Privacy policy
SpamSpike connects to two accounts full of other people's data. This says precisely what it reads, what it keeps, and what it cannot see.
Controller
The entity named above is the data controller for your account with us. For the marketing data SpamSpike analyses on your behalf, you are the controller and we act as your processor.
What we hold about you
- Your identity. The Google account email and profile name you sign in with. There is no password: we never see or store one.
- Your licence. The email that paid, the amount, the currency and the date. Card details never reach us — Stripe handles payment and we only receive the outcome.
- Your connections. OAuth tokens for Google and your Klaviyo API key, encrypted with AES-256-GCM before they are written down. They are never returned to a browser, and revoking either from Settings deletes them.
- Your settings. Tracked domains, alert destinations, and the fixes you have marked done.
What we read from Google and Klaviyo
Aggregate reporting only, and only for the accounts you connect:
- Google Postmaster Tools: per-domain, per-day spam rate, authentication results, IP reputation and Feedback-Loop identifiers. Google publishes these as aggregates — no message and no individual Gmail user is identifiable in them, and Google withholds them entirely below its own volume threshold for exactly that reason.
- Klaviyo: campaign, flow, segment and list metadata — names, subject lines, preview text, send times — and aggregate metrics such as delivered, opened and complaint counts, grouped by audience and by mailbox provider.
What we never touch
- No inbox. The Google connection has no mail scope and could not read a message if asked.
- No individual recipient. We do not fetch, store or process your subscribers’ email addresses, names or profile fields.
- No sending. The Klaviyo key is used for reading reports. SpamSpike cannot send, schedule, edit or delete anything in your account.
Why we are allowed to
We process your account and licence data to perform the contract you entered into by buying a licence. We process the connected marketing data on your instructions, as your processor, for the sole purpose of producing the analysis you asked for. We do not sell data, do not use it to train models, and do not use one customer’s data to serve another.
Where it lives
Each customer’s data sits in a separate encrypted store, keyed to their own sign-in address, and every request is resolved to that store before anything is read. Our processors are Vercel (hosting, EU and US regions), Neon and Vercel Blob (storage), Stripe (payments, as merchant of record), Google and Klaviyo (the sources you connect), and Resend for alert email once you enable it. Each is bound by its own data-processing terms.
How long
For as long as your workspace exists. Deleting your workspace from Settings → Delete data erases the connections, the synced data and the settings. We keep the licence record itself — the email, amount and date — because it is a financial record we are required to retain, and because it is what lets you sign back in later.
Your rights
You can ask for a copy of what we hold, ask us to correct it, or ask us to delete it. Most of that is already a button in Settings; for the rest, write to denas.kulinicius@gmail.com and we will answer within 30 days. If you think we have handled your data badly you can complain to your national data protection authority.
Cookies
One session cookie so you stay signed in, and nothing else. No advertising trackers, no third-party analytics, no consent banner — because there is nothing to consent to.