Privacy Policy
Your privacy is our priority
Last updated: December 1, 2025Introduction
Welcome to Spectra, an AI-powered content optimization and marketing intelligence platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
Spectra helps businesses optimize their content strategy through advanced AI analysis, SEO insights, Google Ads performance tracking, keyword research, AI-generated content creation, and visibility tracking across multiple platforms including search engines and AI systems like ChatGPT, Claude, Perplexity, and Gemini.
Google Services Integration
Spectra integrates with multiple Google services to provide you with comprehensive marketing intelligence and content optimization. Here's a complete overview of all Google OAuth scopes we request and how we use them:
Complete OAuth Scope List:
userinfo.email- Access your email address for account creationuserinfo.profile- Access your basic profile information (name, photo)openid- Authenticate your identity securely
adwords- Read-only access to Google Ads performance data and keyword planner
analytics.readonly- Read-only access to your Analytics dataanalytics- Standard Analytics data accessanalytics.manage.users.readonly- View Analytics account users (read-only)
drive.file- Create and manage only files that Spectra createsdocuments- Create and edit Google Docs for content export
Google Ads API Usage
How We Use Google Ads Data
Using the adwords scope, we access your Google Ads account to provide performance analytics and keyword research capabilities:
What Data We Access:
- Campaign performance metrics (clicks, impressions, CTR, spend)
- Ad performance data (best/worst performing ads)
- Keyword performance and search terms
- Device breakdown (mobile, desktop, tablet) statistics
- Keyword Planner data (search volume, competition, CPC estimates)
- Negative keywords and wasted spend analysis
How We Use This Data:
- Display year-to-date campaign performance reports
- Identify top and worst performing ads for optimization
- Provide keyword research and discovery based on your industry
- Calculate wasted ad spend and provide recommendations
- Show device-level performance comparisons
- Generate competitive keyword insights with search volume data
🔐 Read-Only Access:
We only read your Google Ads data. We never modify campaigns, change bids, pause ads, or make any changes to your advertising accounts. All access is strictly read-only for reporting purposes.
Google Analytics API Usage
How We Use Google Analytics Data
Using the Analytics API scopes, we track AI-driven traffic to your website and provide insights about your digital presence:
What Data We Access:
- Referral traffic specifically from AI platforms (ChatGPT, Claude, Perplexity, Gemini, etc.)
- Session data, page views, and user behavior for AI referrals
- Pages visited through AI-generated recommendations
- Traffic patterns and trends over time
- Bounce rates and engagement metrics for AI traffic
How We Use This Data:
- Display AI Referrals dashboard showing traffic from each AI platform
- Track which pages receive the most AI-driven visits
- Generate timeline charts showing AI referral patterns
- Calculate total sessions and page views from AI sources
- Identify which AI platforms drive the most valuable traffic
What We Don't Access or Store:
- Personal information about your website visitors
- Raw Google Analytics data (we query in real-time only)
- Individual user browsing behavior or tracking data
- Login credentials or sensitive account information
- Non-AI-related traffic or general analytics data
🔐 Real-Time Querying Only:
We query the Google Analytics API in real-time to generate insights and reports. We do not store raw analytics data on our servers. We only retain aggregated, anonymized metrics necessary for displaying your dashboard.
Google Drive & Docs API Usage
How We Use Drive & Docs
Using the Drive and Docs API scopes, we enable you to export AI-generated content and reports directly to your Google Drive:
What We Can Do:
- Create new Google Docs in your Drive with AI-generated content
- Export blog posts, articles, and marketing content to Docs
- Preserve HTML formatting (headings, lists, bold, italics) when exporting
- Save content generation results for easy editing and collaboration
What We Cannot Do:
- Access, read, or modify your existing Drive files
- View files you created outside of Spectra
- Share your files with others without your action
- Delete or move files not created by Spectra
🔐 Limited Scope - drive.file
We use the drive.file scope, which means we can only access files that Spectra creates. We cannot see or interact with any of your existing Drive files or folders. This is the most restrictive Drive permission available.
