PRIVACY
POLICY.
Effective August 21, 2026 · Private AI, secure intake and authorized financial connectivity.
This Privacy Policy explains how Monroe Inc., doing business as SpektAI (“SpektAI,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information when you use SpektAI websites, private AI deployments, secure intake flows, account-connectivity features, AI-enabled services, and related services (collectively, the “Services”).
1. SCOPE
This Policy applies to personal information processed by SpektAI in connection with the Services. It does not replace a separate enterprise agreement, data processing agreement, nondisclosure agreement, or customer-specific privacy term that expressly governs a deployment.
Third-party websites and services have their own privacy practices. Their policies apply to information they process independently.
2. INFORMATION WE COLLECT
Depending on how you use the Services, we may collect:
- Contact and identity information, such as name, business contact information, organization, role, and information you provide during onboarding or support.
- Customer Content and source material that you submit, upload, send, connect, or authorize us to access, including files, messages, images, recordings, prompts, records, instructions, and other business information.
- Deployment and account information, including configuration, permissions, selected integrations, authorized tools, model choices, service status, and commercial records.
- Financial-account information that you choose to connect through Plaid or another authorized connectivity provider, such as institution, account identifiers, account type, balances, transactions, and other categories you expressly authorize.
- Payment and billing information. Payments for public SpektAI deployment products may be processed by Stripe or another payment provider. We generally receive transaction and customer information needed to administer the purchase, while payment-card credentials are handled by the payment provider according to its own policies.
- Device, security, and technical information, such as IP address, browser or device type, event timestamps, authentication events, security logs, error data, and similar information reasonably needed to operate and protect the Services.
- Communications and support information when you contact us, participate in a deployment, or communicate through an authorized SpektAI channel.
We do not ask you to provide information that is unnecessary for the Services you request. Please do not submit highly sensitive, regulated, privileged, or third-party information unless it is necessary for an authorized deployment and appropriate handling terms are in place.
3. FINANCIAL ACCOUNT CONNECTIONS AND PLAID
If you choose to connect a financial account, SpektAI may use Plaid Inc. (“Plaid”) or another authorized provider to facilitate the connection. Plaid Link manages the account-linking and authentication experience and may process information under Plaid’s own End User Privacy Policy.
The categories of financial data available to SpektAI depend on the Plaid products used, the financial institution, the accounts you select, and the permissions you grant. SpektAI uses connected financial data only for the authorized SpektAI functionality or deployment for which the connection was established and related security, support, and compliance purposes.
We do not intentionally request your online-banking password directly when the account connection is handled through Plaid or your financial institution.
You may be able to disconnect or change a financial account connection through the applicable financial institution, Plaid, or a SpektAI interface. Where an account is disconnected or an authorization is withdrawn, we stop requesting new data through that connection, subject to technical processing already underway and lawful retention of information previously received.
Plaid’s privacy information is available at https://plaid.com/legal/.
4. HOW WE USE INFORMATION
We use personal information to:
- provide, configure, personalize, and operate the Services you request;
- authenticate users, maintain authorized context, and enforce permissions;
- retrieve, index, organize, and process Customer Content and authorized source material;
- route authorized tasks to models, tools, infrastructure, and service providers;
- provide private AI deployments, support, maintenance, and troubleshooting;
- process purchases, maintain commercial records, and administer customer relationships;
- protect the Services, investigate security events, prevent fraud or abuse, and enforce agreements;
- comply with legal obligations and respond to lawful requests; and
- improve reliability, usability, security, and deployment methods using information we are permitted to use.
SpektAI does not sell Customer Content or personal information. SpektAI does not intentionally use private Customer Content to train a shared public AI model unless that use is separately disclosed and expressly authorized.
5. AI MODELS AND AUTHORIZED PROCESSORS
SpektAI is designed so that the SpektAI context, permissions, and source relationships remain separate from any single AI-model provider.
When an authorized model or processor is used, SpektAI may send the information reasonably needed to complete the requested operation. The exact provider and data handling can vary by deployment, configuration, and user authorization.
