sparktoprompt

Privacy policy

Last updated 3 August 2026

This policy explains what personal data sparktoprompt collects, why, and the rights you have over it. We keep the data we hold to the minimum needed to run the service.

Who is responsible for your data

The data controller for sparktoprompt (sparktoprompt.com) is Marek Matan, a sole proprietorship (jednoosobowa działalność gospodarcza) registered in Poland. Registered address: ul. Kazimierza Jeżewskiego 5D/43, 02-796 Warszawa, Poland. NIP: 5223268452. REGON: 526180874.

For any privacy question, or to exercise the rights below, contact us at [email protected].

What we collect

  • Account data — the email address you sign up with, and authentication data managed by our hosting provider. We do not store your password; it is handled by Supabase Auth.
  • Your content — the journeys you create (screens, popups, transitions, and any notes you add) and your activity history within the app.
  • Billing data — if you buy a paid plan, your payment details are collected directly by our payment provider (Lemon Squeezy). We receive only the record of your purchase and subscription status, never your full card details.
  • Technical data — standard server logs (such as your IP address and request metadata) that our hosting providers process to serve the site securely.

Why we use it, and our legal basis

  • To provide the service — creating your account, saving your journeys, and letting you export them (legal basis: performance of our contract with you).
  • To take payment for paid plans and keep the tax records the law requires (legal basis: contract and legal obligation).
  • To keep the service secure and working — preventing abuse and diagnosing problems (legal basis: our legitimate interest in a safe, reliable service).

We do not sell your personal data, and we do not use it for advertising.

Who else processes your data

We use a small number of trusted providers (sub-processors) to run sparktoprompt. Each processes data only on our instructions:

  • Supabase — Authentication and database hosting. Your account email, your journeys, and your activity history. Privacy policy.
  • Cloudflare — Website hosting and content delivery (Cloudflare Pages). Standard request metadata (e.g. IP address) needed to serve the site securely. Privacy policy.
  • Lemon Squeezy — Payment processing and Merchant of Record (paid plans). Your billing details and purchase history, collected directly by Lemon Squeezy when you buy a paid plan. Privacy policy.
  • Zoho — Email hosting for our support and privacy inbox (Zoho Mail, EU data centre). Whatever you send us when you get in touch — your email address, and the contents of your message. Privacy policy.
  • Resend — Delivery of our automated account emails (sign-up confirmation, password reset). Your email address, and the contents of those automated messages, in order to deliver them. Privacy policy.

International transfers

Some of our providers operate outside the European Economic Area. Where data is transferred outside the EEA, it is protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses, as described in each provider's privacy policy above.

How long we keep it

We keep your account data and content for as long as your account exists. When you delete your account, your journeys, activity history, and account metadata are permanently deleted. Records we are legally required to keep — chiefly invoices and tax records for purchases — are retained for the period required by law (typically five years) and are held by our payment provider.

Your rights, and how to exercise them

Under the GDPR you have the right to access, correct, delete, export, restrict, and object to the processing of your personal data.

You can exercise the two most common rights yourself, right now, from your Settings page:

  • Export my data downloads a complete ZIP of your journeys, activity, and account metadata as JSON (the right to data portability).
  • Delete my account permanently erases your account and everything in it (the right to erasure).

For any other request, email [email protected]. You also have the right to lodge a complaint with a supervisory authority — in Poland, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO).

Cookies and analytics

We use only the essential storage needed to keep you signed in. We do not use advertising or cross-site tracking cookies, so there is no consent banner to click through.

For basic traffic statistics we use Cloudflare Web Analytics. It is cookieless: it sets no cookies, does not track you across other websites, and does not build a profile of you. It counts page views and aggregate visitor numbers so we can understand how the site is used. Because it stores nothing on your device and collects no data that identifies you personally, it needs no consent banner. We do not use any advertising or behavioural-tracking analytics.

To understand how the product itself is used — for example how many people create a journey, export a specification, or upgrade — we record a small set of high-level actions in our own database (the same activity history shown on your dashboard and included in your data export). This is first-party and cookieless: it sets no cookies, is never shared with a third-party analytics service, and does not track you across other websites. We look at it in aggregate; it is tied to your account, not to any cross-site tracking profile.

Security

Access to your data is protected at the database level so that each account can reach only its own rows. Connections are encrypted in transit. No system is perfectly secure, but we design to keep the data we hold to a minimum and to give you direct control over deleting it.

Children

sparktoprompt is not directed at children, and is intended for users aged 16 or older.

Changes to this policy

We may update this policy as the product evolves. When we make a material change we will update the “Last updated” date above, and where appropriate notify you by email.