Your data, your rules
Spun gives you granular control over what data is stored, processed by AI, and shared with other organizations. Every privacy feature, explained in one place.
Our commitments
Four privacy principles, always on
These aren't toggles — they're how Spun is built.
We never train AI on your data
Your messages, contacts, and conversations are never used to train AI models — not ours, not OpenAI's, not anyone's. AI providers process your data on a per-request basis only.
Per-org data isolation
Every organization's data is isolated at the database level using row-level security (RLS). Even if a query is mistakenly written without an org filter, the database refuses to return cross-org rows.
You own your data
Delete individual messages, purge contacts, wipe your entire database, or close your account at any time. All data deletion is irreversible and completes within 30 days at most.
Encrypted in transit
All communication between your browser, our servers, WhatsApp, and AI providers is encrypted with TLS. Payment processing is handled by Stripe — we never see or store your card numbers.
Deep dive
Read the details
Four dedicated pages cover encryption, the sub-processors that handle your data, our compliance posture, and how Spun stays inside WhatsApp's rules.
Encryption
TLS, row-level security, WebRTC E2EE for 1:1 calls, LiveKit SFU for group calls, R2 storage, Stripe payments.
Read moreSub-processors
Every third-party vendor that processes any part of your data, what they see, and where they operate.
Read moreCompliance
SOC 2, GDPR, ISO 27001, EU AI Act status. Retention limits per plan, regional hosting, DPA available.
Read moreConsent capture, STOP/opt-out handling, anti-spam pacing, ban risk, and per-org kill switch — staying inside WhatsApp's rules.
Read morePrivacy presets
Choose how much of your data reaches AI providers
Three preset levels balance AI quality against data minimization. Switch any time — switching to Maximum also purges existing search embeddings.
Maximum
The strictest setting. Zero personal data leaves your server.
- ●Full PII redaction for chatbot, Weave, summaries, classification
- ●Translation disabled
- ●Search embeddings disabled
- ●Switching here purges existing embeddings
Balanced
Default. Full redaction for AI services, partial for search.
- ●Full PII redaction for chatbot, Weave, summaries, classification
- ●Translation active with financial-data-only stripping
- ●Search embeddings active with financial-data-only stripping
- ●Best balance of privacy + features
Full AI
Best AI quality. No name/phone/email/ID redaction.
- ●No PII redaction for chatbot, Weave, summaries, classification
- ●Translation active
- ●Search embeddings active
- ●Credit cards & secrets always stripped from embeddings
AI privacy controls
Every AI feature can be disabled — globally, per-service, or per-message-type. PII redaction strips sensitive data before any AI provider sees it.
Master AI kill switch
One toggle disables every AI feature at once — compose, smart replies, translation, transcription, summaries, chatbot, intent classification. AI is fully off until you re-enable it.
Per-service PII redaction
Choose how much personal information is stripped before each AI service processes a message. Set different levels for the chatbot, Weave Q&A, contact summaries, intent classification, translation, and search embeddings.
3 privacy presets
Maximum (no data leaves your server — translation and search disabled), Balanced (full redaction for AI, financial-data-only for search/translation), or Full AI (best quality, only credit cards & secrets masked).
Recommended: BalancedDisable individual AI features
Granular per-feature toggles for compose, improve, summarize, smart replies, translation, OCR, classification, audio transcription, voice chatbot, voice translation. Turn off only what you don't want.
AI content logging toggle
Turn the audit trail of AI requests and responses on or off. When on, admins can review every AI interaction. When off, prompts and outputs are not retained beyond the request.
Purge search embeddings
Switching to Maximum privacy purges all search indexes (contact embeddings, conversation chunks, knowledge base). One-click delete of every vector previously generated from your messages.
What gets redacted
Our PII detector finds and masks sensitive data before it leaves your server. Multi-language, script-aware, with keyword + pattern matching.
Names & identities
Personal names, honorifics, and identity introducers are detected and masked. Smart stoplist prevents masking common greetings and titles in 10 language groups.
