Skip to content

Privacy Policy

What personal data SpaltX collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it.

Effective July 31, 2026
Contents · 18 sections

Plain-language overview. We hold your account, the project you described, the thread you and an engineer wrote on it, and any proposal that came out of it. Signing in records an IP address and a browser string, and a handful of account changes write a security event you get emailed about. Nothing on this site takes a payment. We run no advertising and no third-party analytics, we have never sold personal data, and you can export or delete everything from your account without asking us.

Summary only. The numbered sections below are the document.

01

Overview and scope

This Privacy Policy describes how Optiarms Inc., an Ohio corporation doing business as SpaltX Industries (“SpaltX”, “we”, “us”) collects, uses, shares and protects personal data when you visit this site, hold an account, send us a project inquiry, open a support ticket, or apply for a job (together, the “Platform”). SpaltX is the data controller for the personal data described here.

There is nothing to buy on this site. What we hold is an account and the record of work you asked us about.

Personal data inside the files you send us so we can do the work is a separate matter, and Section 5 covers it. Section 8 covers our own design tooling and the one part of it a client ever sees.

02

Personal data we collect

Three kinds: what you type, what the Platform records while you use it, and what a provider acting for us hands back.

Categories of personal data
CategoryWhat it includesSource
Account dataName, email address, whether that address is verified, account role, and creation and update timestamps. Your password is held only as a salted hash and we cannot read it.You, at registration
Second-factor dataIf you turn it on: an authenticator secret, your recovery codes, and the public half of any passkey you register with the device name your browser reports.You, in account security
Project inquiriesThe title, service line and description of the work, the budget band and rough timing you pick, the organization you name, and a contact email and phone number. Plus every message on the thread that hangs off it.You, at the project form
ProposalsThe quote we wrote for you: its lines, its total, the date it stands until, and your decision with any note you left when you made it.Us, then your decision
Support correspondenceYour tickets and the messages on them. Staff notes on a ticket are internal and row-level security keeps them out of your view and out of your export.You and our staff
Contact messagesName, email, an optional company, and whatever you write in the box.You, at the contact form
Job applicationsName, email, phone, location, the links you give us, and your cover letter. Held against the role you applied for.You, at a job posting
Privacy requestsName, email, the region you claim rights under, what you asked for, and the tracking code we issue.You, at the privacy form
Session and device dataA session token, the IP address and browser user-agent string recorded when you sign in, and the expiry on that session.Automatic, at sign-in
Security eventsA record of security-relevant account changes: what happened, when, and the IP address and browser it came from. Signing in from a new device, changing a password, adding or removing a second factor.Automatic
Email delivery recordsFor every message we send you: the recipient address, the subject, which kind of message it was, and what the provider reported back about delivery.Automatic, on each send
Workspace membershipWhich organization workspaces you belong to, in what role, and who admitted you.You and your organization
Audit recordsAn append-only entry for sensitive actions, mostly ours rather than yours, which can carry the acting person's email address.Automatic
Rate-limit countersShort-lived counts keyed to an account or a network identifier, so one visitor cannot flood a form.Automatic
Search termsWhat people type into the search boxes, counted per day and per area of the site. The count is not attached to an account, so a term is never traced back to the person who typed it.Automatic, on each search

We ask you not to put health data, government identifiers or anything similarly sensitive into a form here, and nothing on the Platform asks for it. There are no advertising pixels, no third-party analytics, no session replay and no social trackers on any page.

03

How we use personal data

Only for these purposes:

  • Running your account. Signing you in, keeping the session alive, enforcing the role you hold, and letting you export or delete what we have.
  • Scoping and quoting work. Reading your inquiry, asking questions on the thread, writing a proposal, and recording what you decided about it.
  • Answering you. Support tickets, contact messages, job applications and privacy requests, each answered by a person.
  • Keeping the Platform intact. Rate limiting, spotting credential stuffing, investigating access that should not have happened, and holding an audit trail an administrator cannot edit.
  • Telling you what happened. Service mail about your account, your inquiry, a proposal waiting for you, and security events on your account. We send no marketing mail at all. If that changes it will be opt-in with a working unsubscribe.
  • Meeting a legal obligation. Accounting records, export and sanctions screening where it applies, and answering a lawful demand as Section 6 describes.
  • Deciding what to build. Counts and totals with nobody's name on them. We do not profile you.