Information We Collect
Account Information
- Name, email address, and company information
- Authentication tokens for Google services (encrypted and securely stored)
- Subscription and billing information (processed by Stripe)
- User preferences and dashboard settings
Usage Data
- Feature usage and interaction patterns within Spectra
- AI analysis requests and prompt execution history
- Content generation requests and results
- Dashboard views and report generation activity
- Keyword tracking preferences and saved searches
Company & Website Data
- Company name, industry, and target keywords
- Website URL and associated Google Analytics properties
- Google Ads account IDs and campaign structures
- Competitor information for benchmarking
AI Visibility Metrics
- Brand mention tracking across AI platforms
- Sentiment analysis results from AI responses
- Citation and reference data from LLM outputs
- Competitive positioning insights and visibility scores
- Historical trends and temporal analysis data
How We Use Your Information
Service Delivery
- Generate AI visibility and sentiment reports
- Analyze Google Ads campaign performance
- Track AI referral traffic via Analytics
- Provide keyword research and SEO insights
- Create and export AI-generated content
- Display competitive benchmarking data
Platform Improvement
- Enhance AI algorithm accuracy and relevance
- Develop new features and analytical insights
- Optimize user experience and dashboard performance
- Improve content generation quality
- Refine visibility scoring methodologies
- Train and improve our AI models
Communication
- Send bi-weekly automated AI visibility reports via email
- Notify you of significant changes in your visibility scores
- Alert you to new competitor mentions or trends
- Provide product updates and new feature announcements
- Send billing and subscription-related communications
Data Security & Protection
We implement industry-standard security measures to protect your information:
Technical Safeguards
- End-to-end encryption (TLS/SSL) for data in transit
- Encrypted storage for OAuth tokens and credentials
- Regular security audits and vulnerability scanning
- Secure API endpoints with authentication and rate limiting
- Database encryption at rest
- Kubernetes-based infrastructure with security policies
Access Controls
- Multi-factor authentication (MFA) support
- Role-based access control (RBAC) for team members
- Regular access reviews and permission audits
- Automatic OAuth token expiration and refresh
- Principle of least privilege for all systems
- Audit logging of all data access
Data Retention & Deletion
How Long We Keep Your Data
- Active Accounts: Data is retained while your account is active and for analytical purposes
- OAuth Tokens: Encrypted and refreshed automatically; expired tokens are deleted
- Analytics Data: Aggregated metrics retained for historical trend analysis
- Generated Content: Retained until you delete it or close your account
- Billing Records: Kept for 7 years to comply with accounting regulations
Account Deletion
When you delete your account or request data deletion:
- OAuth tokens are immediately revoked and deleted
- Personal information is deleted within 30 days
- Generated content and reports are permanently removed
- Aggregated, anonymized data may be retained for analytics
- You can export your data before deletion via your dashboard
Third-Party Services & Data Sharing
Spectra integrates with various services to provide comprehensive analytics. We share data with these third parties only as necessary to provide our services:
Google Services
Google Ads API, Analytics API, Drive API for data access and content export. All governed by Google's OAuth 2.0 security.
AI Platforms
OpenAI (GPT-4), Anthropic (Claude), Google AI (Gemini) for content generation, analysis, and visibility tracking. Only necessary prompts and company information shared.
Payment Processing
Stripe for secure payment processing. We do not store credit card information—all payment data is handled by Stripe's PCI-compliant infrastructure.
Infrastructure
Google Cloud Platform (GCP) for hosting, database storage, and infrastructure services. All data stored in US-based data centers.
🔐 No Data Selling:
We never sell your personal information or analytics data to third parties. We do not share your data with advertisers or data brokers.
Your Privacy Rights
You have comprehensive rights regarding your personal data under GDPR, CCPA, and other privacy laws:
Access & Transparency
Request access to all personal data we hold about you and download your information
Correction
Update or correct inaccurate personal information in your account settings
Deletion (Right to be Forgotten)
Request complete deletion of your account and all associated data
Data Portability
Export your data in machine-readable formats (JSON, CSV)
Revoke OAuth Access
Disconnect Google services at any time; tokens immediately revoked
Opt-out of Communications
Unsubscribe from marketing emails while keeping essential service notifications
📧 Exercise Your Rights:
To exercise any of these rights, contact us at karen@tryspectra.com or use the privacy controls in your account dashboard. We will respond within 30 days.
International Data Transfers
Spectra is based in the United States. If you access our service from outside the US, your data will be transferred to and processed in the United States.
We ensure appropriate safeguards are in place for international data transfers, including Standard Contractual Clauses (SCCs) approved by the European Commission and compliance with the EU-US Data Privacy Framework.
Children's Privacy
Spectra is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately, and we will delete it.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated to you via:
- Email notification to your registered email address
- Prominent notice in your Spectra dashboard
- Updated “Last updated” date at the top of this policy
Your continued use of Spectra after changes become effective constitutes acceptance of the updated policy.
Contact Us
If you have any questions about this Privacy Policy, our data practices, or wish to exercise your privacy rights, please contact us:
Email: karen@tryspectra.com
Privacy Officer: Karen Shirvanyan
Address: Burbank, California, United States
This Privacy Policy was last updated on December 1, 2025. We are committed to protecting your privacy and handling your data responsibly.