Legal
Cookie and Tracker Notice
Sparky uses only necessary authentication and invite cookies plus local UI preference storage. No advertising cookies, no cross-site tracking pixels, no browser session recording.
1. Necessary cookies
- Authentication session cookies: keep you signed in and protect authenticated pages and APIs.
- Authentication CSRF/state cookies: protect sign-in and OAuth flows from request forgery.
- Authentication callback cookies: remember where to send you after sign-in.
- Pending-invite cookie: stores a valid invite code for up to thirty minutes so the magic-link sign-in can place you in the correct household.
2. Local browser storage
Sparky uses localStorage for interface preferences such as theme, color mode, browse view, right-panel mode, and right-panel width. This is not sent to the server automatically and is used only to keep the interface stable between visits.
3. Analytics and monitoring
No browser analytics SDK, advertising cookie, cross-site tracker, heatmap, or session-replay tool is active.
Server-side product analytics (PostHog): anonymized, cookieless product analytics run entirely server-side via the PostHog Node SDK (EU region, eu.posthog.com). No browser SDK, no cookies, no session recording, no autocapture. Events carry only a salted SHA-256 hash of your account and household identifiers — never raw emails, filenames, or chat content. Events tracked: sign-ins, invite redemptions, uploads, document opens, chat messages, account export/delete requests, safety cap hits, and billing lifecycle events.
Public pages and demo: the same server-side PostHog records a page-view event for the public marketing pages, guides, comparison pages and legal pages, plus the demo funnel and the free tools. These pages have no account behind them, so each event carries a fresh random identifier rather than anything that could link your visits together. The event records the path, the channel it came from (a campaign tag, the referring site, or the name of the AI crawler that fetched it), and whether the request looked automated. If you answer “how did you hear about us” on the contact form, the event carries one category word derived from your answer, never the answer itself.
Search and crawler statistics: Sparky reads aggregate reports from Google Search Console, Bing Webmaster Tools and Cloudflare — how often pages appear in search, and which crawlers fetched them. These come from our own domain records and search engines' own reports; they involve no code on the page and identify no individual visitor.
Runtime error monitoring (Sentry): the browser-side error monitor captures uncaught JavaScript errors and React rendering failures and reports them to Sentry (EU region) so the operator can diagnose crashes. The browser SDK does not set cookies. It posts events through the same origin via the /monitoringtunnel route (so ad-blockers cannot black-hole the channel). Document content, OCR text, chat content, cookies, and raw IP addresses are stripped before transmission; session replay is disabled.
4. Your choices
You can block cookies in your browser, but sign-in and invite redemption will not work without necessary cookies. You can clear local UI preferences from your browser settings at any time.