Privacy Policy
Updated: 17 September 2026
Spegla is built in Germany and available worldwide. This Privacy Policy explains what data we process when you use Spegla, why we process it, who we share it with, where it is stored, and what rights you have. We follow the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications and Digital Services Data Protection Act (TDDDG, formerly the TTDSG).
Spegla is deliberately small. There is no advertising, we sell nothing to anyone, and we ask for as little as the product needs: an email address to sign in with, and what you type into the checker. There are no payments yet. You can delete your account yourself, in one click, and it is gone immediately.
Two things did change recently and this policy now says so plainly: Spegla has user accounts, and signing in sets two cookies. Section 4 explains exactly which ones and why.
If anything here is unclear, write to support@laddro.com and a person will read it.
1. Who we are
The data controller responsible for processing personal data under Article 4(7) GDPR is:
Laddro Digital UG (haftungsbeschränkt) Belziger Str. 69 to 71 10823 Berlin, Germany Handelsregister: HRB 285589 B, Amtsgericht Charlottenburg Managing Director: Oussama Bentaib Email: support@laddro.com
We have not appointed a Data Protection Officer under Article 37 GDPR. Our processing activities do not currently meet the threshold that requires one. If they do, we will appoint one and update this section.
2. What Spegla is, and where this policy applies
Spegla is an AI visibility checker at getspegla.com. You enter a brand name, a product or service category, and a market language. Spegla generates around ten questions a consumer might ask in that category, puts them to four AI models through their official programming interfaces, analyses the answers, and produces a result page you can share.
You can use the checker without an account. You can also create one, which saves your checks so you can come back to them.
This policy covers the website at getspegla.com, the account service behind api.getspegla.com, the checker itself, and the result pages it produces.
3. The data we process
3.1 Your account
If you create an account we store:
- your email address, which is also how you sign in;
- your name, only if you choose to fill it in; it is optional and stays empty otherwise;
- the interface language you last used;
- the brand and category you track, if you set one;
- the date the account was created;
- a profile picture address and a link to your provider account, only if you sign in through a third-party provider. We do not currently offer that, and we will update this policy before we do.
Signing in works by email link. You type your address, we email you a single-use link, and following it signs you in. There is no password, so there is no password to store or to lose.
Legal basis: performance of our contract with you to provide the account you asked for, Article 6(1)(b) GDPR.
We also rate limit sign-in requests, at most three link requests per account in five minutes, so that nobody can use Spegla to flood an inbox. Legal basis: our legitimate interest in preventing abuse of the sign-in system, Article 6(1)(f) GDPR.
3.2 What you type into the checker
We process the brand name, the product or service category, and the market language you enter. These are usually company and product names, not personal data. But a name you enter may incidentally identify a person, for example if you check a personal brand, a sole trader operating under their own name, or if you enter a person's name directly.
Please do not enter the name of a private individual. Spegla is built for checking brands, products and businesses. If personal data does end up in a check, Section 7 explains how to have it removed.
Where this text goes is important, so here it is exactly:
- The category you type is sent to OpenAI, which generates the ten buying-intent questions for it. Those questions deliberately never name your brand, because the whole measurement is whether the models bring it up on their own.
- Those generated questions are then sent to all four AI providers named in Section 5.
- The brand name you type is sent to OpenAI during the analysis step, together with each answer being analysed, so that a model rather than a keyword match can decide whether the brand was mentioned and how.
So if you type a person's name into either field, that name leaves our systems and reaches AI providers outside the European Union. There is no way to run the check without that happening. This is the single most important thing to understand before you type something into Spegla.
Legal basis: performance of our contract with you to run the check you requested, Article 6(1)(b) GDPR. Where an entry incidentally contains personal data about somebody else, our legal basis is our legitimate interest in operating the service you asked us to run, Article 6(1)(f) GDPR.
