Privacy Policy
Last updated: August 2026
sprkly ("we", "us", "our") is built for creators who want complete control of their content and data. This policy explains exactly what we collect, why, and how long we keep it.
1. Your Media Files
Here is what happens when you upload an image or video:
- Your file is saved in the form you sent it. We do not resize it, re-encode it, or lower its quality.
- We do not remove EXIF data from photos. A photo can carry location, device and timestamp info. If you do not want that stored, strip it before you upload. Your phone or photo app can do this.
- Some platforms need a set format. Instagram and TikTok need JPEG, for example. When that happens we make a converted copy for that post. Your file stays as it is, and the copy is deleted at the same time as the file.
- Your files are reached through signed links our app controls. They are not public and they are not listed anywhere.
- You can delete any file from your dashboard at any time.
Files are stored in Cloudflare R2 object storage.
2. Media Retention & Expiry
Your files are kept according to your plan:
| Plan | Media Retention |
|---|---|
| Trial | 180 days after upload |
| Starter | 60 days after upload |
| Pro | 180 days after upload |
Expired files are deleted daily by an automated cleanup job. You can also delete any file manually via the dashboard at any time.
3. Account Data
We store the following account information to operate the service:
- Email address and display name (from your OAuth provider)
- Profile picture URL (served from your OAuth provider's CDN)
- Connected social platform handles and OAuth access tokens and refresh tokens, encrypted at rest before storage
- Scheduled post captions and target platforms
- Referral codes and reward history
We do not sell, rent, or share your personal data with third parties for advertising purposes.
4. Data Protection and Security
We use administrative, technical, and organizational safeguards designed to protect personal information and sensitive data used to provide sprkly.
- Encryption in transit: sprkly is served over HTTPS/TLS to protect data transmitted between your browser and our service.
- Encryption at rest: OAuth access tokens and refresh tokens for connected platforms, including Google/YouTube, are encrypted before storage using AES-256-GCM. Tokens are decrypted only when needed to connect, refresh, publish, delete, or verify content on your behalf.
- Secret management: API keys, OAuth client secrets, signing secrets, and token-encryption keys are stored separately from application code in protected environment secrets and are not shipped in client-side application bundles.
- Least-privilege access: Access to production systems and stored user data is restricted to authorized personnel and service processes that need access to operate, secure, debug, or support the service.
- Media protections: Your files are stored in Cloudflare R2 and reached only through signed links our app controls. Those links are time limited and are not listed anywhere public. Note that we do not strip EXIF data from photos. See section 1.
- Monitoring and incident response: We monitor service health and errors, investigate suspected unauthorized access, and will notify affected users or authorities when legally required.
5. Google API and YouTube Data
If you connect a YouTube channel, sprkly requests only the Google OAuth scopes needed for YouTube scheduling and publishing, such as YouTube upload and YouTube read-only channel scopes. We use this data to authenticate your channel, display connected-channel information, upload scheduled videos or Shorts, refresh expired access tokens, and record publishing results.
We do not sell Google user data, use it for advertising, or transfer it except as needed to provide sprkly's user-facing features, comply with law, prevent abuse, or protect the service. You can disconnect your YouTube account or delete your sprkly account to revoke sprkly's stored access, and you can also revoke access from your Google Account permissions page.
sprkly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Third-Party Services
- Cloudflare R2 and D1: file storage and database.
- Stripe: payment processing. We only store the Stripe Payment Intent ID; your card details are never on our servers.
- OAuth providers (Google and others): used for sign-in. We receive only the scopes you explicitly grant.
7. Account Deletion & Data Portability
You can delete your account at any time from Settings → Account. This permanently removes:
- Your account record and all associated data
- All media files (optimised versions and thumbnails) from Cloudflare R2
- All scheduled posts, referral records, and credit purchase history
Deletion is irreversible and is completed within 48 hours. Stripe records are subject to Stripe's own retention policies for financial compliance purposes.
To export a copy of your data before deleting, email [email protected].
8. Cookies & Analytics
We use a single session cookie for authentication (HttpOnly, Secure, SameSite=Lax). We do not use third-party tracking cookies or behavioural advertising scripts.
Basic anonymised usage metrics (page views, error rates) are collected via Cloudflare Analytics, which does not use cookies and does not track individuals across sites.
9. Contact
Questions about this policy or your data? Email [email protected]. We respond within 5 business days.