Privacy Policy
Last updated 13 September 2026
This policy covers both spyn3.com — the public website and its beta waitlist — and the SPYN3 application at app.spyn3.com. They are described separately because they process very different things: the website stores an email address and counts page views, while the application holds the connections you make to your own systems.
Business customers connecting data about other people need a data processing agreement as well as this policy. Section 3.1 explains why, and how to ask for one.
The short version. This site sets no cookies, runs no third-party analytics, and does not track you across other websites. If you join the waitlist we store your email address so we can send you an invitation. We also keep anonymous counters of how many people visit and which SPYN3 pages are useful — country, referring site, page path and broad content action only, never your IP address.
If you use the SPYN3 application (section 2.4), the summary is short: we store the connections to your systems, not what flows over them. Your account and those connections are held in the EU. When your agent uses SPYN3 to reach one of your systems, the request and the answer pass through our servers and are not written down. What we do hold, and what makes section 7 worth reading, are the credentials to those systems.
1. Who is responsible
The controller within the meaning of Art. 4(7) GDPR is:
Sascha Wagner — SPYN3Ditzingen, Germany · full postal address in the Imprint
Email: privacy@spyn3.com
We have not appointed a data protection officer, as we are not required to under Art. 37 GDPR.
2. What we collect, and why
2.1 Beta waitlist
When you submit the form on this site, we store:
| Data | Why |
|---|---|
| Your email address | To send you an invitation when the beta opens |
| A short source label (e.g. which section of the page the form was in) | To understand which part of the page people sign up from |
| The referring URL, if your browser sent one | To understand where visitors come from |
Legal basis: your consent, Art. 6(1)(a) GDPR. You give it by submitting the form, and you can withdraw it at any time (see section 6).
Retention: until you ask us to remove you, or until the beta programme ends and the list is no longer needed — whichever comes first.
We do not sell, rent or share this list. We use it for one purpose: telling you when SPYN3 is ready for you.
2.2 First-party traffic counters
To know whether anyone is reading the site and whether a resource or developer guide leads to another useful page, we keep anonymous first-party events. They can contain only:
- a two-letter country code, derived at the network edge;
- the hostname of the referring site, if any — the hostname only, never the full URL;
- a coarse label for what kind of client made the request (for example, whether it announced itself as a crawler);
- the path of the SPYN3 page being read, without a query string or URL fragment; and
- for links on resource, developer and product-facts pages, a broad action label such as “next article”, “developer guide”, “source” or “request early access”, plus an internal destination path where applicable.
The first counter records that a page was served. The second is a small script on the page that reports back about a second after it loads — we count that as a visit, because a program fetching pages in bulk generally does not run it. Resource and developer pages also report the broad link actions described above so we can compare article performance. The script stores nothing on your device — no cookie, no identifier and no local storage. It sends no name, email, IP address, full external URL, query string or fragment.
We do not store your IP address. These events cannot be linked to you or to each other, and no profile is built. If you block scripts, the second counter simply does not fire, and nothing else changes.
Legal basis: legitimate interest, Art. 6(1)(f) GDPR — understanding basic reach of our own website. Because nothing is stored on or read from your device, no consent banner is required under §25 TDDDG.
Retention: these events expire automatically after 400 days.
2.3 Server and connection data
Like any website, this one cannot be delivered without your browser connecting to a server. Our hosting provider processes connection data — including your IP address — transiently in order to deliver the page and to defend against attacks. We do not receive, store or analyse server logs containing IP addresses.
Legal basis: legitimate interest, Art. 6(1)(f) GDPR — operating and securing the site.
2.4 The SPYN3 application
Separately from this website, SPYN3 is a product you can create an account in at app.spyn3.com. If you do, we process:
| Data | Why |
|---|---|
| Your email address and password (stored only as a hash we cannot reverse) | To create and secure your account |
| Your organisation and workspace names | To separate your data from every other customer's |
| Credentials for the systems you connect | To reach them on your agent's behalf. Encrypted before storage (see section 7) |
| The address of each system you connect, and the list of operations it offers | To show your agent what it can do without contacting every system on every request |
| A record of each call your agent made: which system, which operation, whether it succeeded, and how long it took | To show you what your agents did, and to count usage against your plan |
Legal basis: performance of a contract, Art. 6(1)(b) GDPR — this processing is the service. Where you are a business customer, see section 3.1: for anything that passes through us, you are the controller and we act on your instructions.
Retention: for as long as your account exists. Disconnecting a system removes its stored credential and the record of what it offers; deleting your account removes the account and the data belonging to it.
The part worth reading twice: we do not keep your content. SPYN3 is a connection layer. When your agent uses it to reach one of your systems, the request and the answer pass through our servers and are not written down — we store the connection, not what flows over it. What we do record about a call is the four things in the table above: which system, which operation, success or failure, and the duration. Not the arguments your agent sent, and not what came back.
The honest trade is elsewhere. Because we reach your systems for you, we hold the credentials to them — and a credential is a more concentrated thing to lose than a copy of some documents. Section 7 describes how they are stored; if you would rather scope a token narrowly before giving it to us, that is the right instinct and we would encourage it.
