Privacy Policy

Last updated: 13 July 2026 Applies to spark-text.com & sparktext.app

Key points

  • We don’t store your screenshots. When you upload a chat screenshot it is sent to OpenAI to extract the text, then discarded. The image itself is never saved to our database.
  • We keep your recent conversation context for 60 days. To coach you well, SparkText stores the extracted text of your recent conversations, the replies it generates, and its analyses. Everything older than 60 days is automatically and permanently deleted. Coach never remembers anything beyond that window.
  • You control what we remember long-term. Items you explicitly save — facts, preferences, wins — stay in your Match Memory until you delete them.
  • We never sell your data, and we never use your conversations to train AI models.
  • We use a small number of trusted providers. OpenAI processes conversation content; Stripe handles payments; Supabase stores your account data; Google handles optional sign-in.
  • You have real rights over your data. Access, correct, export, or delete it at any time.
  • We’re based in the Netherlands. The Autoriteit Persoonsgegevens is your supervisory authority if you’re in the EU.
  • SparkText is for adults only (18+).

1. About this policy

This Privacy Policy explains how SparkText (“SparkText”, “we”, “us”, “our”) collects, uses, stores and shares your personal data when you use the marketing website at www.spark-text.com and the web application at sparktext.app.

We are the data controller for the personal data described here. Where we use third-party services to process data on our behalf, those parties act as data processors or sub-processors.

We follow the EU General Data Protection Regulation (GDPR) and the UK GDPR, and we aim to respect the privacy rights of users in the United States and other regions.

2. Definitions

Term Meaning
Personal data Any information relating to an identified or identifiable person.
Processing Anything done with personal data — collecting, storing, using, sharing, deleting.
Data controller The party that decides why and how personal data is processed (that’s us).
Data processor A party that processes data on our behalf, under our instructions.
Sub-processor A third party engaged by a data processor to help with processing.
Legal basis The GDPR-recognised reason that makes our processing lawful.
Match Memory In-app feature that lets you explicitly save facts, preferences or wins about a match.
Voice profile A short description of your writing style, derived from samples of your own messages (Spark Pro only).

3. Data we collect

We collect personal data in three ways: directly from you, automatically when you use the service, and from third-party sign-in providers.

3.1 Account & identity data

  • Email address — to identify your account and send service communications.
  • Password — hashed and stored securely by Supabase. We never see your plaintext password.
  • Name and profile picture — if you sign in with Google. We request only openid, email and profile. We do not access Gmail, Google Drive or any other Google service.

3.2 Profile, personalisation & subscription data

We maintain a user profile containing your plan (free, plus or pro), plan status and current period end date, and a Stripe customer ID used to link your account to your billing record. We do not store credit card numbers or full payment details — those live exclusively with Stripe.

We also store the answers you provide during onboarding, used solely to personalise your coaching:

  • Your name, age, gender and location, and optionally education and occupation
  • Your interests, hobbies, skills and favourite food
  • Who you typically text (women, men or both)
  • Your dating intent, communication style, persona and boundaries
  • Where you find dating conversations hardest
  • Your emoji preference and the language you usually text in

3.3 Chat content & screenshots

This section is especially important. Please read it.

When you use SparkText’s coaching features:

  • Screenshots you upload are converted to JPEG in memory on our server and sent to OpenAI’s API, which extracts a text transcript and layout metadata. We never save the raw screenshot.
  • The extracted transcript is stored in your account for up to 60 days. Coach uses it for context across a conversation — remembering what was already said, tracking momentum, and producing Match Insights.
  • Conversation content you paste is treated exactly like an extracted transcript.
  • Coaching output is stored for up to 60 days: the replies Coach generates, your edits of them, and its analyses of a conversation (including Match Insights and, on Spark Pro, Advanced Coaching).
  • The language of a conversation is detected automatically and stored on that match, so we can tell you when SparkText’s English-first coaching may be less accurate.
  • Server logs may capture request metadata such as timestamps and endpoint paths. We do not intentionally log message content in application logs.

