Who we are
SpectreOS ("SpectreOS", "we", "us") provides an AI-native operating platform for private-equity deal teams at spectreos.ai. Questions about this policy: privacy@spectreos.ai.
Information we collect
- Account information. When you sign in with Google, we receive your name, email address and profile photo to create and identify your account.
- Content you provide. Documents and data-room files you (or your firm) upload to the platform, deals you create, and questions you ask.
- Google Drive you pick from (
drive.file). Files you select in the Google Picker, or upload, are brought into a deal vault. This permission lets us see only the files you choose, and nothing else in your Drive. - Google Drive search (
drive.readonly). Granted separately, and only when you first search your Drive from inside a deal. It lets SpectreOS find a file you cannot remember the location of — the per-file permission above can only ever return files you already named. We read file names, metadata and contents to answer that search, and we download a file only when you press Add to vault on it. SpectreOS holds no Drive write permission, so nothing in your Drive can be renamed, moved, changed or deleted by us; importing copies the file into the deal and leaves your original untouched. Only the files you import are stored or indexed. You can use SpectreOS without granting this. - Calendar (
calendar.events). Your events are read to put IC meetings and closing milestones on the deal timeline. Because the product also schedules and reschedules from that timeline, this permission is read AND write on events: SpectreOS can create, change and cancel calendar events when you ask it to, and it tells attendees when it does. It does not read your calendar list or your calendar settings, and it does not act on your calendar on its own. - Google Meet transcripts (
meetings.space.readonly). When a meeting title names one of your deals, SpectreOS fetches the transcript Google generated for that call and files it into that deal's vault as a document, where it is searchable and citable like any other. A meeting whose title names no deal, or names two, is not fetched at all. This permission is read-only: SpectreOS cannot start, join, record or change a meeting. - Sending outreach (
gmail.send). Sends the messages you have written or reviewed and explicitly approved in the app, from your own address. Messages are composed and reviewed inside SpectreOS; we place an approved message on the wire and nothing else. - Drafting into your mailbox (
gmail.compose). Writes a draft into your own Gmail, so you can open it on any device, edit it and send it yourself. It creates and updates drafts SpectreOS itself wrote, and it is not used to read, alter or delete anything else in your mailbox. A draft is subject to the same compliance screen as a send: a message that fails it is not written to your mailbox at all, because a draft is one tap from leaving your firm. - Reading your mail (
gmail.readonly). Used for two things.
Filing mail to your deals. The mail agent reads your recent mail in full: the subject, the sender and recipient addresses, the date and the body of each message. Mail Gmail files as promotions, social or forums, and chat, is not read. We keep a copy of each message it reads, including the body, in our database, tied to your account, so that a message is read from Gmail once and not again. We use it to decide which of the deals you can see a conversation belongs to, by comparing it with those deals' counterparties, company domains and names, and to show it on your Today screen. When one deal clearly matches, the agent files the thread there; when it is not sure, it asks you, and you approve, reject or choose the deal. Mail that belongs to no deal is kept in the same way but is not filed anywhere. For a thread filed to a deal, by the agent or by you, its attachments are copied into that deal's vault and are then handled exactly like a file you uploaded: extracted, indexed, and processed by our model provider so you can search and ask about them. What we keep per rule you save is the sender and the deal. Stored mail is deleted when you delete your account, and you can ask us to delete it sooner.
Reply detection. For outreach you sent through SpectreOS, we check whether the recipient replied so that follow-ups stop. These requests use Gmail'sformat=metadataoption with a header allowlist, and we retain only whether a reply arrived, when, and the sender's address.
SpectreOS cannot send, delete, label or change anything in your mailbox under this permission. - Usage and log data. Standard service logs (requests, timestamps, IP addresses) for security and reliability.
How we use information
Solely to provide the service: indexing the documents you ingest so they are searchable, generating grounded answers, summaries and memos you request, putting calendar events on a deal timeline and making the changes you ask for on it, filing a Meet transcript into the deal its meeting named, finding and importing the Drive files you choose, sending outreach you have approved and stopping a sequence once the recipient replies, and operating, securing and supporting the platform. We do not sell personal data, do not use your data for advertising, and do not use content you ingest to train generalized machine-learning models. Gmail data accessed under gmail.readonly is used only to file your mail to your deals, to show it to you in SpectreOS, and to detect replies, as described above. Only the attachments of threads filed to a deal reach the document index or our model provider, and only so you can search and ask about them; message text is used to decide where a thread belongs and is not currently sent to a model provider. Drive content is read to answer a search you ran, and only a file you chose to import is stored or indexed.
Google API Services — Limited Use
SpectreOS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide user-facing features described above, is never sold, is not used for advertising, and is not read by humans except with your consent, for security purposes, or as required by law.
How data is stored and shared
Data is stored on Amazon Web Services (US regions) encrypted in transit and at rest. We share data only with the subprocessors needed to run the service: Amazon Web Services (hosting, storage, document text extraction and embeddings) and Anthropic (language-model processing of the content you ask about — Anthropic does not train on this data). Access within your workspace is limited to the deals you own or have been granted membership to. We may disclose information if required by law.
Retention and deletion
Content remains available for as long as your account is active. You can delete deals and documents in-app; deletion removes the underlying stored files and derived search indexes. To delete your account and associated data, or to revoke Google access (also possible at myaccount.google.com/permissions), email privacy@spectreos.ai — we action requests within 30 days.
Changes
We will post any changes to this policy on this page and update the effective date above.