Your account
Your data and where it is hosted
Where Spyral stores your firm's documents, who inside and outside your firm can see them, how to download a copy of your data, and how to sign out everywhere.
Fiduciary work means holding other people's financial records, so it is fair to ask where they sit and who can reach them. This page answers that plainly.
Where it is hosted
Spyral runs in the European Union. Document storage, the database behind your workspace, the application itself and the AI processing that reads your documents are all hosted within the EU. Your client documents are not sent outside it in the course of normal use.
Your documents stay in your firm's workspace
Every document, company, annual accounts cycle, bookkeeping entry and chat session belongs to one workspace, and that workspace belongs to one firm. There is no shared pool.
- Colleagues in another firm cannot see your documents, search them, or get an answer drawn from them. Firms are separated at the database level, not only in the interface.
- Within your firm, a document you upload as Global is visible to your colleagues. One uploaded to a project is visible to that project's members. One uploaded as restricted is visible only to the people you named. See Upload your first documents.
- A document placed in the Spyral Private folder of a connected cloud account is visible only to you. One placed in Spyral Sync is shared with the firm. See Integrations.
- What each colleague can do with a document depends on their role. See Team members and roles.
When you ask the assistant a question, it searches only your firm's own documents, and it shows you which document each part of the answer came from.
Downloading a copy of your data
Settings, then Privacy, then Download your data. You get a single JSON file named for the date you exported it, containing your account details and preferences, your documents, your chat sessions and their messages, your activity history, your searches, bookmarks and saved searches.
Exporting requires two-factor authentication. You are asked for a code from your authenticator app, and the export is not available at all to accounts that sign in with emailed codes. If you need an export, set up an authenticator app first: see Security and two-factor authentication.
Repeated wrong codes stop further attempts for half an hour. Exports are recorded in your firm's activity log.
Signing out everywhere
If a laptop or phone goes missing, or you think someone else has your password:
- Go to Settings, then Privacy, then View active sessions to see every device you are signed in on.
- Use Sign out all other sessions to end all of them at once.
- Change your password. This invalidates every session including your own, so it is the more complete action of the two.
Full detail is in Security and two-factor authentication.
Deleting your account
Settings, then Account, then Danger Zone, then Delete Account. You confirm with your password.
If you own your firm's workspace, do not delete your own account. Deleting it removes you from the workspace but does not close the workspace or hand it to a colleague, which leaves your firm's documents and companies without an owner. If your firm is leaving Spyral, or ownership needs to move to someone else, contact us first: see How to get help.
Deleting your account is about your own access. It is not the way to remove a colleague, which is done from the Team page, and it is not the way to delete a client's documents, which is done in the library.
Activity history
Your firm's workspace keeps a record of significant actions: signing in, password and two-factor changes, invitations and role changes, data exports, document deletions, filings and signature events. Each entry carries who did it, when, and the network address it came from. You can read it under Activity.
Further detail
The privacy policy sets out the formal position, including how long data is kept and how to make a request about it.