. You should direct a request about customer-controlled data to the relevant workspace owner first. Spek will support the customer in responding as required by applicable law and the applicable agreement.

3. Data we collect

Depending on how you use Spek, we process the following categories:

  • Account and identity data: name, email address, authentication identifier, job title, avatar URL, invitation data, email and notification preferences, and multi-factor authentication status. Authentication credentials are handled through our authentication provider.
  • Workspace and access data: workspace name and subdomain, membership, role, status, owner, inviter, connected apps, permissions, and administrative actions.
  • Customer Content and product data: app identifiers, bundle or package identifiers, store listings and localizations, keywords, competitors, rankings, reviews and reviewer names, responses, screenshots and other media, events, custom product pages, drafts, approvals, publication records, agent chats, instructions, rules, proposals, and feedback.
  • Store connection data: App Store Connect issuer and key identifiers and private key, together with connection status, verification times, accessible app information, and errors.
  • Billing and transaction data:selected package and billing cycle, purchase-intent and workspace references, Stripe customer, Checkout, subscription, invoice, refund, dispute, and payment-event identifiers, payment status, paid-through and renewal dates, credit grants and debt, cancellation state, sanitized payment recovery state, and your payment-method role and consent record. For display, Spek may retain a card's brand, last four digits, expiry, primary-or-backup role, consent version, actor, and time. Full payment-method details stay in Stripe's hosted Checkout. Spek does not receive or store the full card number or CVC.
  • Technical and security data: session and authentication data, request metadata made available when the Service is used, IP-derived security signals, keyed rate-limit records, feature error records, and information relating to suspected abuse or security events.
  • Communications: support and contact messages, first and last name, email, company website, and other information you choose to send us.
  • Browser storage: authentication, purchase-intent, and workspace cookies and local preferences or editor caches described in our Cookie Policy.

Provide only the information needed for the relevant feature or request. Avoid placing government identifiers, health information, payment-card data, private account passwords, or other sensitive data in prompts, chats, reviews, drafts, screenshots, or support messages unless expressly requested and legally permitted.

4. Where data comes from

We receive data:

  • directly from you when you register, configure, upload, write, or contact us;
  • from workspace owners or administrators who invite you, assign a role, or provide information about an app or team;
  • from Apple when you connect an authorized developer account or request an App Store operation;
  • from Google when you choose Google authentication;
  • from the public App Store and ASO data providers, including public app, developer, listing, review, keyword, ranking, and competitor data;
  • from AI and other service providers that return output, delivery status, security signals, or errors;
  • from Stripe when you enter payment details, complete Checkout, manage billing, or when Stripe reports an invoice, subscription, refund, dispute, or payment event; and
  • automatically from requests and sessions needed to deliver, authenticate, and secure the Service.

5. Store credentials and connected data

Spek uses official token-authenticated APIs. App Store Connect access uses a customer-provided API key that signs an ES256 JSON Web Token. Apple ID passwords, interactive console logins, browser sessions, and provider cookies remain with Apple.

Private signing keys are encrypted with AES-256-GCM before storage using a workspace- and provider-specific cryptographic context. They are decrypted in server memory only when needed to authenticate an official API request. Connection metadata, app data, drafts, and operation records are stored separately as needed to provide the Service.

Disconnecting an integration removes the stored connection from Spek. To invalidate the key itself, revoke or rotate it with Apple. Publishing sends the approved content and necessary identifiers to the App Store, where it is processed under Apple's terms and privacy policy.

6. AI-assisted processing

Spek uses OpenRouter as an AI gateway and, depending on the selected feature, underlying model providers such as Anthropic or OpenAI. Task-relevant data may include prompts and chat history, public store data, app names, subtitles, descriptions, keywords, reviews and reviewer names, reply signatures, selected screenshots, locale information, and draft or proposed content. AI output and related workflow records may be stored in your workspace.

Spek excludes store private keys from AI prompts. Do not include secrets or unnecessary personal data in AI inputs. AI providers process the data they receive under their applicable terms and privacy commitments.

AI features prepare recommendations and drafts for review by authorized users, who decide whether to apply or publish them.

7. Purposes and legal bases

We process personal data for the following purposes:

  • to create accounts, authenticate users, operate workspaces, provide requested features, connect App Store Connect, process instructions, and support users;
  • to research keywords and competitors, produce analysis and AI output, maintain drafts, and carry out authorized publication actions;
  • to prepare and complete subscription purchases, administer plans and credits and one-time credit packages, process renewals, payments, refunds, disputes, invoices, payment recovery and cancellation, record automatic-backup consent, and maintain financial records;
  • to secure the Service, enforce permissions and rate limits, prevent fraud and abuse, troubleshoot, maintain reliability, and investigate incidents;
  • to respond to contact, support, privacy, legal, partnership, and account requests;
  • to comply with law, lawful requests, accounting duties, and to establish, exercise, or defend legal claims; and
  • to evaluate and improve functionality using product records and feedback, without using store credentials for that purpose.

Our legal basis depends on the context and applicable law. We rely on your consent where required; necessity to enter into or perform a contract with you; compliance with legal obligations; protection of rights and security; and other grounds expressly permitted by applicable law. Where a law recognizes legitimate interests, we rely on them only after considering necessity, proportionality, and your rights. You may withdraw consent at any time without affecting prior lawful processing.

