Privacy Policy
Last updated: August 2026
SparkVox ("we", "our", "us") is committed to protecting your privacy. This policy explains what data we collect, how we use it, who we share it with, and your rights. It covers the SparkVox application (app.sparkvox.io) and the marketing website (sparkvox.io).
1. Data We Collect and Store
We collect the following categories of data when you create an account, use the Service, or visit the marketing website.
Account information
- Email address and display name
- Avatar image (if uploaded)
Onboarding answers
Your source material type and professional perspective. These are stored permanently and used to personalise every AI post generation for as long as your account is active. Editable under Settings > Project Presets.
Brief Sparky context
Optional free-text context you provide during onboarding or under Settings > Brief Sparky (up to 4,000 characters). It tells Sparky who you are, who you help, and what topics you cover before your voice profile builds from transcripts. Included in generation prompts and deleted when you delete your account.
Voice profile data
When you process podcast or transcript projects, we extract a structured voice profile from your content and store it on your account. This profile (tone, vocabulary patterns, sentence structure) is included in prompts sent to Anthropic (Claude) when generating posts. It deepens with every project transcript you process. It is deleted when you delete your account.
Voice learning from your review workflow
When you edit a project post before confirming in the schedule modal, we may extract style corrections from the difference between Sparky's draft and your final text. Those corrections can feed back into your voice profile through an async learning loop so future drafts sound closer to how you write. We do not scrape LinkedIn to build your voice profile.
Referral data
- Who referred you (portal referrer ID) and whether a referral bonus was credited to your SparkVox account
- If you are a referrer: commissions, Stripe Connect onboarding, and payout history are stored in the separate referral portal at refer.sparkvox.io when you use that product
Billing
- Stripe customer ID, payment method presence (card type and last four digits only), and your in-app credit balance
- We do not store full card numbers. All payment card data is handled by Stripe.
Integration credentials
- Fireflies, Fathom, Granola: API key, stored encrypted at rest
- LinkedIn, Google Drive, Dropbox, OneDrive, Google Meet, Zoom, HubSpot, Pipedrive, Attio: OAuth access and refresh tokens, stored encrypted at rest
- LinkedIn (at connect): we may store your profile name and headline to label publish identities in the app
Google user data (Drive & Meet)
When you connect Google Drive, SparkVox accesses your Google account email and only the Drive files you explicitly select via the Google Picker (drive.file). When you connect Google Meet, SparkVox accesses your email, Meet conference metadata (meetings.space.readonly), Meet-related Drive files (drive.meet.readonly), and transcript Google Docs (documents.readonly) solely to import meeting transcripts you choose into SparkVox.
We use this data only to provide import, transcription, and AI-assisted post-generation features you request. We do not use Google user data for advertising, credit/lending decisions, or sale to data brokers. We do not use Google Workspace data to train generalized machine-learning models. Transcript content may be processed by Anthropic (Claude) under our commercial agreement; Anthropic does not use API inputs to train models.
Google user data is encrypted in transit (TLS) and at rest (AES-256-GCM for OAuth tokens). You may disconnect integrations or delete your account at any time; disconnection removes stored OAuth tokens, and account deletion removes imported transcript and project data from SparkVox.
Limited Use: The use of raw or derived user data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Project and source data
For URL-based projects (for example YouTube), we store public metadata on the project row (title, description, tags, duration) to improve transcription spelling and post generation. We do not store the video file itself unless you upload or import audio separately.
Generated posts
Post content, original input (text or voice transcript), scheduling status, and attached or AI-generated images (stored on Cloudflare R2). Posts are retained for the lifetime of your account. You can delete individual projects from the dashboard; deleting a project also removes its associated media from our storage.
In-app support chat (Sparky)
When you use Help → Chat, your messages and Sparky's replies are stored in our database so conversations persist across sessions. Message content and your account context (billing, projects, integrations) are sent to Anthropic (Claude) to generate replies. Support chat history is deleted when you delete your account.
