Privacy Policy
Sparcd turns one goal into one small task a day. This policy describes every category of data the app holds, why it holds it, and how to get it out or delete it. Export and deletion are buttons in the app, not requests you have to email us about.
1. Who is responsible
Sparcd is operated by Maybecoded (India). For anything in this policy, including any right below that is not already a button in the app, write to sparcd@maybecoded.com.
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Account | Email address, password hash, or a Google/Apple sign-in identifier; time zone; the policy version you accepted | To create your account, sign you in, and show times in your own day |
| Goal content | The goal you type, its description, your answers to the clarifying questions, and the plan generated from them | This is the product; without it there is nothing to plan |
| Task activity | Tasks, completions, skips, misses, snoozes, and the evidence you attach (a confirmation, checklist, measurement, reflection, link, photo, or timer) | To show progress and to repair the plan when a day does not go to plan |
| Execution model | A compact, inspectable summary of observed patterns — for example which task sizes you finish, and which times of day you tend to act | To size the next task realistically. It is a record of behaviour, not a psychological assessment |
| Notifications | A device push token, your reminder preferences, and whether a reminder was sent, opened, actioned, or dismissed | To send at most three prompts a day and to stop sending ones you ignore |
| Purchases | Whether a subscription entitlement is active, from RevenueCat | To unlock paid features. We never receive your card details |
We do not collect advertising identifiers, contacts, precise location, or health-app data, and the app contains no third-party analytics or tracking SDKs.
3. How AI is used
Sparcd sends your goal and task content to Google Gemini to compile and repair plans and to write your weekly review. There is no chatbot and nothing you write is used to answer other people.
If personalization is on, a short summary of your execution model is included so the plan fits how you actually work. We never send your email address, your name, your credentials, or your payment status to the model provider.
Sparcd currently reaches Gemini through Google's Generative Language API under Google's terms for that service. If you need a contractual commitment that your content is excluded from model training, do not put confidential material into a goal; write to us and we will tell you the current processing terms in force.
You can turn personalization off at any time in Settings → Privacy & data. Turning it off stops profile context reaching the model and deletes the derived memory already held.
4. Why we are allowed to hold it
Where the UK/EU GDPR applies, we rely on contract for everything needed to run your account and produce your plan; on consent for optional personalization and for push notifications, each withdrawable in the app; and on legitimate interests for keeping the service secure and preventing abuse.
5. Who else processes it
| Processor | Purpose |
|---|---|
| Amazon Web Services (us-east-1) | Application hosting, queues, secrets |
| MongoDB Atlas | Application database |
| Google (Gemini) | Plan compilation, plan repair, weekly review |
| Firebase Cloud Messaging | Push notification delivery |
| RevenueCat | Subscription entitlement state |
| Loops | Waitlist email only, for people who joined from the website |
| Google Analytics | Website only. It is not present in the app |
Data is stored in the United States. Where transfers out of the UK/EEA require a safeguard, they rely on the Standard Contractual Clauses operated by these providers.
6. How long it is kept
Your account data is kept until you delete your account. Deleting a single goal removes that goal, its tasks, its queued AI work, its event history, its weekly reviews, and the memory derived from it.
Deleting your account removes all of the above across every goal. Deletion is immediate and cannot be undone; we do not keep a grace-period copy. Backups, if present, are covered by the retention schedule of the providers above.
7. Your rights, and where the buttons are
- Export everything — Settings → Privacy & data. You get one JSON file containing your account, goals, tasks, events, weekly reviews, and execution model.
- Delete everything — Settings → Privacy & data. Immediate and irreversible.
- Turn off personalization — Settings → Privacy & data. Also deletes derived memory.
- Turn off notifications — Settings, or your device's system settings.
- Correct your details — Settings → Profile.
Rights of access, rectification, erasure, portability, restriction, and objection are exercised through those controls. If a control does not cover what you need, or you want to complain about how we handled a request, write to sparcd@maybecoded.com. If you are in the UK/EEA you may also complain to your local supervisory authority.
8. Children
Sparcd is not directed at children and is not intended for anyone under 13. We do not knowingly collect data from children under 13. If you believe a child has created an account, write to sparcd@maybecoded.com and we will delete it.
9. Security
Traffic is encrypted in transit. Passwords are stored only as Argon2 hashes. Access to production data is limited to the operator of the service. No system is perfectly secure, and we will tell affected users about a breach that puts their data at risk.
10. Changes
The version at the top of this page changes when this policy changes materially — new data, a new processor, or a new purpose. Your account records the version you accepted, and the app asks you to review a material change before you continue.