Legal
Privacy Notice
Document details
Version: 2.0 (draft). Effective date: none — this draft is not yet in effect, and nothing in it is in force. Last updated: 12 August 2026. Responsible entity: [SPHEROMNI RESPONSIBLE ENTITY — TBD]. Governing law and jurisdiction: [PRIMARY JURISDICTION — TBD]. Contact: [PRIVACY CONTACT — TBD].
Change history:
- Version 2.0 — full draft written at Milestone 19 alongside the Privacy Centre, the data export, self-serve deletion and the retention policies, replacing the one-paragraph Milestone 2 placeholder. Not in effect.
- Version 1.0 — Milestone 2 placeholder page. It made no data-processing commitments and was never in effect.
1. Who is responsible for your data
The operator of Spheromni, and the controller of the personal data described here, is [SPHEROMNI RESPONSIBLE ENTITY — TBD]. That placeholder is unresolved and blocks finalisation of this notice; until it is filled in by the owner and this document is reviewed by qualified counsel, nothing here is a legal commitment.
Spheromni is the controller for everything in this notice. It acts as a processor for nobody, and it holds no business-customer data on anybody else's behalf.
Contact for any privacy question: [PRIVACY CONTACT — TBD]. The fastest route for anything about your own account is a privacy request in Settings, under Privacy, where a member of staff writes the answer into that same window.
2. What this notice covers
It covers the Spheromni product and this website. It does not cover the identity provider you sign in with, your own Google Drive, or any external site or progressive web app you open inside a Spheromni frame — each of those is operated by somebody else under their own notice.
3. The data Spheromni holds, by zone
Spheromni sorts personal data into four zones and treats each differently. The canonical register is docs/privacy/data-inventory.md; this section mirrors it.
Zone A — your private vault
Note and document contents, file contents you store in Spheromni, calendar entries, in-workspace search activity, companion settings, and clipboard content at the moment you deliberately paste or drop it. Also three device-only classes that never leave your browser: the text of files cached for offline reading, edits you made while offline and have not yet sent, and a list of recently opened file names.
Zone A is never sold, never used for advertising, never used to train a model, and never read by staff. File contents in your connected Google Drive are not stored by Spheromni at all — they stay in your Google account.
Zone B — essential operational data
Your account record and the provider identity linked to it; your sessions; your consent receipts; workspace and window metadata; file and folder metadata (paths, versions, sync state — not content); multi-window coordination messages, which stay inside your browser; security and error events; your subscription state; your account role and any suspension and its note; support notes staff write about your account; privacy requests and the staff answers to them; the admin audit trail; and feature-flag overrides. From the controlled beta: the record that you confirmed you are an adult, the record that an invite code was redeemed for your account, and the feedback you send with any reply written to it.
Two of those deserve stating plainly. A support note is staff-only and is not shown to the person it is about, but it is still their personal data and still subject to an access request. And the admin audit trail names acts rather than people: no account identifier and no email address reaches the client in an audit entry.
Zone C — optional telemetry and error reports
Two separate opt-ins, each with its own control, its own consent record and its own purpose — turning one on does not turn the other on. Performance telemetry: startup timing and frame-rate band, and nothing else. Error reports (from the controlled beta): which of three kinds of failure occurred, the error message truncated, and the path of the page you were on — never the query string, never the fragment, and never a stack trace.
Both are off unless you turn them on, both are first-party (they go to Spheromni's own database, not to any analytics company and not to any error-reporting company), and withdrawing either consent both stops that collection and deletes every row of it already stored for your account. Error reports are additionally deleted after a fixed period, listed in section 14.
Forbidden in this zone whatever your consent says: document content, note content, message content, raw voice, clipboard content, passwords, authentication tokens, full file paths, sensitive filenames, contact lists, and unredacted error payloads containing private information.
Zone D — public and commercial activity
Your community profile, posts, replies, reactions, follows, group memberships, blocks and mutes, reports you file, moderation decisions about you and their notes, appeals, and your Community Guidelines acceptance. Also, if you apply to sell: your seller record, including the legal name and country you supply and the staff review note.
“Public” here means visible to signed-in Spheromni members who have community profiles of their own. There is no unauthenticated community surface and no search engine sees any of it. An account with no community profile does not appear in this zone at all. Blocks and mutes are private to whoever set them.
4. Where the data comes from
From you, when you write, upload, configure or post something. From your identity provider, when you sign in. From your storage provider, when you connect Drive. And from the service itself, as a by-product of running it — session records, timestamps, audit entries and error events.
Spheromni buys no data, receives no data from data brokers, and enriches nothing from third-party sources.
5. Why each category is processed
Zone A is processed only to give you the application functionality you asked for — to show you your file, to save your note, to answer your search.
Zone B is processed to authenticate you, to keep your account and workspace working, to secure it, to prove and honour your consent choices, to answer your data requests, and to hold staff accountable for acts on accounts.
Zone C is processed to measure and improve performance, and to know that failures are happening and roughly where — each only with the matching consent.
