Privacy
How Spatia handles information
Learn what information Spatia collects, how place reports and account data are used, when service providers receive information, and how to make a privacy request.
Effective date and scope
September 8, 2026. This policy describes the information practices of Spatia at runspatia.com and the services used to create, store, purchase, and share Spatia reports. It does not govern a third party's own website or service.
Information Spatia collects
- Account information: the account identifier, email address, display name, and profile image returned through Google sign-in, plus account tier, entitlements, and credit balance.
- Session information: signed session and OAuth-state cookies used to sign you in, protect the sign-in flow, and return you to the requested page.
- Report inputs and results: typed and resolved addresses, coordinates, questions, recent conversation context, clarifications, stated or inferred role and intent, assumptions you provide, selected model settings, report findings, verdicts, citations, and map evidence.
- Service activity and diagnostics: report and run identifiers, timestamps, token usage and cost records, query and tool events, coverage gaps, disputes, failures, logs, and security-related events. These records can include an address or question from a run.
- Purchase information: the email, account identifier, credit pack, amount, currency, payment status, refund state, and Stripe Checkout, payment-intent, and event identifiers associated with a purchase. Stripe handles payment-card details; Spatia does not receive the full card number.
- Device and network information: request metadata such as IP address, browser or device type, referring page, pages visited, timing, and performance information produced by hosting, security, and analytics systems.
- Communications: messages and attachments you send to support, privacy, or legal addresses, plus information reasonably needed to verify and answer a request.
- Public-source and provider facts: geographic, property, environmental, and other facts retrieved from cited public sources or configured data providers for the place you ask about. A public source does not make the resulting address-specific report public by default.
How Spatia uses information
- Authenticate accounts, keep sessions working, and provide account entitlements.
- Resolve a place, understand the question, run relevant analysis, create and store a report, and recover a completed run after a connection interruption.
- Meter report usage, sell and grant credits, issue receipts, process refunds or disputes, and maintain financial records.
- Operate, secure, debug, and improve the service; investigate incorrect findings and coverage gaps; and measure reliability and performance.
- Respond to communications, enforce service rules, prevent abuse, protect users and the service, and meet legal obligations.
- Publish or submit a report for discovery only when the report owner makes the choices described below.
AI, address lookup, and research providers
To create a report, Spatia may send the exact typed or resolved location, your question, recent conversation context, inferred intent or role, summarized analysis results, and report records to one or more configured AI providers: Google Gemini, Anthropic, or OpenAI. Different report stages can use different providers. Spatia's report safeguards keep bulk source rows and GeoJSON out of the model conversation, but they do not keep your address or text away from the configured AI providers.
Address text may also be sent to Spatia's geocoding and autocomplete services. When relevant features are configured and used, an exact address or a research query may be sent to providers such as RentCast or Brave Search, and Spatia may retrieve pages from cited source websites. These providers process information under their own terms and privacy practices.
Service providers may process information in the United States and other countries where they or their subprocessors operate. Laws and protections can differ by location.
When information is disclosed
- Cloudflare provides hosting, delivery, security, compute, database, object-storage, and optional web-analytics services.
- Google supports sign-in; Google Gemini, Anthropic, or OpenAI may process report prompts depending on the configured model route; Stripe provides hosted checkout and payment services; and lookup or research providers perform the requests described above.
- Your browser requests the site's Inter stylesheet and font files from Google Fonts. When you view an evidence map, it may also request map-label glyph assets from Protomaps' GitHub-hosted asset service and basemap tiles from Spatia's Cloudflare-hosted tile service. These requests expose ordinary network and device metadata to the service receiving them.
- Information may be disclosed when reasonably necessary to comply with law or valid legal process, protect rights or safety, investigate fraud or abuse, or secure the service.
- Information may be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the service, subject to applicable notice requirements.
- Report content is disclosed to the public, or submitted to search engines or AI discovery systems for publication, only through the report-publication choices described below or when you otherwise direct Spatia to disclose it. This is separate from private-report processing by the lookup and research providers described above.
