Back to home

Privacy policy

Last updated September 30, 2026

Privacy Policy

This is a starting draft, not legal advice. It lists what the app actually collects, based on how it is built, so that a lawyer has something factual to review rather than boilerplate. Every bracketed item has to be filled in, and the whole document reviewed, before it is published.

Last updated: [DATE]

1. Who is responsible

[COMPANY LEGAL NAME], [REGISTERED ADDRESS], [COUNTRY], is the controller of the personal data described here. Contact: [CONTACT EMAIL]. [If you have a Data Protection Officer or an EU/UK representative, name them here.]

2. What we collect

You give us:

  • Account — email address, password (stored only as a hash), and, if you sign in with Google, the name and email Google gives us.
  • Profile — display name, photo, language, timezone, and any profiles you create for yourself.
  • Content — decks, cards, notes, images you upload, and anything you type into the AI study assistant.
  • Support — what you write in a support message, and the app version and platform at the time.

The app records as you use it:

  • Study activity — which cards you studied, when, and how you answered; streaks, Stars earned and spent, badges, and items acquired.
  • Device and delivery — a notification token so we can send push messages, and the app version and platform.
  • Diagnostics — crash reports and error traces, including the screen you were on and recent failed requests. These carry your account's internal id, never your email or your content.
  • Analytics — events such as opening a screen, starting a study session or acquiring a deck, with the subject and language of what was involved.

3. Why, and on what legal basis

What Why Basis (GDPR)
Account and profile To give you an account and keep it secure Performance of a contract
Content and study activity To run the product — scheduling reviews, showing progress Performance of a contract
AI features To generate cards, images and answers you ask for Performance of a contract
Diagnostics To find and fix faults Legitimate interests
Analytics To understand which features are used and improve them Legitimate interests [or consent, depending on your market]
Advertising To show ads in the free tier Consent where required
Support To answer you Performance of a contract / legitimate interests
Email about the service To tell you about your account Performance of a contract
Marketing email To tell you about new features Consent — withdraw any time

4. Who we share it with

We do not sell your personal data. We use these processors, each for the purpose named:

  • Google Firebase — push notifications, analytics, crash reporting and remote configuration.
  • Google Sign-In — if you choose to sign in with Google.
  • Sentry — error and performance monitoring.
  • Google AdMob — advertising in the free tier.
  • [AI PROVIDER(S)] — generating cards, explanations and images from what you ask for. Your prompt and the deck context are sent for that purpose.
  • [EMAIL PROVIDER] — sending account and support email.
  • [OBJECT STORAGE / CDN PROVIDER] — storing and serving images.
  • [PAYMENT / APP STORE] — handling purchases. We never see your card details.

We also disclose data where the law requires it, or to establish or defend legal claims.

5. Where it is stored

Our servers are in [REGION]. Some processors above operate outside your country; where data leaves the UK or EEA we rely on [TRANSFER MECHANISM — e.g. Standard Contractual Clauses].

6. How long we keep it

  • Your account and content — while the account exists.
  • After you delete your account — suspended immediately, erased permanently after [GRACE PERIOD] days. Signing in again before then cancels the deletion. After erasure we keep only what the law requires us to.
  • Support conversations — [PERIOD], so we can follow up on an issue.
  • Diagnostics and analytics — [PERIOD], in the providers' retention settings.
  • Records that you accepted these documents — for as long as the account exists and [PERIOD] afterwards, because they are the evidence of your agreement.

7. Your rights

Where GDPR or similar law applies, you can ask us to: give you a copy of your data; correct it; delete it; restrict or object to how we use it; or send it to another provider. You can withdraw consent at any time — for marketing email, through the link in the message or in Settings.

Write to [CONTACT EMAIL] and we will answer within [PERIOD — one month under GDPR]. You can also complain to your data protection authority ([AUTHORITY]).

Some of this is built into the app: you can edit your profile at any time, and delete your whole account from Privacy & Security.

8. Children

Spark is not intended for children under [MINIMUM AGE]. We do not knowingly collect data from them, and will delete an account we learn belongs to one. If you believe a child has given us data, write to [CONTACT EMAIL].

9. Security

Passwords are stored hashed, traffic is encrypted in transit, and access to production data is limited to the people who need it and recorded. No system is perfectly secure; if a breach affects you, we will tell you as the law requires.

10. Changes

When this policy changes materially we publish a new version and ask you to accept it. The version you accepted, and when, are recorded on your account.

11. Contact

[COMPANY LEGAL NAME], [REGISTERED ADDRESS] — [CONTACT EMAIL].