Marketing chat (sparkvox.io)
Sparky on the marketing site keeps a short offline copy in your browser (localStorage, up to 7 days) so the widget can reopen quickly. When you open the widget, we also create or resume a server-side conversation record (page path, attribution, message count). Full message text is stored on SparkVox servers when you send your first message so we can follow up, improve support, and let our team reply when you request a human. Anonymous marketing chat transcripts are retained for up to 90 days unless linked to a lead email or account. Legal basis: legitimate interest (Art. 6(1)(f)) for session metadata and support; consent (Art. 6(1)(a)) when you submit the optional email follow-up form. Request deletion via [email protected].
Conversation / chat history (browser)
The Help drawer may also cache recent UI state locally in your browser. Server-side support chat history is separate from this and is described above.
Device identifier (signup only)
At signup, we generate a browser fingerprint using FingerprintJS (open source, MIT-licensed v5) for fraud and abuse prevention. This computation happens entirely in your browser - no fingerprint data is sent to FingerprintJS or any third party. A hash of the result is stored server-side for 24 hours to enforce signup rate limits, after which it is no longer actively queried (records are not automatically purged but contain no personally identifiable information beyond the hash).
Operational / deduplication records
We maintain server-side logs of processed Stripe webhook event IDs to prevent duplicate processing. These records contain only system-generated identifiers and timestamps - no personal data.
Product analytics
When you use the app, we capture usage events (for example page views, project creation, integration actions) via PostHog. Identified profiles are created only after you sign in. Events are associated with your user ID and are used to improve the product - not for advertising.
Marketing website analytics (sparkvox.io)
On the marketing website, after you accept the cookie consent banner, we may load PostHog and Google Analytics 4. These tools may collect page views, referrer, device and browser metadata, and approximate location derived from IP (for example cookies such as _ga). Declining cookies keeps PostHog and GA4 off. Details are in our Cookie Policy.
Meta advertising measurement (sparkvox.io and app.sparkvox.io)
We load the Meta Pixel (Facebook Pixel) on the marketing website and in the app to measure page views, signup, trial starts, and ad attribution for SparkVox campaigns on Meta platforms. It may set Meta cookies (for example _fbp) on .sparkvox.io. This is not controlled by the marketing cookie banner. Marketing-site tracking covers browsing until you click through to signup; signup and card-on-file (trial start) events fire in the app.
When you complete signup or a purchase in the app, our servers also send that event to Meta's Conversions API. This is a server-to-server call. We send a one-way SHA-256 hash of your email address (Meta cannot reverse the hash back into your email), plus your IP address and browser user agent, and any _fbp/_fbc identifiers we stored from your visit. We do not send your name, transcripts, posts, or any other account content to Meta through this channel.
Engage inbox - commenter and reactor data (Pro, Accelerate, and Scale)
When you use Engage (/engage), SparkVox syncs LinkedIn comments and reactions on posts you published through SparkVox. For each comment or reaction we store the LinkedIn actor URN, display name, headline, avatar URL, comment text, timestamps, and whether the comment is from you. This data powers the inbox, People rankings, content seeds, analytics coaching, and optional Engage notifications. Commenter data is third-party personal data - we process it on contract (Art. 6(1)(b)) to deliver the feature you opted into. You can export your account data (including synced comments) from Settings; account deletion removes your copies. We do not sell commenter data or use it for advertising.
Community benchmarks (opt-in)
Under Settings > Profile > Community benchmarks, you can opt in to share anonymized posting-performance data - off by default. When enabled, SparkVox may include your posting activity, stripped of anything that identifies you, in community benchmarks and coaching insights (for example cadence norms such as "founders like you post Mondays at 5pm"). Aggregated insights may also appear in reports shared outside SparkVox. You can turn this off at any time from the same settings panel.
2. How We Use Your Data
Each use below states the GDPR legal basis in parentheses.
