Privacy Policy
Last updated: 17 September 2026
This policy explains what personal data Speca collects, why, and what your rights are.
Who we are. Speca is provided by Speca Ltd, a company registered in England and Wales (company number 17432536), registered office 71–75 Shelton Street, Covent Garden, London WC2H 9JQ. Speca Ltd is the "data controller" for the purposes of UK data protection law.
ICO registration number: ICO:00015578248 (public register).
Contact: hello@speca.co.uk
1. The short version
- We hold your email address, your plan, and a log of when you used each feature (which topic, which type of resource, when). That's essentially it.
- We do not store the content you put into Speca's AI features — not the PowerPoint you upload, not the student answer you paste in for marking, not the resource that comes back.
- We do not hold pupil data, and Speca is not designed to.
- We don't sell your data, and we don't share it with advertisers.
- We use a small number of specialist companies to run Speca (hosting, database, AI, payments, email, error monitoring). Section 5 names every one of them and says exactly what each receives.
2. What we collect
2.1 When you join the waitlist
Your email address, and the date you joined.
There are two waitlist forms and they go to different places:
- The waitlist on the Speca website stores your email address in our own database.
- The waitlist on our standalone marketing landing page submits your email address to Mailchimp, which manages that mailing list for us.
2.2 When you create an account
- Your email address.
- Your password, which is stored securely (hashed) by our authentication provider — we never see or store your password in plain text.
- A profile record containing: your account ID, your email address, your plan (
freeorpro), your Stripe customer and subscription IDs and subscription status if you subscribe, and the dates the record was created and last updated.
2.3 When you use Speca's features (usage records)
We keep a short record each time you use one of the metered features. This is how your allowance is counted, how we detect abuse, and how you can see your own history.
These records contain metadata only — never the content of what you made, uploaded or submitted:
| Feature | What the record contains |
|---|---|
| Downloading a bundle file | your account ID, the topic, the type of asset, the date and time |
| Building a resource from a library topic | your account ID, the topic, the type of asset, whether it succeeded, the date and time |
| Making a resource beyond the library | your account ID, the topic, the type of asset, whether it succeeded, the date and time |
| Adapting your own slides | your account ID, the filename of the file you uploaded, the asset type, whether it succeeded, the date and time |
| AI-assisted marking | your account ID, the topic, the type of asset, whether it succeeded, the date and time |
Two things to call out honestly:
- The filename of an uploaded deck is stored (for example
Y10-Set-3-Fractions-Lesson.pptx). The file's contents are not. If your filenames contain something you'd rather we didn't hold — a pupil's name, for instance — rename the file before uploading it. - The marking record deliberately does not include the student's answer, any student name, or the mark awarded. It records only that a marking happened.
2.4 What we process but do not store
Some things pass through Speca and are then gone. We have checked this in the code rather than assuming it:
- PowerPoint files you upload for adaptation. The file is received in memory, its text is extracted, that text is sent to our AI provider, an adapted deck is built, and the adapted deck is sent straight back to you in the response. Neither your original file nor the adapted version is written to our database or our file storage at any point.
- Student answers you submit for marking. The answer text is sent to our AI provider with the relevant question and mark scheme, the result is returned to you, and nothing is written down.
- The resources Speca produces for you. Generated resources are returned to you as a download, or emailed to you as an attachment, and are not retained on our side.
We can state this because Speca's application code contains no operation anywhere that writes user-submitted or AI-generated content into our storage or database. The only files our storage holds are Speca's own pre-built library and taxonomy.
2.5 Technical and error data
- Sign-in cookies. Essential cookies that keep you logged in.
- Server and hosting logs. Our hosting provider records ordinary web-server information such as IP address, request time and page requested, for security and reliability, for a short period.
- Error reports. When something goes wrong, our error-monitoring tool records the error message, a stack trace, and information about the request that failed, so we can fix it. It is configured not to attach personal identifiers by default.
- No analytics or advertising cookies. Speca uses no analytics, tracking or advertising tools on the app or on the marketing landing page. (Verified 17 Sept 2026: no Facebook pixel, Google tag, or analytics script is present on either.) If we ever add one, we will update this policy and ask for your consent first.
3. Why we collect it, and our lawful basis
Under UK GDPR we must have a lawful basis for each thing we do with your data. Here they are, activity by activity.
| What we do | Why | Lawful basis |
|---|---|---|
| Create and run your account; let you log in | So you can use Speca | Contract — necessary to provide the service you signed up for |
| Send the content you choose to our AI provider and return the result | So the feature works at all | Contract |
| Email a finished resource to your own account address | It's the feature you asked for | Contract |
| Keep usage records to count your allowance | So free allowances and Pro access work correctly | Contract |
| Use those same records to spot abuse, automated misuse and runaway costs | To protect the service and keep it affordable | Legitimate interests — our interest in a secure, financially viable service, balanced against your privacy; the records are metadata only |
| Take payment and manage your subscription | So you can pay for Pro | Contract |
| Keep records of transactions for accounting and tax | Because we have to | Legal obligation |
| Send you service emails (password resets, changes to these terms, billing notices) | So you can use and control your account | Contract |
| Send you waitlist and early-access marketing emails | So you hear when Speca is ready | Consent — given when you join, withdrawable at any time |
| Record and investigate errors and security events | To keep Speca working and secure | Legitimate interests |
You can ask us for our legitimate-interests assessment for any of the rows above.