Zone D is processed to publish what you chose to publish, to moderate the community, to keep evidence for a moderation review, and to decide a seller application.
A full processing-purpose map is maintained in docs/privacy/data-inventory.md.
6. Legal bases
The legal basis for each category is [LEGAL BASIS FRAMEWORK — TBD BY COUNSEL], because the framework depends on [PRIMARY JURISDICTION — TBD], which is unresolved. The engineering position recorded in the data inventory, for counsel to confirm or correct, is: Zone A and most of Zone B as necessary for the contract; audit trails, consent receipts and privacy requests as legal obligation; security events as legitimate interest; Zone C as consent; Zone D as necessary for the contract you enter by opting in, with moderation evidence as legitimate interest.
7. Essential processing and optional processing
Essential processing is what running your account is: the account record, the identity link, sessions, consent receipts, file and workspace metadata, audit and security records. It has no toggle, because a toggle that would break the service if used is not a choice. The way to withdraw from it is to delete your account, which you can do yourself.
Optional processing has a real control, and withdrawing is exactly as easy as granting: performance telemetry, error reports, the Google Drive connection, and community participation. Each is separate; none is bundled with another or with the Terms. Nothing is pre-selected anywhere.
8. Third parties and subprocessors
Four, and no others. Neon hosts the database. Render hosts the application. Google, GitHub, Apple and LinkedIn act as identity providers when you choose one to sign in with — they receive only the sign-in request and return an identifier, your email address and, where available, a name and avatar. Google also acts as a storage provider if, and only if, you connect your own Drive.
The current register is on the Subprocessor List, mirroring docs/privacy/data-inventory.md, which remains canonical.
There is no payment processor. Payment is not activated, no billing provider is configured, no card details are asked for or held anywhere, and no charge has ever been made. That is a fact about the build rather than an omission from this list. If payment is activated after commercial and legal review, a payment processor becomes a subprocessor and this notice changes with it.
There are no analytics providers. The only measurement in the product is the first-party performance telemetry in Zone C, which is off unless you turn it on and goes to Spheromni's own database. No analytics SDK, tag manager or session-replay tool is loaded on any page.
There is no advertising. No advertising network, no ad pixel, no conversion tracking, no audience list, and no sale or sharing of personal data for advertising purposes — by any definition, including the broad ones that treat cross-context disclosure as a sale.
9. AI processing
None. No machine-learning model, no large language model and no AI service is used anywhere in this product. The companion character is deterministic code driven by explicit seeds; it holds no memory of your content and performs no inference. Nothing you store or write is sent to an AI provider or used to train a model, by Spheromni or by anyone else.
10. Voice processing
Voice is push-to-talk and off until you hold the talk control. Spheromni does no speech recognition of its own: it uses your browser's built-in recognition and receives only the resulting text. No audio ever reaches Spheromni — there is no microphone recording, no audio file, and no audio stream anywhere in the build.
The exception is stated because it is real: your browser may transmit the audio to its own vendor's speech service in order to transcribe it. That is a property of your browser, outside Spheromni's control, and the Voice window discloses it whenever the feature is available.
Voice history, when you enable it, is stored in your browser on your device under a local key and is never sent to Spheromni.
11. Community and marketplace processing
Joining the community publishes a profile you create for that purpose — a handle, display name, bio and avatar preset that are separate from your account identity. Your email address and account identifier never appear in the community.
Reporting content stores a snapshot of that content as moderation evidence, so a review survives a later edit or deletion. Moderation decisions and their notes are stored and shown to the affected profile and to nobody else. Applying to sell stores the seller name, legal name and country you provide, read by staff holding the seller-review permission, shown in no public place and destroyed with the account.
12. Security and fraud processing
Session records, security and error events, and the admin audit trail exist to keep accounts and the platform secure and to make staff acts accountable. Community posting is rate-limited, but no counter is stored for it: the limit is applied by counting your own posts from the past day inside the write itself, so there is no separate record of your activity anywhere. There is no fraud-scoring system, no device fingerprinting, no risk model and no third-party fraud service — the honest list is short because the build is.
13. International transfers
The transfer position is [INTERNATIONAL TRANSFERS — TBD BY COUNSEL]. Neon, Render and Google operate infrastructure across regions, and which transfers occur and which mechanism covers them cannot be stated until [PRIMARY JURISDICTION — TBD] is resolved and the deployment regions are fixed. It is an open item in docs/legal/legal-review-issues.md rather than an answered question written vaguely.
14. How long data is kept
Zone A is kept until you delete the item or your account. Zone C is kept only while your consent is active and is deleted on withdrawal. Zone D is kept for as long as the content is published, subject to your own deletion of it. Zone B is kept for the operational or security purpose it serves.
The retention rules below are enforced by a sweep an administrator runs. These periods are engineering drafts pending counsel:
- Sessions that expired or were revoked more than 30 days ago are deleted; until then they remain for security review.