- Operate the Service: authenticate you, store your posts, run background jobs (transcription, publish, voice learning), and manage your credit balance - contract (Art. 6(1)(b))
- Personalise AI generation: your source material, professional perspective, voice profile, and onboarding context are included in prompts sent to Anthropic (Claude) so generated posts match your style and audience - contract (Art. 6(1)(b))
- Ingest podcast and video projects: for YouTube URLs, we fetch public metadata and try native captions first; if captions are unavailable or diarization is required, audio is sent to Gladia for transcription. Uploaded or imported audio is processed the same way. Audio is not retained by SparkVox after the transcript is saved - contract (Art. 6(1)(b))
- Import from cloud storage (Pro): if you connect Google Drive, Dropbox, or OneDrive, you can import MP3/SRT/TXT files (and native Google Docs on Google Drive, exported to text) or attach media to posts. We download or export only the files you select and copy attachments to Cloudflare R2 for publishing - contract (Art. 6(1)(b))
- Create projects from notetakers: if you connect Fireflies, Fathom, or Granola, you provide an API key stored encrypted at rest; if you connect Google Meet or Zoom, you authorize OAuth access. In each case we import only the meeting recordings and transcripts you select to start SparkVox projects - contract (Art. 6(1)(b))
- Generate AI images: if you request an image alongside a post, we send the post text to Anthropic (Claude Sonnet) to draft a hook-anchored visual scene brief, then send that brief to fal.ai (Flux) to generate the image. If the brief step fails, a heuristic prompt that includes post text is used instead. The resulting image is stored on Cloudflare R2 and attached to your post - contract (Art. 6(1)(b))
- Provide in-app support: when you use Help → Chat, your messages and relevant account context are sent to Anthropic (Claude) to generate replies; conversations are stored in our database - contract (Art. 6(1)(b))
- Process payments: charge your saved card and maintain your credit balance via Stripe - contract (Art. 6(1)(b))
- Send transactional emails: account verification, billing notifications, and referral confirmations via Resend - contract (Art. 6(1)(b))
- Send marketing emails: product updates and onboarding sequences via Kit.com - consent (Art. 6(1)(a)); you opt in at signup or via a marketing preference. Transactional emails are separate and do not require marketing consent.
- Publish posts: push approved posts to LinkedIn when connected - contract (Art. 6(1)(b))
- Engage inbox (Pro, Accelerate, and Scale): sync LinkedIn comments and reactions on your published posts, store commenter display data for inbox and reply workflows, and extract content seeds - contract (Art. 6(1)(b))
- Community benchmarks (opt-in): include anonymized posting-performance data in peer benchmarks and coaching insights - consent (Art. 6(1)(a)); off by default under Settings > Profile > Community benchmarks
- Measure product usage: capture usage events via PostHog to understand how the Service is used and improve it - legitimate interest (Art. 6(1)(f)); we balance this against your privacy by using identified_only profiles, no advertising, and no sale of data
- Analyze the marketing website: capture page views, UTM attribution, and aggregate traffic on sparkvox.io via PostHog and Google Analytics 4 - consent (Art. 6(1)(a)); those scripts load only after you accept the cookie banner
- Measure advertising performance (Meta): load the Meta Pixel on sparkvox.io and app.sparkvox.io, and send signup and purchase events to Meta's Conversions API (hashed email, IP address, user agent, and ad-click identifiers when present) - legitimate interest (Art. 6(1)(f)); the Pixel is not gated by the marketing cookie banner
- Export to your CRM (Accelerate and Scale, opt-in): if you connect HubSpot, Pipedrive, or Attio, push LinkedIn-native fields (and engagement custom fields on Pipedrive) for the Engage People rows you select - no email or company data included on HubSpot or Attio; no email addresses on Pipedrive - contract (Art. 6(1)(b)); export is manual and only for rows you choose
- Prevent fraud and abuse: rate-limit signups using browser fingerprinting at the point of account creation - legitimate interest (Art. 6(1)(f)); fingerprint is computed locally in your browser and only a hash is stored server-side
3. Third-Party Processors
We share data with the following processors, strictly for the purposes described.
