Legal

Privacy Notice

Last updated: May 2026

1. Who we are

Spamrisk LLC, trading as IdentitySpark ("we", "us"), is the data controller responsible for personal data processed through this service. For privacy questions: privacy@identityspark.app.

2. Data we collect

  • Account data: email, name (if provided), authentication identifiers (password hash or Google OAuth ID).
  • Generated content: the inputs you submit (industry, tone, references, notes) and the brand systems we generate for you.
  • Usage data: session telemetry, feature usage, IP address, browser/device identifiers, error logs.
  • Support communications: messages you send us.
  • Payment data: processed by Stripe. We receive transaction status, plan, and a customer reference — never your card details.

3. How we use it

  • To create and operate your account (legal basis: contract).
  • To generate brand systems via AI providers (contract).
  • To prevent fraud, abuse, and secure the service (legitimate interest).
  • To improve the product and debug issues (legitimate interest).
  • To respond to support inquiries (contract / legitimate interest).
  • To send transactional emails (contract). Marketing emails only with consent.
  • To comply with legal obligations.

4. Who we share with

  • Stripe: payment processing, subscription management, invoicing, and tax calculation.
  • Hosting & infrastructure: Lovable Cloud (Supabase, Cloudflare) for hosting our application and database.
  • AI providers: Google (Gemini) and OpenAI process your prompts to generate outputs. Prompts may be transient or retained briefly per their policies.
  • Authentication: Google OAuth (only if you sign in via Google).
  • Authorities: where required by law.
  • Professional advisors: legal, accounting (where strictly necessary).

5. International transfers

Our infrastructure may process data outside the EEA/UK. Where we transfer personal data internationally, we rely on appropriate safeguards (adequacy decisions or standard contractual clauses).

6. Retention

We retain account data for as long as your account is active and for a reasonable period afterwards to comply with legal obligations and resolve disputes. Generated brand systems are retained while your account is active and deleted on request. Logs are retained for up to 12 months.

7. Your rights

You have the right to access, rectify, erase, restrict, or port your personal data, to object to processing, and to withdraw consent. To exercise any right, contact privacy@identityspark.app. EEA/UK users have the right to lodge a complaint with their data protection authority. We respond within 30 days.

8. Security

We use industry-standard technical and organizational measures including encryption in transit and at rest, access controls, and audit logging. No system is 100% secure; we will notify you of material breaches as required by law.

9. Cookies

We use essential cookies for authentication and session management. We do not use marketing cookies. Some sub-processors (e.g. Stripe checkout) may set their own cookies during checkout — see Stripe's privacy notice.

10. Changes

We will update this notice as needed. Material changes will be communicated by email or in-app.