Section 14 maps each of these onto a legal basis for readers who need one.

04

Cookies

The Platform sets a small set of first-party cookies: the ones that keep you signed in, and a preference belonging to the staff console. No advertiser and no analytics vendor sets anything here. A few other things sit in your browser storage and never reach our servers at all.

The Cookie Policy names every one of them with its purpose and lifetime, and tells you what blocking each costs you.

05

Files you send us for the work

A drawing, a data set, a spreadsheet or a code base you attach to an inquiry can contain personal data about people who are not you: your staff, your customers, your suppliers. Where that happens you are the controller of it and we handle it for you, under the engagement rather than under this notice.

  • We use it for your project and nothing else. Not to train a model, not to build a data set, and not for another client.
  • Send us the minimum. A test data set with the names stripped out usually proves the same thing as the real one. Where you can pseudonymize before you send, do.
  • Who reads it. The people working on your project, and those keeping the Platform running. Section 10 describes what stops anyone else.
  • It leaves when the work does. Tell us to return or destroy it at the end of an engagement and we will, subject to Section 9.

If your own regulator needs a written processing agreement with us before you can send something, ask for one before you attach it. The confidentiality terms in the Terms of Service already bind us either way.

06

When we share personal data

Only with the recipients below, only for what is stated, and never for their own marketing:

Recipients of personal data
RecipientWhat they receiveWhy
Infrastructure providersEverything the Platform stores passes through managed cloud infrastructure: application hosting (Vercel), the Postgres database (Neon), and object storage where it is enabled (Cloudflare R2). Each processes under contract and none of them uses it for anything of their own.Running the Platform
Email deliveryWhichever provider a deployment is configured for, SendGrid (Twilio) or Resend, receives your address and the body of the message, which can carry your name, an inquiry code, a proposal code or a ticket code. Click and open tracking is off on every message, so neither one reports whether you opened it. Both report whether it was delivered, deferred, bounced or marked as spam, and we keep that against the address and subject.Sending you service mail
Bot protectionOur host screens automated traffic in front of sign-in and the forms that reach a person. It sees the request and can set a first-party cookie to tell a browser from a script.Keeping automated traffic off the forms
AnthropicWhere an AI design engine is configured, the text of a prompt typed in our internal design tooling and our instructions to the model. No geometry, no account identity and no email address. Section 8 has the detail.Running the design engine
RunPodWhere GPU compute is configured for our machine-learning work, a training job and the data set it runs on. Those data sets are imagery we own and hold no customer personal data.Renting GPUs for model training
Authorities and litigantsThe minimum a binding demand actually reaches, or what is necessary to protect somebody's life or the integrity of the Platform. We review every demand and refuse overbroad ones where the law lets us.Legal compliance
A successor businessIn a merger, acquisition or asset sale, personal data may move with the business, under this policy or one at least as protective, and we will tell you.Business continuity
Nothing here takes a payment

The Platform has no payment page, so no card number, bank detail or billing address ever reaches it. Work agreed under an accepted proposal is invoiced away from this site, and the Terms of Service put the amounts and the schedule in that proposal.

We do not sell personal data and we do not share it for cross-context behavioral advertising. Neither has ever happened here. Our machine-learning work trains on imagery data sets we own, never on your correspondence or your files.

On row six, the long form is short enough to state here: we produce user data to a government only against valid legal process that identifies the account, and we tell you before we comply unless a court order forbids it.

07

Security events and the audit log

  • Security events. A sign-in from a browser we have not seen, a password change, a second factor added or removed: each writes an entry holding your account, what happened, the time, and the IP address and user agent behind it. Most of them also send you an email, because the point of the record is that you see it too.
  • Audit log. Sensitive actions, mostly staff ones such as changing a role or deciding an inquiry, are appended to a log that nobody can edit or delete through the application, including us. An entry can carry the acting person's email address, and for a handful of customer-facing actions, your account identifier.

Both are readable only by the roles that need them, enforced in the database rather than in application code. Section 10 describes how.

08

Our design tooling and the design engine

The mechanical team models in software we wrote and run ourselves. It sits behind a staff check and none of it is offered to anyone. It appears in a privacy notice for two reasons: our own staff are people with rights over their data too, and one part of it is visible to a client.