Where available and appropriate, SpektAI uses settings, contracts, or deployment patterns intended to limit third-party use of private deployment data beyond providing the requested service. No third-party system should be assumed to have zero risk, and customer-specific requirements may require additional contractual or technical controls.
6. HOW WE DISCLOSE INFORMATION
We may disclose personal information only as reasonably necessary to:
- service providers and processors that help host, secure, operate, support, communicate, process payments, connect accounts, or deliver the Services;
- AI-model, cloud, communications, storage, financial-data, and integration providers that are authorized for the relevant deployment or operation;
- professional advisers where reasonably necessary and subject to appropriate duties;
- governmental or legal authorities when required by law or necessary to protect legal rights, safety, or security; and
- a successor or transaction counterparty in connection with a merger, financing, reorganization, acquisition, sale of assets, or similar corporate transaction, subject to applicable law.
SpektAI may work alongside BFI Ventures, Schotz Enterprises, NMM, NewCo entities, or other affiliated or collaborating businesses. Those entities do not automatically receive SpektAI Customer Content merely because they appear in the same portfolio or website. Information is shared with another entity only when authorized, necessary for the requested relationship, or otherwise permitted by law.
7. PAYMENT PROCESSING
Public deployment purchases may be processed through Stripe. Stripe independently processes payment information under its own agreements and privacy practices. SpektAI does not need or intend to store complete payment-card credentials when Stripe provides the hosted checkout flow.
8. DATA RETENTION
We retain personal information for as long as reasonably necessary for the purpose for which it was collected, to provide and secure the Services, maintain source and execution records required by the deployment, comply with law, resolve disputes, and enforce agreements.
Retention periods may differ by information type, deployment, source, contractual requirement, and legal obligation. Where a customer-specific retention schedule applies, that schedule controls for the covered data.
When information is no longer required, we may delete, de-identify, or securely archive it as appropriate. Backup, security, audit, and legal-hold copies may remain for a limited period after active deletion where reasonably necessary.
9. SECURITY
SpektAI uses administrative, technical, and organizational measures intended to protect information against unauthorized access, disclosure, alteration, loss, and misuse. Controls may include access restrictions, encryption or secure transport where appropriate, authentication, logging, separation of environments, bounded permissions, and source or execution provenance depending on the deployment.
Our secure intake is designed to route deployment information into controlled SpektAI/BFI operating infrastructure rather than collecting sensitive onboarding material in public checkout fields.
No method of transmission, storage, hosting, network protection, or AI processing is completely secure. We therefore do not promise absolute or “unhackable” security.
10. YOUR CHOICES AND RIGHTS
You can choose not to provide information, although some Services may then be unavailable.
You may request access, correction, deletion, or other action regarding personal information that SpektAI controls by using the SpektAI contact route on the BFI Ventures website. Depending on your jurisdiction and our relationship with you, additional rights may include portability, restriction, objection, appeal, or withdrawal of consent.
If SpektAI processes information solely on behalf of an enterprise customer, that customer may be the appropriate party to handle your privacy request, and we may route your request to that customer.
For connected financial accounts, you may also use controls made available by Plaid or your financial institution to manage or revoke account access.
SpektAI does not sell personal information and does not use personal information for cross-context behavioral advertising.
11. CHILDREN
The Services are intended for adults and business users. We do not knowingly offer the Services directly to children under 13 or knowingly collect personal information from children under 13 through the public Services.
12. INTERNATIONAL PROCESSING
SpektAI is based in the United States. Information may be processed in the United States or other jurisdictions where authorized providers operate. Where required, we will use appropriate contractual or legal mechanisms for cross-border processing.
13. CHANGES TO THIS POLICY
We may update this Policy as the Services, legal requirements, or data practices change. The Effective Date identifies the current version. If a change materially affects how we use previously collected personal information, we will provide notice where required by law.
14. CONTACT
Privacy questions or requests may be submitted through the SpektAI contact route available on the BFI Ventures website while the standalone SpektAI domain is unavailable.
Monroe Inc.
d/b/a SpektAI
United States