← Back to SpecBrief
Privacy & data handling

What happens to your tender documents

Last updated 27 August 2026. This describes how the system actually works today, not a boilerplate template. It is rewritten whenever the system changes, and it is checked against the code rather than from memory.

Who's behind this: SpecBrief is operated by SpecBrief Pty Ltd (ABN 31 701 788 856), an Australian proprietary company registered in New South Wales. Want to know exactly who you are dealing with before you send anything? Ask at the address below and you will get a straight answer.

Where SpecBrief runs

Three separate places, and they are worth keeping apart in your head.

So: processing happens in the United States, and the brief is stored in Australia. If Australian-only processing is a condition of your work, say so before you send anything and you will get a straight answer about whether SpecBrief can meet it today.

What SpecBrief collects

SpecBrief does not need sensitive personal information. Tender packs can still contain names, signatures, email addresses and phone numbers as part of the job. Please do not add personal information that the pack does not need.

The app sets one session cookie once you sign in. It keeps you signed in and protects the forms against cross-site posting. There is no advertising cookie and no third-party tracker on any SpecBrief page.

How your documents get read

SpecBrief reads each document's text. Drawing-image reading is off in production today, so no drawing page image is sent to a vision provider. That is what your brief gets built from. Every number in it — carbon-cap feasibility, volumes, conflict checks — is worked out in SpecBrief's own code. None of that is asked of the AI model. The model reads. The code calculates.

The model provider is Google Gemini, on Google's paid tier. You can check which provider the live service is using yourself — specbrief.onrender.com/healthz names it, and today it answers gemini. This page previously named a different provider and said no model was connected; both were out of date and were corrected on 26 August 2026. The section below is the one that governs.

No customer document has been sent to the model from the live service. Unlike the sentence above, that one is not something this page can prove to you: /healthz reports which provider is configured, not what has been read. It is a statement by SpecBrief, true as at 26 August 2026, and it will be taken down the day it stops being true rather than quietly left standing.

Your document text is sent to the Gemini API. SpecBrief uses the API on a billed account, not a consumer chat app, and that distinction is the whole point — Google's terms for its two tiers are opposites. Google's own published terms say:

That is Google's contractual commitment, not something SpecBrief's code can enforce. It is quoted here so you can read the source rather than take our word for it. If the provider ever changes, this page names the new one before a customer document is sent to it.

The sample brief

The sample and demo buttons on the marketing site take you off that site to specbrief.onrender.com/demo. Worth knowing what that is and is not.

Caching, so you are not billed twice

So an AI provider is not paid twice to read the same document, the extracted result is cached on the app server, keyed to that document's content. The cache holds extracted values, not your file.

There is no scheduled expiry on that cache. Nothing in the code deletes it on a timer, and this page will not pretend otherwise. What limits it instead is the host: the app runs with no persistent disk, so the cache lives on the instance's own temporary filesystem and is wiped every time the service restarts or redeploys. Nothing in it survives a deployment. If you want a specific document's cached extraction cleared sooner, ask and it will be cleared.

Storage & retention

One caveat on kept packs. Retained packs are written to the app host's own disk, and that host currently has no persistent disk. A restart or a redeploy would lose them. Retention is off by default and is not sold today, so nothing is quietly at risk. Treat a kept pack as a convenience, not as an archive, until this page says otherwise.

Confidentiality

SpecBrief does not sell your documents. These are the current services that receive customer or account information to operate the service:

The Vercel marketing site does not receive tender uploads. The published Gmail address is for enquiries and support only; SpecBrief does not accept tender packs by email. Information is also handed over where the law requires it.

Your choices

Ask what is held on you, or ask for it to be deleted. The email address is below.

This is a plain description of how things work right now, not legal advice. If you handle personal information at volume, you may have obligations under the Privacy Act 1988 (Cth). A solicitor has not reviewed this note yet.

← Back to SpecBrief