EFFECTIVE 15 SEPTEMBER 2026
Privacy Policy
This policy explains how SpecNest handles personal information when you use the SpecNest engineering workspace. SpecNest is designed around a user-owned data model: your engineering record is kept in a Google Sheet in your own Google Drive.
Who controls your information
For account and product operations, SpecNest is the controller of the limited personal information described below. You control the engineering information you place in your Google Drive and the people with whom you share it. Questions and privacy requests can be sent to specnest.tool@gmail.com.
Information we handle
- Google identity: your name, email address, and Google account identifier, used to identify your workspace session.
- Engineering records: projects, systems, parts, requirements, parameters, tests, decisions, approvals, notes, audit events, and revision snapshots that you enter.
- Session information: a local sign-in marker and a short-lived Google access token stored in your browser. We do not store your Google password.
- Technical information: hosting and security providers may process ordinary request, device, error, and security logs needed to operate and protect the public website.
How and why we use it
We use this information to authenticate you, open and update the SpecNest workbook you request, show your engineering record, keep the service secure, diagnose failures, answer support requests, and comply with law. Depending on your location, the legal basis may be performance of our agreement, your consent, our legitimate interest in operating and protecting the service, or compliance with a legal obligation.
Google Drive and Google API data
SpecNest requests the drive.file permission so it can create, find, read, update, and delete only the Google Drive files that you create with or open through SpecNest. The browser sends your project information directly to Google APIs. SpecNest does not maintain a separate project database.
SpecNest's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google's own handling of your account and Drive is governed by Google's policies.
Sharing and disclosure
We do not sell personal information, use engineering records for advertising, or use Google Workspace data to train general-purpose AI models. Information may be processed by Google at your direction and by hosting, security, or support providers acting for SpecNest. We may disclose information when legally required, to protect users or the service, or in a business reorganization subject to appropriate safeguards.
Storage, retention, and deletion
Your engineering record remains in your Google Drive until you delete it. Short-lived access tokens stay in browser session storage and are removed when you sign out or close the browser session. Local sign-in state remains until you sign out, delete the workspace, or clear browser storage. Service providers may retain limited security logs for their normal protection and compliance periods.
You can delete the workbook and clear SpecNest's local session from inside the product by choosing Delete SpecNest workspace. You can also delete the “SpecNest Engineering Data” spreadsheet in Google Drive and revoke SpecNest under your Google Account's third-party connections. See the workspace deletion instructions.
International processing
The website and its providers may process information in countries other than yours. Where applicable, we rely on recognized transfer mechanisms and provider safeguards. Your Google Drive data remains subject to the storage location and settings of your Google account or organization.
Your choices and rights
Depending on local law, you may request access, correction, deletion, portability, restriction, or objection; withdraw consent; and complain to a data protection authority. You can directly view, edit, export, and delete the engineering record in Google Drive. We will verify requests as reasonably necessary and honor rights that apply in your jurisdiction. We do not use automated decision-making that produces legal or similarly significant effects.
Security
We minimize requested Google permissions, use HTTPS, and keep access tokens in browser session storage. No service can guarantee absolute security. Protect your Google account, review Drive sharing settings, and promptly report suspected unauthorized access.
Cookies and similar technologies
SpecNest does not use advertising, analytics, or behavioral tracking cookies. It uses local storage and session storage only for the sign-in and Drive session you request. Google and hosting providers may use strictly necessary authentication, security, or load-balancing technologies. Read the Cookies and browser storage notice.
Children
SpecNest is intended for professional and educational engineering use by people aged 16 or older. A younger user may use it only through a parent, guardian, school, or organization that has authority to provide the required consent.
Changes
We may update this policy as the product, providers, or law changes. We will post the revised effective date here and provide additional notice when required.