SparkVox accesses user-selected files only for cloud storage integrations. OAuth tokens and API keys are encrypted at rest in our database.
| Service | Purpose | Data shared |
|---|---|---|
| Anthropic (Claude) | AI post generation, voice learning, on-demand image visual briefs, Sparky chat (in-app + marketing) | Post input text, onboarding answers, voice profile, transcript excerpts; post text for image scene briefs; support chat messages and account context when you use Help → Chat |
| Attio | CRM export from Engage → People (Accelerate and Scale, if connected) | OAuth tokens (encrypted); LinkedIn name, headline, and profile URL for rows you select - no email or company data |
| Cloudflare | Object storage (R2) and CDN for media | Post images, audio uploads, bug-report attachments |
| Dropbox | Cloud import and post media attachment (Pro, if connected) | OAuth tokens (encrypted); files you select in-app |
| FingerprintJS (OSS) | Signup fraud prevention | Browser attributes, computed locally only - no data transmitted to FingerprintJS |
| Fireflies | Notetaker project creation (if connected) | API key (encrypted); meeting recordings and transcripts you authorize for import |
| Fathom | Notetaker project creation (if connected) | API key (encrypted); meeting recordings and transcripts you authorize for import |
| Granola | Notetaker project creation (if connected) | API key (encrypted); meeting notes and transcripts you authorize for import |
| Gladia | Podcast / project transcription (when native captions are unavailable) | Audio URL (YouTube, upload, or direct link) |
| Google (Drive) | Cloud import and post media attachment (Pro, if connected) | OAuth tokens (encrypted); files you select via Google Picker |
| fal.ai (Flux) | AI image generation (optional) | Visual prompt (Sonnet hook-anchored brief or heuristic including post theme) |
| Google (Meet) | Notetaker project creation (if connected) | OAuth tokens (encrypted); meeting recordings and transcripts you authorize for import |
| Google (YouTube Data API) | YouTube URL metadata and native captions for project ingest | Video IDs and public metadata (title, description, tags, duration) |
| Google Analytics 4 | Aggregate traffic measurement (marketing website only) | Page views, referrer, device/browser metadata; only after cookie consent on sparkvox.io |
| HubSpot | CRM export from Engage → People (Accelerate and Scale, if connected) | OAuth tokens (encrypted); LinkedIn name, headline, and profile URL for rows you select - no email or company data |
| Pipedrive | CRM export from Engage → People (Accelerate and Scale, if connected) | OAuth tokens (encrypted); LinkedIn name, headline, profile URL, job title, and engagement custom fields for rows you select - no email addresses |
| Meta (Pixel and Conversions API) | Ad measurement and attribution on sparkvox.io and app.sparkvox.io; Conversions API on every app signup and purchase | Pixel (browser): page views, signup/trial events, browser/device metadata, ad-click identifiers. Conversions API (server): SHA-256-hashed email, IP address, user agent, and ad-click identifiers when present |
| Inngest | Background job processing (transcription, publish, voice learning) | Job identifiers, project IDs, publish metadata |
| Kit.com | Email communications and CRM | Email address, display name, onboarding fields (source material, perspective), payment-funnel fields (payment entry path, LinkedIn connected during onboarding, card on file), lifecycle metrics, LinkedIn URL, referral status |
| Post publishing; Engage comment/reaction sync (Pro, Accelerate, and Scale) | Post content, media URLs, profile/headline at connect, commenter names/headlines/avatars on your posts, OAuth tokens (encrypted) | |
| Microsoft (OneDrive) | Cloud import and post media attachment (Pro, if connected) | OAuth tokens (encrypted); files you select in-app |
| Netlify | Frontend hosting and serverless API functions | Request metadata (for example IP address and user agent) when you use the app |
| PostHog | Product analytics (in-app and website) | User ID, usage events; on sparkvox.io, anonymous visitor events only after cookie consent |
| Railway | Inngest background job execution (transcription, publish, voice learning, lifecycle jobs) | Job identifiers, project IDs, publish metadata; request metadata when Inngest invokes the worker |
| Resend | Transactional email delivery | Email address, display name |
| Stripe | Payments and billing | Email address, payment method, billing events |
| Zoom | Meeting project creation (if connected) | OAuth tokens (encrypted); cloud recordings and transcripts you authorize for import |
| Supabase | Database, authentication, edge functions | All account data |
We do not sell your personal data to any third party.
