Privacy Controls

Your data, your rules

Spun gives you granular control over what data is stored, processed by AI, and shared with other organizations. Every privacy feature, explained in one place.

Our commitments

Four privacy principles, always on

These aren't toggles — they're how Spun is built.

We never train AI on your data

Your messages, contacts, and conversations are never used to train AI models — not ours, not OpenAI's, not anyone's. AI providers process your data on a per-request basis only.

Per-org data isolation

Every organization's data is isolated at the database level using row-level security (RLS). Even if a query is mistakenly written without an org filter, the database refuses to return cross-org rows.

You own your data

Delete individual messages, purge contacts, wipe your entire database, or close your account at any time. All data deletion is irreversible and completes within 30 days at most.

Encrypted in transit

All communication between your browser, our servers, WhatsApp, and AI providers is encrypted with TLS. Payment processing is handled by Stripe — we never see or store your card numbers.

Privacy presets

Choose how much of your data reaches AI providers

Three preset levels balance AI quality against data minimization. Switch any time — switching to Maximum also purges existing search embeddings.

Maximum

The strictest setting. Zero personal data leaves your server.

  • Full PII redaction for chatbot, Weave, summaries, classification
  • Translation disabled
  • Search embeddings disabled
  • Switching here purges existing embeddings
Recommended

Balanced

Default. Full redaction for AI services, partial for search.

  • Full PII redaction for chatbot, Weave, summaries, classification
  • Translation active with financial-data-only stripping
  • Search embeddings active with financial-data-only stripping
  • Best balance of privacy + features

Full AI

Best AI quality. No name/phone/email/ID redaction.

  • No PII redaction for chatbot, Weave, summaries, classification
  • Translation active
  • Search embeddings active
  • Credit cards & secrets always stripped from embeddings

AI privacy controls

Every AI feature can be disabled — globally, per-service, or per-message-type. PII redaction strips sensitive data before any AI provider sees it.

Master AI kill switch

One toggle disables every AI feature at once — compose, smart replies, translation, transcription, summaries, chatbot, intent classification. AI is fully off until you re-enable it.

Per-service PII redaction

Choose how much personal information is stripped before each AI service processes a message. Set different levels for the chatbot, Weave Q&A, contact summaries, intent classification, translation, and search embeddings.

3 privacy presets

Maximum (no data leaves your server — translation and search disabled), Balanced (full redaction for AI, financial-data-only for search/translation), or Full AI (best quality, only credit cards & secrets masked).

Recommended: Balanced

Disable individual AI features

Granular per-feature toggles for compose, improve, summarize, smart replies, translation, OCR, classification, audio transcription, voice chatbot, voice translation. Turn off only what you don't want.

AI content logging toggle

Turn the audit trail of AI requests and responses on or off. When on, admins can review every AI interaction. When off, prompts and outputs are not retained beyond the request.

Purge search embeddings

Switching to Maximum privacy purges all search indexes (contact embeddings, conversation chunks, knowledge base). One-click delete of every vector previously generated from your messages.

What gets redacted

Our PII detector finds and masks sensitive data before it leaves your server. Multi-language, script-aware, with keyword + pattern matching.

Names & identities

Personal names, honorifics, and identity introducers are detected and masked. Smart stoplist prevents masking common greetings and titles in 10 language groups.

Phone numbers

International (E.164) and local phone formats including UK (07XXX), Brazil ((XX) XXXXX-XXXX), India (6-9XXXX XXXXX), Germany (0XXX-XXXXXXX), Israel, US, and more.

Emails & addresses

Email addresses and physical/postal addresses in multiple scripts (Latin, Hebrew, Arabic, Cyrillic, Devanagari) are detected via keyword + script-aware boundary patterns.

National IDs & passports

Country-specific ID numbers: Israel teudat zehut, US SSN, Spanish DNI, Brazilian CPF/CNPJ, Indian Aadhaar, UK NIN, German Steuer-ID, Turkish TC Kimlik, plus passport numbers (letter-prefix + bare-digit formats).

Financial data

Credit card numbers (Luhn-validated), bank account/IBAN numbers, routing numbers, payee details, and secrets. Even in Maximum-quality mode, financial data is always stripped from search embeddings.

10 language groups

PII detection works in English, Hebrew, Spanish, French, Portuguese, Arabic, Russian, German, Italian, and Turkish. Tested with 136+ multi-language test cases.

Data storage controls

You decide what is saved, how long, and when to wipe it. Every deletion feature affects only Spun's database — your WhatsApp is never touched.

Pause data storage

Stop saving new messages to our database. Messages still appear in real-time during your session but are not persisted. Refresh the page and unsaved messages are gone. WhatsApp itself is untouched.

Max messages per chat

Set a hard limit on stored messages per chat (10–5000, or 0 for unlimited). When a chat exceeds the cap, oldest messages are automatically pruned from our database.

Purge old messages

Keep only the last N messages per chat (10–1000+). Older messages are permanently deleted from our database. You can always re-import recent media (up to 30 days) and text from WhatsApp later.

Export your data

Download a machine-readable export of your messages, contacts, and organization data at any time. Fulfils GDPR data-portability rights directly from your settings — no email request needed.

Purge all contacts

One-click delete every imported contact from our database. WhatsApp contacts remain on your phone untouched — you can re-import any time.

Delete all data + pause storage

Nuclear option: wipe every message, media file, conversation, and contact from our database AND pause new storage. Confirmation required. WhatsApp untouched.

Delete account (email-confirmed)

Permanently delete your organization account and all associated data. A confirmation code is sent to your registered email — you must enter it to proceed. Action is irreversible.

