Privacy Policy
How The Spatial Brief collects, uses, and protects your personal data.
⚠️ Draft for review — replace the bracketed placeholders and have counsel confirm before relying on this.
1. Who we are (data controller)
The Spatial Brief is operated by [LEGAL ENTITY NAME], [LEGAL FORM, e.g. SAS], registered in France [SIREN/RCS], registered office at [REGISTERED ADDRESS]. For any privacy request, contact us at [privacy@studiomeije.com]. We have not appointed a Data Protection Officer, as we are not legally required to.
2. What data we collect
- Account: your email address and (for email sign-up) a securely hashed password.
- If you sign in with Google: your Google account identifier and email.
- Technical: a first-party session stored in your browser to keep you signed in.
- MCP access: hashed API keys, key labels, creation dates, revocation dates, and last-used timestamps.
- For admin contributors only: submitted capture metadata (submitter email, page details, user agent, screenshots).
3. Why we use it
- To authenticate you and operate your account.
- To provide account-gated MCP access to the public ecosystem dataset.
- To let signed-in contributors submit source captures through the Chrome extension.
- To keep the service secure and prevent abuse.
4. Legal bases (GDPR Art. 6)
- Performance of a contract — authentication and account features.
- Legitimate interests — securing the service and preventing fraud.
5. Service providers (processors)
We share data only with processors that help us run the service:
6. International transfers
Some processors may process data outside the EU/EEA (e.g. the United States). Where they do, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework.
7. How long we keep it
- Account and profile data: until you delete your account.
- Admin capture submissions: [RETENTION WINDOW]; personal identifiers are removed when the submitting account is deleted.
8. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and object to processing of your data, and to data portability and to withdraw consent. You also have the right to lodge a complaint with your supervisory authority — in France, the CNIL.
9. How to exercise your rights
From your Account page you can download all your data (“Download my data”) and permanently delete your account (“Delete account”). For anything else, email [privacy@studiomeije.com] and we’ll respond within one month.
10. Cookies & local storage
We use only a strictly-necessary first-party session in your browser to keep you signed in. We do not use analytics, advertising, or third-party tracking, so no cookie-consent banner is shown.
11. Changes to this policy
We may update this policy; we’ll revise the date below when we do and, for material changes, notify you.
Last updated: [DATE].