spectre

Data protection

Data protection declaration

Information about the processing of personal data by Spectre.

Status: 9. June 2026

1. Accountable person

The person responsible within the meaning of Art. 4 No. 7 GDPR is:

Operator / CompanyALB Digital Diensliestungen
Legal formALB Digital Diensliestungen
AddressMainzer Strasse, 53179 Bonn, Deutschland
E-mail data protectionprivacy@agentspectre.eu
E-mail in generallegal@agentspectre.eu
Telephone+49 1556 528 3042
Data Protection OfficerA data protection officer is not separately named in the imprint information provided. Please address data protection requests to: privacy@agentspectre.eu.
EU representatives according to Art. 27 GDPRNot applicable, as the operator is resident in Germany according to the information provided.

2. Short review

  • Spectre does not read email passwoerters. The connection takes place via OAuth or provider-related interfaces.
  • Mailbox scans can process senders, subject lines, data and snippets. Relevant signals can be transmitted to backend and AI services; processing is not exclusively local.
  • Response and organization functions can also process message content. Stored process data supports, among other things, the request history and the processing of requests.
  • Loeshan questions are only created or sent after user action. Organizations can refuse or arrest deletions if there are legal retention requirements or exceptions.
  • Payment data is processed by Stripe; Spectre receives payment status, tariff and billing references, but no full card data.

3. Processing claims, purposes and legal bases

Process Data categories Purpose Legal basis
Website provision IP address, time, URL, user agent, technical log data Delivery, security, error analysis, anti-abuse Art. 6 para 1 lit. f GDPR (legitimate interest in secure operation)
Account and login Name, e-mail address, provider ID, profile picture if provided by the provider, tariff, user number Investment, authentication, tariff management, provision of booked functions Art. 6 para 1 lit. b GDPR (contract / pre-contractual measures)
OAuth connection to mail providers OAuth tokens, provider ID, e-mail address, permissions, token expiration data Authorized access to mailbox metadata and authorized sending of requests Art. 6 para 1 lit. b GDPR; insofar as consent for access/final processing is required: Art. 6 para 1 lit. a GDPR and § 25 TDDDG
Mailbox scan sender, subject, date, provider metadata, if applicable. Snippets if technically delivered, recognized organizations, confidence, category Identification of possible accounts, providers and data protection contacts Art. 6 para 1 lit. b GDPR; for optional AI support if applicable. Art. 6 para 1 lit. a GDPR
AI-backed identification and design Minimized account signals, organization name, domain, sender address, language, draft text, references Recognition of data holders, formulation of Art. 17 / DSAR-oriented requests, DPO contact search Art. 6 para 1 lit. b GDPR; with optional use of external AI services depending on the configuration Art. 6 para 1 lit. a or lit. f GDPR
Send requests Name, e-mail address, target organization, recipient address, subject, request content, sending time, status, protocol ID Exercise of data protection rights against third parties and proof for users Art. 6 para 1 lit. b GDPR
Payments Stripe customer ID, checkout ID, payment status, tariff, invoice data if submitted Payment processing, fraud prevention, accounting Art. 6 para 1 lit. b GDPR; Art. 6 para 1 lit. c GDPR for legal storage obligations
Support and Legal Requests Contact details, communication content, technical diagnostic information, processing status Replying to requests, correcting errors, exercising rights Art. 6 para 1 lit. b, lit. c or lit. f GDPR depending on request
B2B / DPO agent functions Organization account, domain, DPO mailbox data, incoming requests, SLA status, audit and Witness logs, API locket metadata Data protection workflow, DSAR/Loeschqueue, audit proof, API integration Art. 6 para 1 lit. b GDPR; Art. 6 para 1 lit. f GDPR for security and proof functions

4. Mailbox and OAuth data

Spectre only requests the permissions required for each function. Depending on the provider, the following scopes or equivalent rights can be used:

  • Gmail: gmail.readonly for header-oriented analysis, gmail.send for user authorized shipping.
  • Microsoft / Outlook: Mail.Read and Mail.Send.
  • Yahoo, GMX, Web.de, iCloud or other IMAP-/SMTP-based providers: provider-dependent read and broadcast rights.

If providers technically provide snippets or subject lines, they can be processed for recognition and prioritization. In response and organization functions, message content can also be processed. Stored process data is used, among other things, to process and document requests.

Users can revoke OAuth accesses at any time at the respective provider. After that, affected functions can no longer be executed until a new authorization takes place.

5. AI support

Spectre can use AI services to identify organizations, research DPO or privacy contacts, create language and jurisdiction, and prepare for privacy requests.