3.3 Your IP address, used only for rate limiting
To keep the free checker available to everyone, we limit how many checks can be run per day. For an anonymous visitor we process the IP address the request arrives with and store only a SHA-256 hash of it, never the address itself. If you are signed in, we hash your account identifier instead, so that a shared office connection does not burn one person's allowance on somebody else's runs.
The hash is used solely to count checks against the daily limit. We do not use it to identify you, to build a profile, or for anything else. We do not treat a hash of an IP address as anonymous data, because the set of possible addresses is small enough to work backwards through, and this policy applies to it in full.
Legal basis: our legitimate interest in protecting a free service from abuse, Article 6(1)(f) GDPR.
Separately, our hosting providers process your IP address in the ordinary course of delivering the website and the API to your browser, as every website's host does. Section 5 names them.
Legal basis: our legitimate interest in operating and securing the service, Article 6(1)(f) GDPR.
3.4 Check results
Each check produces a result: the generated questions, the answers returned by the AI models, and our analysis of those answers. Results are stored under a random identifier and served at a result page address containing that identifier. If you were signed in when you ran the check, the result is also linked to your account so it appears in your history.
Two consequences worth knowing:
- Result pages are accessible to anyone who has the link. They are marked so that search engines are told not to index them, but a link can be forwarded by anyone who holds it. Share result links with that in mind.
- Results are cached and shared. If somebody checks the same brand, category and language within 24 hours of your check, they are shown your stored result rather than a fresh run. This keeps the free tool affordable, and it means a check you run is not private to you.
Legal basis: performance of our contract with you, Article 6(1)(b) GDPR.
3.5 Sign-in emails
To send you a sign-in link we pass your email address and the link to Resend, our email provider. Resend is the only recipient of your address other than us, and it receives it only to deliver that message. We do not use it for newsletters, and there is nothing to unsubscribe from, because the only email Spegla sends is the one you asked for by trying to sign in.
We do not use open tracking or click tracking on these emails.
Legal basis: performance of our contract with you, Article 6(1)(b) GDPR.
3.6 Analytics
We are introducing product analytics through PostHog, so that we can see which parts of Spegla people actually use. We configure it in its cookieless mode: it keeps nothing in cookies, in local storage or in session storage, so nothing about it survives after you close the tab. Events go to PostHog's European cloud, and they are sent through our own domain rather than to a third-party address.
We looked at whether that mode escapes the consent requirement in Section 25 TDDDG, and concluded that it does not. Section 25(1) covers two things: storing information on your device, and reading information that is already there. The cookieless mode removes the storing half. It does not remove the reading half, because the analytics script still reads things your browser holds, such as screen size, language, time zone and the page you arrived from, and sends them to us. The only exemption that could apply, Section 25(2) number 2, covers what is strictly necessary to deliver the service you asked for, and measuring how people use a product is not that. German law has no separate exemption for audience measurement.
So we ask first. Analytics loads only if you agree to it. If you decline, or ignore the question, the analytics script is never loaded and no events are sent. You can change your mind in either direction at any time, and withdrawing is as easy as giving consent was.
Legal basis: your consent, Article 6(1)(a) GDPR and Section 25(1) TDDDG. Withdrawing consent does not affect processing that happened while it was given.
3.7 Error monitoring
We are introducing Sentry to tell us when Spegla breaks. When a page or a request fails, Sentry receives a technical report: the error, where in the code it happened, the address of the page you were on, and details about your browser and operating system.
We do not use session replay, we do not record your screen, and we do not send Sentry your name, your email address or what you typed into the checker. We do not use it to measure usage or to build a profile of you.
We treat this as strictly necessary to deliver and secure the service you asked for, which is why it is not behind the consent question that analytics is behind. That is a judgement, and we would rather state it openly than bury it: fixing crashes is part of running the product, not part of measuring you.
Legal basis: our legitimate interest in keeping the service working, secure and debuggable, Article 6(1)(f) GDPR. You can object to this under Article 21 GDPR, as Section 9 explains.
