Privacy Policy
What personal data SpaltX collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it.
Contents · 18 sections
- 01Overview and scope
- 02Personal data we collect
- 03How we use personal data
- 04Cookies
- 05Files you send us for the work
- 06When we share personal data
- 07Security events and the audit log
- 08Our design tooling and the design engine
- 09How long we keep data
- 10How we protect data
- 11International data transfers
- 12Your rights and choices
- 13US state privacy rights
- 14EEA, UK, and Swiss users
- 15Children
- 16Do Not Track and Global Privacy Control
- 17Changes to this policy
- 18Contact us
Plain-language overview. We hold your account, the project you described, the thread you and an engineer wrote on it, and any proposal that came out of it. Signing in records an IP address and a browser string, and a handful of account changes write a security event you get emailed about. Nothing on this site takes a payment. We run no advertising and no third-party analytics, we have never sold personal data, and you can export or delete everything from your account without asking us.
Summary only. The numbered sections below are the document.
Overview and scope
This Privacy Policy describes how Optiarms Inc., an Ohio corporation doing business as SpaltX Industries (“SpaltX”, “we”, “us”) collects, uses, shares and protects personal data when you visit this site, hold an account, send us a project inquiry, open a support ticket, or apply for a job (together, the “Platform”). SpaltX is the data controller for the personal data described here.
There is nothing to buy on this site. What we hold is an account and the record of work you asked us about.
Personal data inside the files you send us so we can do the work is a separate matter, and Section 5 covers it. Section 8 covers our own design tooling and the one part of it a client ever sees.
Personal data we collect
Three kinds: what you type, what the Platform records while you use it, and what a provider acting for us hands back.
| Category | What it includes | Source |
|---|---|---|
| Account data | Name, email address, whether that address is verified, account role, and creation and update timestamps. Your password is held only as a salted hash and we cannot read it. | You, at registration |
| Second-factor data | If you turn it on: an authenticator secret, your recovery codes, and the public half of any passkey you register with the device name your browser reports. | You, in account security |
| Project inquiries | The title, service line and description of the work, the budget band and rough timing you pick, the organization you name, and a contact email and phone number. Plus every message on the thread that hangs off it. | You, at the project form |
| Proposals | The quote we wrote for you: its lines, its total, the date it stands until, and your decision with any note you left when you made it. | Us, then your decision |
| Support correspondence | Your tickets and the messages on them. Staff notes on a ticket are internal and row-level security keeps them out of your view and out of your export. | You and our staff |
| Contact messages | Name, email, an optional company, and whatever you write in the box. | You, at the contact form |
| Job applications | Name, email, phone, location, the links you give us, and your cover letter. Held against the role you applied for. | You, at a job posting |
| Privacy requests | Name, email, the region you claim rights under, what you asked for, and the tracking code we issue. | You, at the privacy form |
| Session and device data | A session token, the IP address and browser user-agent string recorded when you sign in, and the expiry on that session. | Automatic, at sign-in |
| Security events | A record of security-relevant account changes: what happened, when, and the IP address and browser it came from. Signing in from a new device, changing a password, adding or removing a second factor. | Automatic |
| Email delivery records | For every message we send you: the recipient address, the subject, which kind of message it was, and what the provider reported back about delivery. | Automatic, on each send |
| Workspace membership | Which organization workspaces you belong to, in what role, and who admitted you. | You and your organization |
| Audit records | An append-only entry for sensitive actions, mostly ours rather than yours, which can carry the acting person's email address. | Automatic |
| Rate-limit counters | Short-lived counts keyed to an account or a network identifier, so one visitor cannot flood a form. | Automatic |
| Search terms | What people type into the search boxes, counted per day and per area of the site. The count is not attached to an account, so a term is never traced back to the person who typed it. | Automatic, on each search |
We ask you not to put health data, government identifiers or anything similarly sensitive into a form here, and nothing on the Platform asks for it. There are no advertising pixels, no third-party analytics, no session replay and no social trackers on any page.
How we use personal data
Only for these purposes:
- Running your account. Signing you in, keeping the session alive, enforcing the role you hold, and letting you export or delete what we have.
- Scoping and quoting work. Reading your inquiry, asking questions on the thread, writing a proposal, and recording what you decided about it.
- Answering you. Support tickets, contact messages, job applications and privacy requests, each answered by a person.
- Keeping the Platform intact. Rate limiting, spotting credential stuffing, investigating access that should not have happened, and holding an audit trail an administrator cannot edit.
- Telling you what happened. Service mail about your account, your inquiry, a proposal waiting for you, and security events on your account. We send no marketing mail at all. If that changes it will be opt-in with a working unsubscribe.
- Meeting a legal obligation. Accounting records, export and sanctions screening where it applies, and answering a lawful demand as Section 6 describes.
- Deciding what to build. Counts and totals with nobody's name on them. We do not profile you.
Section 14 maps each of these onto a legal basis for readers who need one.
