Privacy policy
Last updated: October 7, 2026
This policy explains what Specificity collects, why, who it shares it with, and the choices you have. It covers usespecificity.com and the Specificity app at app.usespecificity.com.
Who we are
Specificity is run by Matthew Lin, doing business as Specificity, in Wisconsin, United States ("Specificity", "we", "us"). Questions go to support@usespecificity.com.
What we collect
- Account details: your email address and name, and the session information Clerk, our sign-in provider, uses to keep you signed in.
- What you put in Specificity: tasks, notes, comments, files, your Library, and your teams and projects. When you invite someone, we keep their email address so the invite can reach them.
- Records of AI use: for each AI request, who made it, which feature or agent, the model, the number of tokens, the cost, and whose settings allowed it. We also keep a history of changes to your AI settings, including privacy mode.
- Technical records: our hosting provider's logs of requests to our servers, which include IP addresses, browser details and the addresses requested.
- On usespecificity.com only, and only if you accept: Google Analytics information about your visit, such as the pages you view, how you arrived, your browser and device, and your approximate location.
- Messages you send to support.
We don't collect payment information. Specificity doesn't charge today.
How we use it
- To run Specificity: sign you in, store and sync your work, show it to the people you share it with, and send invites.
- To run the AI tools you turn on (below).
- To keep Specificity safe: limits that stop abuse, checks that block sensitive data, and looking into misuse.
- To answer you when you contact us.
- To see how visitors use usespecificity.com, if you accept analytics.
- To meet legal obligations.
We don't sell your personal information or use it for advertising.
AI tools and privacy mode
The first time you sign in, you choose AI on or privacy mode, and you can change it any time in Account. In privacy mode, nothing you do is sent to any AI model, and anything already running stops. With AI on, each tool has its own switch: Suggestions, Brain Dump review, Ask, Update drafts, each of the six agents, web search, and teams' own agents.
When a tool you've turned on runs, it sends Anthropic, the maker of Claude, the content that tool needs, such as a task's title and notes, the tasks around it, and files on it. Each tool's card in Account lists what it reads. On a team, an agent runs only when both the task's owner and the person who put it to work allow it. Tasks labeled No AI are never sent.
Anthropic says it deletes API inputs and outputs within 30 days, unless they're flagged for breaking its usage policy (then it can keep them up to 2 years), and that it doesn't use them to train its models by default (how long data is kept; model training). When an agent works with files, they go to Anthropic's Files API and code execution container while it runs. We delete them when the run ends, or at once when you turn AI off, and an hourly check removes any left behind. The container can keep data up to 30 days (code execution). The Research Analyst's web search sends search queries through Anthropic to a public search engine. It's instructed to search only for the general question, never names or internal details. Tasks labeled Internal or Restricted never use the web.
AI output can be wrong. Check it before you rely on it.
Who we share it with
- Service providers who run parts of Specificity for us: Clerk (sign-in and invite emails), Replit (hosting, our database and file storage), Anthropic (the AI tools you turn on), and Google (analytics on usespecificity.com, only if you accept).
- People you work with: teammates see your team's work, and other teams in a project see work linked to theirs. Tasks labeled Internal or Restricted show only to the people they're for.
- Anyone the law requires us to tell, or when it's needed to protect someone from harm.
- A new owner, if Specificity is sold or merged. They must follow this policy for information already collected.
Sensitive information
Don't put patient information or other sensitive identifiers in Specificity. The app refuses Social Security numbers, valid payment card numbers, and values labeled MRN or date of birth, and it checks uploaded files. Files it can't read, such as images or scans, need you to confirm they hold no sensitive data, and we keep a record of that confirmation.
How long we keep it
- Your work stays until you delete it or your account. Removed files can be restored for 30 days, then they're deleted.
- Deleting your account (Account, then Delete account) signs you out at once. Teams you led pass to a new lead, and your open team tasks become unassigned. Your own work is kept for 7 days, so you can change your mind by signing in, and is erased within the hour after that.
- Work you did on teams with other people stays with those teams, shown as "Deleted user" once your account is erased.
- Database backups can hold erased data for up to 7 days.
- Anthropic keeps AI inputs and outputs up to 30 days, except as described above.
- Google Analytics keeps visit data linked to your browser for 2 months. Its summary reports, which don't identify you, are kept longer.
- Our hosting provider keeps request logs for 30 days.
We don't currently offer a downloadable copy of your data.
Your choices
- Turn AI tools, or any one tool, on or off in Account.
- Accept or decline analytics on usespecificity.com when the site asks.
- Delete your account in Account.
- Ask what personal information we hold about you, or ask us to correct or delete it, by emailing support@usespecificity.com.
Security
Our database keeps each person's and each team's data apart with row-level security, connections are encrypted, and the app checks permissions on every request. No system is perfectly secure, and Specificity doesn't hold a security certification such as SOC 2 yet.
Children
Specificity is for people 18 and older. We don't knowingly collect information from anyone younger. If you think a child has signed up, email us and we'll delete the account.
Where data is processed
Specificity and its providers process data in the United States.
Changes to this policy
We'll post changes here with a new date. If a change affects how we use your information, we'll tell you in the app or by email before it takes effect.