Phone numbers
International (E.164) and local phone formats including UK (07XXX), Brazil ((XX) XXXXX-XXXX), India (6-9XXXX XXXXX), Germany (0XXX-XXXXXXX), Israel, US, and more.
Emails & addresses
Email addresses and physical/postal addresses in multiple scripts (Latin, Hebrew, Arabic, Cyrillic, Devanagari) are detected via keyword + script-aware boundary patterns.
National IDs & passports
Country-specific ID numbers: Israel teudat zehut, US SSN, Spanish DNI, Brazilian CPF/CNPJ, Indian Aadhaar, UK NIN, German Steuer-ID, Turkish TC Kimlik, plus passport numbers (letter-prefix + bare-digit formats).
Financial data
Credit card numbers (Luhn-validated), bank account/IBAN numbers, routing numbers, payee details, and secrets. Even in Maximum-quality mode, financial data is always stripped from search embeddings.
10 language groups
PII detection works in English, Hebrew, Spanish, French, Portuguese, Arabic, Russian, German, Italian, and Turkish. Tested with 136+ multi-language test cases.
Data storage controls
You decide what is saved, how long, and when to wipe it. Every deletion feature affects only Spun's database — your WhatsApp is never touched.
Pause data storage
Stop saving new messages to our database. Messages still appear in real-time during your session but are not persisted. Refresh the page and unsaved messages are gone. WhatsApp itself is untouched.
Max messages per chat
Set a hard limit on stored messages per chat (10–5000, or 0 for unlimited). When a chat exceeds the cap, oldest messages are automatically pruned from our database.
Purge old messages
Keep only the last N messages per chat (10–1000+). Older messages are permanently deleted from our database. You can always re-import recent media (up to 30 days) and text from WhatsApp later.
Export your data
Download a machine-readable export of your messages, contacts, and organization data at any time. Fulfils GDPR data-portability rights directly from your settings — no email request needed.
Purge all contacts
One-click delete every imported contact from our database. WhatsApp contacts remain on your phone untouched — you can re-import any time.
Delete all data + pause storage
Nuclear option: wipe every message, media file, conversation, and contact from our database AND pause new storage. Confirmation required. WhatsApp untouched.
Delete account (email-confirmed)
Permanently delete your organization account and all associated data. A confirmation code is sent to your registered email — you must enter it to proceed. Action is irreversible.
Cross-organization privacy
Your org's data never leaks to other Spun organizations without explicit, two-sided consent. Connection requests and shared tasks require mutual opt-in from both org admins.
Cross-Org Messaging toggle
Off by default. Controls whether your team can reply in accepted DM threads with users from other organizations. Both orgs must enable it for any cross-org communication to happen.
Cross-Org Connection Requests
Off by default. Controls whether your users can send or receive connection invites to/from other organizations. Required before any cross-org DM is possible.
Cross-Org Task Sharing
Off by default. Controls whether tasks in your org can be shared as guest invitations with connected users in other orgs. Guests see only the task discussion thread, not your projects or other org data.
No-existence-leak protection
Connection requests always return identical success regardless of whether the target user exists, is in your org, or has already blocked you. Prevents using the API to probe whether an email or phone is on Spun.
Phone discoverability toggle
Verify your phone for Spun Chat without becoming discoverable. Off by default — your phone number cannot be used to find your account unless you explicitly turn discovery on.
Keep contact internal
Per-contact preference: when on, outbound messages route via Spun Chat only and WhatsApp sends are hard-blocked at the server level until you explicitly change it. UI cannot override.
Rate-limited invites
5 connection requests per day, 20 per month, max 3 concurrent pending — to prevent spam, abuse, and reduce ban risk on the underlying messaging providers.
Block list
Block individual users from initiating DMs or task invitations with you. Blocked users see normal "delivered" UI but messages never reach you. Bidirectional — they can't reach you and you can't accidentally send to them.
Display & team monitoring
Control what is visible inside your inbox and what team-level monitoring features are active. Defaults to ON for productivity features — turn off any you don't want.
