← Back to home Legal

Privacy Policy

What we collect, why we collect it, who else sees it, and how long we keep it. This describes what the software actually does, not what a template says it might.

Effective: August 8, 2026. Last updated: August 8, 2026.

1. Who we are

spawnpoint ("spawnpoint", "we", "us") runs the service at getspawnpoint.com and app.getspawnpoint.com: a console, an MCP server that AI agents deploy through, and the machines your projects run on. This policy covers all of it. Our Terms of Service govern the rest of the relationship.

For questions, requests, or complaints, email founders@getspawnpoint.com. We answer.

2. What we collect

Your email address. It is the only thing you tell us about yourself, and it is your account identity. We accept it only after our sign-in provider confirms it is verified.

Your projects. For each project you deploy: the name you chose, its status, runtime, entry point, the identifier and public URL of the machine it runs on, timestamps, the machine's hourly rate, health check results, and the output of the deploy itself (the last deploy's console output, capped in size, so a failed deploy is diagnosable). We also fetch your app's own og:image tag if it has one, so the console can show a thumbnail.

Your files, in transit. The files your agent deploys pass through us on the way to your machine. When an agent uploads a bundle out of band, we hold it for at most 30 minutes and delete it the moment it is used. We do not keep a copy of your code on the control plane after it is pushed: it lives on your machine, which you can destroy at any time.

Credentials, hashed. API tokens and OAuth tokens are stored only as SHA-256 hashes, alongside a short display prefix. We cannot recover a token for you, only issue a new one.

Billing records. Your credit ledger (grants, top-ups, adjustments), the identifiers of payments we have processed, and a customer identifier issued by our payment processor. See section 4.

Sharing lists. If you restrict a project to specific people, we store the email addresses you listed. We also record, per project, which of those addresses opened it, when they first and last did, and how many times. That log exists so you can see who used a link you shared.

Technical logs. Our servers log each request: method, path, response status, size, duration, and the caller's IP address. This is ordinary operational logging, used for debugging and for investigating abuse.

Traffic counts on our own site. Our pages call a one-pixel beacon that records the page, the referring domain, and a visitor identifier. That identifier is a one-way hash of a secret, the UTC date, and your IP address. The raw IP is never written down, the same person counts once per day, and because the date is inside the hash, two days of counts cannot be linked to each other. It is counting, not tracking.

3. What we do not collect

4. Payments

Payments are processed by Stripe. When you add credit, you are sent to a page Stripe hosts, and you give your card details to Stripe, not to us. Stripe tells us that a payment of a certain amount succeeded, and we add that amount to your balance.

What we store is a Stripe customer identifier for your account, the identifiers of completed payments, and the resulting ledger entries. What Stripe stores is governed by Stripe's privacy policy. Stripe is an independent controller of the payment data it holds, including any name, billing address, or card details you give it.

5. Cookies

We set three cookies, all of them strictly functional. There are no advertising or analytics cookies, so there is no consent banner to dismiss.

Deployed apps are yours: any cookie your own app sets is your responsibility, not ours.

6. Deployed apps and the people who visit them

Your projects run on machines rented for you, and they are reachable at a public URL. Two consequences worth being explicit about:

For restricted projects, viewers verify their email address through our sign-in provider before the gate lets them through. We store that address on the project's access log so the project's owner can see who opened it.

7. Who else sees your data

We do not sell personal data, and we have never disclosed it for money or for anyone else's advertising. We share it only with the providers we need to run the service:

We may also disclose data if the law requires it, or where we reasonably need to in order to investigate abuse, enforce our Terms, or protect someone's safety. If we are ever compelled to hand over your data, we will tell you unless we are legally prohibited from doing so.

If the business is ever sold or merged, account data may transfer with it. You will be told before that happens.

8. Where your data lives

Our control plane runs in the United States, and our database and logs sit there. Your machines run in the region chosen for them, which may be elsewhere. Our providers operate globally. If you are in the UK, the EEA, or Switzerland, using the service means your data is transferred to the United States, and we rely on the standard contractual clauses our providers offer for those transfers.

9. How long we keep things

10. How we protect it

Everything is served over TLS. Tokens and credentials are stored only as hashes. Restricted projects are gated at a separate origin from the console, so the two cannot reach each other's cookies. Our OAuth implementation requires PKCE, treats authorization codes as single use, and revokes an entire grant family when one is replayed. Payment webhooks are rejected unless they carry a valid signature over the exact bytes sent.

No system is perfectly secure, and we are early software in public beta. If you find a vulnerability, please tell us at founders@getspawnpoint.com before telling anyone else, and we will work with you.

11. Your rights

Wherever you live, you can ask us to:

Email founders@getspawnpoint.com and we will action it within 30 days. We will not charge you, and we will not treat you differently for asking.

Deleting your account destroys your running machines and their contents, which cannot be undone. Some records survive deletion where the law requires it, billing records in particular.

If you are in the UK or the EEA, our legal bases are: performing our contract with you (running your account, your deploys, and your payments), our legitimate interests (keeping the service secure, investigating abuse, and counting traffic in a way that identifies nobody), and compliance with legal obligations (tax records). You have the right to complain to your local data protection authority. If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and the rights above cover the ones it grants you.

12. Children

spawnpoint is not for children under 13, and we do not knowingly collect their data. If you believe a child has given us personal data, email us and we will delete it.

13. Changes to this policy

We will update this policy as the service changes. If a change is material, we will give reasonable notice by email or in the console before it takes effect, and the date at the top of this page will move. Continuing to use the service after that means you accept the updated policy.

14. Contact

Anything at all, including data requests: founders@getspawnpoint.com.

Plain English summary. We know your email address, what you deployed, and what you paid. Cards go to Stripe, never to us. We do not sell anything, run ad trackers, or train models on your code. Our traffic counter hashes IP addresses and forgets them daily. Ask us for your data or for deletion and you get it. This summary is not the policy, the sections above are.