We may share visitor data with Meta via the Meta Pixel and Conversions API for ad measurement and attribution on sparkvox.io and app.sparkvox.io. When you accept cookies on sparkvox.io, we may also share aggregate traffic data with Google via GA4. This is not a sale of personal data. You can opt out of PostHog and GA4 by declining cookies or changing Cookie preferences in the site footer. To object to Meta ad measurement, email [email protected].
4. Data Residency and International Transfers
SparkVox is a US-based service. Most data is processed and stored in the United States. EU and UK users should be aware that data may be transferred outside the EEA.
Where personal data is transferred to a US processor, we rely on one of the following mechanisms:
- EU-US DPF: the processor is certified under the EU-US Data Privacy Framework (and UK Extension where applicable)
- SCC: Standard Contractual Clauses incorporated into the processor's DPA, used where DPF certification is not available
- N/A: no third-country transfer - processor is located in the EU/EEA
| Processor | Data location | Transfer mechanism | Notes |
|---|---|---|---|
| Anthropic (Claude) | US (storage); inference may be global | SCC | Not DPF-certified; SCCs in commercial DPA |
| Attio | United Kingdom | SCC | CRM export from Engage → People (Accelerate and Scale, if connected); LinkedIn-native fields only, no email or company data |
| Vendor-dependent | SCC | Post content and publishing metadata only when connected | |
| Cloudflare (R2) | Configurable; default US | EU-US DPF | Post images, audio uploads, bug-report attachments |
| Fireflies / Fathom / Granola | United States | SCC | API keys encrypted in SparkVox; recordings and transcripts you authorize for project import |
| Gladia | EU (France) | N/A | No third-country transfer; may use sub-processors under SCCs |
| fal.ai (Flux) | US | SCC | Visual prompts for on-demand image generation (Sonnet hook brief or heuristic) |
| Google (YouTube Data API) | US | EU-US DPF | Video metadata and caption text for ingest |
| Google Analytics 4 | United States (Google) | EU-US DPF | Marketing site traffic only; loaded after cookie consent |
| Meta (Pixel and Conversions API) | United States (Meta) | EU-US DPF | Pixel on sparkvox.io and app.sparkvox.io (not gated by marketing cookie banner). Conversions API on every app signup and purchase |
| HubSpot | United States | EU-US DPF | CRM export from Engage → People (Accelerate and Scale, if connected); LinkedIn-native fields only, no email or company data |
| Pipedrive | United States | EU-US DPF | CRM export from Engage → People (Accelerate and Scale, if connected); LinkedIn-native and engagement fields only, no email addresses |
| Google Drive / Dropbox / OneDrive | Vendor-dependent | EU-US DPF | User-selected files only; OAuth tokens encrypted in SparkVox (US, SCC) |
| Google (Meet) | United States | EU-US DPF | Meeting project import; OAuth tokens encrypted in SparkVox |
| Zoom | United States | SCC | Meeting project import; OAuth tokens encrypted in SparkVox |
| Inngest | United States | SCC | Background job payloads; handlers execute on Railway |
| Kit.com | United States | EU-US DPF | All sub-processors US-based |
| Netlify | US/EU edge | EU-US DPF | Request handling for the app and API functions |
| PostHog | United States (US cloud) | EU-US DPF | Product analytics; marketing site only after cookie consent |
| Railway | United States | EU-US DPF | Inngest function execution; job payloads in transit during processing |
| Resend | United States | EU-US DPF | Account data stored in US regardless of sending region |
| Stripe | Primarily US, globally distributed | EU-US DPF | |
| Supabase | Oregon, USA (us-west-2) | SCC | All account data and application records |
Media you attach from cloud storage is copied to Cloudflare R2 in our configured region. Your original files remain in your cloud account unless you delete them there separately.
