Privacy Policy
Last updated: August 16, 2026
This policy explains what personal data Spanli collects, why we collect it, who else processes it, and the rights you have over it. Sprybyte LLC is the controller of the personal data described here.
1. Who we are
Sprybyte LLC651 North Broad Street, Suite 201
Middletown, DE 19709
United States
For any privacy question or request, write to privacy@spanli.com.
2. Data we collect
Account data
Your email address, your name if you give one, and a hashed form of your password. We store passwords using Argon2id and never in a form we can read. We also record each active sign-in session with the time, the browser user agent and the IP address it was created from, so that you can be kept signed in and so that we can detect account abuse.
Project data
Everything you create in Spanli: the messages you send to the AI assistant, the images and files you upload, the pages and content of your website, its settings, and its version history. If you start from a LinkedIn page or an existing website, we also store what we retrieved from that source in order to build your site.
Billing data
Your subscription and plan, your credit balance and a record of each AI turn that consumed credits, and identifiers that link your account to your Stripe customer and subscription. Payments are taken on Stripe’s own hosted checkout page. We never receive or store your card number. Where you have saved a card for automatic top-ups, Stripe holds the card and we hold only a reference to it.
Domain registration data
If you register a domain through us, we collect the registrant contact details ICANN requires: name, any company name, email address, postal address and telephone number. See our Domain Registration Terms for what happens to them.
Form submissions on sites you build
If your published website has a contact or enquiry form, the submissions your visitors send are collected through our infrastructure and stored so that you can read them in your dashboard. For that data you are the controller and we act as your processor: it is your visitors’ data, collected for your purposes, and you are responsible for telling them how you will use it. We use it only to deliver it to you and to keep the service running.
Technical and diagnostic data
Server logs recording requests to our services, including IP address, timestamp, the path requested and error information. We use these to operate the service, investigate faults and detect abuse.
Usage of our public pages
On our public pages — the marketing site, the legal pages and the sign-in and sign-up screens — we use Google Analytics to understand how those pages are used and to measure our advertising, and Microsoft Clarity for heatmaps and anonymised session replays of those pages (typed text is masked). In the European Economic Area, the United Kingdom and Switzerland this runs only with your consent, which the cookie banner asks for and the “Manage cookies” footer link lets you change at any time. It never runs inside your dashboard or your projects, and never on the websites you publish. Our Cookie Policy describes exactly what is stored.
If you create an account, we associate this measurement with an internal account number and with where you first found us (for example, which advertisement or link brought you here), so we can understand which of our marketing actually helps people get a website. The account number is an opaque identifier that tells Google nothing about who you are, and none of your project content is ever part of this measurement.
If you have allowed advertising cookies and you sign up after arriving from one of our advertisements, a one-way scrambled (hashed) version of your email address may be shared with Google to confirm which advertisement led to the signup. The address itself is never shared, and Google cannot reconstruct it from the hash. Declining advertising cookies switches this off entirely.
3. How we use your data, and on what legal basis
Where the General Data Protection Regulation or a similar law applies, these are the bases we rely on.
- To provide the service you asked for (performance of a contract): creating and running your account, building and hosting your sites, processing your payments, registering domains you buy, and answering your support requests.
- To keep the service working and safe (legitimate interests): monitoring, debugging, preventing fraud and abuse, enforcing our Acceptable Use Policy, and improving reliability. We balance these against your rights and do not use your project content for any purpose beyond running the service.
- To meet legal obligations: keeping tax and accounting records, and responding to lawful requests.
- With your consent: where we ask for it, for example before sending marketing email. You can withdraw consent at any time.
We do not sell your personal data, and we do not use your content to train AI models. The one advertising-related processing we do is measuring our own marketing on our own public pages, as described above and in the Cookie Policy — your projects and the data in them are never used for advertising.
4. Sub-processors
Running Spanli requires other companies. Each one below processes personal data on our behalf, under a contract that limits them to our instructions and requires them to keep it secure. This list is current as of the date at the top of this page.
| Provider | What they do for us | Where they process |
|---|---|---|
| Fly.io, Inc. | Hosting and compute for the Spanli application, the per-project build environments and the site preview service, and the managed PostgreSQL database that holds your account, project, chat and billing records. | United States |
| Cloudflare, Inc. | Content delivery, DNS, hosting for published websites, object storage for project snapshots and build artifacts, intake for forms on published sites, and bot protection on those forms. | United States and Cloudflare's global network |
| Stripe, Inc. | Payment processing, subscriptions, hosted checkout and card storage. Stripe holds your card details; we never receive them. | United States |
| Brevo (Sendinblue SAS) | Delivering transactional email: password resets, team invitations, billing notices and domain renewal reminders. Brevo receives the recipient address and the contents of the message. | European Union |
| Anthropic PBC | AI processing. Your instructions and the relevant parts of your project are sent to Anthropic so its models can write and edit your website. | United States |
| Moonshot AI | AI processing, as an alternative model for building and editing your website and for interpreting your answers during onboarding. | China |
| Openprovider (Hosting Concepts B.V.) | Domain registration and renewal. Your registrant contact details are passed to Openprovider and on to the domain registry, as ICANN requires. | Netherlands |
| Rapid (RapidAPI) | Retrieving public LinkedIn profile or company information, only when you choose to start a site from a LinkedIn page. | United States |
| Pexels GmbH | Stock photo search. We send your search terms; your browser loads the preview images directly from Pexels, which means Pexels sees your IP address while the picker is open. | Germany |
| Google LLC (Google Fonts) | Delivering web fonts. During the design step of onboarding your browser requests fonts directly from Google so that each design option previews in its real typeface, which means Google sees your IP address at that moment. | United States |
| Google LLC (Analytics and Ads) | Analytics and advertising measurement on our public pages only — the marketing site, the legal pages and the sign-in screens — subject to your cookie consent where it is required. Never inside your dashboard or projects, and never on the websites you publish. | United States |
| Microsoft Corporation (Clarity) | Heatmaps and anonymised session replays of our public pages only, with typed text masked — subject to the same cookie consent as analytics. Never inside your dashboard or projects, and never on the websites you publish. | United States |
Rapid, Pexels and Google Fonts are only involved when you use the feature described. Openprovider is only involved if you register a domain through us.
