Privacy Policy

Your privacy is our priority

Last updated: December 1, 2025

Introduction

Welcome to Spectra, an AI-powered content optimization and marketing intelligence platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

Spectra helps businesses optimize their content strategy through advanced AI analysis, SEO insights, Google Ads performance tracking, keyword research, AI-generated content creation, and visibility tracking across multiple platforms including search engines and AI systems like ChatGPT, Claude, Perplexity, and Gemini.

Google Drive Logo

Google Services Integration

Spectra integrates with multiple Google services to provide you with comprehensive marketing intelligence and content optimization. Here's a complete overview of all Google OAuth scopes we request and how we use them:

Complete OAuth Scope List:

User Authentication & Profile:
  • userinfo.email - Access your email address for account creation
  • userinfo.profile - Access your basic profile information (name, photo)
  • openid - Authenticate your identity securely
Google Ads API:
  • adwords - Read-only access to Google Ads performance data and keyword planner
Google Analytics API:
  • analytics.readonly - Read-only access to your Analytics data
  • analytics - Standard Analytics data access
  • analytics.manage.users.readonly - View Analytics account users (read-only)
Google Drive & Docs API:
  • drive.file - Create and manage only files that Spectra creates
  • documents - Create and edit Google Docs for content export
Google Ads

Google Ads API Usage

How We Use Google Ads Data

Using the adwords scope, we access your Google Ads account to provide performance analytics and keyword research capabilities:

What Data We Access:

  • Campaign performance metrics (clicks, impressions, CTR, spend)
  • Ad performance data (best/worst performing ads)
  • Keyword performance and search terms
  • Device breakdown (mobile, desktop, tablet) statistics
  • Keyword Planner data (search volume, competition, CPC estimates)
  • Negative keywords and wasted spend analysis

How We Use This Data:

  • Display year-to-date campaign performance reports
  • Identify top and worst performing ads for optimization
  • Provide keyword research and discovery based on your industry
  • Calculate wasted ad spend and provide recommendations
  • Show device-level performance comparisons
  • Generate competitive keyword insights with search volume data

🔐 Read-Only Access:

We only read your Google Ads data. We never modify campaigns, change bids, pause ads, or make any changes to your advertising accounts. All access is strictly read-only for reporting purposes.

Google Analytics

Google Analytics API Usage

How We Use Google Analytics Data

Using the Analytics API scopes, we track AI-driven traffic to your website and provide insights about your digital presence:

What Data We Access:

  • Referral traffic specifically from AI platforms (ChatGPT, Claude, Perplexity, Gemini, etc.)
  • Session data, page views, and user behavior for AI referrals
  • Pages visited through AI-generated recommendations
  • Traffic patterns and trends over time
  • Bounce rates and engagement metrics for AI traffic

How We Use This Data:

  • Display AI Referrals dashboard showing traffic from each AI platform
  • Track which pages receive the most AI-driven visits
  • Generate timeline charts showing AI referral patterns
  • Calculate total sessions and page views from AI sources
  • Identify which AI platforms drive the most valuable traffic

What We Don't Access or Store:

  • Personal information about your website visitors
  • Raw Google Analytics data (we query in real-time only)
  • Individual user browsing behavior or tracking data
  • Login credentials or sensitive account information
  • Non-AI-related traffic or general analytics data

🔐 Real-Time Querying Only:

We query the Google Analytics API in real-time to generate insights and reports. We do not store raw analytics data on our servers. We only retain aggregated, anonymized metrics necessary for displaying your dashboard.

Google Drive Logo

Google Drive & Docs API Usage

How We Use Drive & Docs

Using the Drive and Docs API scopes, we enable you to export AI-generated content and reports directly to your Google Drive:

What We Can Do:

  • Create new Google Docs in your Drive with AI-generated content
  • Export blog posts, articles, and marketing content to Docs
  • Preserve HTML formatting (headings, lists, bold, italics) when exporting
  • Save content generation results for easy editing and collaboration

What We Cannot Do:

  • Access, read, or modify your existing Drive files
  • View files you created outside of Spectra
  • Share your files with others without your action
  • Delete or move files not created by Spectra

🔐 Limited Scope - drive.file

We use the drive.file scope, which means we can only access files that Spectra creates. We cannot see or interact with any of your existing Drive files or folders. This is the most restrictive Drive permission available.

