Privacy Policy
How WeaveSpec collects, uses and protects data when you connect your repositories and generate documents.
Last updated: August 4, 2026
1. Who we are
WeaveSpec connects several GitHub repositories into one project, analyses what they do, and generates cross-repository product and technical documents and Jira issues from that analysis. This policy explains what data that requires, why we need it, and who else touches it.
WeaveSpec is currently in early access. Access is granted by request, the product is free, and no payment or card data is collected at this stage.
2. Data we collect
- Account data. Your name, email address and profile picture, taken from the sign-in method you use — email and password, or Google sign-in. Authentication is handled by Supabase; we never see or store your Google password.
- Early access request data. The details you submit when requesting access, so we can review it by hand.
- Repository content and metadata. When you install our GitHub App on a repository, we read source files, directory structure, commit metadata and configuration in order to analyse it. Access is read-only: WeaveSpec never writes to, commits to, or opens pull requests against your code.
- Content you create. Projects, product intents, chat messages, generated documents and their revisions.
- Integration data. If you connect Jira, the project, issue type and field metadata needed to create the issues you approve. Integration credentials are stored encrypted and are readable only by the service that uses them.
- Audit and usage records. Who did what and when inside your account — sign-ins, invitations, role changes, analyses, document generations, exports. These records are append-only by design: they can be read and exported, but not edited or deleted, including by us.
- Technical data. IP address, browser and device type, pages visited and error traces, used for security, abuse prevention and diagnosing failures.
3. How we use it
- To run the product: analysing repositories and generating the documents you ask for.
- To authenticate you and enforce who in your account may see or spend what.
- To create the Jira issues you explicitly approve — nothing is written to a connected tool without an approval step.
- To measure and enforce the quotas that apply to your account.
- To send service notices: security alerts, access decisions and support replies.
- To detect abuse, investigate incidents and meet legal obligations.
We do not sell your data, and we do not use your repository content or generated documents to train our own models or anyone else's.
4. AI processing
Analysis and document generation send extracts of your repository content and your product intent to a third-party large language model provider. Those extracts are processed to produce the output you requested and are not used by the provider to train models under our agreement with them.
Generated output is a draft. It cites the files and commits it relied on so a technical reader can check it, and it is your team's job to review it before acting on it.
5. Who else processes your data
We use a small number of service providers to operate WeaveSpec:
- Supabase — database, authentication and file storage.
- Railway — hosting for the web application and the background analysis worker.
- GitHub — the source of the repository content you connect.
- Atlassian (Jira) — only if you connect it, and only for the issues you approve.
- A large language model provider — analysis and document generation, as described above.
- PostHog — product analytics, so we can see which parts of the product are used and where they fail.
Beyond these, we disclose data only when the law requires it, or when it is necessary to protect our rights, our users or the safety of the service.
6. Cookies
We use cookies for sign-in sessions, for your interface preferences and for product analytics. What each one does is set out in our Cookie Policy.
7. Security
Data is isolated per account at the database level, so one customer's project can never be read from another's session. Integration credentials are stored encrypted and are not readable through the API. Access inside your account is governed by roles, and every consequential action is written to the audit log.
No system is perfectly secure. If a breach affects your data, we will notify you and, where required, the relevant supervisory authority.
8. Retention and deletion
We keep your data for as long as your account is active. When you delete a project, its repositories, analyses and documents are deleted with it. When you close your account, we delete your content within 30 days, except for records we are required to keep — audit entries and billing records, where they exist.
Disconnecting the GitHub App stops all further access to that repository immediately.
9. Your rights
You can access, correct, export or delete your personal data at any time, object to particular processing, or ask us to restrict it. Most of this is available directly in the product; for anything else, write to us and we will act on it within 30 days. If you are in the EEA or the UK, you also have the right to complain to your local data protection authority.
10. Changes and contact
If we change this policy in a way that affects you, we will update the date above and, for material changes, tell you before they take effect.
Questions about this policy or about your data: [email protected].