3.8 Support
If you write to us, we keep your message, the address you wrote from, and our reply.
Legal basis: our legitimate interest in providing support, Article 6(1)(f) GDPR.
4. Cookies and what is stored on your device
Spegla sets cookies only for signing in. There are no advertising cookies, no marketing pixels, no session recording, and no cross-site tracking of any kind.
| Cookie | What it is for | How long it lasts |
|---|---|---|
accessToken |
Proves you are signed in on each request | 15 minutes |
refreshToken |
Renews the short-lived access cookie so you stay signed in | 30 days |
oauth_state |
Security check during sign-in with a third-party provider, set only if you start one. We do not currently offer this | 10 minutes |
All of them are set on .getspegla.com, are marked httpOnly so that no script on the page can read them, are sent only over HTTPS in production, and are marked SameSite=Lax.
These are strictly necessary to provide the signed-in service you expressly requested, so under Section 25(2) number 2 TDDDG they need no consent. Nothing here is optional: without them, staying signed in is not technically possible. Their basis under the GDPR is Article 6(1)(b), performance of our contract with you.
Signing out deletes both session cookies and destroys the session record on our side, so the tokens cannot be replayed afterwards.
Analytics is the one thing on Spegla that does ask for consent, and Section 3.6 explains why. If you never create an account and never accept analytics, Spegla stores nothing on your device at all.
5. Providers we use
These providers process data on our behalf, or receive data from us, when you use Spegla. Where data leaves the European Economic Area we rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-U.S. Data Privacy Framework. Section 6 has the detail.
| Provider | What they do for us | Where they process |
|---|---|---|
| OpenAI | Generates the category questions, answers them as ChatGPT, and runs the analysis step | United States |
| Anthropic | Answers the generated category questions as Claude | United States |
| Answers the generated category questions as Gemini | United States | |
| Perplexity | Answers the generated category questions as Sonar | United States |
| Vercel | Hosts the website and runs the checker functions | United States and global edge network |
| Google Cloud | Runs the account and sign-in API on Cloud Run | European Union, europe-west4 |
| Supabase | Database storing accounts, sessions, check results and rate limit counters | European Union, AWS eu-central-1, Frankfurt |
| Resend | Delivers sign-in emails, on Amazon Web Services infrastructure | European Union, eu-west-1, with a US-based provider |
| PostHog | Product analytics, only if you consent | European Union, with a US-based provider |
| Sentry | Error monitoring | United States |
The AI providers receive the generated questions and, in OpenAI's case, the brand name and the answers being analysed. They do not receive your IP address from us, your email address, or anything else about your account. Under these providers' published terms for their programming interfaces, content sent through them is not used to train their models. We rely on those published terms and cannot independently verify a provider's practice beyond them.
We do not sell data. We do not share it with advertisers. There is no advertising on Spegla.
6. Where data is stored, and transfers outside the EEA
Accounts, sessions, check results and rate limit counters are stored in the European Union, in a Supabase database running on AWS in Frankfurt. The account and sign-in API runs on Google Cloud Run in the Netherlands. Sign-in emails are delivered from Amazon Web Services in Ireland. The website and checker functions run on Vercel. The AI providers process the generated questions and answers in the United States, as does Sentry.
For each transfer outside the European Economic Area we rely on one or more of the following safeguards under Chapter V GDPR:
- The European Commission's Standard Contractual Clauses, Decision (EU) 2021/914.
- Certification under the EU-U.S. Data Privacy Framework, where the provider is certified.
- Supplementary measures including encryption in transit and access control.
Some providers store data inside the European Union but are companies established in the United States, which means administrative or support access from there cannot be ruled out. Resend, PostHog and Supabase are in that position. The same safeguards apply.
You can ask us for details of the safeguards applied to any transfer by writing to support@laddro.com.
