specgit trust center
Security and data privacy
specgit is built around Zero Content Retention: we never keep a copy of your documents or comments. GitHub remains the source of truth, and the narrow temporary exceptions are disclosed on this page.
The short version
- Zero Content Retention — we never keep a copy of your documents or comments; the temporary exceptions (live collaboration, user-invoked AI, explicitly shared feedback) are disclosed below.
- Product analytics are content-free and processed by PostHog Cloud EU; regional choices, retention, access, and deletion are detailed in Privacy.
- No ad tech, retargeting, enrichment brokers, sale of information, or content analytics.
- Your content is never used to train AI models; the optional specgit AI runs only when you invoke it, and every AI change requires your approval.
- Sign-in is a fine-grained GitHub App — repo-by-repo grants, short-lived tokens, no separate password.
These aren't policy promises bolted onto the product — they fall out of the architecture, which is documented on How specgit works.
Does specgit store my documents?
No. specgit reads documents from GitHub when you open them and saves edits back to GitHub through commits, branches, pull requests, and comments. Your repository remains the source of truth. Where docs are held is also a product question, not just a security one — we compare the approaches in Notion vs GitHub for product specs.
What happens during live collaboration?
Live collaboration uses temporary realtime state so multiple people can edit together. That state is deleted after publish or direct commit, and inactive rooms are swept after up to 7 days.
How does specgit use product analytics?
specgit uses content-free product analytics processed by PostHog Cloud EU. Outside the EEA, UK, and Switzerland, public measurement is cookieless and unidentified; signed-in events are pseudonymous and can be opted out. In those regions — or when region is unknown — nothing is sent before separate, informed, revocable opt-in. Analytics never receive documents, comments, prompts, selections, chat, audio, repo names, filenames, paths, raw URLs, or input text. No ad tech, sale, or retargeting. See the Privacy Policy for retention and controls.
How does GitHub sign-in work?
You sign in through GitHub directly, via the specgit GitHub App — there is no separate password and specgit never sees your GitHub credentials. The App uses fine-grained, least-privilege permissions and short-lived tokens, and it can only reach the repositories you (or your organization's admin) explicitly grant when installing it. GitHub access is used only to perform actions you request, such as reading files, saving edits, creating review branches, opening pull requests, and posting comments.
What access does the specgit GitHub App have?
The App installation requests four fine-grained repository permissions, only on the repositories granted to it. GitHub handles user authorization separately: signing in identifies the person using specgit but does not install the App or change repository access. Organization members who aren't admins can request an installation, and an admin chooses its repository grant. Access is revocable at any time from GitHub's settings. Approving for an organization? There's a one-page brief for IT admins covering each permission and why it's needed.
Installation permissions
- Contents (Read & write) — Read the Markdown and HTML files people open, and save their edits back as ordinary git commits on review branches.
- Pull requests (Read & write) — Open a pull request for each draft, post review comments, and merge when someone publishes.
- Issues (Read & write) — Post and read the discussion comments on those pull requests (GitHub serves PR-level comments through its issues API).
- Metadata (Read-only) — List the repositories the installation grants — the mandatory baseline permission for every GitHub App.
The installation cannot
- change repository settings, branch protections, or webhooks
- manage collaborators, teams, deploy keys, or invitations
- reach any repository outside the ones the installation grants
- move the durable document or review record out of GitHub; GitHub remains the source of truth
How do the AI features handle my documents?
The AI features (the in-editor AI assistant, AI review comments, comment triage, and voice) are optional and only run when you invoke them. When you explicitly start an AI action, the document text (and its review comments, for review and triage) is sent to our AI model provider to generate the response; voice sessions stream conversation audio for the duration of the session. specgit keeps none of that content in routine AI usage records—only usage metadata (token counts, model, cost, and timestamps) plus anonymous accepted/dismissed proposal totals. The one exception is explicit consent: if you tick "share this conversation" when rating an AI response, that transcript is kept for up to 90 days and used only to diagnose and improve the AI. Nothing is sent for AI processing in the background or without an explicit request, your content is not used to train models, and every AI-proposed change requires your approval before it is applied or posted.
Our AI model provider is xAI. specgit's xAI account has Zero Data Retention enabled: API inputs and outputs are processed to generate the response and are not persisted by xAI — the default 30-day abuse-monitoring retention does not apply, and voice conversation history is not retained. API inputs and outputs are never used to train xAI's models.
What we do not retain long term
- Your documents and comments — specgit never keeps a copy and runs no document database. Temporary collaboration state and explicitly shared AI feedback have the bounded retention described below.
- Your GitHub password or credentials — sign-in happens on GitHub directly.
- Document content in AI usage records — those records are metadata only (token counts, model, cost, timestamps), and AI quality counters are anonymous daily approved/dismissed proposal totals with no account, document, or content attached.
- AI chat history on our servers — it stays on your device.
What we retain (and for how long)
- Temporary realtime editing state — deleted after publish or direct commit; inactive rooms are swept after up to 7 days.
- GitHub access tokens — stored server-side for active sessions only, encrypted at rest (AES-256-GCM), and deleted on sign-out or after 30 days of inactivity.
- Account preferences (theme, editor layout, AI auto-approve settings) and your terms-of-use acceptance — stored with your GitHub identity so they follow you across devices; settings only, never document content.
- Operational logs — retained for up to 30 days.
- Raw product analytics events are retained for no more than 12 months; aggregate statistics may remain longer.
- AI usage metadata — token counts, model, cost, and timestamps for metering and the usage dashboard.
- AI feedback — ratings, optional notes, and conversation transcripts you explicitly chose to share — retained for up to 90 days, then deleted.
Evaluating specgit for your company?
specgit is built for teams whose security review asks where the data lives: GitHub remains the source of truth, specgit never keeps a copy of your documents or comments, and your content is never used to train AI models. Contact us and we'll answer your security questionnaire directly.
Where can I read the full policy?
Read the full Privacy Policy and Terms of Use, or contact support.