The 60-day window

Everything above is deleted automatically 60 days after it is created, by a scheduled job that runs every day. This is a hard limit, not a target: Coach cannot use conversation content older than 60 days because it no longer exists in our systems.

Voice matching (Spark Pro only)

If you are on Spark Pro, SparkText builds a voice profile so suggested replies sound like you rather than generic. To do this we store short excerpts of your own writing:

  • Messages you sent, taken from the “You” side of English-language screenshots you upload (maximum 5 per upload)
  • Replies you edited or copied
  • Any sample you chose to paste during onboarding

From these we derive a short description of your writing style — typical length, emoji use, punctuation, humour, directness. This constitutes profiling under Art. 4(4) GDPR. It is used solely to style your suggested replies, produces no legal or similarly significant effects, and is never used to evaluate you as a person. Voice samples follow the same 60-day deletion window, and you can clear your voice data at any time.

What is stored until you delete it

These are not subject to the 60-day window, because you chose to save them:

Save action What gets stored
“Save as fact” A specific piece of information you mark as a fact about your match
“Save as preference” A preference you note about your match
“Save as win” A positive moment or success you choose to record

4. How we use your data

4.1 Providing the service

  • Authenticate you and manage your sessions.
  • Deliver suggested replies and coaching guidance based on the content you share.
  • Maintain up to 60 days of conversation context so Coach can follow a conversation over time and generate Match Insights.
  • Build a voice profile (Spark Pro) so replies match your writing style.
  • Save your Match Memory items when you choose to save them.
  • Manage your subscription and grant access to paid features.
Legal basis: Performance of a contract (Art. 6(1)(b) GDPR).

4.2 Payment processing

  • Create and manage your Stripe customer record.
  • Process subscription payments in USD or GBP.
  • Handle subscription lifecycle events via Stripe webhooks.
Legal basis: Performance of a contract (Art. 6(1)(b)) and compliance with a legal obligation (Art. 6(1)(c)) for accounting records.

4.3 Security & fraud prevention

  • Detect and prevent unauthorised access or abuse.
  • Monitor for unusual or suspicious activity, including usage limits.
Legal basis: Legitimate interests (Art. 6(1)(f)) — protecting the service and its users. We have balanced these against your rights and consider them proportionate.

4.4 Service improvement & debugging

  • Analyse error logs and aggregate usage patterns to fix bugs and improve the product.
  • We do not use your chat content or messages to train AI models.
Legal basis: Legitimate interests (Art. 6(1)(f)) — improving reliability and quality.

4.5 Legal & compliance

  • Comply with applicable laws, court orders or requests from competent authorities.
  • Establish, exercise or defend legal claims.
Legal basis: Legal obligation (Art. 6(1)(c)) or legitimate interests (Art. 6(1)(f)).

4.6 Transactional communications

  • Send account, password reset and billing notification emails.
  • We do not currently send marketing emails. If we introduce them, we will ask for your consent first.
Legal basis: Performance of a contract (Art. 6(1)(b)); consent (Art. 6(1)(a)) for any future marketing.

5. How we share your data

We do not sell your personal data. We share it only with the providers below, who process it on our behalf under contractual obligations to protect it.

5.1 OpenAI — conversation processing

  • What is shared: Base64-encoded JPEG data of screenshots you upload; the extracted or pasted conversation text; the saved Match Memory items and onboarding preferences relevant to a request; and, on Spark Pro, short excerpts of your own writing used for voice matching.
  • Why: To extract chat transcripts, generate suggested replies, analyse conversations and derive your voice profile.
  • How it works: Data is transmitted over HTTPS to OpenAI’s API. Conversation text is sent each time you request a reply or an analysis.
  • Storage by OpenAI: We treat OpenAI as a sub-processor under a Data Processing Agreement. Content submitted via the API is not used to train OpenAI’s models.
  • Data transfer: OpenAI’s infrastructure may sit outside the EEA. Transfers are governed by Standard Contractual Clauses or equivalent safeguards.

