Geekflare Ltd, trading as Sparkian (Sparkian, we, or us), is committed to protecting your personal data. We are registered in England and Wales under company number 12085510, with a registered office at 71–75 Shelton Street, London, United Kingdom, WC2H 9JQ.
This Policy explains what personal data we collect, why we collect it, who we share it with, and the rights you have over it. Read it alongside our Terms of Service and Cookie Policy.
1. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email, authentication identifier, and workspace membership | You and our authentication provider, at signup or sign-in |
| Billing data | Billing name and address, tokenised payment method, transaction history, and business tax ID | You and our payment processor |
| Content data | Chat messages, prompts, uploaded files, generated output, and Knowledge base documents | You, as you use the Services |
| Usage data | Feature usage, model selection, Spark consumption, performance, errors, session activity, and timestamps | Automatically, as you use the Services |
| Technical data | IP address, device and browser type, approximate location, and log data | Automatically, through our infrastructure and security providers |
| Communications | Support requests, survey responses, and marketing preferences | You, when you contact us or subscribe to updates |
2. How we use your data
| Purpose | UK/EU GDPR lawful basis |
|---|---|
| Provide and operate the Services, including processing prompts through third-party AI models | Performance of a contract with you |
| Process payments and manage subscriptions | Performance of a contract; legal obligations for tax and accounting |
| Detect and prevent fraud, abuse, and security incidents | Legitimate interests in protecting the Services and our users |
| Understand feature usage, improve performance and reliability, and provide support | Consent where required; otherwise legitimate interests subject to applicable opt-out rights |
| Send transactional emails such as billing receipts, password resets, and service notices | Performance of a contract; legitimate interests |
| Send marketing communications | Consent, which you may withdraw at any time |
| Comply with legal obligations and lawful requests | Legal obligation |
3. Who we share data with
We do not sell your personal data. We share data with service providers engaged under appropriate data-processing terms solely to help us provide the Services.
| Provider | Purpose | Data typically involved |
|---|---|---|
| Google Cloud Platform | Application hosting and infrastructure | Account, content, and usage data |
| Cloudflare | Frontend delivery, object storage, DDoS protection, and web application firewall | Content, technical, and traffic metadata |
| AI model providers, including OpenAI, Anthropic, Google, and others we may add | Processing prompts and content to generate output | Prompts, relevant uploads, and limited account identifiers |
| Stripe | Payment processing | Billing and transaction data |
| Postmark | Transactional email delivery | Email address and transactional content |
| Google Identity Services | Optional Google One Tap authentication on the landing page | Google identity token used to authenticate with Firebase |
| Google Tag Manager | Consent-aware tag management | Consent state and technical request data |
| c15t and Inth | Consent management, regional policy resolution, and consent records | Consent choices and limited technical and regional data |
| PostHog | Consented website and product usage analytics, session replay, performance analysis, and support | Opaque account identifier when signed in, visible page and input text, URLs, usage events, console output, client errors, and technical performance and network timing; Sparkian does not apply custom masking, while request and response payloads, headers, canvases, and cross-origin iframe content are not recorded |
| Tolt | Affiliate referral attribution and commission calculation | Referral identifier and relevant subscription or payment events |
We may also disclose data where required by law, to enforce our Terms, to protect Sparkian, our users, or others, or in connection with a merger, acquisition, or sale of assets.
4. International data transfers
Some providers, including AI model providers, Google Cloud, and Cloudflare, may process data outside the UK and European Economic Area, including in the United States and India. We use appropriate safeguards for international transfers where required by law. You may contact us for information about the safeguards relevant to your personal data.
5. Data retention
| Data type | Retention period |
|---|---|
| Account data | While your account is active and for a limited period after closure |
| Chat and content data | Active history is retained for 30 days on Free plans and 365 days on paid plans; deleted or expired content may remain recoverable for up to 30 more days before purge |
| Marketing data | Until you unsubscribe or withdraw consent |
| Analytics data | For the configured analytics retention period and only while needed for product improvement, performance, support, and security purposes |
| Consent records | For as long as needed to demonstrate and apply your privacy choices and meet legal obligations |
We may retain data for longer where required by law, to resolve disputes, protect the Services, or enforce our agreements.
6. Your rights
If you are located in the UK or EEA, you may have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data, subject to legal exceptions.
- Port your data to another provider in a structured, machine-readable format.
- Restrict certain processing of your personal data.
- Object to processing based on legitimate interests or for direct marketing.
- Withdraw consent at any time where processing is based on consent, without affecting earlier processing.
6.1 California residents
The California Consumer Privacy Act, as amended by the CPRA, may give you additional rights to know, delete, or correct personal information, limit certain uses of sensitive personal information, and opt out of its sale or sharing. You also have the right not to receive discriminatory treatment for exercising applicable rights. We do not sell personal information and honor applicable browser-based opt-out preference signals.
To exercise a privacy right, use our contact form. You may also complain to the UK Information Commissioner’s Office or your local EEA data protection authority.
7. Cookies and tracking
We use cookies and similar technologies for essential functionality, security, fraud prevention, preferences, and any analytics enabled in accordance with our Cookie Policy.
For signed-out visitors, PostHog analytics and session replay run only after an explicit measurement choice allows them. Signed-in product usage is measured and associated with an opaque account identifier so product journeys and failures can be understood. PostHog keeps its analytics identity and session state in session storage so the same-tab journey can continue through navigation and reloads; that browser storage clears when the tab is closed. Replay records visible page and input text, URLs, console output, client errors, and technical performance and network timing. Sparkian does not apply custom masking to captured data. Request and response payloads, headers, canvases, and cross-origin iframe content are not recorded by this integration. PostHog and browser safeguards still protect security-sensitive fields such as password inputs. Supported browser opt-out signals are respected. Cookie settings remain available from the account Help menu for signed-out browsing preferences.
8. Children’s privacy
The Services are not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided personal data, please contact us.
9. Automated decision-making
Generating an AI response is not automated decision-making that produces legal or similarly significant effects about you. It is a service you actively request and control. We do not otherwise use personal data to make such automated decisions.
10. Security
We apply technical and organisational measures designed to protect your data. No system can be guaranteed to be completely secure.
11. Changes to this Policy
We may update this Policy from time to time and will publish the updated version here.