5. Data Retention
| Data | Retained until |
|---|---|
| Account profile, onboarding answers | Account deletion |
| Billing record (card type, last 4, balance) | Account deletion |
| Browser-local UI cache (Help drawer, global search recents, per-channel analytics date range) | Cleared when you clear site data or delete your account |
| Community benchmarks opt-in preference and any anonymized posting data already aggregated | Preference: account deletion. Anonymized data already folded into aggregate benchmarks cannot be individually withdrawn, since it no longer identifies you |
| Cloud provider originals (Drive, Dropbox, OneDrive) | Remain in your cloud account; SparkVox does not delete them |
| Generated posts, transcripts, and project metadata | Account deletion, or earlier when you delete the parent project |
| In-app support chat history | Account deletion |
| Integration tokens (LinkedIn, Google Meet, Zoom, Drive, Dropbox, OneDrive) | Until you disconnect the integration, or account deletion |
| Integration API keys (Fireflies, Fathom, Granola) | Until you disconnect the integration, or account deletion |
| Notifications | Account deletion |
| Post images and uploaded audio (Cloudflare R2) | Account deletion, or earlier when you delete the parent project |
| Post suggestions | Account deletion |
| Product analytics events (PostHog) | Per PostHog project retention settings |
| Marketing website analytics (PostHog, Google Analytics 4) | Per each vendor's retention settings; scripts load only after cookie consent |
| Meta Pixel ad measurement events (sparkvox.io and app.sparkvox.io) | Per Meta's retention settings |
| Meta Conversions API delivery log (app.sparkvox.io) | Per Meta's retention settings; SparkVox itself only keeps a success/failure record, not the hashed data sent |
| HubSpot export records (Engage → People) | Account deletion, or when you disconnect HubSpot; exported contacts remain in your own HubSpot account |
| Pipedrive export records (Engage → People) | Account deletion, or when you disconnect Pipedrive; exported Persons and Organizations remain in your own Pipedrive account |
| Attio export records (Engage → People) | Account deletion, or when you disconnect Attio; exported people records remain in your own Attio workspace |
| Product referral bonus status (referred-by attribution on your SparkVox account) | Account deletion |
| Referrer portal data (commissions, Connect onboarding, payouts) when you use refer.sparkvox.io | Per referral portal retention policy; contact us to request deletion |
| Signup fingerprint hashes | Retained indefinitely (no personal data - hash and timestamp only) |
| Source audio (Gladia processing) | Never stored by SparkVox - discarded after transcription |
| Stripe dedup logs | Retained indefinitely (system identifiers and timestamps only) |
| UTM / referral attribution (sessionStorage) | Cleared when the browser session ends |
| Marketing Sparky chat transcripts (sparkvox.io) | Up to 90 days for anonymous threads, unless linked to a lead email or account; contact us to request removal |
| Voice profile, voice health trends (approval and edit rates), voice regression findings, and onboarding voice seed | Account deletion |
| Post analytics snapshots (impression time series per direct LinkedIn publish, used for decay curve learning) | Account deletion |
| Engage inbox - synced LinkedIn comments and reactions on your published posts (commenter display names, headlines, avatars, comment text) | Account deletion |
Account deletion is immediate and permanent - database records and associated Cloudflare R2 media (project audio, post images, bug-report attachments) are removed with no recovery possible. Active Stripe subscriptions are cancelled when applicable. You can delete your account from Settings → Profile, or by emailing [email protected].