OpenAI privacy policy

5.2 Stripe — payments

  • What is shared: Your email address and billing country. Card data is entered directly into Stripe’s secure form and never touches our servers.
  • Why: To process subscription payments and manage billing lifecycle events.
  • Data transfer: Stripe Inc. is US-based. Transfers are covered by SCCs and Stripe’s compliance frameworks.

Stripe privacy policy

5.3 Supabase — database & authentication

  • What is shared: All data stored in our database (account info, subscription metadata, conversation context, Match Memory) and authentication credentials.
  • Why: Supabase provides our hosted Postgres database and authentication infrastructure.
  • Data location: We use an EU region where available. Any processing outside the EEA is covered by Supabase’s DPA and applicable SCCs.

Supabase privacy policy

5.4 Google — optional sign-in

  • What is shared: If you use “Sign in with Google”, Google provides your name, email address and profile picture URL via an OpenID Connect token.
  • Scopes requested: openid, email and profile only.
  • Why: To authenticate you without requiring a password.

Google privacy policy

6. Data retention

We keep your data only as long as needed. Conversation-derived content is deleted automatically after 60 days by a scheduled daily job.

Data category How long we keep it
Account information While your account is active. Deleted within 30 days of an account deletion request.
Onboarding & personalisation data Same as account information.
Subscription & billing metadata 7 years from the transaction date, to meet Dutch and EU accounting obligations — retained even after account deletion.
Stripe customer ID Alongside billing records, for the same 7-year period.
Uploaded screenshots Never stored. Processed in memory only.
Extracted transcripts & pasted conversations Up to 60 days, then permanently deleted.
Generated replies, edits & conversation analyses Up to 60 days, then permanently deleted.
Voice samples & derived voice profile (Pro) Up to 60 days, then permanently deleted. Clearable at any time.
Match Memory items Until you delete them.
Match records (name, setup, avatar) Until you delete the match or your account.
Technical / server logs Up to 30 days, unless required for an active security investigation.
Analytics data Per the analytics provider’s own retention settings.

7. International data transfers

SparkText is based in the Netherlands. Some providers process data outside the European Economic Area, including in the United States. Where that happens we rely on appropriate safeguards: Standard Contractual Clauses adopted by the European Commission, adequacy decisions where they apply, and the UK’s International Data Transfer Agreement for UK transfers.

  • OpenAI: SCC-based DPA or equivalent.
  • Stripe: SCC-based DPA; certified under applicable frameworks.
  • Supabase: SCC-based DPA; EU region selected where possible.
  • Google (sign-in): SCC-based DPA.

If you have questions about a specific transfer mechanism, contact us using the details in section 13.

8. Your rights

If you are in the EU or UK you have the rights below. We respond to verified requests within one month, extendable by two further months for complex requests.

8.1 Summary of your rights

  • Access (Art. 15) — request a copy of the personal data we hold about you.
  • Rectification (Art. 16) — ask us to correct inaccurate data or complete incomplete data.
  • Erasure (Art. 17) — ask us to delete your personal data. We comply unless we have a legal obligation to retain it, such as financial records.
  • Restriction (Art. 18) — ask us to pause processing in certain circumstances.
  • Portability (Art. 20) — receive the data you provided in a structured, machine-readable format.
  • Object (Art. 21) — object to processing based on legitimate interests at any time.
  • Withdraw consent (Art. 7(3)) — where processing relies on consent, withdraw it at any time without affecting prior lawful processing.
  • Automated decision-making (Art. 22) — SparkText does not make decisions based solely on automated processing that produce legal or similarly significant effects. Voice matching is profiling used only to style suggested replies.

8.2 How to exercise your rights

  • In the app: edit your details in Profile and Settings; delete individual Match Memory items; delete a match and its stored context.
  • Voice data (Pro): clear your stored writing samples and derived voice profile from Settings.
  • By email: support@spark-text.com for access, export, correction or full account deletion.

