Spirit

Privacy

What we do with information about you, in the order you are likely to care about it. No defined terms you have to look up, and nothing hidden in a clause.

In effect · 2 October 2026

Spirit is made by ASLYNX INC. (“Aslynx”, “we”, “us”), a corporation in Guelph, Ontario, Canada. Spirit is software that does a firm's recurring work — it reads documents, writes drafts, and files things into the software the firm already owns.

Which half of this policy applies to you depends on something that is easy to miss, so it is first:

Information about you, as somebody dealing with us
You read this website, join the waitlist, hold an account, or pay us. We decide what happens to that information, and this policy is our answer for it.
Information inside a workspace
The documents, email and records a customer puts through Spirit — which, for a law firm or an accounting practice, usually describe that firm's own clients. We hold it on the firm's instruction and use it for nothing of our own. The firm answers to its clients for it; what we owe the firm is in the Data Processing Agreement.

1Who we are, and who to write to

ASLYNX INC., Guelph, Ontario, Canada. Our privacy officer — the person accountable for everything in this policy, as Canadian law requires us to name — is reachable at info@aslynx.com. Write “Privacy” in the subject line and it gets handled as a privacy request rather than as support.

Canadian federal privacy law (PIPEDA) governs what we do, together with the privacy law of the province you are in.

2If you only read the website

Then we do not know you were here.

There is no analytics on this site. No Google Analytics, no tag manager, no advertising pixel, no session recording, no fingerprinting, no A/B testing tool, and no third-party script of any kind that reports your visit to somebody else. This is checkable rather than a claim: open your browser's network panel and the only things that load are this site's own pages, its stylesheet, its fonts and its images.

Our web server sees your IP address, because an address is how a reply finds you. It is not written to an access log. Fonts are served by us, not by Google, so loading this page tells Google nothing.

3If you join the waitlist or ask for a demo

We keep what the form collected and nothing more:

  • Your email address.
  • Your name, if the form you used asked for one. It is optional, and we do not check it.
  • Which part of the page you submitted from, and the page that sent you to us — so we know which words brought people in.
  • The time you submitted.
  • A salted one-way hash of your IP address, not the address itself. It exists to spot one machine filling the form a hundred times. It cannot be turned back into an address.

Your raw IP address is held for sixty seconds while the form's rate limit runs, and is then gone. That window is the only moment the address exists anywhere in our systems, and nothing writes it down.

Each signup is also posted to our own internal workflow so that a person actually sees it. That workflow is where signups are worked from; the copy in our database is secondary.

We use this to talk to you about Spirit, and for nothing else. It is not sold, not rented, and not handed to an advertising network. Reply to any message and ask us to remove you, and we will — no form, no reason needed.

4If a firm sends you a form, or writes to you through Spirit

You may meet Spirit without ever having heard of us — a contractor filing a job sheet from a phone, a client sending a firm some details, somebody getting a reminder about a document they owe. This section is for you.

If you filled in a form

  • A firm using Spirit can publish a form, or a link that starts a piece of work, which anybody holding it can use without an account.
  • The firm chose the questions, not us. We did not design the form, we do not inspect what it asks for, and we have no view on whether it should be asking.
  • What you submit goes into that firm's workspace and becomes an input to their work. We hold it for them, on their instruction, exactly as we hold everything else they put through Spirit.
  • There is a limit of 5,000 characters on any one answer. Past that the form refuses it rather than quietly cutting it in half, because a truncated answer is worse than a rejected one.

If a firm wrote to you through Spirit

  • A Job can email you a result, and it can chase you on a schedule until you answer — a document outstanding, an approval waiting.
  • The firm is the sender. The words are theirs, the decision to write to you is theirs, and your address is in our systems because they put it there. We are the post, not the correspondent.
  • There is no tracking pixel and no wrapped link in anything Spirit sends. We do not know whether you opened it.

5If you hold an account

You

  • Your name and email address, whether that address has been verified, and which language you read in.
  • A link to your profile picture, if you signed in with Google or Microsoft and they provided one.
  • Which ways your account can sign in — an email link, Google, Microsoft — so you can see how you get back in.
  • A token from Google or Microsoft if you sign in that way. It establishes who you are and is used for nothing else.
  • Your sessions, so that staying signed in works.
  • If you move your account to a new address: the new address, and a hashed copy of the confirmation token, until the change completes or lapses.

Your workspace, and the people in it

  • The workspace's name and time zone, who is in it, and what each person's role is.
  • Invitations: the address invited, who invited it, when it was accepted. The invitation's token and code are stored hashed, so reading our database does not let somebody finish an invitation they were not sent.
  • An activity record — who created a Job, who approved a write, who removed somebody. This is for your colleagues, not for us: a workspace where nobody can tell who changed the rules is a workspace where nothing can be trusted.

