Skip to main content

Privacy Policy

Last updated: October 7, 2026

This Privacy Policy explains how Conspecta LLC ("we," "our," or "us") collects, uses, shares, and protects personal information when you use our websites, applications, and related services (the "Service"), and when you otherwise interact with us, for example when you contact us, meet us at an event, or we contact you about Conspecta. This Privacy Policy forms part of our Terms of Service.

Information We Collect

We may collect the following categories of information:

  • Account information: email, login credentials, and billing details. You may also add a profile, such as your name, job title, and a photo, which is optional and is shown to the people you share teams and projects with. We may ask for other details, such as your institution, when needed for billing, academic pricing, or support.
  • Usage information: your device type, operating system, and browser; the IP address recorded with sign-in and security events, and the approximate location derived from it (shown to you in your list of active sessions); sign-in times and session identifiers; error reports, which are sent automatically when something in the Service fails and carry your account ID and email so we can follow up; if you turn on notifications in our mobile apps, the push token your phone issues for them; and a record of which features you use and when. These records do not include Your Content (defined below).
  • Communications and business contacts: when you contact us, we contact you, or we meet, we keep your name, contact details, organization and role, and a record of our communications with you, including any description you add to an error report. We may add details you have made public, for example on your institution's website or a professional profile, or that a colleague gives us when introducing you.
  • Content: the files, data, and other content you upload to or create in the Service ("Your Content") are stored on our cloud infrastructure to enable the Service. Depending on the features you use, processing of Your Content may occur locally within your web browser, on our cloud servers, or a combination of both. Your Content is encrypted at rest and in transit. We use access controls so that only the people given access to a project can see its data.
  • Cookies and tracking: our website may use cookies, local storage, or similar technologies in order to operate, secure, or improve the Service. You can control cookies through your browser settings. If required by law, we will provide notice and obtain consent before placing non-essential cookies, and such cookies will not be used without your consent. Our content delivery network and web servers also generate standard log data about visits to our website (such as page requests, approximate location, and device, browser, and referral information), which we use to operate, secure, and improve the website. We may also use measurement tools to understand overall website usage for these purposes. We do not use third-party trackers for cross-site behavioral advertising. We do not respond to browser Do Not Track signals, because there is no industry standard for honoring them. We use Cloudflare Turnstile to protect forms from automated abuse; Cloudflare's use of the data it collects is governed by the Cloudflare Turnstile Privacy Policy (opens in new tab).

We do not intend for the Service to be used with protected health information (PHI) or other highly sensitive categories of data (such as government identification numbers, full financial account numbers, or biometric identifiers), and we do not knowingly collect such information. Please do not submit these types of data to the Service.

How We Use Information

We use personal information to:

  • Provide, operate, and improve the Service
  • Process payments and manage subscriptions
  • Communicate with you, including answering your questions, sending service and account messages, and asking for your feedback
  • Maintain security, prevent fraud, and enforce our Terms (including detecting and preventing unauthorized access, account sharing, circumvention of licensing or technical protections, automated scraping, and other misuse of the Service)
  • Comply with legal obligations

We use usage information for security, troubleshooting, license verification, and abuse detection (such as detecting automated scraping, unusual account sharing, or attempts to bypass technical protections), as well as to operate and improve the Service. We review this information in aggregate. We review an individual account's records only to investigate a problem or complaint concerning that account, or to carry out the security and abuse checks described above, and only to the extent necessary for that purpose.

We may aggregate or de-identify personal information so that it can no longer reasonably be used to identify you. We may use such aggregated or de-identified information to improve the Service, analyze usage patterns, or publish aggregate statistics. We will not attempt to re-identify individuals from such data.

We do not use Your Content to train our models or to otherwise improve the Service unless you explicitly enable a feature that clearly states that such data will be used for that purpose.

We may occasionally send you marketing or promotional communications by email. You can opt out at any time by using the unsubscribe link in any such email or by contacting us. Opting out of marketing communications does not affect transactional messages related to your account (such as billing confirmations, security alerts, or service notifications).

Legal bases for EU/UK users: processing is based on (a) performance of a contract (providing the Service), (b) compliance with legal obligations, (c) legitimate interests (such as operating, improving, and securing the Service, managing our relationships with customers and prospective customers, and telling you about Conspecta features and products similar to those you use), or (d) your consent, where the law requires it for marketing communications or optional features.

Data Retention

We retain personal information only as long as necessary to provide the Service, meet legal obligations, resolve disputes, or enforce agreements. Your Content (images, projects, and related data) is retained while your account is active. If your team's paid subscription ends, its projects become read-only and remain available to view and export for 90 days, after which we may permanently delete them. Reactivating a plan within that window restores full access. If your free-tier account remains inactive (no login) for 36 months, we may delete Your Content after providing 90 days' notice to your registered email address.

Billing and payment records may be retained for up to 10 years where required by applicable tax and accounting laws. Web server, API gateway and firewall logs, which include IP addresses, are kept for 90 days. Error reports are also kept for 90 days. The record of which features you use is kept for up to 12 months and then deleted or aggregated. A push token is deleted when you sign out of the mobile app. Business contact and communication records are kept for as long as we have a relationship with you or need them for the purposes described above, and are then deleted or anonymized. If you ask us not to contact you, we keep the minimum needed to honor that request. In some cases where we reasonably suspect fraud, abuse, or security incidents, we may retain relevant logs and identifiers for a longer period as necessary to investigate, mitigate, or cooperate with law enforcement or legal proceedings. You may request deletion of your personal information at any time (see "Your Rights" below).

