Privacy Policy

Last updated: 30 April 2026

This Privacy Policy explains how Sparkle ("we", "us") collects, uses and shares personal data when you use our AI entertainment app. Sparkle is an AI product — see our AI Disclosure for what that means in practice.

1. Who we are

The data controller for personal data processed in connection with Sparkle is the operator of the Sparkle service. You can reach us at privacy@sparkle.app.

2. What we collect

  • Account data: email, username, password hash, authentication provider IDs (e.g. Google, GitHub).
  • Profile data: avatar, preferences, language, settings you configure.
  • Conversation data: the text, images and other content of messages you send and receive in chats with AI characters.
  • Billing data: records of purchases, subscriptions, Coin balances and transactions. Card details are handled by our payment processor (Whop) and are not stored on our servers.
  • Technical data: IP address, device type, browser, approximate location inferred from IP, app version, crash logs and basic usage telemetry.
  • Moderation data: reports you file, automated moderation flags and decisions taken on your account.

3. How we use it

  • To provide and operate the Sparkle service (including generating AI replies).
  • To process payments and manage subscriptions.
  • To moderate content, prevent abuse, detect fraud, and enforce our Terms.
  • To communicate with you about your account, service updates and support.
  • To analyse usage in aggregate so we can improve the product.
  • To comply with legal obligations.

Legal bases (GDPR): performance of our contract with you (Art. 6(1)(b)), our legitimate interests in operating and securing the service (Art. 6(1)(f)), your consent where required (Art. 6(1)(a)), and legal obligations (Art. 6(1)(c)).

4. AI providers and conversation content

To generate replies from AI characters, the content of your messages is sent to third-party AI providers. We currently use OpenRouter for text and optional image generation. That provider processes the messages on our behalf so they can return model output. See our subprocessor list for details.

Conversations may include sensitive topics. Please do not share personally identifying information, financial information, government IDs, medical details, or anything you would not want stored on a third-party AI provider in chats. We cannot control what you choose to type into a chat.

5. Sharing

We share data only with:

  • Service providers acting as processors on our behalf (hosting, database, payment processing, AI inference, email, analytics, error reporting).
  • Authorities where we are legally required to do so (court orders, valid law-enforcement requests).
  • Acquirers in the event of a merger, acquisition or asset sale, subject to equivalent protection.

We do not sell personal data.

6. International transfers

Some of our service providers (notably AI inference and hosting) are based outside the European Economic Area, including in the United States. Where we transfer personal data outside the EEA we rely on the European Commission's Standard Contractual Clauses or an applicable adequacy decision.

7. Retention

  • Account data: retained while your account is active, and for up to 90 days after deletion (longer where required by law or to defend legal claims).
  • Conversation content: retained while your account is active. When you delete your account, conversation data is removed; backups are purged within 30 days.
  • Billing records: retained for the period required by tax and accounting law in our jurisdiction (typically 7–10 years).
  • Moderation logs: retained for up to 12 months for safety and abuse prevention.

8. Your rights

Subject to applicable law (in particular GDPR for EU/EEA residents and the CCPA for California residents), you have the right to:

  • access the personal data we hold about you;
  • correct inaccurate data;
  • delete your data ("right to be forgotten");
  • restrict or object to certain processing;
  • request data portability;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with your supervisory authority.

You can exercise most rights from inside the app (settings → data & privacy) or by emailing privacy@sparkle.app.

9. Security

We use industry-standard administrative, technical and physical safeguards (encryption in transit, encryption at rest, access controls, audit logging) to protect personal data. No system is perfectly secure; please use a strong, unique password and enable any available multi-factor authentication.

10. Children

Sparkle is not intended for users under 18, and we do not knowingly collect personal data from anyone under 18. If you believe a minor is using Sparkle, please contact us.

11. Cookies

We use strictly-necessary cookies for authentication and security, and optional analytics cookies that you can accept from our cookie banner. Without opt-in, usage may be measured cookieless (no cookie, no persistent identifier). See our Cookie Policy for details. We do not use third-party advertising cookies. Location search may send queries from your browser to OpenStreetMap Nominatim (see subprocessors).

12. Changes

We may update this Policy. Material changes will be communicated in-app and the "last updated" date will reflect the most recent revision.

13. Contact

Questions about your data? Email privacy@sparkle.app.