4. Special note: we do not collect pupil data
Speca is a tool for teachers. We do not knowingly collect any information from, or about, school pupils, and no pupil-level personal data is stored by the Service.
The one place a pupil's work can enter Speca at all is the AI-assisted marking feature, where a teacher pastes in a student's typed answer. As set out in section 2.4, that text is not stored — it is processed to produce the mark and then discarded. We ask teachers not to include a student's name or any other identifying detail, and our Terms require this.
If you are a teacher: you remain the data controller for your students' information, and you should follow your school's own policies on student work and AI tools.
5. Who we share data with
We use the following companies ("processors") to run Speca. We don't sell your data, and we don't share it with advertisers.
| Processor | What it does for us | What it receives |
|---|---|---|
| Supabase | Database, sign-in, and file storage (hosted in London, UK) | Your email address, your hashed password, your session, your profile record and your usage records |
| Vercel | Website and application hosting | Ordinary web request data, including your IP address |
| Anthropic | The AI models that produce and mark content | The content of the request: the topic you chose, the fixed refinement wording Speca attaches, Speca's own taxonomy or library text, the text extracted from a deck you upload, and the student answer text you submit for marking. It does not receive your name, email address or account ID |
| Resend | Sends the emails that deliver a resource to you | Your account email address, the message, and the attached file |
| Stripe | Payments and subscriptions | Your email address, your account ID, and your payment details (which you give to Stripe directly — we never see or store your card number) |
| Sentry | Error monitoring | Error messages, stack traces and request information when something fails |
| Mailchimp | Runs the marketing landing page's mailing list | Your email address, if you sign up there |
Each of these is bound to use your data only on our instructions, under their standard data processing terms which we have accepted.
On AI training: we do not use your content to train AI models. Our AI provider's commercial terms state that content submitted through its business API is not used to train its models.
6. Cookies
Speca uses only essential cookies needed to keep you logged in. We don't use marketing or analytics cookies. Because these cookies are strictly necessary to provide the service you asked for, we don't need to ask your consent for them.
7. International transfers
Our database is hosted in the UK (London).
Some of the providers listed in section 5 are based outside the UK or operate global networks, and personal data may therefore be transferred outside the UK — in particular to the United States. Where that happens, the transfer is covered by the provider's own safeguards: the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, and/or the UK Extension to the EU-US Data Privacy Framework where the provider is certified.
8. How long we keep data
| Data | How long |
|---|---|
| Your account and profile | For as long as your account is open |
| Your usage records | For as long as your account is open. They are automatically deleted when your account is deleted — the records are linked to your account so that removing it removes them |
| Content you upload or submit to the AI features | Not retained at all (see section 2.4) |
| Waitlist email addresses | Until you unsubscribe, or until we've completed the early-access rollout, whichever is sooner |
| Payment and transaction records | Six years, as required for UK tax and accounting purposes |
| Server and error logs | Short-term, as set by our hosting and monitoring providers (typically 30–90 days) |
Speca has no automated job that deletes old usage records on a schedule. They are removed when the account they belong to is deleted, and not before.
9. Automated decision-making
Speca's AI features produce content and suggested marks, but no decision with a legal or similarly significant effect on anyone is made automatically. AI-assisted marking output is a suggestion for a teacher; the teacher reviews it and decides. Speca is not used to grade students, and its output should never be recorded as a final grade without a teacher's own judgement.
10. Security
Access to your account requires your email address and password. Our database enforces row-level access rules so that a signed-in user can read their own profile and their own usage history and nobody else's, and the parts of the system that can bypass those rules run only on our servers, never in your browser. Passwords are hashed by our authentication provider, and payment details go straight to Stripe rather than through us.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours and tell you where we are required to.
11. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you, and get a copy of it.
- Correct anything that's inaccurate.
- Delete your data ("right to erasure") — deleting your account removes your profile and your usage records.
- Restrict or object to our processing, including objecting to anything we do on the basis of legitimate interests.
- Portability — receive the data you gave us in a common, machine-readable format.
- Withdraw consent at any time where we rely on consent (for example, waitlist emails — every one has an unsubscribe link).
To exercise any of these, email hello@speca.co.uk. We'll respond within one month.
If you're unhappy with how we've handled your data, you can complain to the Information Commissioner's Office, the UK's data protection regulator — though we'd appreciate the chance to put it right first.
12. Changes to this policy
We'll update this page if anything changes, and note the date at the top. If a change materially affects how we use your data, we'll tell you directly.
13. Contact
Speca Ltd · hello@speca.co.uk