  • What a client sees. A read-only share link, which is how we show you a model. Opening one is counted against the link's view cap and nothing about you is recorded. We do not know who opened it, and the link stops resolving the moment it is revoked or expires.
  • What staff work in. Projects, parts, drawings, revision history and the branch structure behind them, each revision stamped with the account that wrote it.
  • The staff override. A workspace someone does not belong to can still be reached by staff, which is how a request gets answered and how an abuse report gets investigated. Creating, moving, sharing or deleting a project that way writes an audit entry. An edit made inside the studio does not.
  • Design-engine prompts. The text typed into the engine, what it returned, which engine ran, and how long it took.
What leaves our infrastructure

Where an AI engine is configured, the prompt goes over the network to Anthropic, which runs the model and returns a part script. Anthropic receives the prompt text and our instructions to the model. It does not receive the geometry, the project, an account identity or an email address, and it is engaged as a processor under contract.

The other engine runs on our own infrastructure and sends nothing anywhere. Every result records which of the two produced it.

None of this trains a model. Not the geometry, not the prompts, not a client file that arrived as part of an engagement.

09

How long we keep data

We hold personal data for as long as it serves what it was collected for, then delete or anonymize it.

Retention periods
DataRetention
Account dataLife of the account, then deleted within 30 days of deletion, except where a row below needs longer.
SessionsExpire after at most 7 days without renewal. Expired rows are purged routinely.
Project inquiries, threads and proposalsLife of the account, and a deletion takes the inquiry, its thread and its proposals with it. Where an accepted proposal is a contract we have accounting and limitation duties over, a person handles that request rather than a script, and keeps only what those duties require.
Your acceptance of these documentsThe record of which version of the Terms you accepted, and when, held while the account exists. It is written by us and neither you nor our staff can edit it.
Support tickets and contact messagesUp to 24 months after the thread closes, so we have the context if it comes back.
Job applications12 months from the decision, so we can come back to you about a later role. Ask us and we will delete yours sooner.
Privacy requests24 months, as the record that we answered you and what we answered.
Security events24 months. They are what lets you and us reconstruct an account compromise after the fact.
Email delivery records12 months. A bounce record is how we know an address stopped working.
Audit logKept as an integrity record for the life of the Platform, holding the least personal data that leaves the entry meaningful.
Rate-limit countersMinutes. A counter lives for its window, typically 60 seconds to 15 minutes, then is overwritten or dropped.
Search termsCounted per day and kept as a total. There is nothing to delete, because no term was ever attached to a person.
Design content and revision historyUntil deleted. Deleting a part or a project removes it and its revisions within 30 days.
Design-engine prompts and results12 months from the generation, so a part can be traced back to what produced it.
Share linksUntil revoked or expired, then 90 days as a record of what was published, then deleted.
Files you sent us for the workFor the engagement, and afterward for as long as we would need them to answer a question about what we delivered. Ask us to return or destroy them and we will.
10

How we protect data

The layers are independent, so a failure in one does not open the others:

  • Transport and storage. Everything travels over TLS. Databases and backups are encrypted at rest by our infrastructure providers. Passwords are salted hashes and nobody here can read one.
  • Server-side authorization. Every page and every action that touches your data checks your session and your role on the server before it runs.
  • Row-level security in the database. Policies keyed to the acting account decide which rows exist for that account. You reach your own inquiries, your own proposals and your own tickets, and nobody else's. Password hashes and session tokens answer only to the service context. The audit log is append-only for everyone. These hold even when application code has a bug, and we prove the whole matrix against a throwaway database on every change.
  • Abuse controls. Sign-in, registration, the forms that reach a person, and administrative writes are all rate limited, and the sensitive ones are audited.

No system is perfectly secure. If a breach affects your personal data we will tell you and the relevant authority without undue delay, and say what happened, what was involved and what we are doing.

11

International data transfers

SpaltX operates from the United States and our providers hold data primarily in the United States. Using the Platform from anywhere else means your personal data is transferred here and processed here.

Where transfer law requires safeguards, for a visitor from the EEA, the UK or Switzerland, we rely on the Standard Contractual Clauses in our agreements with the providers named in Section 6. Write to us and we will tell you which safeguard covers your data.

No Article 27 representative

SpaltX has not appointed a representative in the EU or the UK under Article 27 of the GDPR, and is not certified under the EU-US Data Privacy Framework. If you are in the EEA or the UK, write to support@spaltx.com and your request reaches us directly. You may also complain to your own supervisory authority without going through us at all.

