Privacy Policy
Last updated: July 3, 2026
Speculos lets you publish apps you build in your own tools, such as Claude Code: you type deploy, and your app goes online at a link you can share. This policy explains what we collect, how we use it, and the choices you have.
1. What we collect
- Published apps. When you publish, your app is built on your own computer and we receive the output your tools produce for deployment — for frontend apps, a built bundle rather than your project's source files; apps with backends also include the runnable code they need to serve requests. We store and host what we receive so your link works.
- App data. If you publish an app with a backend, the data that app stores or processes lives in its isolated environment on our infrastructure. We process it only to run your app, and it is deleted with the deployment.
- Deployment details. The app's link, when it was published, and its access level. Choosing your own link name and access level is part of the Team and Enterprise plans; free-tier links can be opened by anyone who has the link.
- Account information. Your email address when you create an account, and your name, work email, and company name when you contact us about Team and Enterprise plans. On team plans, sign-in uses your work email and your admins control which email domains can join.
- Company data connections (team plans). If your admin connects a company data source, we store the connection's settings and the access rules the admin defines — which people and apps may use it. The access tokens themselves are held by Composio, not by Speculos (see Subprocessors). Data read from a connected source is processed only to serve the apps authorized to use it.
- Server logs. Standard technical logs (such as IP address and request time) when you visit speculos.ai or open a published link. Used for security, abuse prevention, and reliability.
- Website analytics. We use Google Analytics on speculos.ai to understand which pages are visited. It sets analytics cookies; you can block them in your browser or with Google's opt-out tools. This does not touch your published apps' data.
2. How we use it
- To host your published apps and serve them at their links
- To enforce the access level set for each app
- To respond when you ask about Team and Enterprise plans
- To send technical notices, security alerts, and support replies
- To detect abuse and protect the Service
- To improve the Service using aggregated, de-identified usage patterns
We do not train machine learning models on your apps or your data, and we do not sell your personal information.
3. What we don't collect
- Your project. The build happens on your computer. Your project folder — source files, history, and anything you didn't publish — stays there. We receive only the deploy output described above.
- Your credentials. Publishing frontend apps needs no account, API keys, or tokens — an account is only created when your app needs a backend — and Speculos never asks builders for keys to databases or company tools. On team plans, an admin can choose to connect a company data source; those connections run through Composio, a SOC 2 and ISO 27001:2022 compliant connector platform, which holds the access tokens — Speculos does not store your data-source credentials.
- Content for AI processing. Speculos does not send your apps or their content to any AI model. You build in your own tools (such as Claude Code) under your own agreements with those providers; Speculos only receives the result.
4. Where your apps run
Frontend apps are served as static files from our hosting. Apps with backends run in their own isolated sandbox environment. You can delete a deployment yourself at any time; when you do, the hosted copy and its environment are removed, and residual copies in logs or backups are purged within 30 days. For teams that need it, Speculos can also run inside your own cloud — in that setup your apps and their data stay on your infrastructure.
5. Subprocessors
We use a small number of vendors to deliver the Service, under agreements that limit how they may use the data.
- AWS — hosting and delivery of published frontend apps
- Daytona — isolated sandbox environments where published apps with backends run
- Cloudflare — hosting and delivery of the speculos.ai website
- Composio — connects team-plan data sources and holds their access tokens; SOC 2 and ISO 27001:2022 compliant
- Formspree — processes contact requests submitted through our form
- Google Analytics — website analytics for speculos.ai
The up-to-date list is available on request — email privacy@speculos.ai.
6. Your rights and choices
- Delete a deployment. You can take any published app offline yourself at any time — no request to us needed. Deletion works as described in section 4.
- Delete your account. Deleting your account removes your account information, your deployments, and associated logs within 30 days, except limited records we must keep to comply with law, resolve disputes, or prevent abuse.
- Access and correction. Depending on where you live, you may have rights to access, correct, port, or object to processing of your personal data. Email us to exercise any of these.
To exercise any of the above: privacy@speculos.ai. We respond within 30 days.
7. Security
Published apps are served over HTTPS, and apps with backends run in isolated sandbox environments. Publishing frontend apps requires no account, keys, or tokens, so there are no credentials to lose. Data-source access tokens for team plans are held by Composio, not stored on Speculos infrastructure. Access to production infrastructure is restricted to a small team.
8. Changes and contact
We may update this policy as the product evolves; we'll update the date above and post a notice on this site for material changes. Questions, complaints, or deletion requests: privacy@speculos.ai.