Private, shared, and discoverable reports
A completed report is private by default and available through owner-scoped account access. If you choose link sharing, anyone with the public link can view the resolved address, findings, sources, verdict, and map evidence without signing in. The public version removes the raw typed input and internal intent or persona fields, but its verdict can still reflect the context of the original request.
Requesting search and AI discovery is a separate choice from link sharing. The report must also pass Spatia's publication checks before its URL can enter the sitemap or be submitted through services such as IndexNow. Search engines and other systems decide how they crawl, cache, display, archive, or reuse public material.
You can make a report private from the report page; after Spatia's caches update, Spatia stops serving it through the public link. You can instead withdraw only the discovery request while keeping the public link usable; this removes Spatia's discovery submission but does not make the report private. Neither choice can guarantee deletion from browser or CDN caches, search results, archives, previously downloaded copies, or third-party AI systems. Contact privacy@runspatia.com for help with a removal request.
Cookies, analytics, and tracking choices
Spatia uses a signed, HttpOnly session cookie. The session token generally expires after 24 hours, while the browser cookie can remain for up to 30 days; signing out clears it. A separate OAuth-state cookie lasts up to 10 minutes. Theme preference may be stored in your browser. Blocking required cookies can prevent sign-in and account features from working.
When enabled, Cloudflare Web Analytics measures page use and performance. Cloudflare and other infrastructure providers also process ordinary request and security metadata. Spatia does not use third-party advertising cookies and does not currently sell personal information or share it for cross-context behavioral advertising.
Spatia does not currently change service behavior in response to the legacy browser Do Not Track signal. Because Spatia does not currently sell personal information or share it for cross-context behavioral advertising, a Global Privacy Control signal does not change those practices. Spatia does not authorize third parties to track activity on Spatia over time and across unrelated services for advertising; providers such as Google or Stripe may independently collect information when you interact with their services under their own policies.
Retention
There is no single retention period for every category. Session credentials use the expirations described above. Diagnostic run traces are count-limited per account rather than deleted on one fixed schedule. Completed reports, report evidence, usage records, purchase records, disputes, and operational telemetry do not all have an automatic expiration and may remain until removed through an operational process.
Spatia evaluates verified deletion requests and may retain information needed to complete a transaction, keep financial, security, or publication records, resolve disputes, prevent fraud or abuse, enforce agreements, document publication choices, or meet legal obligations. Withdrawing publication is separate from deleting the underlying account record, report, or evidence object.
Your choices and privacy requests
You can sign out, decline to buy credits, avoid submitting information you do not want processed, and keep reports private. Report owners can separately enable or withdraw link sharing and search/AI discovery requests.
Email privacy@runspatia.com or write to the address below to ask whether Spatia holds information about you, request access to it, correct it, request deletion, or ask about its use or disclosure. Depending on where you live and whether the relevant law applies, you may have additional rights. Spatia may request enough information to verify your identity and authority before acting, and legal exceptions may apply. Spatia will not treat you differently for making a good-faith privacy request, except where a requested deletion or restriction makes a feature impossible to provide.
Security
Spatia uses safeguards that include HTTPS, signed HttpOnly and Secure cookies in production, short-lived session tokens, private-by-default reports, owner-scoped access checks, and access-controlled report evidence. No internet service can promise absolute security. Please contact privacy support if you believe your account or report information has been exposed.
Children
Spatia is not directed to children under 13. If you believe a child under 13 submitted personal information to Spatia, contact privacy@runspatia.com so the situation can be reviewed and appropriate action taken.
Changes to this policy
Spatia may update this policy as the service or its practices change. The effective date at the top will change when the policy changes. For a material change, Spatia will provide additional notice where appropriate, such as a prominent site or account notice, before the change takes effect when required.
Contact
Privacy requests: privacy@runspatia.com. Operator and business correspondence address: Zhaoting Zhou, 1752 E Lugonia Ave, Ste 117 #1488, Redlands, CA 92374, US.