Privacy Notice
Specify is a founder-stage company. This notice describes what we actually collect today, not what we might collect later.
- Before you use the preliminary audit
- Remove names, personal data, prices and confidential project details from any enquiry text you paste. The preliminary audit is not the place for material you would not want leaving your organisation.
What is collected
- Contact details you supply when requesting a founder review or applying for a Sprint: name, work email, company, optional website and role.
- The enquiry text you submit, exactly as you wrote it.
- The preliminary analysis shown to you, stored alongside your submission as a record of what you saw.
- Your answers to the two adaptive questions.
- Your consent selections.
- If you join the founding-partner list: your work email and how you describe what you sell.
- If you apply to be a founding partner: your company, the request you describe, your answers about how enquiries reach you, why you would be a valuable partner, and what you would use the credit for.
- The name and role of the person you nominate as able to approve what your business can deliver. If that is not you, they have not visited this site, so tell them their details were shared and that they can ask us to remove them.
- If you send an unsolicited application: your name, email, where you are, your current education or role, any links you supply, and your written answers about what you would add, one piece of your work, and whether you can work on site.
- Standard technical logs produced by hosting.
Why it is collected
- To produce the preliminary Enquiry Audit.
- To produce a founder-reviewed version and reply to you.
- To assess whether a Request Readiness Sprint is a reasonable fit.
- To assess founding-partner applications and to tell you when we open your sector.
- To understand where Catalogue Blind Spots and Capability Gaps are commercially significant across early enquiries.
- To consider an application and reply to it. Applications are not used for anything else, and they are not shared outside the two founders.
- To operate and secure the service.
Who can access it
Submissions are visible to the two founders. They are not shared with other companies, and they are not published or used publicly without separate written permission.
Three categories of provider process data on our behalf:
- OpenAI, the enquiry text you submit for analysis is sent to OpenAI to produce the preliminary result. If you do not want text leaving our systems, do not use the paste or describe options; the worked locker example runs entirely in your browser.
- Resend, used to send notification email.
- Microsoft Azure, for hosting, database and file storage.
- Needs confirmation before publication
- Processing regions for each provider, the exact retention period for submissions and analyses, the deletion process, and whether a Data Processing Agreement is in place with each sub-processor. Do not publish this page until these are stated concretely and a lawyer has reviewed it.
Model training
Submitted customer and company information is not used to train general-purpose models.
Job applications
An unsolicited application is read by the two founders and nobody else. It is not shared with other companies, it is not used to train anything, and it is not used for any purpose other than considering you.
- Needs confirmation before publication
- How long an unsuccessful application is kept, and whether we may keep one on file to contact you about something later. Both are decisions the company has to make rather than assume, and neither should be guessed at in a privacy notice. Until they are settled, an applicant who asks us to delete their application is the only reliable mechanism, which is not good enough on its own.
Deletion
You can ask us to delete a submission or an application and we will do so. Contact details for that request are on the Security page.