Legal

Privacy Policy

Last updated: April 16, 2026

1. Introduction

GMH Labs LLC, doing business as Spooled (“Spooled,” “we,” “us,” “our”) operates the Spooled behavioral testing platform, including the SDK, CLI, hosted dashboard, API, and this website (collectively, the “Service”). This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.

2. Content-Blind Architecture

Spooled captures execution structure — not call content. Prompt text, LLM response text, tool argument values, and tool output values are stripped at the SDK level before storage or transmission.

The SDK transmits structural metadata including: agent identifiers, tool function names, output field key names (not values), interaction types, sequence numbers, latency measurements, token counts, tags, session identifiers, and git branch names. These labeling fields should not contain personally identifiable information. See our Privacy Architecture documentation for a complete enumeration.

3. Data We Collect

3a. Website Visitors

When you visit spooled.ai, we collect minimal data necessary to serve the website. We do not use cookies, analytics scripts, or third-party tracking tools. Server logs may contain IP addresses, browser user-agent strings, and page URLs, which are retained for up to 30 days for security and debugging purposes.

3b. SDK and CLI Users (Free Tier)

On the Free tier, all data stays on your infrastructure. The SDK writes structural trace files to your local filesystem (.spooled/traces/). No data is transmitted to Spooled servers. We do not collect telemetry, usage metrics, or crash reports from the SDK unless you explicitly opt in.

3c. Paid Service Users (Pro Tier)

When you use the hosted Spooled service, we collect and process:

  • Account information: email address, organization name, API keys (stored as SHA-256 hashes, not plaintext)
  • Structural trace metadata: agent IDs, tool names, interaction types, sequence numbers, latency, token counts, error codes, fingerprint hashes, output field key names
  • Baseline data: behavioral fingerprints, intent summaries, run statistics
  • CI report data: comparison results, policy outcomes, signal detections
  • Billing information: processed by Stripe. We do not store credit card numbers.

We do notcollect: prompt content, LLM response text, tool arguments, tool output values, PII from your end users, or any data classified as “content” by the SDK’s stripping architecture.

4. How We Use Your Data

We use the data we collect to:

  • Provide, maintain, and improve the Service
  • Compare agent behavioral fingerprints against baselines
  • Detect behavioral drift and generate CI reports
  • Process payments and manage your account
  • Respond to support requests
  • Comply with legal obligations

We do not sell your data. We do not use your structural metadata to train machine learning models. We do not share your data with third parties except as described in Section 6.

5. Data Retention

Structural trace data is retained for 90 days on the Pro tier. Baseline and CI report data is retained for the duration of your subscription. Account information is retained until you request deletion. Server logs are retained for up to 30 days.

You may request deletion of your data at any time by contacting hello@spooled.ai. We will delete your data within 30 days of a verified request, except where retention is required by law.

6. Third-Party Services

We use the following third-party services:

  • Stripe: payment processing. Stripe’s privacy policy applies to payment data.
  • AWS: infrastructure hosting (DynamoDB, Lambda, S3). Data is processed in the US.
  • Vercel: website hosting for spooled.ai.
  • Clerk: authentication for the hosted dashboard. Clerk processes your email address and OAuth tokens. Clerk’s privacy policy applies to authentication data.

We do not use analytics services, advertising networks, or data brokers.

7. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: request a copy of the data we hold about you
  • Correction: request correction of inaccurate data
  • Deletion: request deletion of your data
  • Portability: request your data in a machine-readable format
  • Objection: object to processing of your data
  • Restriction: request restriction of processing

To exercise any of these rights, contact hello@spooled.ai. We will respond within 30 days.

California Residents (CCPA)

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. You have the right to know what data we collect, request deletion, and opt out of sale (though we do not sell data). Contact us at the email above to exercise these rights.

8. Cookies

The Spooled website does not use cookies for tracking or analytics. We may use essential cookies for session management if you are logged into the hosted dashboard. No third-party cookies are set.

9. International Data Transfers

If you are located outside the United States, your data may be transferred to and processed in the United States where our servers are located. By using the Service, you consent to this transfer. We take reasonable measures to protect your data during transfer.

10. Children’s Privacy

The Service is not directed to children under 13. We do not knowingly collect personal information from children. If we learn we have collected data from a child under 13, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised “Last updated” date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact

For questions about this Privacy Policy or to exercise your data rights, contact us at hello@spooled.ai.

GMH Labs LLC, d/b/a Spooled

OpenAI, Anthropic, LangChain, LlamaIndex, AutoGen, GitHub, Datadog, and other product names mentioned on this site are trademarks of their respective owners. Spooled is not affiliated with or endorsed by these companies.