Legal

Usage Policy

Effective Oct 8, 2026 · Version 2026-10-08--01

Spell is built for studios doing client work. This policy describes how it may be used. It forms part of our Terms of Service and applies to everyone with access to a Spell instance — team members, contractors, clients and candidates.

1. Use it for the work

  • Invite only people who need access, give them the narrowest role that does the job, and remove them when they no longer need it.
  • Put people’s information into Spell only when you have a right to, and only what the work requires.
  • Send client-facing comments, approvals, signature requests and emails only to people who expect them.
  • Connect only integrations and accounts you are authorized to connect.

2. Not allowed

Do not use Spell — including its files, comments, emails, Sign, the careers site or Astra — to:

  • break the law, defraud, impersonate anyone, or forge or misuse signatures;
  • harass, threaten or abuse anyone, or promote violence or hatred against people for who they are;
  • share sexual content involving minors, or intimate images of anyone without their consent;
  • send spam or deceptive invitations, signature requests or job postings;
  • infringe others’ intellectual property or publish other people’s private information;
  • discriminate unlawfully in hiring, or make decisions about people based solely on Astra’s output;
  • use Astra’s research to profile private individuals rather than businesses;
  • store payment card numbers, government identity numbers or health records where Spell is not designed to hold them.

3. Security and fair use

  • Keep your login to yourself and do not share accounts.
  • Do not try to reach another studio’s instance, test Spell’s security without our written permission, or get around its limits.
  • Do not upload malware, scrape the Service, or load it in ways that degrade it for others.
  • Do not resell or give access to Spell to people outside your studio, other than your own clients and contractors.

4. Reporting a concern

Tell us at hello@letsjam.design about misuse, a security issue or content that infringes your rights. Include where you saw it, what happened and how to reach you. If you find a vulnerability, please give us a chance to fix it before you share it.

5. How we respond

We keep our response in proportion to the problem. Usually we will ask the studio to fix it first; if needed we may remove content, disable an integration or a shared link, restrict a user, or suspend an instance. We act immediately, and may tell you afterwards, when there is a security risk, a legal requirement or a risk of serious harm.

If you think we got it wrong, write to us and we will review it. Asking for a review does not restore access by itself.

6. Changes

We may update this policy as Spell and the law change. The effective date above shows the current version.

Spell uses a few cookies and a little browser storage to run the site and the app. Strictly necessary ones stay on. The optional one is off until you switch it on. Details are in our Cookie Policy and Privacy Policy.

Strictly necessaryAlways active

Needed for the site and the app to work: remembering your privacy choices, keeping you signed in, protecting sign-in and connection steps, and remembering small layout choices you make inside Spell. They cannot be switched off here; blocking them in your browser stops those things working.

  • spell_cookie_preferences

    Spell · 180 days

    Remembers the cookie choices you make on this site.

  • sb-<project>-auth-token

    Spell (Supabase Auth) · Until you sign out; refreshed while you are signed in

    Keeps you signed in and protects your session. Set only when you sign in.

  • spell-next

    Spell · 10 minutes

    Returns you to the page you were going to after you sign in with Google.

  • spell_slack_state

    Spell · 10 minutes

    Protects the step that connects your Slack account to Spell.

  • spell_view_as

    Spell · 1 hour

    Lets an administrator see Spell as another person sees it. Ends on its own.

  • sidebar_state

    Spell · 7 days

    Remembers whether you left the app’s sidebar open. Set only inside the app.

  • spell_admin_people_collapsed

    Spell · 1 year

    Remembers which sections an administrator folded on the People page.

  • App preferences

    Spell · Until you clear it

    Remembers small choices inside the app, such as your light or dark theme and the last project you picked.

Performance

Measures how quickly our public pages load, so we can keep them fast. Off unless you switch it on. It sets no cookies and does not follow you to other sites.

  • Vercel Speed Insights

    Vercel, for Spell · Nothing stored in your browser

    Records loading-speed measurements (Core Web Vitals) with the page address and your browser and device type.

Change or withdraw your choice at any time from Cookie settings at the foot of every page. Saying no to the optional setting never stops you using the site. Spell does not sell personal information or use advertising cookies.