We also maintain security and audit logs (records of significant account and security events, which may include your email address and the IP address associated with sign-in and security events) to protect the Service, maintain the integrity of our records, and support our security and compliance obligations. We retain these logs for up to 24 months and then delete them. The exception is the history of who changed or approved each record, and when: that is kept for as long as the project exists and for up to 24 months after the project is deleted.

International Transfers

If you access the Service from outside the United States, your information will be transferred to and processed in the United States and other countries where our service providers operate. Where required, we use appropriate safeguards to protect your data, such as Standard Contractual Clauses or other transfer mechanisms approved under applicable law. Your Content is stored in the United States unless a written agreement with us provides for another region.

Data Sharing

We do not sell personal information, and we do not give it to other companies for their marketing. We share personal information in the following cases:

  • With the members of the teams and projects you join or invite people to, who can see your profile and the Content shared there
  • With third parties you direct us to send data to, such as software you connect to Conspecta or the public databases the genetics tools search, as described below
  • With service providers who perform services on our behalf (such as payment processors, hosting providers, or customer support tools), under confidentiality obligations
  • With legal authorities if required by applicable law or to comply with valid legal process
  • Where we reasonably believe it is necessary to enforce our Terms, or to protect the rights, property, or safety of Conspecta, our users, or others
  • In connection with a business transfer, such as a merger, acquisition, or sale of assets

We use a limited number of trusted third-party service providers (for example, payment processors, hosting providers, and customer support tools) to operate the Service. We require these providers to use personal information only as necessary to perform services for us, to protect it appropriately, and to comply with applicable law. We maintain an up-to-date list of our subprocessors, which is available upon request.

To provide certain features, such as automated image analysis or AI-generated content, we may process Your Content on our own servers or, where a feature requires it, with third-party AI service providers. Your Content is transmitted securely and processed solely to provide the requested feature, and we do not permit any service provider to retain or use Your Content for their own purposes, such as training their own models.

You can also connect your own AI assistant or other software to Conspecta. Software connected this way reads and writes Your Content through your account, with the access you gave it, and what it retrieves is processed by that software's provider under your agreement with them, governed by their terms rather than this Privacy Policy. You control the connection and can end it at any time.

The genetics tools search public reference databases operated by other organizations: the National Center for Biotechnology Information (NCBI) and UniProt. When you run one of these searches, our servers contact those databases on your behalf and pass on the sequence, accession, or search term you submitted. Those databases receive our server’s IP address rather than yours, and no Conspecta account information is sent with the request. These searches only run when you ask for them, and BLAST asks you to confirm before your sequence is sent. Anything sent to those databases is held by them under their own privacy policies, and we cannot retrieve or delete it.

Where we process personal information on behalf of an institutional or enterprise customer under a separate data processing agreement or similar contract, that agreement will govern our processing of personal information to the extent it conflicts with this Privacy Policy.

Automated Processing

The Service may use automated systems to detect fraud, enforce usage limits, provide AI-powered features, or support other functionality. If an automated decision significantly affects your account or access to the Service, you have the right to request human review of that decision by contacting us.

Your Rights

Depending on your location, you may have the following rights:

  • Access your personal information
  • Correct or update inaccurate data
  • Request deletion of your personal information
  • Restrict or object to certain processing
  • Export your data and Your Content in portable, standard formats
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with a supervisory authority

We aim to respond to requests within 30 days, and always within the time applicable law requires. In some cases, we may need to verify your identity before processing your request. When you request deletion, we remove your personal information from our active systems, subject to the security and audit log retention described under "Data Retention" above. Copies may remain in our encrypted backups for up to 90 days until those backups are rotated. If you delete your account, work you shared into other people's projects stays with those projects under the project lead's name, and your name and email in records we keep are replaced with an anonymous placeholder.

California residents also have rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know what personal information we collect, to request its deletion or correction, and to be free from discrimination for exercising these rights. We do not sell personal information or share it for cross-context behavioral advertising, as the CCPA/CPRA defines those terms.

Children's Privacy

The Service is intended for individuals who are at least 13 years of age, or older where the law of your country sets a higher minimum age for using an online service without parental consent. If you are under 18, you may use the Service only with the permission of a parent, guardian, or the school or institution supervising your work. We do not knowingly collect personal information from children under 13. If we become aware that we have done so, we will delete it promptly.

Security

We implement appropriate technical and organizational measures designed to protect personal information. However, no system is completely secure, and we cannot guarantee absolute security. We may update and improve these measures from time to time as technology and threats evolve.

In the event of a data breach that affects your personal information, we will notify you and any applicable regulatory authorities without undue delay and within the time applicable law requires.

Changes

We may update this Privacy Policy from time to time. When we do, we change the "Last Updated" date above. If a change materially affects how we use or share your personal information, or the rights you have, we will also notify you through the Service or by email before it takes effect.

Contact

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us through our contact form or by mail at our registered agent address:

Conspecta LLC
611 South DuPont Highway, Suite 102
Dover, Delaware 19901, USA