If your firm pays us

  • Your plan, your billing period, identifiers that point at your customer and subscription records in Stripe, your invoices, and every movement of credits in or out of your balance.
  • Card numbers never reach Spirit. Stripe collects them on its own pages and holds them. What comes back to us is the brand, the last four digits, and whether the charge worked.

If you write to us

Your message, our reply, and anything you attach. Support correspondence about a specific document is the one way a file can reach us without an invitation, so send a redacted copy where you can.

6If we meet you to set Spirit up

Setting a firm up starts with a conversation about how the firm actually works, and we work from a written transcript of it afterwards. Worth being exact about what that is:

  • Spirit does not record anything. The transcript is text, pasted or uploaded by one of our people, from a meeting everybody in it knew was being transcribed. If that was not made clear to you, tell us and we will delete it.
  • It contains the names of the people in the room and what they said about how the work gets done — which documents matter, where the exceptions are, who signs what.
  • It is ours, not a workspace's. It lives on the other side of a wall from customer data: the role that reads transcripts has no permission at all on customer workspaces, and the role that runs the product cannot see transcripts. Neither can reach the other.
  • It is used to draft that firm's configuration, and afterwards distilled into a de-identified playbook that a person reads and approves — no names, no documents, no figures. The terms of use describe what a playbook is and how to tell us you would rather we kept nothing.
  • We keep a transcript while the engagement runs and for twelve months after it, then delete it. Ask sooner and we delete it sooner.

7What we do not do

Shorter than the list above, and more useful:

  • We do not sell personal information, and we do not share it for advertising. There is no ad network, no data broker and no “partner” in this product.
  • We do not train AI models on your content — not our own, and not a provider's. This is a contractual commitment in the Data Processing Agreement, not just a position.
  • We do not pool one customer's work into another's. What Spirit learns from your corrections, and the starting points it offers your next Job, are built from your workspace and stay inside it. There is no aggregate built across customers, because nobody consented to one.
  • We do not read your workspace content for our own purposes. §12 is how that is enforced rather than promised.
  • We do not track whether you opened our email. No tracking pixel, no wrapped links, no read receipts — in anything we send, or anything a customer's Job sends through us.
  • We do not make automated decisions about you that have a legal effect on you.

One thing we do score automatically, and it is about the workspace rather than about you: whether a firm's standing work is still running. It is computed from counts, statuses and timestamps — never from content — by a process with no permission to read a document, a result or a Job's rules. It exists so that we notice a customer has gone quiet before they give up on us, and nothing it produces has a legal effect on anybody. §12 describes how that boundary is enforced.

8The companies that help us run it

Spirit is not self-contained. These are the providers that touch data in the normal course of the service, what each one does, and where it does it. The same list, with more contractual detail, is Annex B of the Data Processing Agreement.

Service providers, as at the date of this policy.

  • ProviderAnthropic
    What it doesThe model that reads a document and does the work. Every run goes through it.
    WhereUnited States
  • ProviderOpenAI
    What it doesTwo uses, both optional: the embeddings behind semantic recall in memory, and running a Job on an OpenAI model where a customer chooses one.
    WhereUnited States
  • ProviderStripe
    What it doesPayments, cards, subscriptions and invoices.
    WhereUnited States and elsewhere
  • ProviderCloudflare (R2)
    What it doesStores the files in a workspace's Vault, encrypted at rest.
    WhereNorth America
  • ProviderMicrosoft (Graph)
    What it doesSends our email — sign-in links, invitations, run results, approval requests.
    WhereDepends on our tenant's region
  • ProviderOur hosting provider
    What it doesRuns the application, the database and the queue.
    WhereCanada

Two things that look like this list and are not. The software you connect — your Microsoft 365, your SharePoint, your accounting system, a dispatch system — is not our provider: it is yours, Spirit reaches it because you told it to, with credentials you supplied, and what happens there is governed by your agreement with them. And a government or a court may compel us to produce information; §16 is what we do when that happens.

9Where it is kept, and when it leaves Canada

The application, the database and the queue run on servers in Canada. Nightly database backups are kept on the same server.

Files are a different answer and we would rather give you the accurate one. A workspace's documents are stored in Cloudflare R2, which lets a customer pin a bucket to Europe or to a US government region but offers no Canadian jurisdiction. Ours is a North American bucket. So: your database records are in Canada; your files are in North America, which may mean the United States.

The model providers, Stripe and our mail transport process outside Canada regardless of where anything is stored, because that is where those services are.

10How long we keep things

Retention, by category. Where you can shorten it yourself, the row says so.

