Updated 30 September 2026
Privacy notice
Controller and contact
The controller’s full legal name and postal address must be added here before launch.
For privacy questions, contact hi@spektiv.fi. You can ask to access or delete your personal data.
Information processed
Google sign-in is handled through Firebase Authentication. A user account includes a Firebase identifier and may include an email address. API keys are shown only once when created; Firestore stores a hash of the key. OAuth connections store the client identifier, name, host, redirect URIs, and authorization data such as a short-lived PKCE challenge and optional state value. The database stores hashes of authorization-request identifiers, authorization codes, access tokens, and refresh tokens. Questions and claims are processed to produce answers and select statistical sources.
Service providers and use
Google Firebase and Cloud services provide authentication, database, and service logging. The homepage demo and claim checker use the OpenAI Responses API with response storage disabled. Other MCP question runs use the configured model provider (Gemini by default; OpenAI can be configured), and search queries may be sent to Google Gemini to create an embedding. Under OpenAI’s default controls, prompts and responses may be retained in abuse-monitoring logs for up to 30 days, with limited exceptions described in its policy; disabling response storage does not disable that default. See OpenAI API data retention controls. Statistical publishers receive search terms and selected table/value identifiers from tool calls; a search term may reflect the wording of the question. The question-answer cache stores prompts, answers, source rows, calculations, structured answer metadata, and tool activity traces. The claim-check cache stores only the curated landing-page example claims and their structured assessments, evidence, and tool traces; custom claim checks are not persisted in this cache. Each cache record is assigned a 30-day expiration from its write. Service-usage metrics use a hashed account identifier and client host. When Plausible analytics is enabled, it receives page views and connection events; the application does not send it question text or account identifiers. Do not submit confidential or sensitive information.
Retention and your choices
Answer-cache records are set to expire after 30 days. The application stops serving an expired answer and attempts to delete its record when read after expiry. Automatic Firestore expiration is not yet enabled for the project, so physical deletion may be delayed until it is enabled. For older records, the application derives expiration from the write time; it rejects a record on read if that time is unavailable. First-tool-call metric records are assigned a 400-day expiration and daily activity records a 120-day expiration. OAuth authorization requests and codes expire after five minutes, access tokens after one hour, and refresh tokens after 30 days. User-account and registered-client details remain until deleted; log retention follows the Google Cloud project settings. Email us to request access to or deletion of your data.
Open statistical data
Open Statistics Finland data shown by the service is available under CC BY 4.0; source attribution is included with results.