Privacy Policy
Last Updated June 18, 2026
Privacy Policy
This Privacy Policy explains how Conspecta LLC ("we," "our," or "us") collects, uses, shares, and protects personal information when you use our websites, applications, and related services (the "Service"). By using the Service, you agree to this Privacy Policy.
Information We Collect
We may collect the following categories of information:
- Account information: email, billing details, and login credentials. We may also collect other identifiers you choose to provide (for example, your name, date of birth, or institution) when necessary for billing, account setup, or support.
- Usage information: device type, operating system, browser, IP address (recorded with sign-in and security events, such as logging in or authentication failures), and activity within the Service (for example, feature usage, login time, session identifiers, error events, and basic interaction logs). We use this information for security, troubleshooting, license verification, and abuse detection (such as detecting automated scraping, unusual account sharing, or attempts to bypass technical protections), as well as to operate and improve the Service. Retention of this data is described under "Data Retention" below.
- Support communications: information you provide when requesting support, including logs or error reports if you choose to share them.
- Content: your scientific images, research data, and other content ("Your Content") are stored on our cloud infrastructure to enable the Service. Depending on the features you use, processing of Your Content may occur locally within your web browser, on our cloud servers, or a combination of both. Your Content is encrypted at rest and in transit. We implement access controls that logically isolate your data from other users.
- Cookies and tracking: our website may use cookies, local storage, or similar technologies in order to operate, secure, or improve the Service. You can control cookies through your browser settings. If required by law, we will provide notice and obtain consent before placing non-essential cookies, and such cookies will not be used without your consent. Our content delivery network and web servers also generate standard log data about visits to our website (such as page requests, approximate location, and device, browser, and referral information), which we use to operate, secure, and improve the website. We may also use measurement tools to understand overall website usage for these purposes. We do not use third-party trackers for cross-site behavioral advertising. We do not currently respond to browser Do Not Track signals, as there is no industry-standard technology for honoring them; however, we do not engage in cross-site tracking.
- Security verification: we use Cloudflare Turnstile to protect forms from automated abuse. Cloudflare's use of data collected through this service is governed by the Cloudflare Turnstile Privacy Policy (opens in new tab).
We do not intend for the Service to be used with protected health information (PHI) or other highly sensitive categories of data (such as government identification numbers, full financial account numbers, or biometric identifiers), and we do not knowingly collect such information. Please do not submit these types of data to the Service.
How We Use Information
We use personal information to:
- Provide, operate, and improve the Service
- Process payments and manage subscriptions
- Respond to support requests and communications
- Maintain security, prevent fraud, and enforce our Terms (including detecting and preventing unauthorized access, account sharing, circumvention of licensing or technical protections, automated scraping, and other misuse of the Service)
- Comply with legal obligations
We may aggregate or de-identify personal information so that it can no longer reasonably be used to identify you. We may use such aggregated or de-identified information to improve the Service, analyze usage patterns, or publish aggregate statistics. We will not attempt to re-identify individuals from such data.
We do not use Your Content to train our models or to otherwise improve the Service unless you explicitly enable a feature that clearly states that such data will be used for that purpose.
We may occasionally send you marketing or promotional communications by email. You can opt out at any time by using the unsubscribe link in any such email or by contacting us. Opting out of marketing communications does not affect transactional messages related to your account (such as billing confirmations, security alerts, or service notifications).
Legal bases for EU/UK users: processing is based on (a) performance of a contract (providing the Service), (b) compliance with legal obligations, (c) legitimate interests (such as improving and securing the Service), or (d) your consent (for marketing communications or other optional features where consent is required).
Data Retention
We retain personal information only as long as necessary to provide the Service, meet legal obligations, resolve disputes, or enforce agreements. Your Content (images, projects, and related data) is retained while your account is active. If your paid subscription ends, we retain Your Content for six (6) months before deletion. If your free-tier account remains inactive (no login) for thirty-six (36) months, we may delete Your Content after providing ninety (90) days' notice to your registered email address.