  • WhatA waitlist entry
    How longUntil you ask us to remove it, or until we stop running the waitlist.
    Who ends itYou, by replying to any message
  • WhatYour account and your profile
    How longWhile the account exists.
    Who ends itYou, in Settings — see §11
  • WhatWorkspace content: documents, runs, outputs, corrections, memories, the things Spirit filed
    How longUntil you delete it, or until the workspace is deleted. Some of it ends on its own: a memory can carry an expiry, a correction's window closes, and an unanswered write approval expires after 14 days.
    Who ends itYou
  • WhatWhat a mailbox contained
    How longNothing is kept from a mailbox beyond what a run actually used as an input. The sweep re-reads a rolling 30-day window each time rather than keeping its own copy, and reading mail in Spirit changes nothing in the mailbox — the permission we ask for cannot mark, move, send or delete.
    Who ends itAutomatic
  • WhatYour credit ledger and invoices
    How longArchived rather than deleted when a workspace goes, because it is a financial record and tax law requires us to be able to produce it. Six years.
    Who ends itUs, by law
  • WhatDatabase backups
    How longNightly, kept 14 days, then deleted. So something you delete today is gone from the backups within two weeks.
    Who ends itAutomatic
  • WhatOperational logs
    How long30 days. They record what happened — which workspace, which Job, which run, and any error — so that we can answer “what went wrong on Tuesday”. Credentials and tokens are stripped by a central rule rather than by whoever wrote the log line, and your documents and results are not in them.
    Who ends itAutomatic
  • WhatA one-way hash of your email address, after you delete your account
    How longIndefinitely. §11 explains why, and what it can and cannot do.
    Who ends itNobody

11Deleting your account or your workspace

You can do it yourself, in Settings, without asking us and without waiting for us. It is not a request that goes into a queue.

Deleting a workspace happens in this order, and the order is deliberate:

  1. If work is still running, or a write is still waiting for somebody's approval, we refuse and tell you. A run halfway through writing into your accounting system must not be orphaned.
  2. Your subscription is cancelled with Stripe immediately — not at the end of the period. A workspace that is gone and still billing is the worst outcome available.
  3. Every file belonging to the workspace is deleted from storage.
  4. The credit ledger is archived, emptied, and the workspace is dropped.

Deleting your account also destroys the workspaces you alone own, in the same action — otherwise deleting the last one would simply mint you a fresh empty one and the account could never go.

The three things that survive

  • A one-way hash of your email address, kept indefinitely. Spirit gives 150 free credits once per person, ever; deleting an account erases the record of having had them, so without this, deleting and signing up again would be a way to take them repeatedly. It is a SHA-256 hash and not the address: it cannot be read, cannot be mailed, and cannot be matched against anything. The only question it can answer is “has this address already had its free credits”. The product itself cannot even reach the table.
  • The archived credit ledger and your invoices, for the six years tax law requires.
  • Backups, for up to 14 days, after which the backup containing you is deleted on its own schedule.

12What people at Aslynx can see

Most vendors answer this with a sentence about internal policies. Ours is four separate database roles, each with its own password and its own grants, so the answer is enforced by Postgres rather than by our good intentions.

  • The product runs as a role that is subject to row-level security on every workspace-scoped table, forced on even for the table's owner. A request can reach the workspace it is for and no other. There is a test in our build that proves this rather than assuming it.
  • Our operator's console — where we see that a deployment is healthy and can add credits to a balance — is read-only over customer data with exactly one exception, which is adding a row to a credit ledger. It deliberately cannot read a workspace's content: not a document, not a run's output, not a Job's rules.
  • Our retention engine, which tells us when a customer's standing work has quietly stopped running, has grants written column by column. It can read counts, statuses and timestamps. It cannot read a Job's rules, a run's output, the words in a correction, a trigger token or a Stripe identifier — not because it doesn't ask, but because it has no permission to.
  • The setup assistant, which drafts a new customer's configuration from a discovery meeting, runs as a role with no access at all to customer data. Meeting transcripts sit on one side of that wall and customer workspaces on the other.

And when we do need to see your files

We have to be invited, by you, into your workspace — a `support` seat you grant. While we hold it: it is visible on your team roster, so the firm can see we are there; you can remove it at any moment, without asking us; and it is deliberately excluded from approving writes into your own systems, so we cannot authorise Spirit to put something into your software on your behalf.

We make this a contractual promise and not just an architectural one — see “When we can see your content” in the Data Processing Agreement.

13How it is protected

  • In transit, everything is over TLS, with HSTS set so a browser will not try it any other way.
  • Credentials for the software you connect are encrypted with AES-256-GCM, and the key is held outside the database — so a stolen database dump does not hand somebody your accounting system.
  • Files are encrypted at rest by the storage provider and reached only through short-lived signed links, scoped to one workspace's own prefix.
  • Tenant separation is row-level security in the database, not a `where` clause in our code that somebody could forget to write.
  • Our console needs a password and a time-based one-time code, and lives on its own hostname so it shares no cookie or origin with anything public.
  • A connection you add is read-only unless you make it otherwise, and a Job that writes into your systems can be set to stop and ask a person first — which is a security control as much as a workflow one.
  • Outbound requests are checked against a guard that refuses internal addresses, so a document that tries to make Spirit fetch something inside our own network gets nowhere.