Data is minimized. No full mailbox dumps, e-mail passwoerters or attachments to AI services should be submitted. Depending on the function, however, sender address, domain, subject, date, organization name, category, language, draft content and source URLs can be processed.

AI results are operational propositions, not legal advice. Users check recipients, content and shipping themselves.

6. Recipients and processors

Personal data may be transmitted to the following categories of recipients, insofar as this is necessary for the respective function:

Recipient/ServiceRolePurposeStatus
Static hosting / serverless functionsProcessorsProvision of the website, OAuth callbacks, checkout functions, API routes, security protocols and protection against abuseThe live configuration must comply with this declaration and the respective processing contracts.
AppwriterProcessorsAccount, database, user, request history, if applicable. DPO queueProvided in the application code for account, database and queue functions; region and contract must conform to the productive configuration.
StripeOwn controller or processor depending on the payment transactionPayment processing, fraud prevention, settlement, payment statusOnly for paid plates / checkout.
Google APIs / GmailOwn provider of the user accountOAuth, mailbox access, shippingProvider data protection notices apply additionally
Microsoft Graph / OutlookOwn provider of the user accountOAuth, mailbox access, shippingProvider data protection notices apply additionally
Yahoo / GMX / Web.de / iCloud or other mail providersOwn account providersOAuth, IMAP/SMTP or provider-related mail functionsProvider data protection notices apply additionally
AI service, if activatedProcessor or own provider depending on the contract setupMinimized mailbox signals for identification, contact search, voice and design supportOnly if the respective function is activated in the productive environment.
Target organizations / DPO contactsOwn responsible personsReception and processing of the request sent by the userOnly after user approval / shipping action

7. Third country transfers

Some service providers may process personal data outside the EU/EEA, especially in the USA. Where necessary, we base such transfers on adequacy decisions, the EU-U.S. Data Privacy Framework, standard contractual clauses according to Art. 46 GDPR or express consent. The productive provider and region configuration must match this explanation.

8. Browser storage, cookies and TDDDG

Spectre can use technically necessary inputs into local storage, session storage or comparable end-devices, for example for login status, OAuth-State/PKCE, language setting, tariff status, security recommendations and temporary storage of running scans.

Access to final information takes place for absolutely necessary functions on the basis of § 25 para 2 TDDDG. For non-necessary storage, analysis or marketing cookies, a prior consent according to § 25 para 1 TDDDG and Art. 6 para 1 lit. a DSGVO must be obtained. This page assumes that no unnecessary marketing or tracking cookies are currently used. If such tools are added, this explanation and consensus mechanism must be updated.

9. Storage periods

DataStandard period
Server and security logsUp to 30 days, longer only in case of security or legal enforcement.
Account and tariff dataAs long as the account exists; thereafter deletion or blocking, insofar as no legal obligations conflict.
OAuth tokensAs long as the mailbox is connected or until revocation, logout, token expiration or account deletion.
Scan results and identified data holdersAs long as they are required for the user review or request history; cancellable via account/support process.
Transit logs and request historyAs long as required for proof, performance of the contract or legal defence; regular verification after 24 months.
Payment and billing dataAfter legal trading and tax periods, regularly up to 10 years.
Support communicationsUp to 24 months after conclusion, longer for ongoing legal or security cases.

10. Data subject rights

In accordance with the GDPR, affected persons have the following rights in particular:

  • Information according to Art. 15 GDPR
  • Correction according to Art. 16 GDPR
  • Deletion according to Art. 17 GDPR
  • Limitation of processing according to Art. 18 GDPR
  • Data transferability according to Art. 20 GDPR
  • Objection according to Art. 21 GDPR
  • Revocation of granted consents with effect for the future according to Art. 7 para 3 GDPR
  • Complaint to a data protection supervisory authority according to Art. 77 GDPR

Please address requests to: privacy@agentspectre.eu. The supervisory authority responsible for Bonn / North Rhine-Westphalia is particularly relevant for complaints: State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia.

11. Security

We use technical and organizational measures to protect personal data against loss, misuse, unauthorized access and unauthorized disclosure. This includes transport closure, OAuth-based authorization, access restrictions, server-side secret management, protocol minimization and role-based access controls for organization functions.

No Internet service can guarantee absolute security. Security issues are assessed and reported in accordance with Art. 33 and 34 GDPR.

12. Changes

This data protection declaration is adapted when functions, service providers, legal bases or legal requirements change. The current version is under /datenschutz.html retrievable.