Legal
Privacy Policy
Sparky stores account, document, chat, memory, usage, and support data to operate a beta document assistant. Documents and chats may be sent to subprocessors needed for storage, email, AI, observability, and support.
1. Who is responsible
Sparky Fetch is operated by the project operator, based in British Columbia, Canada. The operator is accountable for personal information handled by the service under Canada's PIPEDA and British Columbia's PIPA. For privacy requests, contact [email protected]. If you use Sparky for a household or workspace, the account owner or inviter may also share responsibility for what is uploaded. Sparky is intended for use by adults; documents about children should be added only by a responsible adult household member who has the authority to do so.
2. Data we collect and create
- Account data: email address, name and avatar from the auth provider, account id, household membership, role, and sign-in timestamps.
- Security data: hashed IP addresses, user agents, auth audit events, rate-limit events, CSRF/CSP reports, and operator review records.
- Document data: uploaded files, canonical file bytes, file names, MIME type, size, hash, OCR text, extracted metadata, category, parties, tags, summary, visibility, ownership, archive/trash/star state, and generated embeddings or index entries.
- Chat and AI data: user messages, assistant replies, tool calls, document references, model names, token counts, feedback, and trace ids.
- Memory data: stored observations, retained memory cards, recall metadata, source tags, lifecycle metadata, and derived summaries used to personalize future answers.
- Telegram data: Telegram user id, username, display name, linked account id, messages, attachments, and commands sent to the bot when you link Telegram.
- Usage and support data: event type, model, bytes, pages, chunks, tokens, estimated cost, plan state, payment metadata when paid plans are used, and support correspondence.
- Tool and reminder data: if you give one of our free public tools (such as the passport-expiry checker) an email address and an expiry date without signing in, we keep just those two fields to send the reminder you asked for and its confirmation. They are stored on their own in the
app.tool_reminderstable, kept out of our analytics and observability tracing, and deleted when you unsubscribe. - Contact-form data: the name, email address, topic, message, and optional answer to “how did you hear about us” that you type into the contact form. All of it is emailed to the operator so they can reply, and nothing from that form is stored in a database. The answer about how you found us is reduced to a single category word (for example
search,friend,ai_assistant) before it reaches analytics — the sentence you wrote is never sent there.
3. Where data is stored
Account, chat, catalog, audit, and usage data are stored in Postgres. Canonical document files are stored in Cloudflare R2. A cross-provider archive of document files is mirrored to Backblaze B2. OCR and temporary processing may use the host filesystem briefly during a job. Memory data is stored in a Sparky-operated memory service. Observability events are stored in a Sparky-operated tracing service. Runtime errors and crashes are reported to Sentry (EU region) with document content, OCR text, chat content, cookies, and raw IPs stripped before transmission. Outbound transactional email is sent through Resend. Depending on the component, data may be stored or processed in Canada, the European Union, or the United States; the subprocessor list shows each vendor's role.
4. Subprocessors and third-party services
Sparky uses subprocessors listed at /legal/subprocessors. They include storage, email, auth, AI model, observability, and communications vendors. Sparky will update this list and the Privacy Policy before a new subprocessor begins processing user data.
5. AI and model providers
To answer questions, classify documents, create summaries, retain memory, or extract structured information, Sparky sends the relevant document text, metadata, chat context, and instructions to AI model providers configured for that workflow. Sparky routes most model calls through OpenRouter; downstream models may include providers such as OpenAI, Anthropic, Google, or DeepSeek depending on the route. Sparky sends only what the selected workflow needs. OpenRouter requests are configured with zero-data-retention enforcement (data_collection: "deny" and zdr: true) so that only providers that do not store or train on user data are eligible for routing.
Memory sub-processing. Sparky's self-hosted memory system (Hindsight) also uses external AI providers as part of its internal pipeline. When Hindsight extracts structured facts from chat content — such as names, dates, locations, and relationships — it sends the relevant chat text to its configured LLM provider (currently Groq or Gemini) for extraction and to OpenRouter for embedding generation. Only email addresses are scrubbed before the content leaves Hindsight; phone numbers, addresses, document numbers, and other personal identifiers may be included in the payload sent to these providers. This channel is distinct from Sparky's direct AI model calls and is subject to each provider's data-processing terms.
6. Who can see data
- Members of your household or workspace can see shared documents, shared chat context, and shared memory where the product exposes them.
- Private document visibility is enforced by the application. The operator may still need access for support, security, deletion, export, backup, or legal obligations.
- Subprocessors may process data only to provide their service to Sparky, subject to their own terms and data-processing controls.
7. Retention
- Active account, document, chat, memory, and usage data are retained while your account or household remains active, unless deleted earlier.
- Deleted documents and account data are removed from primary systems when the deletion workflow runs. Backups and archives may retain copies until their retention window expires.
- Database backup dumps are retained for thirty days on a rolling basis.
- Auth audit, security, and abuse-prevention records may be retained longer where needed to protect the service, investigate abuse, or comply with legal obligations.
8. Export, correction, and deletion
To request access, correction, export, restriction, objection, or deletion of your personal data, email [email protected]. Sparky responds without undue delay and aims to complete ordinary requests within one month. Some records may be retained where legally required, needed for security, or still present in backups until the backup retention period expires. If you are not satisfied with the response, you may complain to the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia.
10. Security
Sparky uses account-based access controls, Auth.js sessions, HTTPS-only deployment, CSRF checks for state-changing APIs, role checks for administrative screens, rate limits, database access controls, storage controls, and operator audit logs. No internet service is risk-free. If a data breach creates a real risk of significant harm, the operator will notify affected users and the relevant privacy authorities as required by applicable law. Report suspected security or privacy issues to [email protected].
11. Connecting Google Drive
- Google Drive sync is optional and only runs after you connect it from Settings. If you never connect it, none of the below applies.
- Sparky requests Google's
drive.filepermission. This scope lets Sparky see and manage only the files it creates in your Drive — it gives Sparky no access to any other file already in your Google Drive. - When connected, Sparky keeps a one-way copy of your documents in a Sparky Fetch folder it creates in your Drive, organized into sub-folders. Deleting a document in Sparky moves its Drive copy to an Archive sub-folder rather than destroying it.
- Google acts as a subprocessor for this feature. To enable it, Sparky stores an OAuth refresh token for your Google account, encrypted at rest (AES-256-GCM). Sparky never receives your Google password.
- You can disconnect at any time from Settings; Sparky revokes the token and stops syncing. Files already exported stay in your Drive — disconnecting never deletes them. To remove them, delete the Sparky Fetch folder in your Drive.
12. Changes
The operator may update this Policy. Material changes will be communicated in the product or by email before they take effect.