Privacy Policy

Our privacy policy and how we use your data

Last updated: August 8, 2026

How We Treat Your Content

Your queries, uploads, and generated reports are encrypted in transit and at rest, are never used to train AI models, and are never sold. Access is limited to authorized personnel, is logged, and happens only where support, security, or a legal obligation requires it.

We build Sparlo for R&D teams and patent practitioners working on confidential material. Rather than claim your content is invisible to us, we state the controls that govern it, so you can verify them instead of trusting them.

How Your Data Flows

Here is exactly what happens when you use Sparlo:

  • Encrypted everywhere: Your data is encrypted in transit (TLS 1.3) and at rest (AES-256).
  • Access-controlled and logged: Your queries and generated reports are stored in your account. Staff access requires a documented operational reason, is limited to authorized personnel, and is logged.
  • Processed via third-party AI: Your queries are sent to a third-party AI API provider for processing. The results come back to your account.
  • Not used for AI training: We use a commercial API tier under terms that prohibit the provider from training on customer content. This is their contractual commitment, not just our policy.
  • Not sold or shared: Your data is never sold to advertisers, data brokers, or any other third parties.

Your IP Stays Yours

We make no claims on anything you submit or anything we generate for you.

  • No ownership claims: Your content and generated solutions belong entirely to you.
  • Isolated processing: Your queries are processed in isolation. Nothing crosses between accounts.
  • Full deletion: Request deletion anytime. We permanently remove your content, on the timeline set out under Data Retention below.

What We Can Access

Routine operations use:

  • Your email address and subscription status.
  • Anonymized usage statistics (page views, feature usage).
  • Technical logs for debugging (timestamped events, not content).

Your queries, prompts, uploaded documents, and generated reports are not part of routine operations. Authorized personnel can reach them only to investigate a support request, diagnose a failure, protect the security of the Service, or comply with a legal obligation. That access requires justification and approval, is limited to what the task requires, and is audit-logged.

We never see your payment details. Stripe handles card data directly, and we do not receive or store card numbers.

Security

  • Infrastructure: Hosted on SOC 2 Type II certified cloud providers.
  • Access controls: Strict authentication and authorization at every level.
  • Regular audits: Security testing and vulnerability scanning.

Third-Party Services

We rely on third-party services to operate Sparlo:

  • AI processing: Your queries are processed by a third-party AI API provider. We use their commercial tier, whose terms contractually prohibit training on customer content.
  • Authentication: Account login handled by Supabase Auth.
  • Payments: Payment processing handled by Stripe. We never see your card details.
  • Analytics: PostHog for usage analytics (opt-in only, privacy-focused). PostHog Privacy Policy.

Sparlo IP

Sparlo IP is used by patent practitioners on client material, so a few specifics apply:

  • Your uploads are not training data: The documents you upload and the questions you ask are not used to train or fine-tune any model, ours or our AI provider's.
  • Public documents come from public records: Analyses of issued and published patents retrieve those documents from public sources by patent number. Your unpublished drafts and disclosures are not sent to search providers.
  • Account isolation: IP analyses are pinned to the account that created them. They are not visible to teammates or to other firms, and nothing leaves your account unless you create a share link.
  • Analytical assistance only: Sparlo is not a law firm and does not provide legal advice. Using Sparlo IP does not create an attorney-client relationship with Sparlo and does not change your own professional obligations.

The full confidentiality architecture and the subprocessor list are at sparloip.com/subprocessors.

What We Collect

Account information

Email, authentication credentials, and basic profile info from social logins.

Usage data

Pages visited, features used, and timestamps. This helps us improve the product.

Content you submit

Your queries, research topics, and uploaded documents are processed to generate analyses. This data stays in your account.

Payment

Handled entirely by Stripe. We never see or store card numbers.

What We Do Not Do

  • Sell your data to anyone.
  • Share your data with advertisers or data brokers.
  • Share data between customers.
  • Train or fine-tune any model on your content, or let our AI provider do so (their commercial terms prohibit it).
  • Access your content for anything other than operating and supporting the Service for you, or complying with the law.

Data Retention

  • Active accounts: Data retained while active.
  • Deletion: Permanently removed within 30 days of account deletion.
  • Legal holds: May retain longer if required by law.

Your Rights

You can:

  • Access a copy of your data.
  • Correct inaccurate information.
  • Delete your data and account.
  • Export your data.
  • Opt out of marketing.

Contact privacy@sparlo.ai to exercise these rights.

International Transfers

Data is processed in the United States. We maintain appropriate safeguards for international transfers.

Policy Changes

We may update this policy. Material changes will be posted here and emailed to you. Continued use after changes means acceptance.

Contact

This site uses cookies to improve your experience.