Spoonbill← Back to site
Legal

Privacy Policy

Last updated July 18, 2026

This Privacy Policy explains how Spoonbill (“Spoonbill,” “we,” “us”) collects, uses, and protects information when you use our website and application (the “Service”). Spoonbill is an AI search tool that answers questions from a city’s own publicly adopted planning documents. We keep our data practices deliberately narrow, and this policy reflects that.

The short version: the documents we index are public records. The only private information we hold is your account email and the questions your team asks. We never sell your data, and we never use it to train shared or third-party AI models.

1. Who we are

Spoonbill is currently operated as a sole proprietorship in the United States. This policy will be updated to name our legal entity once the business is formally incorporated. You can reach us about privacy at hello@spoonbill.dev.

2. Information we collect

Information you provide

  • Account information — the email address you use to sign in. We use passwordless “magic link” sign-in, so we do not ask you to create or store a password.
  • Questions and answers — the questions your team submits to the Service and the answers returned, kept as your conversation history so you can refer back to them.
  • Billing information — if you subscribe, your billing contact details and plan. Card payments are processed by Stripe; we never receive or store full card numbers.
  • Communications — information you send us by email or through support.

Information collected automatically

  • Usage and log data — basic technical information such as IP address, browser and device type, pages viewed, and timestamps, used to operate and secure the Service.
  • Cookies — we use only essential cookies required to keep you signed in and to keep the Service secure. We do not use advertising or cross-site tracking cookies.

The documents we index

To answer your team’s questions, we index your jurisdiction’s publicly adopted documents — for example your zoning ordinance, fee schedule, and adopted plans. These are public records, not personal information.

3. How we use information

  • To provide the Service: authenticate your team, answer questions from your documents, and keep your conversation history.
  • To process billing and manage your subscription.
  • To provide support and respond to your requests.
  • To maintain security, prevent abuse, and meet legal obligations.
  • To operate and improve the Service using aggregated or de-identified usage information.

What we never do: we never sell your personal information, and we never use your documents or your team’s questions to train shared or third-party AI models.

4. How answers are generated (AI processing)

When your team asks a question, the relevant passages from your own indexed documents are sent to our AI provider, Anthropic (the maker of Claude), to compose an answer grounded in those passages. Under Anthropic’s commercial API terms, your inputs and outputs are not used to train Anthropic’s models. The Service answers only from your adopted documents; it does not draw on the open web.

5. Service providers (subprocessors)

We share information only with the vendors that help us run the Service, each bound to protect it and use it only on our instructions:

  • Cloudflare — application hosting and database (United States).
  • Pinecone, on Amazon Web Services (US East) — the search index of your documents.
  • Anthropic — the AI that composes answers from your documents.
  • Railway — automation used to keep your indexed documents current.
  • Stripe — payment processing.

We keep this list current as our providers change. We do not otherwise disclose your information except to comply with the law, enforce our agreements, protect rights and safety, or as part of a business transfer, in which case this policy will continue to apply.

6. Where your data is stored

Your account information and conversation history are stored on United States infrastructure (Cloudflare), and your document index is hosted in the United States (Amazon Web Services, US East region).

7. Data retention

We keep your information for as long as your account is active and as needed to provide the Service. You may ask us to delete your account data at any time, and we will do so within a reasonable period, except where we must retain limited records to meet legal, security, or billing obligations.

8. Security

We protect your data with encryption in transit and at rest (AES-256), passwordless sign-in, access controls, and US-based hosting. No method of storage or transmission is perfectly secure, but we work to protect your information and to limit what we hold in the first place.

9. Your rights and choices

Depending on where you are located, you may have the right to:

  • Know what personal information we hold and access a copy of it.
  • Correct inaccurate information.
  • Delete your personal information.
  • Receive your information in a portable format.

Because we do not sell or share personal information for advertising, there is nothing to opt out of on that front. To exercise any right, email hello@spoonbill.dev from your account address. We will not discriminate against you for exercising your rights. California residents have these rights under the CCPA/CPRA; the categories of personal information we collect, our purposes for using it, and the providers we share it with are described in the sections above.

10. Children

The Service is intended for government and professional staff and is not directed to children under 16. We do not knowingly collect personal information from children.

11. Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide notice through the Service.

12. Contact

Questions about this policy or your data? Email us at hello@spoonbill.dev.

AboutPrivacy PolicyTerms of ServiceAccessibility
© 2026 Spoonbill