Privacy Policy
Effective Date: January 1, 2026
Last Updated: February 1, 2026
Privacy at a Glance (Fact Sheet)
| Category | Our Commitment |
|---|---|
| Data Ownership | You own it. Export your workspace as a JSON bundle anytime. We believe in zero "lock-in." |
| File Storage | Local-First + BYOC. Images and attachments are stored locally. You can connect your own Google Drive for private backup. |
| AI Privacy | On-Device OCR. Receipt scanning runs locally in your browser. Raw images are never sent to third-party AI models for training. |
| Security | Zero-Access Support. Our team cannot see your private vault, financial entries, or uploaded documents. |
| Ad Tracking | None. We do not sell your data. GA4 is used only on public-facing marketing pages. |
| Portability | GDPR Standard. Access, move, or permanently delete your data with one click. |
1. Introduction and Scope
SparkyMinis ("Company," "We," "Us," or "Our") is committed to protecting your privacy and ensuring you have complete control over your data. This Privacy Policy outlines our practices regarding the collection, use, and disclosure of information when you use our web application and services (collective, the "Service").
We operate on a Hybrid Data Architecture. Structured business and life data (invoices, tasks, contacts) are synchronized via our secure cloud to ensure multi-device accessibility. However, high-stakes personal files, images, and "Secure Vault" attachments prioritize local device storage with user-controlled backup options.
By accessing or using the Service, you consent to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1. Information You Explicitly Provide
To facilitate the Service, we collect the following:
* Identity Data: When you register, we collect your authentication token and basic profile information (Name, Email Address) from your chosen Identity Provider (e.g., Google or Microsoft). We do not store your password.
* Structured Content: This includes invoices, expense records, project details, contacts, and travel itineraries. This data is synced to our secure cloud to enable access across your devices.
* Files & Attachments: Images of receipts and documents uploaded to the "Secure Vault." These files are stored locally in your browser. To prevent data loss, we provide an optional integration to back these up to your own private Google Drive account.
* Billing Information: If you subscribe to a paid plan, our Payment Processors (Razorpay) collect your payment method details. We do not store complete credit card numbers on our servers.
2.2. Automated Usage Data
When you access the Service, specific data is automatically collected to ensure performant delivery and security:
* Telemetry: Anonymous metrics regarding feature usage (e.g., "Invoice Created," "Export Generated"). This data is aggregated and cannot be used to reconstruct your User Content.
* Third-Party Analytics (Public Pages Only): On our public-facing pages (e.g., Home, Pricing, Blog), we use Google Analytics 4 (GA4) via Cloudflare Zaraz. This tracking is not present within the logged-in Dashboard area.
* Device Information: Browser type, operating system version, and screen resolution to optimize the user interface.
* Network Data & Anti-Spam: We collect your IP address and basic browser telemetry via Cloudflare Turnstile specifically for security logging, rate-limiting, and bot-prevention on our public forms.
3. Lawful Basis for Processing (GDPR Compliance)
Under the General Data Protection Regulation (GDPR), we process your personal data under the following lawful bases:
1. Performance of a Contract (Article 6(1)(b)): We process your Identity Data and User Content to provide the Service you have requested (e.g., syncing your invoices between your laptop and phone).
2. Legal Obligation (Article 6(1)(c)): We retain certain transaction records to comply with tax and financial regulations.
3. Legitimate Interests (Article 6(1)(f)): We process Usage Data to detect security threats, prevent DDOS attacks, and improve system stability.
4. Consent (Article 6(1)(a)): Where strictly required (e.g., optional marketing newsletters), we process data based on your explicit consent, which you may withdraw at any time.
4. How We Process and Store Data
4.1. Hybrid Storage & Backup
* Structured Data: Synchronized to our secure cloud infrastructure to enable multi-device access and backup recovery.
* Files & Images (Local-First Philosophy): Attachments and vault files are stored within your browser's secure sandbox (IndexedDB). Because we do not store these files on our own servers, we offer a "Bring Your Own Cloud" (BYOC) integration with Google Drive, allowing you to maintain a private backup that remains under your exclusive control.
4.2. Hybrid Intelligence & Gen AI Analytics
While our "Smart Camera" and "OCR" features prioritize Client-Side Processing to ensure raw documents stay in your browser, our Gen AI Analytics features (such as project insights or expense summaries) utilize secure cloud-based processing. Gen AI features are Off by default and require an explicit user opt-in to activate. Anonymized workspace context fragments may be processed via our trusted Gen AI partners (e.g., Anthropic) to provide you with actionable intelligence. These partners are strictly prohibited from using your data to train their models.
5. Data Sharing and Trusted Third Parties
We do not sell your personal data. We disclose data only to the following categories of Trusted Service Providers, bound by strict confidentiality and data processing agreements:
* Cloud Infrastructure Providers: To host the encrypted database required for structured data syncing.
* Identity Providers: To authenticate your login session without requiring us to manage passwords.
* Gen AI Service Providers (Anthropic): To provide Gen AI Analytics and workspace insights using anonymized data fragments.
* Payment Processors (Razorpay): To handle PCI-DSS compliant payment transactions. We share only necessary data (Name, Email, Payment Metadata) with Razorpay.
* Legal Authorities: Only if compelled by a valid court order or binding legal process.
6. Data Security
We implement industry-standard technical and organizational measures to secure your data:
* Encryption: Data is encrypted in transit using TLS 1.2+ and at rest within our cloud storage facilities.
* Row-Level Security (RLS): Our database architecture enforces strict isolation, ensuring your User ID is cryptographically required to read or write your specific records.
* Zero-Access Support: Our support team does NOT have access to your app data. We cannot view your Invoices, Vault files, or Trip plans. If you require technical assistance, you must explicitly grant transient permission; we cannot "log in as you."
* Access Control: Internal access to production data is restricted to authorized personnel with a critical business need, protected by Multi-Factor Authentication (MFA).
7. Your Data Rights (GDPR & Global Standards)
Regardless of your location, we extend the following rights to all users:
* Right to Access (Article 15): You may request a copy of all personal data we hold about you.
* Right to Rectification (Article 16): You have the ability to correct inaccurate profile data directly within the "Settings" panel.
* Right to Erasure ("Right to be Forgotten") (Article 17): You may request the permanent deletion of your account. Upon such request, we will purge your data from our active systems within 30 days.
* Right to Portability (Article 20): We adhere to the principle of "Your Data is Yours." You may generate a full "Sparky Export Bundle" (machine-readable JSON format) at any time via the Security Settings.
* Right to Object (Article 21): You may object to our processing of your data for direct marketing purposes.
To exercise these rights, please contact our Data Protection Officer at [email protected].
8. Data Retention
We retain your personal data only for as long as is necessary for the purposes set out in this Privacy Policy.
* Active Accounts: Structured data is retained to provide the Service. Files stored locally remain until you clear your browser cache or disconnect your backup.
* Deleted Accounts: User Content is soft-deleted immediately and permanently purged from backups within 90 days.
* Financial Records: Transaction data is retained for a minimum of 7 years in accordance with applicable tax laws.
9. International Data Transfers
Our Service utilizes a global edge network. Your data may be stored and processed in any country where we or our Service Providers have facilities. We utilize Standard Contractual Clauses (SCCs) where applicable to ensure data protection.
10. Children's Privacy
Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child has provided us with Personal Data, we will take steps to delete such information.
11. Contact Us
If you have questions about this Privacy Policy, your data rights, or our compliance practices, please contact our Data Protection Officer:
* Support Portal: SparkyMinis Connect
* Email: [email protected]
For data requests, email [email protected]