7. Result pages and data about other people
A check result contains AI-generated statements about the brand you checked and often about other brands in the same category, including competitors. These statements are reproductions of what publicly available AI models say when asked. They are not claims made or endorsed by us, and they can be wrong.
If a result page contains personal data about you, or statements about you or your brand that you want removed, write to support@laddro.com with the result page link. We will review the page and delete it or remove the relevant content where the law requires it, and usually simply on request. The rights in Section 9 apply to you even though you never used Spegla yourself.
8. How long we keep things
| Category | Retention |
|---|---|
| Account data: email, name, language, tracked brand and category, creation date | Until you delete your account, which takes effect immediately |
| Sign-in links | Stop working 30 minutes after we send them, and are deleted the moment you use one or request another |
| Session records | A session stops working 30 days after its last use. The record is deleted the moment you sign out or delete your account |
| Check results | Kept so that result links keep working, and reused as a cached answer for 24 hours. Deleted on request |
| Generated question sets | Reused for 7 days for the same category and language, then regenerated and overwritten |
| Rate limit counters | A hashed identifier and a count, kept per day and not used after that day |
| Analytics events, if you consented | No longer than 12 months |
| Error reports | No longer than 90 days |
| Support correspondence | Up to 3 years after the matter is closed |
Deleting your account. In Settings, deleting your account removes the account record immediately and permanently. Your sessions, your pending sign-in links and any third-party provider links are deleted with it, so every device you were signed in on is signed out at once. There is no grace period and no way for us to undo it.
Checks you ran are the one exception, and we would rather be exact than flattering: the link between those checks and you is removed, so nothing points back at you, but the stored result itself is kept so that shared result links do not break. If you want the results themselves deleted too, tell us and we will delete them.
9. Your rights
If you are in the EEA, the United Kingdom, or another jurisdiction with comparable rights, you have the right to:
- Access, Article 15. Ask for a copy of the data we hold about you.
- Rectification, Article 16. Ask us to correct anything wrong. If you have an account you can change your name and language yourself in Settings.
- Erasure, Article 17. Ask us to delete data about you, including a check result that contains your personal data. If you have an account you can delete it yourself in Settings, and it happens immediately.
- Restriction, Article 18. Ask us to pause processing while something is checked.
- Portability, Article 20. Ask for the data you gave us in a structured, machine readable format.
- Objection, Article 21. Object to processing based on legitimate interest, which covers rate limiting and error monitoring. We stop unless we can show overriding grounds.
- Withdraw consent, Article 7(3). Withdraw your agreement to analytics at any time, as easily as you gave it.
- Complain to a supervisory authority, in particular the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), or the authority where you live or work. You can do this without going through us first.
If you have an account, write from the address the account uses and we can identify you straight away. If you used Spegla without an account, we usually cannot connect a stored check to a particular person by ourselves, so tell us the result page link or the brand name and approximate date of the check. Write to support@laddro.com. We reply within one month, as Article 12(3) GDPR requires. For a complex request we may extend by up to two further months and will tell you if we do.
10. No automated decisions about you
Spegla does not make decisions about you with legal or similarly significant effects using automated processing, within the meaning of Article 22 GDPR. The AI models answer questions about brands, and the scoring measures a brand. Nothing on Spegla scores, profiles or evaluates the person using it.
11. Children
Spegla is a tool for checking brands and is not directed at children. Under Article 8 GDPR and Section 25 BDSG the age for consenting to information society services in Germany is 16. We do not knowingly create accounts for anyone below that age. If you believe a child has created an account, write to support@laddro.com and we will delete it.
12. Changes to this policy
We may update this policy, for example when we introduce the paid plans we are planning. When we do, we change the date at the top. A materially changed policy will be published on this page before it takes effect.
13. Contact
Laddro Digital UG (haftungsbeschränkt) Belziger Str. 69 to 71 10823 Berlin, Germany Email: support@laddro.com