Privacy and data
How SparkVox handles your audio, transcripts, voice profile, cookies, and account data.
What SparkVox processes
Project audio and video are transcribed via Gladia when native captions are unavailable (diarized when needed). SparkVox does not retain raw source audio after the transcript is saved. For YouTube URL projects, public metadata (title, description, tags, duration) is stored on the project to improve spelling and generation.
Post text is generated with Anthropic Claude. Optional images use Claude Sonnet for a hook-anchored visual brief, then fal.ai (Flux) for the image, and are served from SparkVox media storage (Cloudflare R2). Your voice profile is built from your transcripts and optional edit feedback when you confirm posts with Schedule - not from LinkedIn scraping. Voice regression findings (clustered edit patterns) are stored on your voice profile until you delete your account or reset your profile.
For direct LinkedIn publishes, SparkVox stores time-series post analytics snapshots on each sync to power personalised decay curves in Post Analytics. Snapshots are deleted when you delete your account.
In-app support chat (Help → Chat) stores your messages on SparkVox servers after you send your first message so conversations persist across sessions. We record the app page you were on when the thread started. Message content and account context are sent to Anthropic (Claude) to generate replies. Support chat is deleted when you delete your account.
The Sparky widget on sparkvox.io stores conversations on SparkVox servers after you send your first message (anonymous visitor id until you optionally submit an email on the lead form). We record which marketing page you were on when the thread started. Opening the widget without messaging does not create a stored conversation. Marketing chat transcripts may be retained up to 90 days unless linked to a lead or account.
On sparkvox.io, PostHog and Google Analytics 4 load after cookie consent. Declining cookies keeps those scripts off. The Meta Pixel runs separately for ad measurement (not gated by the banner). Details: sparkvox.io/help/cookies-and-analytics and sparkvox.io/cookie-policy.
Google Workspace (Drive & Meet)
When you connect Google Drive, SparkVox accesses your Google account email and only files you explicitly select via the Google Picker (drive.file), including native Google Docs you pick for Import from cloud (exported to plain text for processing). When you connect Google Meet, SparkVox accesses your email, Meet conference metadata (meetings.space.readonly), Meet-related Drive files (drive.meet.readonly), and transcript Google Docs (documents.readonly) solely to import meetings you choose.
We use Google user data only for import, transcription, and AI-assisted post generation you request. We do not use it for advertising, credit/lending decisions, or sale to data brokers. We do not use Google Workspace data to train generalized machine-learning models.
Limited Use: SparkVox's use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Full legal detail: sparkvox.io/privacy.
Community benchmarks (optional)
Under Settings → Profile, Share anonymized posting data is off by default. When you opt in, SparkVox may include your posting activity - with anything that identifies you removed - in community benchmarks and coaching insights (for example cadence norms like "founders like you post Mondays at 5pm EST"). Aggregated insights may also appear in reports shared outside SparkVox. Turn the toggle off anytime and Save to stop including new data.
Deletion
Deleting a project removes its posts and associated media on SparkVox (R2). Deleting your account removes all of your data and media permanently. Active Stripe subscriptions are cancelled when applicable. Your data is never used to train models for other users.
Security
SparkVox aligns its security controls with SOC 2 Trust Services Criteria (Security). We use TLS in transit, encryption at rest, AES-256-GCM for integration credentials, and row-level isolation per account. Core infrastructure runs on SOC 2 Type II providers (Supabase, Stripe, Cloudflare, Railway). OAuth tokens and API keys are encrypted at the application layer before being written to the database.
For cookies, marketing analytics, third-party processors, data residency, and GDPR rights, see sparkvox.io/help/cookies-and-analytics and sparkvox.io/privacy.