Hide chat avatars
Remove profile pictures from chat lists for a cleaner, more private view in shared workspaces. No avatar data is rendered to the DOM when off.
Hide WhatsApp status
Disable WhatsApp status/stories entirely. Status posts never appear in the app and all status-related processing is skipped — no thumbnails, no view tracking, nothing.
Manager Dashboard opt-out
Disable named per-user performance metrics that are otherwise visible to organization managers. Once off, managers see aggregated team metrics only — no individual attribution.
Peer Leaderboards opt-out
Disable team performance rankings visible to team members. Removes all ranked lists, scoreboards, and competitive UI from the inbox.
Working Circle opt-out
Disable the inferred collaboration graph that maps who works with whom based on shared tasks, mentions, DMs, and handoffs. Stops the graph from being computed or displayed.
Affiliate Network Visibility
For affiliate partners: toggle whether your aggregate metrics (org name, status) are visible to the referral partner who introduced you to Spun.
Sprint (Focus Mode)
Time-boxed focus session that suppresses push notifications, SSE-triggered UI refreshes, and alarm sounds. Your activity during the sprint is private to you — no metrics broadcast to managers.
Admin access & audit
Limit which team members can see what. Permissions are enforced server-side, not just hidden in the UI.
Granular admin permissions
22 separate permission keys covering every admin panel page. Each key supports three access levels: none, read-only, or read-write. Server-side enforcement — not just UI hiding.
Preset admin roles
Five built-in roles — Affiliate Support, Customer Support A, Customer Support B, Financial, Tech Support — for common access patterns. Or customize each permission individually.
Team member role restrictions
Org users without manager role cannot access plans, billing, AI tokens, storage controls, dashboard, contacts CRM, or campaigns. Read-only inbox role disables the message composer entirely.
AI Logs audit trail
Optional log of every AI request/response across your organization. View, search, and export. Disabled = no AI content retained beyond the request.
Infrastructure & compliance
Under the hood: how we protect your data even when you're not actively managing settings.
TLS encryption everywhere
All traffic — browser ↔ Spun, Spun ↔ WhatsApp providers, Spun ↔ OpenAI, Spun ↔ Stripe — uses TLS 1.2+ in transit.
Row-level security at DB level
PostgreSQL row-level security (RLS) enforces org isolation on every query. Even direct database access through our code is gated by org context — cross-org leakage is structurally prevented.
No card data stored
Payment processing is handled end-to-end by Stripe (PCI-DSS Level 1 compliant). We receive only an opaque customer ID — never card numbers, CVCs, or expiry dates.
EU data center + global edge
Application servers and database in Hetzner Nuremberg (Germany, EU) — a single data tier. Marketing site and media (images, video, files) served globally from Cloudflare's edge network and R2 object storage.
Regional proxy relays (EU + US)
Self Proxy WhatsApp traffic is carried by Spun-operated relay servers in Nuremberg, Germany (EU) and Manassas, Virginia (USA) — your connection uses the relay closest to your computer. Relays forward encrypted traffic in real time and store nothing.
WhatsApp itself is never modified
Every data-deletion feature on Spun affects only Spun's database. Your WhatsApp account, messages, and contacts always remain on your phone and WhatsApp's servers, unaffected.
Plan-based retention limits
Free trial: 30 days. Basic: 90 days. Pro: 1 year. Power: unlimited. Older messages are automatically pruned. Account deletion removes or anonymizes all personal data within 30 days.
Where to find these settings
Inside the Spun inbox, open Settings from the left sidebar:
- Safety & Privacy tab — master AI kill switch, PII redaction presets, data storage controls, account deletion, privacy controls for cross-org & monitoring features.
- AI tab — per-feature AI toggles, AI content logging, context presets, model preferences.
- General tab — display preferences, chat avatars, status visibility.
- Admin Privileges page (platform admins only) — manage granular permission keys and preset roles for team admins.
Try Spun with privacy built in
Start with the Balanced preset (recommended) and tune any setting to fit your team.
Questions about a specific feature? Email [email protected].