Ultima actualizare

Guvernanța AI

v2026-08-28

Spinrun puts AI agents in front of real accounts: a mailbox, a CRM, a spreadsheet, a chat workspace. That makes the question of what the model can see, what it can do, and who decides more than an ethics statement — it is the design of the product. This page sets out how BirdAI S.R.L. answers it.

Where this page describes a contractual position — training, data protection roles, acceptable use — the Terms and Conditions, Privacy Policy and Data Processing Agreement are the binding texts. This is the plain-language version of them.

  1. 01Purpose and scope

    This page covers every part of the Service that sends data to a language model or acts on what one produces: the playground, Brain's document ingestion and search, and any agent — yours or one of ours — that calls tools through the gateway.

    It does not cover the models your own agents run on. If you connect Claude, ChatGPT, Cursor or another client to the gateway, that client's provider governs the model; we govern what the model can reach through us.

  2. 02Models and providers

    Two parts of the Service send data to a model. The playground sends your conversation and the tool results it receives. Brain sends the documents you ingest, in order to turn them into embeddings that make search work.

    Both go to Google's Gemini models, and both reach them only through the Vercel AI Gateway — we hold no model-provider keys of our own. The gateway is the single route, which means there is exactly one place to look when you want to know where a prompt went, and one line to change on the subprocessor list if the provider ever does.

  3. 03Your data is not used for training

    We do not use your content or your connected application data to train machine-learning models, and we do not permit the providers we use to do so either. Neither we nor the providers we route through are permitted to train on your content.

    This holds for everything that passes through the Service — call arguments, responses, artifacts, Brain documents and playground conversations — and it is not a setting you have to find and switch off.

  4. 04Human oversight

    Oversight is built into the gateway rather than left to the prompt. Read, write and destructive rules are enforced before a call reaches the connected application, so a rule that says "this agent may read anything and delete nothing" holds regardless of what the agent was told or talked itself into.

    Destructive actions in the playground wait for a person to approve them. Every call an agent makes is written to the activity log — which tool, which action, the outcome, how long it took — so what an agent did is always something you can read back rather than infer.

    Whether an agent should be allowed to act unattended is your decision. The Service gives you the rules and the log to make it responsibly; it does not make it for you.

  5. 05EU AI Act: our role and yours

    Regulation (EU) 2024/1689, the AI Act, allocates duties by role. Spinrun is a gateway and a set of tools around general-purpose models built by others; we are not the provider of those models, and we do not place a high-risk AI system on the market as that term is defined in the Act.

    How you use the Service determines which of the Act's obligations reach you. If you deploy an agent in a context the Act treats as high-risk — employment decisions, access to essential services, law enforcement among them — the deployer obligations are yours to assess and meet, and the Service is not designed or represented as fit for that use.

    If you publish or distribute AI-generated or AI-modified content, meeting the transparency and labelling obligations that apply to it — including under the EU AI Act — is yours. We make no claim of conformity assessment, CE marking or registration for the Service, because none applies to it in its current form.

  6. 06Transparency of outputs

    Model output is generated text: it can be wrong, incomplete, biased, or unsuitable for what you intend to do with it, and it is not legal, financial, medical, tax or other professional advice. Reviewing it is yours.

    Inside the product, what came from a model and what came from a tool are kept distinct — a tool result is recorded as such in the activity log, with the call that produced it — so an agent's summary can always be checked against what it actually read. Nothing the model produces is used by us to make a decision about a person with legal or similarly significant effect.

  7. 07Prohibited uses

    The Terms set the full acceptable-use rules. The ones that bear on AI specifically: you must not, and must not let an agent or a teammate:

    • use the Service for unlawful, fraudulent, deceptive or harmful purposes;
    • generate or distribute illegal content, harassment, threats, defamation, or material that infringes someone else's rights;
    • send unsolicited bulk messages, run phishing campaigns, or impersonate a person or organisation;
    • use the Service to train a foundation model or to build a competing product, without our written consent;
    • put personal, confidential or regulated data through the Service without the authority and lawful basis to do so;
    • work around usage limits, permission rules, billing or security mechanisms.
  8. 08Data protection interplay

    For data you send through the gateway — including everything a model sees on your behalf — you are the controller and we are your processor: you decide what your agents do, and we carry it out under the Data Processing Agreement. For your own account and billing details, we are the controller.

    Providing notice to the people whose data an agent handles, and having a lawful basis for it, remains yours. Where a data subject comes to us directly about data we hold as your processor, we pass the request to you rather than act on it ourselves.

    The supervisory authority for BirdAI S.R.L. is Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) — https://www.dataprotection.ro/.

  9. 09Changes

    We update this page when the models, the providers, the controls, or the law change. The date at the top always reflects the current version. A change of model provider is also a change to the subprocessor list, and is announced the way that list's changes are: by email to workspace owners, before it takes effect.

    Questions about any of this go to legal@spinrun.ai.

Înainte să se încarce ceva

Am vrea să activăm analiza traficului, ca să vedem ce pagini merită păstrate. Nu s-a încărcat încă nimic și nu se va încărca nimic până nu alegi. Cookie-urile care te țin autentificat și îți rețin limba nu fac parte din asta.

Citește Politica de cookie-uri