14What you can ask us for

Under Canadian privacy law you can ask us to:

  • Tell you what we hold about you, where it came from, and who we have disclosed it to.
  • Correct it, if it is wrong or incomplete.
  • Stop using it — withdraw your consent. For marketing, that is immediate and costs you nothing. For an account, withdrawing consent and closing the account are the same act, because we cannot run the service without the few things in §5.
  • Explain ourselves, if we refuse any of the above. We will say which exemption we are relying on and who you can complain to.

Write to info@aslynx.com. We answer within 30 days, free, in all ordinary cases. If we need to confirm you are who you say you are before handing over your information, we will ask for only as much as that takes.

If our answer does not satisfy you, complain to the Office of the Privacy Commissioner of Canada (1-800-282-1376). In Quebec you can also go to the Commission d'accès à l'information, and Alberta and British Columbia have their own commissioners. You do not need our permission to complain and we will not hold it against you.

15If something goes wrong

If personal information in our care is lost, taken, or seen by somebody who should not have seen it, we contain it, work out what happened and who it touched, and then tell people.

  • Affected customers hear from us without undue delay, and in any event within 72 hours of our becoming aware — what happened, what information was involved, what we have done, and what we think they should do. This is a commitment in the Data Processing Agreement as well as a statement here.
  • Where the law requires it — where there is a real risk of significant harm — we report to the Privacy Commissioner and notify the individuals affected.
  • We keep a record of every breach, including the ones that turn out to be nothing, for the 24 months the law requires, and we will show a customer the record that concerns them.
  • We will not quietly tell your clients on your behalf. If you are a firm and your clients need to hear something, that is your call and your voice; we will give you everything you need to make it.

16If somebody demands your information

A subpoena, a warrant, a production order or a regulator's demand may reach us instead of you. What we do:

  • We check that it is valid, and that it actually covers what it asks for. We do not treat a letter as an order.
  • We tell you, before we produce anything, unless we are legally forbidden to — in which case we tell you as soon as that prohibition lifts.
  • Where we can, we point the requester at you instead, because the information is yours and the arguments about privilege and relevance are yours to make.
  • We produce the narrowest thing that answers the order, and nothing else.

For a law firm this matters more than it sounds: the architecture in §12 means that for most demands the honest answer is that we do not hold readable access to the content in question, and that is a better answer for your client than any policy we could write.

17Cookies

Two, and you will not be asked to click a banner, because there is nothing here to consent to.

Every cookie Spirit sets.

  • Cookie`spirit_lang`
    What it is forRemembers whether you read in English or French, so the choice survives moving between the website and the product.
    How longOne year
  • CookieThe session cookie
    What it is forKeeps you signed in to the product. Without it there is no way to be logged in at all.
    How longUntil it expires or you sign out

One is strictly necessary and the other is a preference you set yourself; neither follows you anywhere, and there is no third cookie to refuse. If you pay by card, Stripe sets its own cookies on its checkout pages, under its own policy — those pages are Stripe's, which is also why your card number never reaches us.

18Children

Spirit is software for businesses and professional practices. It is not for children, we do not market it to them, and we do not knowingly hold an account for anybody under 18. If you think we have, write to us and we will remove it.

19If Aslynx is sold

If this business is bought, merged, or transfers the part of itself that runs Spirit, the information described in this policy moves with it. That is how a business sale works and Canadian law permits it where the information is necessary to the transaction — but there are three things we will do about it, and they are the part worth writing down.

  • During the talking, a prospective buyer gets as little as possible, under a confidentiality agreement, and never a workspace's content. Diligence is answered with counts and descriptions, not with your documents.
  • We tell the owner of every workspace before a transfer takes effect, not after.
  • Whoever buys it is bound by this policy as it stands on the day, until they give you notice of something different — at which point you can read it and decide, including by leaving and taking your data with you.

If the business simply stops instead, you get notice, an export window, and then deletion on the timetable in §10.

20Changes to this policy

When this changes, the new version goes up here with a new date at the top, and the old one stays available if you ask for it.

If a change materially reduces the protection you have — a new category of provider, a new purpose, a shorter promise — we email the owner of every workspace before it takes effect rather than after. A policy that can be quietly loosened is not a commitment.

Questions about any of this go to info@aslynx.com. A plain question gets a plain answer — you should not need a lawyer to find out what we do with your work.