Legal

Privacy Policy

How Sproutkit collects and uses personal data. We aim to collect as little as possible.

Last updated: 15 June 2026

1. The data we hold about you (the buyer)

  • Account / payment: name, email, billing country and a payment token. Held by our payment processor (Lemon Squeezy) on our behalf, and by us only as a record of your licence.
  • Licence key: a unique string we generate so the App can verify your purchase.
  • Support emails: when you email us, we keep the thread to provide help.

2. The data on your machine

Leads you discover, sites you generate, chat history and API keys are stored locally on your computer in an SQLite database. API keys are encrypted using your operating system's secure keychain. We have no access to any of this.

3. CMS data (your customers' websites)

When you "Set up CMS" for a paying customer of yours, the following data is stored on our servers (currently Supabase, EU region):

  • Site slug, business name and the customer's auth email/password (hashed)
  • The site's content (text, photos, theme settings)
  • The customer's edits and publish history

We are a data processor for this content; you (the App user) are the controller. We do not sell, share or train AI on this data.

4. Anonymous telemetry

The App does not send analytics, tracking pixels or telemetry to us. Network requests originate from your machine to the third-party APIs you've configured (Anthropic, Google, Vercel, etc.).

5. Third parties we use

  • Lemon Squeezy — payment processing & receipts
  • Supabase — CMS content storage (EU region)
  • Vercel — hosting for sproutkit.app and any sites you deploy through your own Vercel token
  • Cloudflare — DNS & email forwarding for hello@sproutkit.app

Each of these has their own privacy policies. We share only what is strictly necessary for them to provide their service.

6. Your rights (GDPR)

If you're in the UK or EU, you have the right to access, correct, export or delete personal data we hold about you. Email hello@sproutkit.app and we will respond within 30 days.

7. Data retention

We keep purchase records for 6 years (UK tax requirement). CMS content remains for as long as you maintain the site; if you delete a site or cancel, content is purged within 30 days. Support emails are kept for 2 years.

8. Cookies

sproutkit.app uses one essential session cookie for login on the customer dashboard. We do not use any analytics, advertising or tracking cookies.

9. Contact

Privacy questions: hello@sproutkit.app.

Questions? Email hello@sproutkit.app