- Account-link requests that expired more than 7 days ago are deleted.
- Performance telemetry older than 180 days is deleted even while consent remains active.
- Share invitations that were accepted, declined or revoked more than 30 days ago are deleted, removing the invitee email they carry. A still-pending invitation has no expiry in this product and is never deleted by the sweep.
- Error reports older than 30 days are deleted even while consent remains active. Withdrawing error-telemetry consent deletes them immediately, and deleting the account removes them with it.
- Workspace memory snapshots are deleted once they are older than the retention period you chose for memory (30, 90 or 365 days; 90 if you have never chosen), and in every case once they are older than 365 days. The windows recorded in a snapshot are deleted with it.
- Notifications older than 90 days are deleted regardless of their state — unread, read or dismissed alike.
The sweep is on-demand: there is no automatic schedule in this build, and the administration window says so rather than implying a nightly job that does not exist. Everything not covered by one of those rules is kept for the life of the account and deleted with it — including beta feedback, which has no age-based sweep in this release and is deleted with the account.
15. Deleting your data
You can delete your account yourself, immediately, from Settings under Privacy. It takes the account and every cascade with it: files and folders, installed applications, community profile with its posts and replies, consent history, sessions and privacy requests. There is no recovery window, no grace period and no backup copy. What survives is one audit row saying an account was deleted, with nothing in it that identifies you.
One consequence is recorded here rather than left implicit: after a deletion, Spheromni holds no consent receipt for that person, because the consent records go with the account. That was a deliberate choice — erasure that leaves a consent history behind is not erasure — and it is flagged for counsel.
Two kinds of account are refused self-deletion with the reason stated: the platform's super administrator, and an account holding a seller record. Both are directed to the staff-reviewed deletion request in the same window, which reaches the same outcome after a person has looked at it.
16. Safeguards
Session tokens are stored hashed and never leave the server in a form that could be replayed. Storage-provider credentials are encrypted at rest and are never exported, logged or shown. Every page is served under a strict content security policy that admits no third-party script. Access to production data by staff is limited to the explicit permissions their role holds, and every staff act on an account is written to the audit trail in the same database operation as the act itself. Staff have no surface anywhere in this product that can read a user's files.
Two limits are stated rather than glossed: there has been no independent penetration test, and there are no backups you could be restored from.
17. Your rights
Subject to the law of the jurisdiction finally chosen, you can expect rights of access, portability, correction, erasure, restriction, objection, and withdrawal of consent. What Spheromni already gives you without asking anyone:
- Access and portability — download everything Spheromni holds about your account as a single JSON file, from Settings under Privacy.
- Erasure — delete your account yourself, immediately.
- Consent withdrawal — a control per optional purpose, in the same place you granted it.
- Session control — see every active session and sign the others out.
- Correction, restriction and objection — file a privacy request in Settings; a person reads it and answers in writing, in that window.
Response deadlines, the identity-verification standard for a request, and the grounds on which one may be refused are [DATA REQUEST PROCEDURE — TBD BY COUNSEL] and are open items. Spheromni sends no email, so every answer is delivered in your Settings window and nowhere else.
18. Withdrawing consent
Withdrawal is as easy as granting, in the same place, with no persuasion and no extra step. Performance telemetry: turn it off in Settings under Privacy, or on the account page — collection stops and every stored row for your account is deleted. Community Guidelines: withdraw in Settings; your account and existing posts remain, and new posting is blocked until you accept again. Google Drive: disconnect in Settings; the stored access grant and the cached Drive metadata are deleted.
19. Complaints
Write to [PRIVACY CONTACT — TBD] first. You also have the right to complain to a supervisory authority; which authority, and on what terms, is [SUPERVISORY AUTHORITY — TBD BY COUNSEL] and depends on [PRIMARY JURISDICTION — TBD].
20. Children
Spheromni is adults-only in this release. There are no child or family accounts, no age-appropriate mode and no parental consent mechanism, so it is not offered to anyone under the age of majority. Spheromni collects no date of birth and performs no age verification, so the restriction is stated and unenforced — that is the honest description, and an age-assurance mechanism is an open item for counsel.
21. Automated decision-making
There is none. No profiling, no scoring and no automated decision producing a legal or similarly significant effect happens anywhere in this product. Every moderation decision, every seller decision, every role change and every privacy-request answer is made by a person, and the product carries no automated enforcement at all.
22. Cookies and local storage
Spheromni sets two cookies, both strictly necessary, and stores several things in your browser that never leave your device. There are no advertising cookies and no third-party analytics cookies. The full list, with purposes and lifetimes, is in the Cookie Notice.
23. Changes to this notice
Changes are recorded as a new version in the change history above. Note the honest limit: this build sends no notice of a change and has no re-acknowledgement flow for one. Both are tracked open items that must exist before this notice is put into effect.
24. Contact
[PRIVACY CONTACT — TBD], or a privacy request in Settings under Privacy — which is faster, and is where the answer will appear.