Privacy Policy
Last updated: September 12, 2026
If you're having thoughts of suicide, self-harm, or harming someone else
Stop the conversation with the AI and seek real help immediately. SPOCOI is not an emergency service and cannot intervene in a crisis.
- Emergency services: 112
- EU-harmonized emotional support line (available in most member states): 116 123
If the number above doesn't work where you are, call your local emergency number or go to the nearest medical facility.
This policy describes how Delgra SRL (Moldova), spocoi's current operator and part of the SPOCOI group alongside SPOCOI OÜ (Estonia, holding company, in the process of registration), collects, uses, and protects your data.
We follow GDPR (General Data Protection Regulation) principles. The infrastructure that stores user data is hosted within the European Union — the database runs on Supabase, in the Frankfurt, Germany region.
Minimum age
The minimum age to use spocoi is 16. Users aged 16 to 18 may use the service only with the consent and supervision of a parent or legal guardian. We do not knowingly collect data from anyone under 16.
What data we collect
- Account data: email address, preferred language, and an optional display name you can set later in account settings.
- Conversation logs: the content of conversations with the AI, by voice or text.
- Technical and usage data: device type, operating system, approximate IP address, app usage statistics.
- Payment data: for users on a paid plan, payments are processed by Stripe; spocoi does not store your full card number.
Legal basis for processing
We process account data and conversation content because it's necessary to provide the service you sign up for (performance of a contract). Where a conversation reveals health-related or other special-category information about you, we rely on your explicit consent, given as a separate, specific checkbox at sign-up — not bundled with general acceptance of these terms. You can withdraw that consent at any time by turning off personalization in your account settings or by deleting your account; withdrawal doesn't affect processing already carried out.
Pricing adapted to your location
On the pricing page, we automatically determine your region (Moldova, Romania, or the rest of the European Union) from your connection's approximate IP address, so we can show you the right price without asking you to choose manually. This check happens in real time, on every visit — we don't build a history of your locations for pricing purposes.
Automatic detection can occasionally be wrong (for example, if you use a VPN or are roaming). If the price shown doesn't match your country, write to us at support@spocoi.co and we'll sort it out manually.
Cookies and similar technologies
spocoi does not use advertising or analytics cookies, and doesn't run any third-party tracking scripts. We only set two strictly technical cookies, both required for the service to function:
- a session cookie, set when you log in, so you stay signed in between visits — deleted when you sign out or your session expires;
- an anonymous device identifier (a random id, not a device fingerprint), kept for up to 1 year, used exclusively to prevent abuse of the sign-up and waitlist forms (for example, one person creating many free accounts in a row). It is never used for advertising, analytics, or tracking your activity on the service.
Who else processes your data (sub-processors)
We share data with a small number of specialized providers, only to the extent needed to run the service:
- Supabase (database and authentication), hosted in Frankfurt, Germany — within the EU.
- Anthropic (the AI model that powers conversations, memory personalization, and daily summaries), based in the United States. Sending conversation content to Anthropic for processing is what allows the AI to reply to you at all. We are formalizing a Data Processing Agreement and EU Standard Contractual Clauses with Anthropic to govern this transfer; until that is complete, treat this transfer as a known, disclosed limitation rather than a settled guarantee.
- Vercel (hosting and content delivery).
- Stripe (payment processing, paid tiers only) — see below.
We do not sell your data, and we do not share it with anyone for their own marketing purposes.
How long we keep data
Retention depends on the type of data:
- Conversation messages (the raw text/voice content): kept for 30 days, then automatically and permanently deleted by an automated job.
- Daily conversation summaries and mood check-ins: also kept for 30 days, then automatically deleted.
- Personalization memory (specific facts the AI remembers about you, when personalization is turned on): kept for as long as your account is active. You can review and delete individual memory entries, or turn personalization off entirely, at any time from your account settings; doing so does not delete entries already extracted unless you remove them yourself.
- Anti-abuse records (IP address and the anonymous device id described above, tied to sign-up/waitlist attempts): kept for 30 days, then automatically deleted.
You can request deletion of your data earlier at any time by contacting us at support@spocoi.co, or by deleting your account directly from account settings. Some data (for example, billing-related data) may be kept for longer when required by law.
Your rights under GDPR
As a user in the European Union or the Republic of Moldova, you have the right to:
- access your personal data;
- correct inaccurate or incomplete data;
- have your data deleted ("the right to be forgotten");
- receive your data in a structured, portable format;
- object to certain processing of your data, or ask us to restrict it;
- withdraw consent at any time, where we rely on consent;
- lodge a complaint with your national data protection supervisory authority (in Moldova, the Centrul Național pentru Protecția Datelor cu Caracter Personal; in an EU country, your local authority) if you believe we've mishandled your data.
To exercise any of these rights, write to us at support@spocoi.co. We will respond within 30 days.
Security and breach notification
Data is encrypted both in transit and at rest. Access to infrastructure is restricted through role-based access controls, available only to the team members who actually need it to operate the service. If a personal data breach occurs that is likely to affect your rights or freedoms, we will notify the relevant supervisory authority within the timeframe required by law and inform affected users without undue delay.
Related to the AI's limitations
For details on how conversations relate to the AI and its limitations, see the About the AI page.
Contact
For any question about privacy, write to us at support@spocoi.co.