AI Transparency Policy

Last updated: May 8, 2026

This AI Transparency Policy explains how Waybound AS (organization number 937 496 184) uses artificial intelligence in SpaceMD, in accordance with the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), Article 5 of the U.S. Federal Trade Commission Act, the UK pro-innovation AI regulatory framework, and applicable transparency requirements in other jurisdictions.

1. Overview

SpaceMD integrates AI-powered features to enhance your writing and collaboration experience. We are committed to transparency about how AI is used, what data it processes, and what its limitations are. This policy supplements our Privacy Policy and Terms of Service.

2. How We Use AI

AI features in SpaceMD may include:

  • Content assistance — Writing suggestions, text generation, summarization, and editing assistance.
  • Smart formatting — Automated formatting and structuring of Markdown content.
  • Search and discovery — Intelligent search across your documents and workspaces.
  • Content analysis — Categorization, tagging, and insight extraction from documents.

AI features are designed to assist, not replace, human judgment. AI-generated outputs are presented as suggestions that you may accept, modify, or reject. Outputs that may reasonably be perceived as authored by a human are clearly labelled as AI-generated where required by EU AI Act Art. 50.

3. First-Party AI Models & Providers

SpaceMD acts as a deployer (under EU AI Act terminology) of third-party AI systems. We do not develop our own foundation models. The following providers are integrated by SpaceMD and may receive content you submit through AI features:

  • OpenAI, L.L.C. — GPT family models, accessed via the OpenAI API.
  • Anthropic PBC — Claude family models, accessed via the Anthropic API.
  • Google LLC — Gemini family models, accessed via Vertex AI / Generative Language API.

Additional providers may be made available over time and will be added to /sub-processors with appropriate notice. Each provider operates under a written data processing agreement with us.

4. User-Supplied (BYOK) Providers

SpaceMD also lets you bring your own API keys and connect additional AI providers, including (without limitation) Azure OpenAI, OpenRouter, Cohere, Z.AI, Moonshot/Kimi, local Ollama, and any OpenAI-compatible endpoint you configure. When you use a BYOK provider, your relationship is governed by that provider's own terms; we have no contract with that provider and we do not warrant or control its data handling, training practices, or retention policies. You are responsible for reviewing and accepting your chosen provider's terms before sending content to it.

5. Data Handling for AI Features

When you use AI-powered features:

  • Only the portions of your content needed to fulfil the request are sent to the chosen provider.
  • Transmission is encrypted in transit (TLS 1.2+).
  • For first-party providers, content is not retained beyond the duration necessary to complete the request, subject to each provider's data processing agreement.
  • For BYOK providers, retention is governed by the provider's own policies.

6. Use of Your Content for Training

SpaceMD does not use your User Content to train AI models. For our first-party providers (OpenAI, Anthropic, Google), the API agreements we use prohibit those providers from using customer content submitted via the API to train their underlying models. We periodically re-confirm these terms with each provider. For BYOK providers, please consult the provider's terms — some may use your content for training unless you opt out.

7. Accuracy & Limitations

AI-generated content is provided without any warranty of accuracy, completeness, or fitness for any particular purpose. AI systems may:

  • Produce factually incorrect or misleading information ("hallucinations");
  • Reflect biases present in their training data;
  • Generate content that is inappropriate or not aligned with your intent;
  • Fail to capture nuance, context, or domain-specific requirements.

You are solely responsible for reviewing, verifying, and validating any AI-generated content before using, publishing, or relying on it. Subject to your mandatory consumer rights, Waybound AS accepts no liability for decisions made based on AI-generated outputs.

8. Human Oversight & Disabling AI

All AI features are designed with human-in-the-loop principles:

  • AI features require explicit user initiation; they do not modify your content without your action.
  • AI suggestions are clearly distinguishable from user-created content.
  • You can accept, edit, or discard any AI-generated output.
  • You can decline to add AI providers or remove existing providers from Account > AI providers; once no providers are configured, AI features that depend on them are unavailable in your account.

9. No Significant Automated Decisions

SpaceMD does not use AI to make decisions producing legal or similarly significant effects on you (Article 22 GDPR; CPRA Automated Decisionmaking Technology regulations; Quebec Law 25 Art. 12.1; Colorado AI Act). We do not use AI for employment, credit, housing, education, healthcare, or insurance decisioning.

10. AI and Minors

AI features are not directed at users under 16 (EEA / UK) or 13 (United States). We do not knowingly process children's data through AI providers. Where the UK ICO Children's Code or comparable regimes apply, we apply data-minimisation and high-privacy defaults.

11. Your Rights

In relation to AI processing of your data, you may:

  • Decline AI-powered features at any time;
  • Request information about how AI has processed your data;
  • Exercise your data protection rights as outlined in our Privacy Policy.

12. EU AI Act Compliance

SpaceMD is a deployer (not a provider) of third-party general-purpose AI ("GPAI") systems. We do not place any AI system or GPAI model on the market and we do not deploy any high-risk AI system listed in Annex III of Regulation (EU) 2024/1689.

In line with EU AI Act Article 50 (transparency obligations applicable from 2 August 2026):

  • Art. 50(1) — chatbot disclosure. Where you interact with an AI system, the interface clearly identifies the response as AI-generated.
  • Art. 50(2) — synthetic content marking. AI-generated text published or circulated to inform the public on matters of public interest will be marked as AI-generated; this duty falls on the publisher of such content (typically you, when you publish through SpaceMD).
  • Art. 50(3) — emotion recognition / biometric categorisation. SpaceMD does not deploy such systems.
  • Art. 50(4) — deep-fake disclosure. SpaceMD does not generate deep-fake image, audio, or video content.

We maintain internal documentation of the AI systems we deploy and conduct periodic risk and impact assessments.

13. UK and U.S. AI Frameworks

In the UK, our use of AI is consistent with the cross-sector principles in the UK government's pro-innovation AI regulatory framework (safety, transparency, fairness, accountability, contestability) and ICO guidance on AI and data protection.

In the United States, our representations about AI are made in compliance with Section 5 of the FTC Act prohibiting unfair or deceptive practices. We do not deploy AI in any way that would trigger the Colorado Artificial Intelligence Act, NYC Local Law 144 (employment), Illinois HB3773, or comparable state-level high-risk-AI laws.

14. Changes to This Policy

We may update this AI Transparency Policy as our use of AI evolves. Material changes will be communicated through our website and, where appropriate, by email.

15. Contact

For questions about our use of AI, contact us at:
Waybound AS
Organization number: 937 496 184
0763 Oslo, Norway
Email: privacy@spacemd.ai