8. How data is shared

We do not sell or rent personal data. We may share personal data, as reasonably necessary, with the following categories of recipients when you use the relevant feature or the circumstances require it:

  • Workspace users: authorized members can see data and activity available to their role.
  • Infrastructure: Supabase for authentication, database, and storage, and Vercel for hosting and application delivery.
  • Communications: Brevo for authentication, invite, contact, support, and account email delivery.
  • Payments: Stripe hosts card entry and processes Checkout and payment-method setup, subscriptions, invoices, payment methods, renewal recovery, refunds, disputes, and the billing portal. Stripe handles payment data under its own privacy terms and applicable payment rules.
  • AI: OpenRouter and the selected underlying model provider for AI generation, vision, or embeddings.
  • Store and ASO services: Apple, AppTweak, and public App Store services for connected operations, public store retrieval, keyword research, and related metrics.
  • Public-store network support: GeoNode may provide network routing for requests for publicly available app-store information. Authenticated Apple developer-account connections use the official App Store Connect API.
  • Legal and business recipients: professional advisers, auditors, insurers, competent authorities, courts, and a buyer or successor in a genuine corporate transaction, subject to confidentiality and applicable law.

If you instruct Spek to publish content, that content becomes available to the relevant app store and may become public by design. We may disclose data when reasonably necessary to comply with law, protect rights or safety, investigate misuse, or enforce agreements.

9. International transfers

Spek is based in the United Arab Emirates and uses providers that may process data in other countries. As a result, personal data may be transferred to or accessed from jurisdictions whose laws differ from those where you live. The countries involved depend on the providers and features you use.

Where applicable law requires a transfer mechanism or safeguard, Spek will use an available lawful mechanism before making the transfer. Contact us for information relevant to your transfer.

10. Retention and deletion

We retain personal data only for as long as reasonably necessary for the purpose collected, to provide the Service, secure systems, comply with law, resolve disputes, and enforce agreements. Retention periods vary by record and context. We consider account and workspace status, data sensitivity and volume, operational need, risk, provider capabilities, legal obligations, and applicable limitation periods.

  • account, membership, and active workspace data is generally kept while the relevant account or workspace is active;
  • store credentials are kept until the integration is disconnected, the controlling workspace is deleted, or they must be removed for security or legal reasons;
  • workspace content is generally kept while the workspace remains active, until the relevant record or workspace is deleted where deletion is available, or longer where retention is required or permitted;
  • contact records are kept while needed to respond, manage the request or relationship, prevent abuse, or satisfy legal obligations;
  • billing, invoice, payment-method role and consent, recovery attempt, refund, dispute, credit-grant, and related transaction records are kept for the subscription relationship and as long as required for accounting, tax, fraud prevention, legal claims, and other legal obligations;
  • security, diagnostic, and legal records are kept for a period proportionate to the risk and purpose; and
  • public App Store snapshots and facts may remain as historical research records sourced from the public App Store.

Self-service account deletion requires multi-factor verification. If you own a shared workspace, you must first transfer or resolve that ownership to protect other members' data. Content in a workspace you do not own may remain under the workspace owner's control after your account is deleted. Limited residual copies may persist in logs, caches, provider systems, or backups until isolated, overwritten, or deleted under the relevant retention process. We may retain data where law, a legal hold, fraud prevention, or a dispute requires it.

11. Security

We use measures designed to protect personal data, including encrypted store credentials, authentication, role- and workspace-based access checks, and restricted server-side handling of privileged credentials. We review and update these safeguards as the Service changes.

You are responsible for protecting your account, choosing least-privilege store roles, reviewing workspace members, and notifying us of suspected compromise. More detail appears on our Security page.

If a personal-data breach occurs, we will investigate and notify affected individuals and competent authorities within the period and in the manner required by applicable law.

12. Your rights

Depending on the law that applies, you may have rights to receive information about processing; access personal data; correct or complete inaccurate data; erase data; restrict or stop processing; object to direct marketing or other processing; request a portable copy of personal data where applicable law grants that right; withdraw consent; and obtain information or human review concerning qualifying automated processing.

Rights are not absolute. We may need to verify your identity and authority, protect another person's rights, preserve security, or retain information where law permits or requires. If a workspace customer controls the data, we may refer the request to that customer and assist it as required. We will respond within the period required by the law that applies to the request.

To exercise a right, email hello@spek.app and describe the data, workspace, and request. You may use an authorized representative where applicable law permits, subject to verification.

13. Your choices

Depending on your role, you can update profile or workspace information, manage workspace members, disconnect store integrations, revoke store keys at Apple, manage eligible subscription payment methods and their primary or backup role, invoices, and cancellation through Stripe-hosted surfaces, and delete an eligible account through account settings. You can clear cookies or local storage through your browser, although essential storage is needed for sign-in and some requested functions.

If we send optional promotional communications, you may unsubscribe using the message instructions or by contacting us. Transactional, security, legal, and account-service messages may still be sent where needed. Spek's cookie and similar-technology practices are described in the Cookie Policy.

14. Changes to this policy

We may revise this Policy to reflect changes in the Service, our providers, law, or processing. We will publish the revised version and provide additional or advance notice where a change is material and applicable law requires it. Where consent is the required legal basis for a new purpose, we will request it before that processing begins.

15. Contact and complaints

The responsible company is RELOAD TECHNOLOGIES - FZCO, Dubai, United Arab Emirates. Send privacy questions, requests, or complaints to hello@spek.app or use our contact page.

You may also submit a complaint to the data protection authority competent for your location or the relevant processing where applicable law gives you that right. We encourage you to contact us first so we can address the concern.