We may ask you to verify your identity before acting on a request.

8.3 Complaints

We would always prefer the chance to resolve things with you directly first. You also have the right to complain to a supervisory authority:

  • Netherlands — Autoriteit Persoonsgegevens: autoriteitpersoonsgegevens.nl
  • United Kingdom — Information Commissioner’s Office: ico.org.uk
  • Other EU member states — your local supervisory authority.

9. Cookies & tracking

SparkText uses cookies and similar technologies. Non-essential tools are blocked until you give consent through our cookie banner.

9.1 Essential cookies

Required for SparkText to work; these cannot be turned off.

  • Session / auth token — set by Supabase Auth to keep you signed in.
  • CSRF protection tokens — to prevent cross-site request forgery.

9.2 Analytics & marketing cookies

Plausible Analytics (requires Statistics consent)

Plausible helps us understand which pages are visited and where traffic comes from. It is privacy-first: no tracking cookies, no device fingerprinting, no sharing with advertising networks — anonymous aggregate statistics only.

  • Data collected: page URL, referrer, browser type, country, device type. No personal identifiers.
  • Cookies set: none. Data location: EU.
  • Plausible privacy policy

Meta Pixel (requires Marketing consent)

We use the Meta Pixel to measure whether advertising on Facebook and Instagram leads to visits. This data may be shared with Meta Platforms, Inc.

  • Cookies set: _fbp (browser identifier, 90 days), _fbc (click identifier, session).
  • Data collected: page views, browser and device identifiers, referral URL.
  • Data location: United States, governed by Meta’s SCCs.
  • Meta privacy policy

The Meta Pixel does not load unless you accept Marketing cookies.

9.3 Cookie banner

We use Cookiebot as our consent management platform, with three categories: Necessary (always active), Statistics (opt-in) and Marketing (opt-in). All non-essential scripts are auto-blocked until you choose. You can change your preferences at any time via the cookie link in the footer; withdrawing consent stops non-essential tracking immediately and does not affect prior lawful processing. Consent records expire after 12 months.

Cookiebot privacy policy

10. Children’s privacy

SparkText is intended for adults aged 18 and over. We do not knowingly provide the service to, or collect personal data from, anyone under that age. If you are a parent or guardian and believe your child has created an account, contact us at support@spark-text.com and we will promptly delete the account and associated data.

11. Security

  • All traffic between your browser and SparkText is encrypted with HTTPS/TLS.
  • Passwords are stored as salted hashes — we never store or transmit plaintext passwords.
  • Database access is protected by row-level security, so users can only reach their own data.
  • Access to production systems is restricted to authorised personnel on a least-privilege basis.
  • Our infrastructure provider applies encryption at rest.
  • API keys and secrets are stored in environment variables, never in code.

Important: no system is completely secure. While we apply industry-standard practices, we cannot guarantee absolute security. If you suspect unauthorised access to your account, contact us immediately and change your password.

12. Changes to this policy

We may update this policy from time to time. When we do, we update the “Last updated” date above. For material changes we will notify you by email or with a prominent in-app notice at least 14 days before the change takes effect. Continued use after the effective date means you accept the updated policy. Older versions are available on request.

Material change — July 2026. We clarified how conversation content is stored. A previous version of this policy stated that extracted transcripts were not stored. In fact, transcripts and coaching output are retained for up to 60 days to provide conversation context and Insights, and are then deleted automatically. We also introduced voice matching for Spark Pro. No conversation data has ever been sold, shared for advertising, or used to train AI models.

13. Contact us

Business name SparkText
Legal form Eenmanszaak (sole proprietorship), Netherlands
KvK number 42000479
VAT number NL005424236B12
Registered address Salamander 69, 1187 BS Amstelveen, Netherlands
Support email support@spark-text.com
Website www.spark-text.com
Steered by Coach
Built for momentum