Project deletion removes the project, its posts, and associated R2 media (audio and post images) for that project.
6. Cookies and Local Storage
We use browser storage for in-app UI state (for example Help drawer preferences, recent global search selections, and per-channel Post Analytics date-range preferences) and to persist marketing attribution parameters (utm_*, referral codes) in sessionStorage across page navigations during a session. These are strictly necessary for the Service to function and do not require consent.
App (app.sparkvox.io)
PostHog (product analytics): PostHog is initialised when the app loads. After you sign in, PostHog identifies your session and may set first-party cookies on .sparkvox.io (for example ph_phc_*) to distinguish sessions and attribute usage events to your account. We configure PostHog with person_profiles: "identified_only" - anonymous visitors are not profiled and no person record is created until you sign in. PostHog is used for product analytics only, not advertising.
Before sign-in (for example on the signup page), PostHog may still set session cookies and capture anonymous pageview events. We rely on legitimate interest (Art. 6(1)(f)) for this limited pre-login analytics on the app, balanced against the privacy impact (no person profiles, no advertising, first-party cookies only).
Meta Pixel (ad measurement): the Meta Pixel also runs in the app to record signup and trial-start events and set ad-attribution cookies on .sparkvox.io. See Section 1 for details.
In-app support chat messages are stored on our servers as described in Section 1.
Marketing website (sparkvox.io)
The marketing website uses a separate PostHog project from the app, plus Google Analytics 4 for aggregate traffic measurement. PostHog and GA4 load only after you accept via the cookie consent banner. Declining or dismissing the banner keeps them off. Use Cookie preferences in the site footer to change that choice at any time. The Meta Pixel runs separately and is not controlled by the banner.
See our Cookie Policy for a full breakdown of what we store in your browser and why.
7. Security
SparkVox aligns its security controls with SOC 2 Trust Services Criteria (Security). Core infrastructure vendors include SOC 2 Type II certified providers (Supabase, Stripe, Cloudflare, Railway).
- All data is transmitted over TLS
- The app frontend and API are hosted on Netlify; background jobs (Inngest) execute on Railway; user-uploaded media is stored on Cloudflare R2 and served via our CDN (media.sparkvox.io)
- OAuth tokens and API keys for third-party integrations are encrypted at the application layer using AES-256-GCM before being written to the database. A per-value random initialization vector (IV) and GCM authentication tag are stored alongside each ciphertext so that the plaintext can only be recovered using our server-side encryption key.
- Supabase also applies platform-level AES-256 encryption for all data at rest on disk and in backups. Row Level Security (RLS) policies ensure users can only access their own rows.
- Cloud storage integrations use provider OAuth with least-privilege scopes; SparkVox accesses only files you explicitly select in the picker
- Payment card data is never stored by SparkVox - it is handled entirely by Stripe
- Server-side operations use service credentials (for example Stripe secret keys) that never reach the browser
- Your data is never used to train models for other users
- No method of transmission over the internet is 100% secure, but we follow industry-standard practices to protect your data
8. Your Rights
Depending on your location (including GDPR and CCPA jurisdictions), you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Export your data in a portable format
- Delete your data, including your voice profile
- Restrict or object to specific processing
- Withdraw cookie consent for PostHog and Google Analytics 4 via Cookie preferences in the site footer (or decline the banner). This does not stop the Meta Pixel or Meta Conversions API described in Section 1 - email [email protected] to object to Meta ad measurement specifically.
To exercise any of these rights, email [email protected]. We aim to respond within 30 days (extendable to 90 days for complex requests, with notice). You can also delete your account directly from within the app (Settings → Profile), which triggers immediate hard-deletion of all your data. PostHog and GA4 stop loading when you decline cookies; that does not delete historical events already held by those vendors - contact us or the vendor if you need that removed. The Meta Pixel is not controlled by that banner choice.
9. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes by email or by posting a notice in the Service.
10. Contact
Privacy questions? Email [email protected].