Skip to content

Your specs are product IP.We treat them that way.

CrystalSpec is designed for teams that put sensitive product intent, implementation detail, and AI-assisted decisions in one place. This page summarizes the privacy and security practices described in the Privacy Policy.

Privacy posture

AI training

Prohibited — never on your data

AI providers

No-training terms enforced

Human gate

Every AI edit reviewed

AI providers may change over time. The rule does not: your data is never used to train AI models — ours or theirs. Retention and abuse-monitoring practices are documented in the applicable provider terms, data-processing agreement, and subprocessor list.

The practical safeguards

AI features use the context needed to respond

When you use an AI feature, CrystalSpec sends the relevant prompts, chat history, project or workspace context, and requested structured-output schema to its AI providers so the feature can respond.

Human approval stays in front of every AI edit

AI can draft, analyze, and propose changes, but it cannot silently rewrite your project. Proposed create, update, and delete actions wait for review before they become part of the spec.

Access follows the same project permissions

Users and integrations operate within the roles, teams, projects, and revisions they are allowed to access. CrystalSpec uses access controls, transport encryption, password hashing, role-based permissions, and operational monitoring to protect personal data.

Your data never trains AI models

CrystalSpec never trains models on Customer Content, and its AI providers are prohibited from using your data for training. Retention and abuse-monitoring practices are documented in the applicable provider terms, data-processing agreement, and CrystalSpec subprocessor list.

Deletion and retention are documented

Account and workspace data is deleted or anonymized within 90 days after verified deletion, subject to legal, security, fraud-prevention, billing, dispute, and backup requirements. The Privacy Policy explains the remaining records and how to request their removal.

Useful AI, constrained by design.

CrystalSpec never uses Customer Content to train AI models, and its AI providers are prohibited from training on your data. The model receives a bounded prompt, returns a proposed result, and humans decide what lands. Retention and abuse-monitoring practices are governed by the applicable provider terms, data-processing agreement, and subprocessor list.

  • CrystalSpec never uses Customer Content to train AI models — its own or anyone else's.
  • AI providers are prohibited from using your prompts or content for model training. Retention and abuse monitoring are governed by the applicable provider terms, data-processing agreement, and subprocessor list.
  • AI features send relevant prompts, chat history, project or workspace context, and requested structured-output schemas to AI providers so they can respond.
  • AI usage and quota data is processed to provide, secure, and maintain the service.
  • Do not submit sensitive personal data, secrets, credentials, or content you are not authorized to process through AI features.

Need enterprise controls?

For privacy, data-handling, security-review, or procurement questions, contact us at support@crystalspec.com.

Contact enterprise support

Privacy practices you can review.

Customer Content is processed to provide and secure the service.
A current subprocessor list is available on request from support.
International transfers rely on adequacy decisions, Standard Contractual Clauses, and supplementary measures where appropriate.
Billing, account, security, and operational records are retained as described in the Privacy Policy.

Bring your security requirements to the table.

Share your data-handling requirements. We can explain CrystalSpec's current privacy practices before your team commits.