Files you send us for the work
A drawing, a data set, a spreadsheet or a code base you attach to an inquiry can contain personal data about people who are not you: your staff, your customers, your suppliers. Where that happens you are the controller of it and we handle it for you, under the engagement rather than under this notice.
- We use it for your project and nothing else. Not to train a model, not to build a data set, and not for another client.
- Send us the minimum. A test data set with the names stripped out usually proves the same thing as the real one. Where you can pseudonymize before you send, do.
- Who reads it. The people working on your project, and those keeping the Platform running. Section 10 describes what stops anyone else.
- It leaves when the work does. Tell us to return or destroy it at the end of an engagement and we will, subject to Section 9.
If your own regulator needs a written processing agreement with us before you can send something, ask for one before you attach it. The confidentiality terms in the Terms of Service already bind us either way.
Security events and the audit log
- Security events. A sign-in from a browser we have not seen, a password change, a second factor added or removed: each writes an entry holding your account, what happened, the time, and the IP address and user agent behind it. Most of them also send you an email, because the point of the record is that you see it too.
- Audit log. Sensitive actions, mostly staff ones such as changing a role or deciding an inquiry, are appended to a log that nobody can edit or delete through the application, including us. An entry can carry the acting person's email address, and for a handful of customer-facing actions, your account identifier.
Both are readable only by the roles that need them, enforced in the database rather than in application code. Section 10 describes how.
Our design tooling and the design engine
The mechanical team models in software we wrote and run ourselves. It sits behind a staff check and none of it is offered to anyone. It appears in a privacy notice for two reasons: our own staff are people with rights over their data too, and one part of it is visible to a client.
- What a client sees. A read-only share link, which is how we show you a model. Opening one is counted against the link's view cap and nothing about you is recorded. We do not know who opened it, and the link stops resolving the moment it is revoked or expires.
- What staff work in. Projects, parts, drawings, revision history and the branch structure behind them, each revision stamped with the account that wrote it.
- The staff override. A workspace someone does not belong to can still be reached by staff, which is how a request gets answered and how an abuse report gets investigated. Creating, moving, sharing or deleting a project that way writes an audit entry. An edit made inside the studio does not.
- Design-engine prompts. The text typed into the engine, what it returned, which engine ran, and how long it took.
Where an AI engine is configured, the prompt goes over the network to Anthropic, which runs the model and returns a part script. Anthropic receives the prompt text and our instructions to the model. It does not receive the geometry, the project, an account identity or an email address, and it is engaged as a processor under contract.
The other engine runs on our own infrastructure and sends nothing anywhere. Every result records which of the two produced it.
None of this trains a model. Not the geometry, not the prompts, not a client file that arrived as part of an engagement.
How long we keep data
We hold personal data for as long as it serves what it was collected for, then delete or anonymize it.
| Data | Retention |
|---|---|
| Account data | Life of the account, then deleted within 30 days of deletion, except where a row below needs longer. |
| Sessions | Expire after at most 7 days without renewal. Expired rows are purged routinely. |
| Project inquiries, threads and proposals | Life of the account, and a deletion takes the inquiry, its thread and its proposals with it. Where an accepted proposal is a contract we have accounting and limitation duties over, a person handles that request rather than a script, and keeps only what those duties require. |
| Your acceptance of these documents | The record of which version of the Terms you accepted, and when, held while the account exists. It is written by us and neither you nor our staff can edit it. |
| Support tickets and contact messages | Up to 24 months after the thread closes, so we have the context if it comes back. |
| Job applications | 12 months from the decision, so we can come back to you about a later role. Ask us and we will delete yours sooner. |
| Privacy requests | 24 months, as the record that we answered you and what we answered. |
| Security events | 24 months. They are what lets you and us reconstruct an account compromise after the fact. |
| Email delivery records | 12 months. A bounce record is how we know an address stopped working. |
| Audit log | Kept as an integrity record for the life of the Platform, holding the least personal data that leaves the entry meaningful. |
| Rate-limit counters | Minutes. A counter lives for its window, typically 60 seconds to 15 minutes, then is overwritten or dropped. |
| Search terms | Counted per day and kept as a total. There is nothing to delete, because no term was ever attached to a person. |
| Design content and revision history | Until deleted. Deleting a part or a project removes it and its revisions within 30 days. |
| Design-engine prompts and results | 12 months from the generation, so a part can be traced back to what produced it. |
| Share links | Until revoked or expired, then 90 days as a record of what was published, then deleted. |
| Files you sent us for the work | For the engagement, and afterward for as long as we would need them to answer a question about what we delivered. Ask us to return or destroy them and we will. |
How we protect data
The layers are independent, so a failure in one does not open the others:
- Transport and storage. Everything travels over TLS. Databases and backups are encrypted at rest by our infrastructure providers. Passwords are salted hashes and nobody here can read one.
- Server-side authorization. Every page and every action that touches your data checks your session and your role on the server before it runs.
- Row-level security in the database. Policies keyed to the acting account decide which rows exist for that account. You reach your own inquiries, your own proposals and your own tickets, and nobody else's. Password hashes and session tokens answer only to the service context. The audit log is append-only for everyone. These hold even when application code has a bug, and we prove the whole matrix against a throwaway database on every change.
