> Privacy Protocol
Last updated: September 24, 2026
This document outlines how Spear Systems collects, processes, and protects information within our infrastructure. Review this protocol before accessing our services.
It applies to this website (spear.systems) and to the Spear platformat platform.spear.systems, including the analyses you submit there, the reports produced from them, and the account you use to reach them. Where this protocol refers to "the Service", it means both.
> Definitions
> Data Collection
Client Information
When engaging with our services as a B2B client, we may collect:
- Email address
- Name (first and last)
- Phone number
- Company name
- Billing address
- Usage data
Platform Account Data
When you create an account on the Spear platform, we collect your email address, your name, your organization's name, and the role you hold within that organization (owner, admin, or member). We also record the times you sign in and the actions you take in the console, including analyses you request, credit purchases, and API keys you create.
Creative Content You Upload
The platform analyses advertising creatives. When you submit one, we store the file you upload (video or image), along with any brief, notes, or context you attach to it, and we associate it with your organization. You should not upload material you have no right to submit.
Analysis Output
Each submission produces a report — scores, panels, risk flags, transcripts, timelines, and a record of the model calls made to generate them — which we store alongside the creative so that you can revisit and compare results.
Automatic Collection
Usage data is collected automatically when accessing the Service, including: device IP address, browser type and version, pages visited, visit timestamps, time spent on pages, and device identifiers.
Tracking Technologies
We utilize cookies, beacons, tags, and scripts to monitor activity and improve service delivery. You may configure your browser to refuse cookies, though this may limit functionality.
> Sign-In Providers
You may sign in using an account you already hold with a third-party identity provider rather than creating a Spear password. We support Google and Microsoft.
What We Receive
When you choose this option, the provider confirms who you are and shares a limited set of data with us:
- Your email address
- Your name, as held by that provider
- Your profile picture, where the provider supplies one
- A provider-specific account identifier, so we recognise you on later sign-ins
We never receive your provider password, and we cannot access any other data held in your provider account.
How We Use It
Sign-in data is used only to authenticate you and to associate your provider identity with your Spear account. Where the provider reports a verified email address that matches an existing account, we link the two so that either sign-in method reaches the same account and the same data. Information received through sign-in is never used for advertising or profiling, and is never sold.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used solely to provide the sign-in functionality described in this section.
Your Control
You can revoke our access at any time from your provider's own settings — for Google, under Security → Third-party apps & services; for Microsoft, under the My Apps page. Revoking access stops future sign-ins by that method, but does not by itself delete your account or the data already held under it.
What We Do Not Do With Google User Data
Information received from Google is used only to provide and improve the sign-in functionality described above. Specifically, we do not:
- use it for targeted, personalised, retargeted, or interest-based advertising, or for any user advertising;
- sell it, or provide it to data brokers or information resellers;
- use it to determine credit-worthiness, or for lending purposes;
- use it to build databases for any of the purposes above;
- transfer it to any third party for any of the purposes above; or
- use it to develop, improve, or train generalised, non-personalised artificial-intelligence or machine-learning models.
The platform does not use Google Workspace APIs. Our integration with Google is limited to the OpenID Connect sign-in flow described in this section, and we request no other Google scopes.
> Data Processing
Your information is processed for:
- Service maintenance: Monitoring and maintaining operational infrastructure.
- Account management: Managing registration and authenticated access.
- Delivering the platform: Accepting the creatives you submit, producing the analysis you request, storing the results, and returning them to you.
- Transaction processing: Processing payments, fulfilling orders, generating invoices.
- Communications: Contacting you regarding updates, security notices, and contracted services.
- Marketing: Providing news, offers, and service information (opt-out available).
- Request handling: Responding to your inquiries and support requests.
- Safety and abuse prevention: Detecting misuse, enforcing our terms, and protecting the Service and its users.
Legal Bases
Where the GDPR or an equivalent law applies, we rely on these bases:
- Performance of a contract: to provide the Service you have signed up for, including producing your analyses and administering your account and credits.
- Legitimate interests: to secure the Service, prevent abuse and fraud, and maintain and improve our infrastructure — balanced against your rights, and you may object at any time.
- Consent: for marketing communications, and for any optional feature that asks for it. You may withdraw consent at any time.
