spacesheep

Privacy policy

Last updated 1 September 2026

spacesheep publishes pages you (or your AI agent) create, and hosts the conversations around them. This page describes exactly what that means for your data. Questions: support@spacesheep.dev.

What we store

DataWhyWhere
Your email address, a username and profile you choose, and a salted hash of your password if you set oneIdentifies your account, your URL namespace, who a space is shared with, and lets you sign in without Google. The hash cannot be reversed — we never see your passwordCloudflare D1
The files of every space you deploy, and their version historyThey are the product — a space is served from what you deployedCloudflare R2
Space metadata: title, description, visibility tier, org, access list, comments and reactionsDashboard, access control, and the conversation on a pageCloudflare D1
Messages you exchange with the agent, on the web or through a connected surface (Telegram, Slack, iMessage/SMS)The agent needs the thread to answer in contextCloudflare D1 and Durable Objects
Secrets you save (API keys, tokens) and API keys you or a connected app mintRun worker-mode spaces and authenticate clients. Secret values are never returned by the API, and are redacted from responses that would leak themCloudflare D1
Product analytics: page views and feature events, tied to your accountUnderstanding what people actually useMixpanel
Request logs (paths, status codes, timings)Debugging and abuse handling. Retained about 30 daysCloudflare

Who else processes it

We do not sell personal data, and we don't use your space content to train models.

Who can see a space

Visibility is yours to set, per space: Private (you and people you name), Members (an invite-only list), Public (anyone with the link, and search engines may index it). Public means public — don't publish anything there you wouldn't put on the open web. Comments are visible to everyone who can see the space.

Connected apps

When you authorize a client — Claude, ChatGPT, Grok, a local agent — through OAuth, it acts as you: it can read, deploy, and share your spaces. Each connection appears in Settings and revoking it there cuts off that client's access.

Retention and deletion

Spaces, comments, messages and secrets are kept until you delete them. Deleting a space removes its files and versions. To delete your account and everything attached to it, email support@spacesheep.dev from the address on the account; we action it within 30 days. Backups and logs age out on their own schedules (about 30 days).

Your rights

You can ask for a copy of your data, correction of it, or its deletion, at the address above. If you're in the EEA or UK, the legal basis for processing is performing the contract you signed up for, plus a legitimate interest in keeping the service working and free of abuse.

Children

spacesheep isn't intended for anyone under 13, and we don't knowingly collect their data.

Changes

If this policy changes materially, the date at the top changes and we'll say so in the changelog.