- Abuse controls. Sign-in, registration, the forms that reach a person, and administrative writes are all rate limited, and the sensitive ones are audited.
No system is perfectly secure. If a breach affects your personal data we will tell you and the relevant authority without undue delay, and say what happened, what was involved and what we are doing.
International data transfers
SpaltX operates from the United States and our providers hold data primarily in the United States. Using the Platform from anywhere else means your personal data is transferred here and processed here.
Where transfer law requires safeguards, for a visitor from the EEA, the UK or Switzerland, we rely on the Standard Contractual Clauses in our agreements with the providers named in Section 6. Write to us and we will tell you which safeguard covers your data.
SpaltX has not appointed a representative in the EU or the UK under Article 27 of the GDPR, and is not certified under the EU-US Data Privacy Framework. If you are in the EEA or the UK, write to support@spaltx.com and your request reaches us directly. You may also complain to your own supervisory authority without going through us at all.
Your rights and choices
These are yours wherever you live, not only where a statute grants them:
- Access and export. A copy of what we hold about you, in a format a machine can read.
- Correction. Fix account data that is wrong. Name and email you can change yourself.
- Deletion. Close the account and take the personal data with it. We keep only what Section 9 says we must.
- Objection and restriction. Object to processing we run on legitimate interests, or ask us to pause it, and we stop unless we have compelling grounds not to.
Three ways to use them:
- Yourself, now. Signed in, you can download everything and start a deletion from Account, Privacy without waiting on anybody.
- By form. With an account or without one, ask through Your Privacy Choices and get a tracking code back.
- By email. Write to support@spaltx.com with PRIVACY REQUEST in the subject, from the address on your account.
We verify against the account email and may ask about recent activity. No notarization, no identity documents. We answer within 30 days, extend once at most and tell you why if we do, and charge nothing unless a request is plainly excessive. An authorized agent can act for you with proof, and we will still confirm with the account email.
Exercising a right never costs you anything here: the same service, on the same terms, afterward.
US state privacy rights
Residents of California, and of the other states with comprehensive privacy laws in force, hold specific statutory rights. Section 12 already extends the substance of them to everybody. In addition:
- Right to know. Section 2 is the list of categories we collect and Section 6 the list of who receives them. We collect no sensitive personal information as those laws define it.
- Sale and sharing. Neither happens. There is still a Your Privacy Choices page to put a formal opt-out on the record, and where a law reads a Global Privacy Control signal as an opt-out we honor it. We do not run targeted advertising or profiling with legal effects.
- Appeals. If we refuse a request we explain why, and you can appeal by replying with APPEAL in the subject. We answer an appeal within 45 days. A failed appeal leaves you free to go to your state attorney general.
- California Shine the Light. We disclose nothing to third parties for their direct marketing, so there is nothing to report under Civil Code Section 1798.83.
EEA, UK, and Swiss users
Under the GDPR and the UK GDPR, SpaltX is the controller for the data in Section 2, and a processor for personal data inside the files covered by Section 5. Our legal bases:
| Processing | Legal basis |
|---|---|
| Accounts, inquiries, proposals, support, and performing an engagement | Performance of a contract, or steps taken at your request before one (Art. 6(1)(b)) |
| Job applications | Steps taken at your request before an employment contract (Art. 6(1)(b)) |
| Security events, rate limiting, the audit trail, investigating abuse | Legitimate interests (Art. 6(1)(f)): keeping accounts and the Platform intact |
| Accounting records, export and sanctions screening, answering a binding demand | Legal obligation (Art. 6(1)(c)) |
| Anything optional we add later | Consent (Art. 6(1)(a)), which you can withdraw whenever you like |
On top of Section 12 you can:
- Take your data elsewhere in a structured, commonly used, machine-readable format, for what we process by automated means on contract or consent.
- Complain to your supervisory authority. We would rather you came to us first, and you are under no obligation to.
No automated decision produces legal effects about you here, and we build no profiles. Account and inquiry data is contractually necessary: without it there is no way to scope work or send you a proposal.
Children
The Platform is not for children. You must be 18 to hold an account or send us an inquiry, and we do not knowingly collect personal data from anyone under 13, or under the higher age your jurisdiction sets for online consent. If you think a child gave us data, write to support@spaltx.com and we will delete it.
Do Not Track and Global Privacy Control
Both signals ask a site to stop following you around the web. Nothing here follows you in the first place, so what they ask for is already how this site works. Where a law treats Global Privacy Control as a formal opt-out we honor it, and honoring it changes nothing, because there is no sale and no sharing to switch off.
Changes to this policy
We update this when our practices change or the law makes us, and the effective date at the top moves when we do. A material change, a new category of data or a new kind of recipient, gets advance notice on the Platform or by email before it takes effect. Earlier versions are available on request.
Contact us
Privacy questions, requests and complaints all go to support@spaltx.com with PRIVACY REQUEST in the subject line. We answer privacy mail within ten business days and finish verified requests on the timeline in Section 12.
