Privacy Commitment
Privacy Policy
Last Updated: September 4, 2026
•
SparkTrail Privacy Standard
At Sparktrail, we take your privacy seriously. This Privacy Policy outlines what information we collect, how we protect it, and the strict limits of our access to your data.
Zero Data Selling Guarantee: Your private sparks, notes, and workspace
data are never read, sold, or used to train machine learning models.
1 Information We Collect
We collect only the minimum necessary information required to run and secure Sparktrail:
- Account Information: Your email address, date joined, and password hash (encrypted via Django's default cryptographic hashing).
- Profile Metadata: Optional display name, custom avatar image, preferences, or avatar emoji.
- Workspace Data: Your Sparks, custom categories (including color selections), tags, and Markdown notes.
- Security PIN: If enabled, a cryptographically salted, PBKDF2-hashed 4-digit PIN. Your raw PIN is never stored or transmitted to our servers in plaintext.
- Billing Information: Payment and subscription processing is handled entirely by our third-party processor, Stripe. Sparktrail never stores or has access to your full credit card number or billing credentials.
2 How Your Data is Protected
- Data in Transit: All connections between your device and Sparktrail's servers are encrypted using Transport Layer Security (TLS 1.2 or greater / HTTPS).
- Data at Rest: User-generated content and database tables are encrypted at rest using industry-standard AES-256 encryption.
- Network Integrity: Public endpoints are shielded behind firewalls and Cloudflare proxies.
3 Clear Disclosure on Encryption and Server Access
- Encryption Model: Sparktrail encrypts your data at rest on our secure cloud servers (hosted via Linode in Newark and cached in Sydney).
- Developer Access Policy: To support critical features like our multi-operator search parsing engine, server-side PDF generating tools, and dynamic dashboards, Sparktrail's keys are managed on the server. However, our internal developer policy dictates that personnel will only ever access your workspace data for the express purpose of troubleshooting problems or recovering content at your request. Your private notes are never read, sold, or used to train machine learning models.
4 Data Location and Regional Caching
- Primary Server: Your primary data is stored securely in a MySQL database housed on our primary server in Newark, USA.
- Edge Caching: To deliver instant loading speeds for our Oceania and Asia-Pacific users, we utilize a secure regional edge node in Sydney, Australia. This node temporarily caches note lists and categories in a local Redis memory cache. This cache is fully isolated, encrypted, and automatically flushed or invalidated in real-time as you modify your notes.
5 Data Portability, Deletion, & Deactivation
- Self-Serve Export: You can export all of your data at any time in CSV or Markdown format from your profile settings.
- Account Deletion: You can request or perform account deletion. Upon deletion, your user profile, Sparks, categories, and tags are permanently purged from our active MySQL database tables, and any associated Redis caches are instantly cleared.
Your privacy is built into the architecture
Read our complete Terms of Service or create your account today.