12

Your rights and choices

These are yours wherever you live, not only where a statute grants them:

  • Access and export. A copy of what we hold about you, in a format a machine can read.
  • Correction. Fix account data that is wrong. Name and email you can change yourself.
  • Deletion. Close the account and take the personal data with it. We keep only what Section 9 says we must.
  • Objection and restriction. Object to processing we run on legitimate interests, or ask us to pause it, and we stop unless we have compelling grounds not to.

Three ways to use them:

  • Yourself, now. Signed in, you can download everything and start a deletion from Account, Privacy without waiting on anybody.
  • By form. With an account or without one, ask through Your Privacy Choices and get a tracking code back.
  • By email. Write to support@spaltx.com with PRIVACY REQUEST in the subject, from the address on your account.

We verify against the account email and may ask about recent activity. No notarization, no identity documents. We answer within 30 days, extend once at most and tell you why if we do, and charge nothing unless a request is plainly excessive. An authorized agent can act for you with proof, and we will still confirm with the account email.

Exercising a right never costs you anything here: the same service, on the same terms, afterward.

13

US state privacy rights

Residents of California, and of the other states with comprehensive privacy laws in force, hold specific statutory rights. Section 12 already extends the substance of them to everybody. In addition:

  • Right to know. Section 2 is the list of categories we collect and Section 6 the list of who receives them. We collect no sensitive personal information as those laws define it.
  • Sale and sharing. Neither happens. There is still a Your Privacy Choices page to put a formal opt-out on the record, and where a law reads a Global Privacy Control signal as an opt-out we honor it. We do not run targeted advertising or profiling with legal effects.
  • Appeals. If we refuse a request we explain why, and you can appeal by replying with APPEAL in the subject. We answer an appeal within 45 days. A failed appeal leaves you free to go to your state attorney general.
  • California Shine the Light. We disclose nothing to third parties for their direct marketing, so there is nothing to report under Civil Code Section 1798.83.
14

EEA, UK, and Swiss users

Under the GDPR and the UK GDPR, SpaltX is the controller for the data in Section 2, and a processor for personal data inside the files covered by Section 5. Our legal bases:

Legal bases under GDPR
ProcessingLegal basis
Accounts, inquiries, proposals, support, and performing an engagementPerformance of a contract, or steps taken at your request before one (Art. 6(1)(b))
Job applicationsSteps taken at your request before an employment contract (Art. 6(1)(b))
Security events, rate limiting, the audit trail, investigating abuseLegitimate interests (Art. 6(1)(f)): keeping accounts and the Platform intact
Accounting records, export and sanctions screening, answering a binding demandLegal obligation (Art. 6(1)(c))
Anything optional we add laterConsent (Art. 6(1)(a)), which you can withdraw whenever you like

On top of Section 12 you can:

  • Take your data elsewhere in a structured, commonly used, machine-readable format, for what we process by automated means on contract or consent.
  • Complain to your supervisory authority. We would rather you came to us first, and you are under no obligation to.

No automated decision produces legal effects about you here, and we build no profiles. Account and inquiry data is contractually necessary: without it there is no way to scope work or send you a proposal.

15

Children

The Platform is not for children. You must be 18 to hold an account or send us an inquiry, and we do not knowingly collect personal data from anyone under 13, or under the higher age your jurisdiction sets for online consent. If you think a child gave us data, write to support@spaltx.com and we will delete it.

16

Do Not Track and Global Privacy Control

Both signals ask a site to stop following you around the web. Nothing here follows you in the first place, so what they ask for is already how this site works. Where a law treats Global Privacy Control as a formal opt-out we honor it, and honoring it changes nothing, because there is no sale and no sharing to switch off.

17

Changes to this policy

We update this when our practices change or the law makes us, and the effective date at the top moves when we do. A material change, a new category of data or a new kind of recipient, gets advance notice on the Platform or by email before it takes effect. Earlier versions are available on request.

18

Contact us

Privacy questions, requests and complaints all go to support@spaltx.com with PRIVACY REQUEST in the subject line. We answer privacy mail within ten business days and finish verified requests on the timeline in Section 12.

Summary of commitments
Minimum data. No ad trackers, no profiling, no selling. No payment page, so no card details anywhere. Delete your account and the personal data goes with it, apart from the records accounting law makes us hold.
Privacy Policy | SpaltX