Privacy Policy
Last updated: October 1, 2026
SpecHawk Inc. ("SpecHawk," "we," "us") makes SpecHawk, a QA platform that connects to web applications you choose, maps how they work, writes and runs tests, and reports the results with evidence. This policy explains what we collect, how we use it, who we share it with, and the choices you have. It applies to spechawk.ai and the SpecHawk service.
If your company has a signed agreement with us, such as a design partner agreement or an order form, that agreement controls how we handle your company's data where it differs from this policy.
1. The two kinds of data we handle
Account and website data is information about you and how you use our website and service. We decide how it is used, and this policy describes that.
Customer Data is what your company connects to SpecHawk, and what SpecHawk captures from the environments you ask it to test: environment addresses, sign-in details, page content, screenshots, recordings, logs, test steps, results and findings. We process Customer Data on your company's behalf, to provide the service to your company.
2. What we collect
Account details. Your name, work email, company and role in your workspace, and your password, which we store only as a one-way hash. If you sign in with Google, we get your name and email address from Google instead, and no password.
Environment setup. The web addresses you add and any sign-in details you give us, such as usernames and passwords, saved session cookies, extra login fields and proxy settings. We encrypt sign-in secrets before we store them and decrypt them only when SpecHawk signs in to an environment: to map it, run a test or check that sign-in works. The product never shows a saved password back to you.
What SpecHawk sees while it works. When SpecHawk maps an environment or runs a test, it opens pages in a browser the way a person would and records what it needs to show you results: page addresses, page text and structure, screenshots, video recordings of runs, console messages, failed requests, the cookies and headers a site sends, and the code libraries a page loads.
Emailed sign-in codes. An environment that signs in with emailed one-time codes gets its own inbox address on our domain. For each message sent to that address we keep the sender, the subject and the time it arrived, and we store the message body and the code encrypted. We delete each message 24 hours after it arrives. Messages that fail spam or virus checks are dropped and not stored.
Connected tools. If you connect Jira, we read the tickets you choose to turn into tests. If you link a GitHub repository, we copy it for the length of a scan and read its routes, file paths, frameworks and the names and versions of its packages. We delete the copy when the scan ends and keep only what we read. We do not store your source code.
Usage and device data. Your IP address and browser type, which reach our servers and our network provider with every request, and error logs. We do not run website analytics or tracking scripts.
What you send us. Messages you send us, and your answers when you apply to our design partner program.
3. How we use it
- To provide the service: sign you in, map environments, write and run tests, store results, run schedules and send the notifications you ask for.
- To keep SpecHawk and your data safe: detect abuse, investigate problems and prevent fraud.
- To support you, and to improve SpecHawk using de-identified, aggregated usage information that does not identify you or your company.
- To contact you about your account and important changes, and, if you agree, about news. You can opt out of marketing emails at any time.
- To meet legal obligations.
We do not sell personal information, and we do not share it for targeted advertising.
4. AI features
SpecHawk uses large language models to write tests from plain English or tickets, name and group the workflows it finds, repair test steps that stopped working, and answer questions in the Hawk, our assistant. To do this, we send the relevant content, such as page structure, page text, a screenshot and your instructions, to an AI model provider, which processes it and returns a result.
On SpecHawk's own key, requests go through OpenRouter to the model your workspace picks: DeepSeek (the default), Z.ai or OpenAI. If your workspace adds its own key for OpenRouter, Anthropic or OpenAI, requests go to that provider instead. We ask our AI router to send requests only to providers that don't keep the content and don't train on it.
We do not use Customer Data to train AI models. What a model provider may do with the content it receives is set by its own terms. If your workspace adds its own AI provider key, requests made with that key are covered by your own agreement with that provider.
5. Who we share it with
We share data with service providers that help us run SpecHawk. Where they process personal information or Customer Data for us, they are bound by contracts that limit how they can use it.
- Amazon Web Services, for hosting, storage, databases and receiving email, in the United States.
- Cloudflare, which carries traffic to our site and service and protects it from attacks.
- Google, if you choose to sign in with your Google account.
- AI model providers, through OpenRouter or with your own key, as described above.
- Tools you choose to connect, such as Atlassian Jira and GitHub.
- A proxy service you configure for an environment, if you add one. SpecHawk's browser traffic for that environment then goes through it.
We also send package names and versions, with the package registry they come from (npm), and nothing else, to OSV, the public open-source vulnerability database, to look up known advisories.
We may disclose information if the law requires it, to protect the rights, property or safety of SpecHawk, our users or others, or as part of a merger, acquisition or sale of assets, in which case this policy continues to apply to it.
6. Cookies
We set one cookie, to keep you signed in. Scripts on the page cannot read it, it is only sent over HTTPS, and it expires after 7 days. We also save a few things in your browser's own storage: preferences such as light or dark mode and your list filters, and your recent chats with the Hawk. We do not use analytics or advertising cookies.
7. How long we keep data
- Account data: while your account is open.
- Customer Data: while your workspace is active. When a workspace closes, we delete its Customer Data from our active systems within 30 days of a request, unless your agreement with us says otherwise. Copies in backups are overwritten in the normal course.
- Emailed sign-in codes: 24 hours.
- Logs and usage data: only as long as we need them for security and to run the service.
8. Security
We use HTTPS everywhere, encrypt sign-in secrets at rest, limit access to people who need it, and serve screenshots through signed links that expire within an hour. No system is perfectly secure. If you find a security issue, email us at the address below and we will look into it quickly.
9. Your choices and rights
You can ask us to access, correct, export or delete your personal information, and you can opt out of marketing emails using the link in any of them. Depending on where you live, for example in the European Economic Area, the United Kingdom or California, you may have further rights, such as objecting to or restricting certain processing, and the right to complain to your local data protection authority. We will not treat you differently for using these rights.
If your request is about Customer Data that your company controls, please contact your company's SpecHawk admin. We will help them respond.
Where EU or UK law applies, we rely on these legal bases: performing our contract with you or your company, our legitimate interest in running and improving a secure service, your consent where we ask for it, and compliance with the law.
10. Data transfers
SpecHawk is based in the United States and stores data there. If you use SpecHawk from outside the United States, your information will be transferred to and processed in the United States, with appropriate safeguards where the law requires them.
11. Children
SpecHawk is for businesses and is not meant for anyone under 16. We do not knowingly collect personal information from children.
12. Changes to this policy
When we change this policy, we will update the date at the top. If a change is significant, we will tell you by email or in the product before it takes effect.
13. Contact
Questions or requests: [email protected]