If we add a sub-processor, we update this table. Write to privacy@spanli.com if you would like to be notified of changes in advance.
5. AI processing
Spanli builds your website by sending your instructions, and the parts of your project that are relevant to the request, to an AI provider. Depending on which model is serving your project, that provider is Anthropic (United States) or Moonshot AI (China). The provider generates a response, which we apply to your site.
If your project contains personal data, that data may be included in what is sent. Do not put special category data, payment card numbers, health records or government identifiers into a Spanli project.
These providers process the data under their own terms and their own security arrangements. We do not permit them to use your content to train their models, and we do not use it to train ours.
6. International transfers
We are based in the United States and our infrastructure is primarily in the United States, so personal data you give us is transferred there. As the table above shows, some processing also takes place in the Netherlands, in Germany and, for one AI provider, in China.
Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum or the Swiss addendum where those apply, and we assess whether additional safeguards are needed. You can ask us for details of the safeguards that apply to a particular transfer by writing to privacy@spanli.com.
7. Cookies
Two cookies come from us: one keeps you signed in, one remembers your cookie choices. We also store some interface preferences in your browser. On our public pages, Google Analytics may set analytics and advertising-measurement cookies — where consent is required, only after you give it in the cookie banner, and you can change your answer at any time with the “Manage cookies” footer link. Our Cookie Policy lists each cookie and what it is for.
8. Retention and deletion
We keep your data for as long as your account is open and you need the service, and then for as long as we are required to.
- Deleting a project removes its published website from our hosting, detaches its domains, and deletes its workspace, its stored snapshots and build artifacts, its content, and its chat history. This is not reversible.
- Closing your account deletes your account data and the projects it owns on the same basis.
- Billing and tax records are kept for as long as accounting and tax law requires, typically several years, even after an account is closed.
- Domain registration records are kept for as long as the registration lasts and afterwards for as long as ICANN and the registry require.
- Server logs are kept for a limited operational period and then discarded.
9. Your rights
If the GDPR or UK GDPR applies to you
You have the right to ask us for a copy of your personal data, to have inaccurate data corrected, to have your data deleted, to restrict or object to our processing of it, to receive it in a portable format, and to withdraw any consent you gave. You also have the right to complain to your national data protection authority.
If you are in California or another United States state with a privacy law
You have the right to know what personal information we have collected about you and why, to request a copy of it, to have it corrected or deleted, and not to be discriminated against for exercising those rights. We do not sell personal information. Google’s advertising measurement on our public pages may count as “sharing” for cross-context behavioural advertising under some state laws; you can opt out at any time with the “Manage cookies” link in the footer of every public page, and we honour that choice. You may also make any of these requests in writing.
How to make a request
Write to privacy@spanli.com from the email address on your account, or tell us which account you are asking about. We will respond within the time the applicable law allows, normally within one month. We may need to verify your identity before we act. If we refuse a request we will tell you why, and you can appeal by replying to our decision.
If your request is about data held in a site that someone else built with Spanli, for example a form you submitted to a business, ask that business first: they control that data, and we hold it for them.
10. Security
We protect your data with measures appropriate to the risk, including: encryption in transit over HTTPS; passwords stored only as Argon2id hashes; session cookies marked HttpOnly, Secure and SameSite so that scripts cannot read them and other sites cannot replay them; role-based access control on every project, so that only people you have invited can reach it; isolation of each project’s build environment from every other project; and browser security headers including a content security policy.
No service can promise perfect security. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority where the law requires it. To report a vulnerability, see our security page.
11. Children
Spanli is not directed to children. You must be at least 16 to hold an account, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to privacy@spanli.com and we will delete it.
12. Other sites
Websites built by other people with Spanli are not ours, and this policy does not cover them. Nor does it cover sites we link to. When you follow a link to another site, that site’s privacy policy applies.
13. Changes to this policy
We may update this policy. When we do, we change the date at the top of this page. If a change materially affects how we handle your personal data, we will tell you by email or in the product before it takes effect.
14. Contact
Privacy questions and data requests: privacy@spanli.com.
Everything else: support@spanli.com.