Cross-organization privacy

Your org's data never leaks to other Spun organizations without explicit, two-sided consent. Connection requests and shared tasks require mutual opt-in from both org admins.

Cross-Org Messaging toggle

Off by default. Controls whether your team can reply in accepted DM threads with users from other organizations. Both orgs must enable it for any cross-org communication to happen.

Cross-Org Connection Requests

Off by default. Controls whether your users can send or receive connection invites to/from other organizations. Required before any cross-org DM is possible.

Cross-Org Task Sharing

Off by default. Controls whether tasks in your org can be shared as guest invitations with connected users in other orgs. Guests see only the task discussion thread, not your projects or other org data.

No-existence-leak protection

Connection requests always return identical success regardless of whether the target user exists, is in your org, or has already blocked you. Prevents using the API to probe whether an email or phone is on Spun.

Phone discoverability toggle

Verify your phone for Spun Chat without becoming discoverable. Off by default — your phone number cannot be used to find your account unless you explicitly turn discovery on.

Keep contact internal

Per-contact preference: when on, outbound messages route via Spun Chat only and WhatsApp sends are hard-blocked at the server level until you explicitly change it. UI cannot override.

Rate-limited invites

5 connection requests per day, 20 per month, max 3 concurrent pending — to prevent spam, abuse, and reduce ban risk on the underlying messaging providers.

Block list

Block individual users from initiating DMs or task invitations with you. Blocked users see normal "delivered" UI but messages never reach you. Bidirectional — they can't reach you and you can't accidentally send to them.

Display & team monitoring

Control what is visible inside your inbox and what team-level monitoring features are active. Defaults to ON for productivity features — turn off any you don't want.

Hide chat avatars

Remove profile pictures from chat lists for a cleaner, more private view in shared workspaces. No avatar data is rendered to the DOM when off.

Hide WhatsApp status

Disable WhatsApp status/stories entirely. Status posts never appear in the app and all status-related processing is skipped — no thumbnails, no view tracking, nothing.

Manager Dashboard opt-out

Disable named per-user performance metrics that are otherwise visible to organization managers. Once off, managers see aggregated team metrics only — no individual attribution.

Peer Leaderboards opt-out

Disable team performance rankings visible to team members. Removes all ranked lists, scoreboards, and competitive UI from the inbox.

Working Circle opt-out

Disable the inferred collaboration graph that maps who works with whom based on shared tasks, mentions, DMs, and handoffs. Stops the graph from being computed or displayed.

Affiliate Network Visibility

For affiliate partners: toggle whether your aggregate metrics (org name, status) are visible to the referral partner who introduced you to Spun.

Sprint (Focus Mode)

Time-boxed focus session that suppresses push notifications, SSE-triggered UI refreshes, and alarm sounds. Your activity during the sprint is private to you — no metrics broadcast to managers.

Admin access & audit

Limit which team members can see what. Permissions are enforced server-side, not just hidden in the UI.

Granular admin permissions

22 separate permission keys covering every admin panel page. Each key supports three access levels: none, read-only, or read-write. Server-side enforcement — not just UI hiding.

Preset admin roles

Five built-in roles — Affiliate Support, Customer Support A, Customer Support B, Financial, Tech Support — for common access patterns. Or customize each permission individually.

Team member role restrictions

Org users without manager role cannot access plans, billing, AI tokens, storage controls, dashboard, contacts CRM, or campaigns. Read-only inbox role disables the message composer entirely.

AI Logs audit trail

Optional log of every AI request/response across your organization. View, search, and export. Disabled = no AI content retained beyond the request.

Infrastructure & compliance

Under the hood: how we protect your data even when you're not actively managing settings.

TLS encryption everywhere

All traffic — browser ↔ Spun, Spun ↔ WhatsApp providers, Spun ↔ OpenAI, Spun ↔ Stripe — uses TLS 1.2+ in transit.

Row-level security at DB level

PostgreSQL row-level security (RLS) enforces org isolation on every query. Even direct database access through our code is gated by org context — cross-org leakage is structurally prevented.

No card data stored

Payment processing is handled end-to-end by Stripe (PCI-DSS Level 1 compliant). We receive only an opaque customer ID — never card numbers, CVCs, or expiry dates.

EU data center + global edge

Application servers and database in Hetzner Nuremberg (Germany, EU) — a single data tier. Marketing site and media (images, video, files) served globally from Cloudflare's edge network and R2 object storage.

Regional proxy relays (EU + US)

Self Proxy WhatsApp traffic is carried by Spun-operated relay servers in Nuremberg, Germany (EU) and Manassas, Virginia (USA) — your connection uses the relay closest to your computer. Relays forward encrypted traffic in real time and store nothing.

WhatsApp itself is never modified

Every data-deletion feature on Spun affects only Spun's database. Your WhatsApp account, messages, and contacts always remain on your phone and WhatsApp's servers, unaffected.

Plan-based retention limits

Free trial: 30 days. Basic: 90 days. Pro: 1 year. Power: unlimited. Older messages are automatically pruned. Account deletion removes or anonymizes all personal data within 30 days.

Where to find these settings

Inside the Spun inbox, open Settings from the left sidebar:

  • Safety & Privacy tab — master AI kill switch, PII redaction presets, data storage controls, account deletion, privacy controls for cross-org & monitoring features.
  • AI tab — per-feature AI toggles, AI content logging, context presets, model preferences.
  • General tab — display preferences, chat avatars, status visibility.
  • Admin Privileges page (platform admins only) — manage granular permission keys and preset roles for team admins.

Try Spun with privacy built in

Start with the Balanced preset (recommended) and tune any setting to fit your team.

Questions about a specific feature? Email [email protected].