Privacy Policy
Effective Oct 8, 2026 · Version 2026-10-08--01
This policy explains how Squaaads Design Services Inc., doing business as Jam (“Jam”, “we”, “us”) handles personal information in connection with Spell — our public site, the waitlist, walkthrough bookings, and the Spell instances we run for studios. If you are in a particular region, the Regional Privacy Supplement adds to it.
1. Who decides what happens to your information
Jam decides for information about visitors to our public pages, people who join the waitlist or book a walkthrough, and the administrators who manage a studio’s relationship with us. For that information we are responsible as the “controller” (or the organization accountable for it).
The studio decides for everything inside its Spell instance — its team, contractors, clients, candidates and their work. There, we act as the studio’s service provider (a “processor”) and handle the information only on its instructions. If you are a studio’s client, contractor or candidate, the studio’s own privacy notice applies, and questions about that information are best sent to the studio; we will help it answer.
2. What we collect
When you join the waitlist
Your email address and, if you add them, your studio’s name and team size, plus which form you used. To stop abuse we also record your network (IP) address and email for at most a day, then delete them.
When you book a walkthrough
Bookings are made through Calendly, which collects your name, email and any answers you give, under its own privacy policy. We receive those details to hold the meeting.
When you use a Spell account
Your name, email address, role, handle and profile picture, and the sign-in method you use — a password, which is stored only as a secure hash, or your Google account’s name, email and picture.
What a studio puts into its instance
Clients and their contacts; engagements, projects, tasks, comments and files; hours, rates and costs; contracts, signatures and their audit trail; meeting notes and transcripts; job applications, résumés, interview notes and evaluations; invoices, payables and expenses; and conversations with Astra. When a document is signed in Sign, the audit trail records the signer’s name, email, network address, browser details and the time of each step, including each view.
Connected services
If a studio connects Slack, Dropbox, Google, Xero or Hubdoc, Spell keeps the access tokens it needs and exchanges data with those services within the permissions granted.
Technical information
Our hosting providers keep request logs (network address, browser, pages and times) to run and protect the Service. Each instance keeps an audit log of changes and usage figures its administrators can see. Cookies and browser storage are described in our Cookie Policy.
3. How we use it
- To provide Spell, operate each instance and keep it secure.
- To answer the waitlist, arrange walkthroughs and onboard studios.
- To send the emails Spell sends — invitations, notifications, signature requests and reminders.
- To support studios, investigate problems and prevent abuse.
- To improve Spell, using information about how the product is used rather than the content of your work.
- To meet our legal obligations and enforce our agreements.
4. Astra and artificial intelligence
Astra is off unless a studio switches it on. When someone uses an Astra feature, the question and the content needed to answer it — and any file they attach — are sent to our AI provider, Anthropic, which processes it to produce the answer. Anthropic’s commercial terms do not permit it to train models on that content, and we do not train models on it either.
Astra reads the instance with the permissions of the person asking, so she cannot show anyone more than they could already see. Client research uses web search to gather public information about businesses, at an administrator’s request. Feedback people give Astra is kept as rules inside the studio’s instance. Astra makes no decisions about people on her own: in hiring, her evaluation supports a person who decides.
6. No selling, no advertising
We do not sell personal information, share it for cross-site advertising, or use advertising cookies. If that ever changed, we would update this policy first and offer the choices the law requires.
7. Where it is stored
Each studio’s instance keeps its database and files in Canada (Montréal). Spell’s application code runs in the same region, and static parts of the site are served from a global network.
Some providers process information elsewhere — for example email delivery and Astra are handled in the United States. Where information leaves the country it was collected in, we rely on the safeguards the law requires, such as contractual protections.
8. How long we keep it
- Waitlist: until you ask us to remove you, or 24 months after you join if we have not onboarded your studio by then.
- Instance content: for as long as the studio uses Spell, then deleted as our Terms describe — 30 days to export, then deletion within a further 60 days.
- Job applications: deleted automatically a set number of months after the role closes — 12 by default, chosen by the studio for each role.
- Abuse prevention records: at most one day.
- Logs and backups: on our providers’ schedules, after which they expire.
9. How we protect it
Every studio has its own database. Access is enforced inside the database by row-level security on every table, so a person can reach only what their role allows. Information is encrypted in transit and at rest, changes are audited, and access by Jam’s team is limited to supporting and securing the Service. No system is perfectly secure; if a breach affects your information, we will notify you and the authorities as the law requires.
10. Your rights and choices
Depending on where you live, you can ask to see, correct, delete or export your personal information, object to or restrict some uses, withdraw consent, and complain to a privacy authority. Email hello@letsjam.design to make a request. We will verify that it comes from you, and reply within 30 days unless the law allows longer.
If your information is in a studio’s instance, we will pass your request to that studio, which decides how to answer it, and help it respond.
You can unsubscribe from any marketing email. Messages that are part of using Spell, such as invitations and notifications, are managed in Spell’s settings.
11. Children
Spell is a tool for businesses and is not meant for anyone under 16. We do not knowingly collect their information.
12. Changes to this policy
When we change this policy we will update the effective date above, and for significant changes we will tell studio administrators and waitlist members by email before they take effect.
13. Contact and privacy officer
Our Privacy Officer is responsible for this policy and can be reached at hello@letsjam.design. Squaaads Design Services Inc., doing business as Jam.