Information We Collect

Account Information

  • Name, email address, and company information
  • Authentication tokens for Google services (encrypted and securely stored)
  • Subscription and billing information (processed by Stripe)
  • User preferences and dashboard settings

Usage Data

  • Feature usage and interaction patterns within Spectra
  • AI analysis requests and prompt execution history
  • Content generation requests and results
  • Dashboard views and report generation activity
  • Keyword tracking preferences and saved searches

Company & Website Data

  • Company name, industry, and target keywords
  • Website URL and associated Google Analytics properties
  • Google Ads account IDs and campaign structures
  • Competitor information for benchmarking

AI Visibility Metrics

  • Brand mention tracking across AI platforms
  • Sentiment analysis results from AI responses
  • Citation and reference data from LLM outputs
  • Competitive positioning insights and visibility scores
  • Historical trends and temporal analysis data

How We Use Your Information

Service Delivery

  • Generate AI visibility and sentiment reports
  • Analyze Google Ads campaign performance
  • Track AI referral traffic via Analytics
  • Provide keyword research and SEO insights
  • Create and export AI-generated content
  • Display competitive benchmarking data

Platform Improvement

  • Enhance AI algorithm accuracy and relevance
  • Develop new features and analytical insights
  • Optimize user experience and dashboard performance
  • Improve content generation quality
  • Refine visibility scoring methodologies
  • Train and improve our AI models

Communication

  • Send bi-weekly automated AI visibility reports via email
  • Notify you of significant changes in your visibility scores
  • Alert you to new competitor mentions or trends
  • Provide product updates and new feature announcements
  • Send billing and subscription-related communications

Data Security & Protection

We implement industry-standard security measures to protect your information:

Technical Safeguards

  • End-to-end encryption (TLS/SSL) for data in transit
  • Encrypted storage for OAuth tokens and credentials
  • Regular security audits and vulnerability scanning
  • Secure API endpoints with authentication and rate limiting
  • Database encryption at rest
  • Kubernetes-based infrastructure with security policies

Access Controls

  • Multi-factor authentication (MFA) support
  • Role-based access control (RBAC) for team members
  • Regular access reviews and permission audits
  • Automatic OAuth token expiration and refresh
  • Principle of least privilege for all systems
  • Audit logging of all data access

Data Retention & Deletion

How Long We Keep Your Data

  • Active Accounts: Data is retained while your account is active and for analytical purposes
  • OAuth Tokens: Encrypted and refreshed automatically; expired tokens are deleted
  • Analytics Data: Aggregated metrics retained for historical trend analysis
  • Generated Content: Retained until you delete it or close your account
  • Billing Records: Kept for 7 years to comply with accounting regulations

Account Deletion

When you delete your account or request data deletion:

  • OAuth tokens are immediately revoked and deleted
  • Personal information is deleted within 30 days
  • Generated content and reports are permanently removed
  • Aggregated, anonymized data may be retained for analytics
  • You can export your data before deletion via your dashboard

Third-Party Services & Data Sharing

Spectra integrates with various services to provide comprehensive analytics. We share data with these third parties only as necessary to provide our services:

Google Services

Google Ads API, Analytics API, Drive API for data access and content export. All governed by Google's OAuth 2.0 security.

AI Platforms

OpenAI (GPT-4), Anthropic (Claude), Google AI (Gemini) for content generation, analysis, and visibility tracking. Only necessary prompts and company information shared.

Payment Processing

Stripe for secure payment processing. We do not store credit card information—all payment data is handled by Stripe's PCI-compliant infrastructure.

Infrastructure

Google Cloud Platform (GCP) for hosting, database storage, and infrastructure services. All data stored in US-based data centers.

🔐 No Data Selling:

We never sell your personal information or analytics data to third parties. We do not share your data with advertisers or data brokers.

Your Privacy Rights

You have comprehensive rights regarding your personal data under GDPR, CCPA, and other privacy laws:

Access & Transparency

Request access to all personal data we hold about you and download your information

Correction

Update or correct inaccurate personal information in your account settings

Deletion (Right to be Forgotten)

Request complete deletion of your account and all associated data

Data Portability

Export your data in machine-readable formats (JSON, CSV)

Revoke OAuth Access

Disconnect Google services at any time; tokens immediately revoked

Opt-out of Communications

Unsubscribe from marketing emails while keeping essential service notifications

📧 Exercise Your Rights:

To exercise any of these rights, contact us at karen@tryspectra.com or use the privacy controls in your account dashboard. We will respond within 30 days.

International Data Transfers

Spectra is based in the United States. If you access our service from outside the US, your data will be transferred to and processed in the United States.

We ensure appropriate safeguards are in place for international data transfers, including Standard Contractual Clauses (SCCs) approved by the European Commission and compliance with the EU-US Data Privacy Framework.

Children's Privacy

Spectra is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately, and we will delete it.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated to you via:

  • Email notification to your registered email address
  • Prominent notice in your Spectra dashboard
  • Updated “Last updated” date at the top of this policy

Your continued use of Spectra after changes become effective constitutes acceptance of the updated policy.

Contact Us

If you have any questions about this Privacy Policy, our data practices, or wish to exercise your privacy rights, please contact us:

Email: karen@tryspectra.com

Privacy Officer: Karen Shirvanyan

Address: Burbank, California, United States

This Privacy Policy was last updated on December 1, 2025. We are committed to protecting your privacy and handling your data responsibly.