3. Who processes data for us
We use the service providers below, each under a data processing agreement pursuant to Art. 28 GDPR. Where a provider is named for the application, it is also a sub-processor for the purposes of section 3.1.
| Provider | What they do | Where |
|---|---|---|
| Cloudflare, Inc. 101 Townsend St, San Francisco, CA 94107, USA |
Hosts and delivers this website; stores the anonymous traffic counters described in 2.2 | Served from Cloudflare's global edge network. Cloudflare is certified under the EU–US Data Privacy Framework, and we rely on EU Standard Contractual Clauses in addition. |
| Fly.io, Inc. 2261 Market St, San Francisco, CA 94114, USA |
Runs the SPYN3 application servers and the background process that reads your connected sources (2.4) | Runs in the EU. Our machines are pinned to Fly's Amsterdam region, so application processing happens inside the EEA. Fly.io, Inc. is established in the United States, so access by its staff for support or infrastructure purposes is covered by the safeguards in section 4. |
| Upstash, Inc. Palo Alto, CA, USA (provisioned through Fly.io) |
Holds short-lived request counters used to rate-limit the API. Entries identify a workspace or an IP and a count — no content of any kind | Runs in the EU. Provisioned in the Amsterdam region alongside the application. |
| Supabase, Inc. 970 Toa Payoh North, Singapore 318992 |
Stores the waitlist email addresses described in 2.1, and the accounts, connections and call records described in 2.4; sends account emails such as confirmation and password reset | Stored in the EU. The database is hosted in Supabase's West EU (Ireland) region, so waitlist email addresses, accounts and the stored connections to your systems are held inside the EEA. Supabase, Inc. is itself established outside the EEA, so any access by its staff for support purposes is covered by the safeguards in section 4. |
We use no advertising networks, no tracking pixels, and no social media plugins.
This list is exhaustive as at the date above, and names only providers actually in use — not ones we might add. Error tracking and payment processing are configured in the software but not switched on, so no data reaches them; if that changes, this list changes first.
3.1 When you are the controller and we are not
The distinction matters and is easy to miss. For your account — your email address, your plan, your usage — we are the controller, and this policy describes what we do.
For what passes through us, we are not. When your agent reaches one of your systems through SPYN3 and the answer contains personal data about your colleagues, customers or suppliers, you are the controller of that data and we are your processor under Art. 28 GDPR. We transmit it because you told us to, we use it for no purpose of our own, we do not use it to train anything, and we do not retain it — it is not written to disk at any point. What we retain is the connection itself, which we delete when you disconnect the system or close the account.
That relationship needs its own contract, not a privacy policy. Business customers should request a data processing agreement (Auftragsverarbeitungsvertrag) from privacy@spyn3.com before connecting data about other people. The providers named above are the sub-processors it will list.
Web fonts
This page loads typefaces from Google Fonts (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Your browser contacts Google's servers to fetch them, which transmits your IP address to Google. Legal basis: legitimate interest, Art. 6(1)(f) GDPR — consistent presentation of the site. If you prefer to avoid this, most browsers and content blockers can block that request; the page remains fully readable.
4. Transfers outside the EU
Where a provider named above is established outside the European Economic Area, the transfer is safeguarded by EU Standard Contractual Clauses under Art. 46(2)(c) GDPR and, where applicable, by the provider's certification under the EU–US Data Privacy Framework.
No processing step of ours sends your content to the United States. That was not true of an earlier version of this product, which sent document text to OpenAI for indexing; that step no longer exists and OpenAI is no longer a sub-processor. Every provider named above — Cloudflare, Fly.io, Upstash, Supabase — holds our data inside the EEA, in Ireland or Amsterdam, and the residual transfer risk is limited to staff access for support and operations.
There is one thing this does not promise, and burying it would be the same mistake in reverse. SPYN3 connects to systems you choose. If you connect a service hosted in the United States, your agent's requests and their answers travel to that service — because that is what you asked SPYN3 to do. We are not a barrier between you and your own suppliers, and the transfer in that case is yours to assess, not ours to safeguard. What we can say is that SPYN3 itself adds no destination outside the EEA.
5. Is any of this required?
No. Joining the waitlist is entirely voluntary — you are not obliged to provide your email address, there is no contractual requirement to do so, and the only consequence of declining is that we cannot notify you when the beta opens.
There is no automated decision-making and no profiling within the meaning of Art. 22 GDPR.
6. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15);
- Rectify inaccurate data (Art. 16);
- Erasure — have your data deleted (Art. 17);
- Restrict processing (Art. 18);
- Data portability — receive your data in a machine-readable format (Art. 20);
- Object to processing based on legitimate interest (Art. 21);
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3)).
To exercise any of these, email privacy@spyn3.com. To come off the waitlist, one line saying so is enough — we do not ask for a reason and we do not try to talk you out of it.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in the EU member state of your habitual residence, place of work, or the place of the alleged infringement.
7. Data security
The site is served exclusively over HTTPS. Waitlist submissions are sent to our own server-side endpoint rather than directly to the database from your browser, and the credential used to write them is insert-only — it cannot read the list back out.
For the application described in 2.4:
- Credentials for the sources you connect are encrypted before they are stored, and the key that protects them is held by the application, not by the database.
- API keys are stored only as hashes. We cannot show you a key again after it is created, because we no longer have it.
- Every record carries the workspace it belongs to, every query filters on it, and the database enforces the same rule independently underneath. The separation between customers is checked automatically on every change to the code, including by deliberately breaking it to confirm the checks notice.
- Passwords are handled by Supabase Auth and never reach our servers in readable form.
No system is immune, and we would rather describe what we do than claim a guarantee. If you believe you have found a security problem, email privacy@spyn3.com — we will not pursue anyone who reports something in good faith.
8. Changes to this policy
We may update this policy as the service develops. The date at the top always reflects the current version, and we will not quietly add a category of processing or a new provider without it appearing here first.