SPARKIT

Legal

Privacy

Effective July 14, 2026

This is a draft pending review by counsel before public launch. Questions: info@sparkit.science.

This Privacy Policy describes how SPARKIT ("we," "us") handles personal information collected through the SPARKIT API and the sparkit.science website.

1. Information we collect

Account information. When you sign up, we collect your email address and a hashed password.

API credentials. We mint API keys on request and store only their hashes; the plaintext key is shown to you exactly once.

Billing data. When you start a paid plan, we collect your Stripe customer ID, subscription state, and invoice history. Stripe, not SPARKIT, handles your card details directly.

Research queries and results. We store the questions you submit, the structured Markdown reports we return, and metadata about each job (model, tools used, runtime, token count) for billing and quality purposes.

Usage logs. We retain request logs (request ID, endpoint, status code, timestamps, IP address, User-Agent) for security, abuse prevention, and debugging.

Model and search processing. To answer a question, we send the question and relevant context to our model providers. The agent may send derived search terms, URLs, publication identifiers, or other lookup values to search and scientific-data providers. We do not intentionally send your account password, API key, or payment-card details to those providers.

Cookies and website analytics. The dashboard at app.sparkit.science uses one essential session cookie (sparkit_session) for authentication. Marketing pages use Vercel Web Analytics, which records aggregate page-view information without third-party cookies. We do not use Google Analytics or advertising cookies.

2. How we use it

  • Provide and operate the API and dashboard
  • Bill you and prevent fraud
  • Detect abuse and enforce rate limits
  • Improve the service and debug issues
  • Communicate service-affecting changes
  • Comply with legal obligations

We do not sell your data. We do not use your research queries or returned reports to train models, and we do not opt customer content into provider model-training programs. Model providers may retain API traffic for security and abuse monitoring under their API terms and any account-level data controls available to SPARKIT.

3. Service providers and external data sources

We rely on the following providers to operate the service. Model providers receive questions and relevant context for inference. Search and scientific-data providers generally receive search terms, URLs, publication identifiers, or database lookup values derived from the question.

ProviderPurpose
StripePayment processing, subscriptions, and invoices
ModalAPI and research-agent compute
NeonPostgres database hosting
VercelWebsite hosting and aggregate, cookie-free Web Analytics
AnthropicPrimary model inference, query screening, and figure analysis
OpenAIFallback model inference when the primary model cannot complete a request
SentryError monitoring and performance diagnostics with customer payload scrubbing
Exa and TavilyWeb and literature search using terms derived from a research question
Semantic Scholar, NCBI/PubMed, PubChem, UniProt, AlphaFold DB, ClinicalTrials.gov, UCSC Genome Browser, and UnpaywallScientific literature, metadata, and public-database retrieval

Each provider operates under its own privacy policy and contractual obligations.

4. Data retention

  • Account information is retained while your account is active. You may request deletion by emailing the address below. We verify the request and address active subscription or payment obligations before deleting account-owned operational records.
  • Completed, failed, and cancelled research jobs, including their stored questions, reports, errors, trace events, and share links, are automatically deleted 365 days after the job reaches its terminal state. Running and queued jobs are not deleted by this schedule.
  • Security audit events are automatically deleted after 90 days. These events contain request metadata and may contain an opaque customer identifier, but not the research question or report body.
  • When an account is deleted, SPARKIT copies the minimum subscription, credit, usage, and referral ledger facts needed for accounting into a separate billing archive. That archive may include the account email and Stripe customer ID, never includes research questions or reports, and is automatically deleted seven years after account deletion.
  • Stripe retains payment and invoice records under its own retention obligations.
  • Database backups, when enabled by the hosting provider, may retain deleted records until the applicable backup expires or is overwritten.
  • Infrastructure, model-provider, search-provider, and error-monitoring retention is governed by the applicable provider terms and SPARKIT's configured data controls. Sentry events are scrubbed of request bodies, cookies, query strings, arbitrary extra context, and stack-frame local variables before transmission.

5. Your rights

You may at any time:

  • Request a copy of your data
  • Request deletion of your account and data, subject to legal retention
  • Update your account email or password
  • Schedule subscription cancellation at the end of your current 12-month commitment term

Email info@sparkit.science to make a request.

6. Children

The service is not directed to anyone under 13 (or 16 in jurisdictions that require it). We do not knowingly collect data from children.

7. International transfers

We operate primarily in the United States. By using SPARKIT, you consent to processing in the U.S. and other jurisdictions where our subprocessors operate.

8. Changes

We may update this policy. Material changes will be announced on sparkit.science/blog or by email. The effective date above always reflects the current version.

9. Contact

Questions, requests, or concerns: info@sparkit.science.