Privacy policy
Last updated · 2026-07-15 · applies to all SpecRecord services
What we collect. Account email + name. For installers: NWFA cert number, installer profile data, and every job you record (fields, photos, signatures, sensor readings). For homeowners: properties you claim + who you invite. For manufacturers: brand aliases + contact email. For suppliers: chain-of-custody records the same way installers record installs. We do not sell or rent personal data. We do not run any third-party analytics scripts in the dashboards.
Who can see a record
A SpecRecord is private by default. Knowing an address, certificate slug, or QR URL does not grant access. The list below is the whole audience — nobody else sees it.
Private (your tenant only). Drafts before lock, private vendor invoices, crew notes, unmerged photo uploads, and internal daily-recap emails. Only members of your tenant (installer company, supplier org, manufacturer account) can see these, and only through their signed-in dashboard.
Shared with authorized property parties. When a job is locked, invited property owners and job participants can accept a secure transfer and view it from their signed-in workspace. QR codes take the viewer to sign-in; they are references, not bearer credentials.
Not available through public search. Address lookup, record details, evidence photos, readings, signatures, and PDFs require an authorized account. The cryptographic fingerprint may be independently verified without exposing the underlying job data. Vendor invoices, cost data, and crew notes remain tenant-only.
Inspector access
An inspector account does not provide platform-wide lookup. When an NWFA inspector, insurance adjuster, or arbitrator needs a record for an active issue, they must request access for that specific claim and property.
Request and review. The request includes the inspector's identity, credential, claim number, and property. SpecRecord or the record owner verifies the request before granting read-only access. Requests and access are audited.
No cross-customer browsing. Inspectors cannot search or retrieve other customers' records merely because they have an inspector role. Until the grant workflow is automated, requests are handled through the Off-Record request page.
Immutability & deletion
Locked records are immutable by design — their content hash is HMAC-sealed at lock and submitted to OpenTimestamps for Bitcoin anchoring (typically confirmed within hours, sometimes longer). Personal data captured in the record (customer name, installer name, property address) becomes part of the sealed evidence once locked and cannot be rewritten retroactively. Drafts can be deleted before lock; sealed records cannot, because rewriting them would defeat the whole point of the seal.
If a locked record contains a factual error, the path is to file a corrective record (referenced from the original) rather than modify the original — the same way a paper trail works. Email privacy@specrecord.com for help with corrections.
Cookies
One httpOnly session cookie for signed-in users. One cookie each for locale preference and acting-user preference (only used when a tenant admin is acting on behalf of another member of their org). No third-party trackers.
Subprocessors
Railway (hosting), Cloudflare R2 (object storage for photos + PDFs), Postgres on Railway (data), OpenTimestamps Calendar / Bitcoin network (anchoring), Anthropic API (adhesive cut-sheet parsing + optional record-summary generation — content of records is sent to Anthropic only when tenants opt in; retention is bounded per Anthropic's zero-retention policy).
Your rights
Email privacy@specrecord.com to request access, export, or deletion of your account. We respond within 30 days. Sealed records and their Bitcoin anchors cannot be deleted (see above), but the underlying drafts, tenant admin metadata, and account-level PII can be removed on request.