Billing and payment records may be retained for up to ten (10) years where required by applicable tax and accounting laws. Other categories of data, such as logs or support communications, are kept only as long as needed for technical, security, or support purposes and are then deleted or anonymized. In some cases where we reasonably suspect fraud, abuse, or security incidents, we may retain relevant logs and identifiers for a longer period as necessary to investigate, mitigate, or cooperate with law enforcement or legal proceedings. You may request deletion of your personal data at any time (see "Your Rights" below).
We also maintain security and audit logs (records of significant account and security events, which may include your email address and the IP address associated with sign-in and security events) to protect the Service, maintain the integrity of our records, and support our security and compliance obligations. We retain these logs for up to twenty-four (24) months and then delete them.
International Transfers
If you access the Service from the EU, UK, or other regions with data protection laws, please note that your information may be transferred to and processed in countries outside your region (including the United States). Where required, we use appropriate safeguards to protect your data, such as Standard Contractual Clauses or other transfer mechanisms approved under applicable law. We may update or replace these safeguards over time as legal requirements evolve.
We may offer data residency options that allow you to store Your Content in specific geographic regions. If available, such options will be described in your account settings or plan documentation.
Data Sharing
We do not sell personal information. We may share information only in these limited cases:
- With service providers who perform services on our behalf (such as payment processors, hosting providers, or customer support tools), under confidentiality obligations
- With legal authorities if required by applicable law or to comply with valid legal process
- In connection with a business transfer, such as a merger, acquisition, or sale of assets
We use a limited number of trusted third-party service providers (for example, payment processors, hosting providers, and customer support tools) to operate the Service. We require these providers to use personal information only as necessary to perform services for us, to protect it appropriately, and to comply with applicable law. We maintain an up-to-date list of our main subprocessors, which is available upon request.
To provide certain features — such as automated image analysis or AI-generated content — we use our own models, and where a feature requires it, trusted AI service providers, to process Your Content. Your Content is transmitted securely and processed solely to provide the requested feature, and we do not permit any service provider to retain or use Your Content for their own purposes, such as training their own models. If we make available an option to connect your own third-party AI provider and you choose to use it, Your Content will be processed by that provider under your agreement with them, governed by its terms rather than this Privacy Policy.
Where we process personal information on behalf of an institutional or enterprise customer under a separate data processing agreement or similar contract, that agreement will govern our processing of personal information to the extent it conflicts with this Privacy Policy.
Automated Processing
The Service may use automated systems to detect fraud, enforce usage limits, provide AI-powered features, or support other functionality. If an automated decision significantly affects your account or access to the Service, you have the right to request human review of that decision by contacting us.
Your Rights
Depending on your location, you may have the following rights:
- Access your personal information
- Correct or update inaccurate data
- Request deletion of your personal information
- Restrict or object to certain processing
- Export your data in portable formats (the Service allows you to export images, notebooks, data tables, data summaries, and analysis models in standard formats)
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority
We will respond to access, correction, and deletion requests within thirty (30) days. In some cases, we may need to verify your identity before processing your request. When you request deletion, we remove your personal information from our active systems, but we may retain limited security and audit-log records (which can include your email address and the IP address of sign-in or security events) for up to twenty-four (24) months where necessary for security, record integrity, and legal-compliance purposes, after which they are deleted.
California residents also have rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know what personal data we collect, request deletion or correction, and opt out of any "sale" or "sharing" of personal data (we do not sell your data). We also do not "share" personal information for cross-context behavioral advertising as defined by the CCPA/CPRA.
Children's Privacy
The Service is intended for individuals who are at least 18 years of age (or the age of majority in their jurisdiction, if higher) and who are legally able to enter into binding agreements (see our Terms of Service). We do not knowingly collect personal information from children under 18. If we become aware that we have collected such information, we will delete it promptly.
Security
We implement appropriate technical and organizational measures designed to protect personal information. However, no system is completely secure, and we cannot guarantee absolute security. We may update and improve these measures from time to time as technology and threats evolve. You are responsible for maintaining the confidentiality of your account credentials.
In the event of a data breach that affects your personal information, we will notify you and any applicable regulatory authorities as required by law, typically within 72 hours of becoming aware of the breach.
Changes
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last Updated" date and, where appropriate, notify you through the Service or by other means. Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.
Contact
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us through our contact form or by mail at our registered agent address:
Conspecta LLC
611 South DuPont Highway, Suite 102
Dover, Delaware 19901, USA