EFFECTIVE AUGUST 19, 2026
Privacy Policy
Spatial OS follows data minimization, local processing and deny-by-default access. A connected home is not an analytics dataset.
Home Assistant data
Room names, device entities, states, scene instructions, policy previews and execution traces are processed in the browser. Home Assistant authorization is stored only in the current browser session and is cleared when the session ends or the user disconnects. Spatial OS does not intentionally upload the home graph, device states, policy text or execution proof to its website servers.
SmartThings data
If the SmartThings connector becomes available, OAuth access and refresh tokens are encrypted before server-side storage. The connection expires after seven days unless the user reconnects, and disconnecting deletes the stored connection. Home snapshots are returned to the authorized browser and are not retained as telemetry.
Account and payment data
Creem processes checkout, tax, receipt and subscription information as merchant of record. Spatial OS receives identifiers and status needed to grant or revoke paid access. Payment-card details are not received or stored by Spatial OS. Verified webhook receipts retain only a minimal event type, object identifier, status and timestamp for up to 90 days; raw payment webhook payloads are not retained.
Product analytics
Spatial OS stores daily aggregate counters for a limited event allowlist, such as page visits, virtual-lab launches, beta starts, checkout starts and successful activations. It does not retain per-visit event records, IP addresses, device names, room names, policy content or command targets. Daily aggregate counters expire after 120 days.
Lead information
If you submit an email for product updates, it is stored only for that purpose and expires after 365 days unless renewed. You can request deletion using the reply address in a product communication or your Creem receipt.
Beta feedback
If you submit a founding-beta report, Spatial OS stores the selected platform, test stage, result, short note, attribution source and submission time. An email address is stored only when you voluntarily include one for a reply. Reports expire automatically after 180 days. The form instructs users not to provide credentials, private URLs, entity identifiers, configuration exports, names or household details and rejects common token patterns.
Security controls
Physical commands require an explicit approval for that single run. Critical actions such as exterior unlock are blocked. Supported actions are allowlisted, executed one at a time and checked against observed state. Security headers, encrypted secrets, short-lived authorization and no-store API responses reduce exposure, but no connected-home software can eliminate all risk.
Your choices
You may use the Virtual Home Lab without connecting a real home. Disconnecting removes the active home authorization. Creem's customer portal provides subscription cancellation, invoices and payment-method controls.
Changes
Material changes will be posted on this page with a revised effective date.