← Back to specgit

specgit

Privacy Policy

Last updated: July 17, 2026

Fn First Holdings LLC ("Fn First," "we," "our," or "us") respects your privacy. This policy explains how specgit handles information when you use specgit.com and related services.

1. The Short Version

Zero Content Retention means specgit never keeps a copy of your documents or comments — GitHub remains the source of truth. The narrow, temporary exceptions: live- collaboration state may remain for up to 7 inactive days; content is sent to xAI only when you invoke AI; and AI feedback content is kept for up to 90 days only when you explicitly choose to share it.

2. Information We Handle

  • GitHub account information: your GitHub username, display name, avatar, and repository access needed to sign you in and show repositories you can access.
  • Repository content you choose to open: document content, images, and comments are read from GitHub so specgit can display and save your work. GitHub remains the durable source of truth.
  • Temporary realtime editing state: when live collaboration is enabled, in-progress editing state may be held temporarily on our server so multiple editors can work together.
  • Session information: we keep the minimum information needed to keep you signed in, such as a session ID and non-sensitive account display details.
  • Account preferences: settings you choose — theme, editor layout, and AI auto-approve toggles — plus the terms-of-use version you accepted, stored with your GitHub identity so they follow you across devices. Settings only, never document content; AI chat history stays on your device.
  • Support communications: if you contact us, we receive the information you choose to send.
  • Operational logs: our servers may record technical metadata such as request timing, errors, IP address, and browser details to keep the service secure and reliable.
  • Product analytics: allowlisted, content-free events used for product improvement, funnel diagnosis, reliability, and controlled growth experiments. Events may contain route templates, closed enums or buckets, normalized campaign, landing, or CTA slugs, release and environment, and random pseudonymous IDs for signed-in use. They never contain the content or identity categories listed in Product Analytics below.

3. What We Do Not Do

  • We do not sell information about you or your use of specgit.
  • We do not use ad tech, advertising pixels, retargeting, enrichment brokers, or content analytics. We do use the content-free product analytics described below.
  • We do not ask for or store your GitHub password.
  • We do not keep a copy of your documents or comments beyond the temporary processing described in this policy.

4. Product Analytics

specgit uses PostHog Cloud EU as a processor for allowlisted product analytics events. Product analytics never contain documents, comments, prompts, selections, chat, audio, pasted values, DOM or input text, screenshots, repository, account, or user names, document IDs, filenames, paths, raw URLs or referrers, email addresses, GitHub logins, IP addresses or country, error messages or stacks, or network bodies.

Outside the EEA, UK, and Switzerland, when region is known to be non-restricted, public-site measurement is cookieless and unidentified and signed-in events are pseudonymous and content-free; either can be opted out. In the EEA, UK, Switzerland, or when region is unknown, we send no public-site or signed-in analytics to PostHog until you separately give informed, revocable consent. Analytics consent is separate from these Terms. We respect Global Privacy Control and make a best-effort to honor Do Not Track.

Request IP is used locally only to select the regional gate; it is not sent to PostHog or retained as analytics location data. Raw analytics events are retained for no more than 12 months. Non-person aggregate statistics may remain longer. You may request access to or deletion of pseudonymous analytics events through the privacy contact below.

5. AI Features

The AI features (the in-editor AI assistant for co-editing, document review, comment triage, and voice) are optional and only run when you invoke them. Plans differ in how much AI usage they include, not in how your content is handled. When you invoke an AI action:

  • What is sent: the text of the document being worked on (and its review comments, for review and triage) is sent to our AI model provider, xAI, to generate the response. For voice sessions, conversation audio is streamed to the provider for the duration of the session.
  • What the provider does with it: specgit's xAI account has Zero Data Retention enabled — xAI processes API inputs and outputs to generate the response and does not persist them; the default 30-day abuse-monitoring retention does not apply, and voice conversation history is not retained. API inputs and outputs are never used to train xAI's models.
  • When: only when you explicitly invoke an AI action. Documents are never sent for AI processing in the background, and if you never use the AI features, no content is ever sent.
  • What routine usage records keep: only metadata — token counts, the model used, the computed cost, and timestamps — to meter usage, enforce your spending limits, and power your usage dashboard. They do not include prompts, document text, or audio. Explicitly shared feedback is the separate exception below.
  • What the AI does: it can only propose changes. Every document edit, comment, reply, or resolution the AI suggests requires your explicit approval in the editor before anything is applied or posted, and anything posted to GitHub is attributed under your account with an AI marker.
  • Quality signals: to measure AI quality, specgit records whether AI proposals were approved, dismissed, or failed to apply — as anonymous daily totals only, with no account, document, or content attached.
  • Feedback you choose to share:rating an AI response records only the rating. If you explicitly tick "share this conversation" when giving feedback, that chat transcript (which includes the document text within it) is sent to us and stored so we can diagnose and fix the failure. This is the only case where specgit keeps content, it happens only with your consent, it is retained for up to 90 days and then deleted, and it is used solely to improve the AI features — never to train models.
  • Training: specgit does not use your content to train AI models.

6. How We Use Information

We use information only to:

  • sign you in through GitHub;
  • show repositories and files you are allowed to access;
  • save edits, create review branches, open pull requests, and post comments;
  • support live collaboration;
  • improve the product, diagnose funnels, protect reliability, and run controlled growth experiments using content-free analytics;
  • respond to support requests;
  • protect the service from misuse and troubleshoot errors; and
  • comply with legal obligations.

7. Sharing

We share information only when needed to provide specgit, when you direct us to do so, or when legally required. GitHub receives the actions you take through specgit, such as commits, pull requests, and comments. Our production service runs on Microsoft Azure. xAI processes content only when you invoke an AI feature, under the terms described above. PostHog Cloud EU processes only the content-free analytics described above. We may disclose limited information if required by law, to protect rights and safety, or as part of a business transfer, subject to appropriate protections.

8. Retention

  • Documents and comments: retained in your GitHub repository according to your own GitHub and repository settings.
  • Realtime editing state: deleted after a document is published or directly committed, and automatically deleted after a short inactivity window of up to 7 days.
  • GitHub access tokens: stored server-side for your active session, encrypted at rest (AES-256-GCM), and deleted when you sign out. Sessions expire automatically after 30 days of inactivity.
  • Account preferences and terms acceptance: retained while you use specgit; deleted on request (see Your Choices and Rights).
  • Operational logs: retained for up to 30 days.
  • Product analytics: raw events retained for no more than 12 months; non-person aggregate statistics may remain longer.
  • AI usage and quality counters: daily totals only (usage counts per seat; anonymous approved/dismissed proposal counts with no account, document, or content attached), retained as statistics.
  • AI feedback: ratings, optional notes, and conversation transcripts you explicitly chose to share are retained for up to 90 days, then deleted.
  • Support messages: retained as long as reasonably needed to respond and maintain support history.

9. Security

We use reasonable administrative, technical, and physical safeguards to protect information, including HTTPS for data in transit, limited internal access, and operational controls for our production environment. No internet service can be guaranteed 100% secure, but we design specgit to minimize what we hold in the first place.

10. Your Choices and Rights

You can sign out of specgit at any time. You can revoke specgit's GitHub access from your GitHub account settings. Outside the EEA, UK, and Switzerland, you can opt out of public-site and signed-in product analytics at any time. In those regions, or when your region is unknown, analytics remain off until you separately opt in; you can withdraw that consent at any time. Make or change that choice on the Analytics choices page. Analytics choices are separate from accepting the Terms. Depending on where you live, you may also have rights to access, correct, delete, restrict, or object to the processing of personal information, including access to or deletion of pseudonymous analytics events. To make a privacy request, use our support form and select Privacy Inquiry, or email privacy@fnfirst.com.

11. Children's Privacy

specgit is not intended for children under 16. We do not knowingly collect personal information from children under 16.

12. Changes

We may update this policy from time to time. When we do, we will update the date above. Material changes may be announced on the site or through another appropriate channel.

13. Contact

Fn First Holdings LLC
Attn: Privacy Officer
30 N Gould St STE 11959
Sheridan, WY 82801 USA
privacy@fnfirst.com
Contact support