Last updated 1 September 2026
spacesheep publishes pages you (or your AI agent) create, and hosts the conversations around them. This page describes exactly what that means for your data. Questions: support@spacesheep.dev.
| Data | Why | Where |
|---|---|---|
| Your email address, a username and profile you choose, and a salted hash of your password if you set one | Identifies your account, your URL namespace, who a space is shared with, and lets you sign in without Google. The hash cannot be reversed — we never see your password | Cloudflare D1 |
| The files of every space you deploy, and their version history | They are the product — a space is served from what you deployed | Cloudflare R2 |
| Space metadata: title, description, visibility tier, org, access list, comments and reactions | Dashboard, access control, and the conversation on a page | Cloudflare D1 |
| Messages you exchange with the agent, on the web or through a connected surface (Telegram, Slack, iMessage/SMS) | The agent needs the thread to answer in context | Cloudflare D1 and Durable Objects |
| Secrets you save (API keys, tokens) and API keys you or a connected app mint | Run worker-mode spaces and authenticate clients. Secret values are never returned by the API, and are redacted from responses that would leak them | Cloudflare D1 |
| Product analytics: page views and feature events, tied to your account | Understanding what people actually use | Mixpanel |
| Request logs (paths, status codes, timings) | Debugging and abuse handling. Retained about 30 days | Cloudflare |
We do not sell personal data, and we don't use your space content to train models.
Visibility is yours to set, per space: Private (you and people you name), Members (an invite-only list), Public (anyone with the link, and search engines may index it). Public means public — don't publish anything there you wouldn't put on the open web. Comments are visible to everyone who can see the space.
When you authorize a client — Claude, ChatGPT, Grok, a local agent — through OAuth, it acts as you: it can read, deploy, and share your spaces. Each connection appears in Settings and revoking it there cuts off that client's access.
Spaces, comments, messages and secrets are kept until you delete them. Deleting a space removes its files and versions. To delete your account and everything attached to it, email support@spacesheep.dev from the address on the account; we action it within 30 days. Backups and logs age out on their own schedules (about 30 days).
You can ask for a copy of your data, correction of it, or its deletion, at the address above. If you're in the EEA or UK, the legal basis for processing is performing the contract you signed up for, plus a legitimate interest in keeping the service working and free of abuse.
spacesheep isn't intended for anyone under 13, and we don't knowingly collect their data.
If this policy changes materially, the date at the top changes and we'll say so in the changelog.