- Legal obligation: to keep records required by tax, accounting, and other applicable law.
Automated Analysis
To generate findings and report text, DORU-1 may send analysis prompts and relevant text, selected image frames, or audio from your creative to Google's Gemini API. Google's data handling depends on the applicable API service tier. Under Google's unpaid-service terms, it may use submitted content and responses to improve its products, and human reviewers may process them. Under its paid-service terms, Google does not use prompts or responses to improve its products, but may temporarily log them for abuse monitoring. Which terms apply depends on the Google Cloud project associated with our API key. See Google's Gemini API terms and data-retention guidance. We do not promise zero data retention. DORU-1 produces advisory output about advertising material. It does not make decisions about you as an individual, produce legal effects, or profile you. Scores are estimates, carry uncertainty, and remain yours to accept or reject.
> Data Retention
We keep your information only for as long as we need it for the purposes above:
- Account data is retained while your account is active and for a reasonable period afterwards, so that we can meet legal, accounting, and dispute-resolution obligations.
- Creative content and analysis output are retained while your account is active. To request deletion of your account and the content and results held under it, emailrandy@spearleads.com from the address associated with your account, or use our contact form. We verify the request before deletion. Billing records and other information we must keep by law are not removed by an account-deletion request.
- Billing records are retained for the period required by tax and accounting law.
- Server and security logs are retained for a limited period and then discarded.
Backups are taken on a rolling cycle, so a deletion may persist in a backup for a short period before that backup is itself overwritten. Backups are not used to restore individual deletions.
> Data Sharing
We do not sell your personal information, and we do not share it for advertising. We disclose it only in the circumstances below.
Service Providers
The following external services support specific parts of the platform:
- Cloudflare — hosting, content delivery, and network protection for our websites and services, plus R2 object storage for submitted creative files.
- Google Gemini API — receives analysis prompts and relevant creative content to generate DORU-1 findings and report text. Its data-use and retention terms vary by API service tier, as described above.
- Translation providers — from time to time, we may use third-party translation services to render report text in English. These providers may receive report text only.
- Stripe — payment processing. Card details are entered directly with Stripe and never reach our servers.
- Resend — delivery of transactional email such as confirmations and password resets.
Legal Compliance
We may disclose your information where required by law, or in response to a valid subpoena, court order, or government request. Where we are permitted to do so, we will tell you.
Business Transfers
If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will give notice before your information becomes subject to a different privacy policy.
Affiliates and Group Companies
We may share information with organizations under common ownership, which are bound by this protocol.
> Security
We protect your information with measures including:
- Encryption in transit (TLS) for all traffic to our websites, console, and APIs.
- Passwords are never stored by us in readable form — authentication is handled by a dedicated identity service which stores only salted one-way hashes.
- Credentials and API keys for our own infrastructure are held in an encrypted secret store, not in source control.
- Data is isolated per organization at the database layer, so one customer's records cannot be read through another's session.
- Production data is backed up on a schedule, and write access to production systems is limited to those who need it.
- We review activity logs and monitor for abnormal access.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any relevant regulator as required by applicable law.
> Children's Privacy
The Service is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.
> Lead Data Disclaimer
This Privacy Protocol does not apply to the personal information of individual "leads" delivered through our services. Lead data is generated through separately operated brand properties with distinct privacy policies governing collection, use, and consent.
> Governing Law
This protocol is governed by the laws of New South Wales, Australia, excluding conflict of law provisions.
Dispute Resolution
Any disputes regarding privacy should first be addressed informally by contacting the Company.
EU User Rights
European Union users retain rights under the General Data Protection Regulation (GDPR) and applicable member state laws.
Australian Privacy Rights
As an Australian entity, we comply with the Privacy Act 1988 and Australian Privacy Principles (APPs). You may:
- Access personal information we hold about you
- Request correction of inaccurate information
- Lodge complaints regarding APP breaches
> Protocol Updates
We reserve the right to modify this protocol at any time. Material changes will be communicated with 30 days notice. Continued use after updates constitutes acceptance of revised terms.
> Contact
Email: randy@spearleads.com
Mail: 5 Bronte Cl, Wetherill Park NSW 2164, Australia
Registered business: RANDY BAYNOKA (ABN 96971740501)